Abstract visualization of ISMS and BCMS: a continuous management cycle with resilience and recovery paths.

Governance, Risk & Compliance

ISMS, BCMS & Incident Readiness

ISO 27001/22301-aligned management systems, business impact analysis, BCM, emergency and crisis plans, exercises, audit readiness and evidence management - operationally resilient, not just audit-ready.

Overview

When it counts, what matters is operationally resilient structures, not just audit preparation. ENISA names business continuity, patching and testing as central implementation problems; ISO 22301 and DORA require resilient, tested continuity structures. We build management systems that hold when it counts - and produce the evidence along the way.

The framework is an ISMS aligned with ISO/IEC 27001: risk-based, with a clear Statement of Applicability, lived policies and an internal audit and improvement cycle. We set it up to serve as a shared basis for further duties - from NIS2 to DORA - rather than as an isolated certificate.

For continuity we add a BCMS per ISO 22301: based on a business impact analysis we determine critical processes, recovery objectives (RTO/RPO) and continuity strategies. This is complemented by emergency and crisis plans with clear roles, escalation and communication paths.

Incident readiness means being prepared before something happens. We design and support exercises - from tabletop to simulation - ensure audit-ready evidence management and feed lessons from real incidents back into the plans. This turns a management system into lived resilience.

We deliver each of these services in three stages: as an assessment (baseline and gap analysis), as program build and implementation (structures, measures, evidence) and as ongoing steering - optionally as an interim mandate, fractional lead, evidence office or exercise and audit office. You decide how much responsibility to outsource and where to build your own capacity.

Standards & norms

  • ISO/IEC 27001
  • ISO 22301
  • Business Impact Analysis (BIA)
  • DORA (Resilienztests)

Frequently asked questions

Why ISMS and BCMS together?

Because security and continuity are two sides of the same resilience. An ISMS protects information, a BCMS keeps critical processes running. NIS2 and DORA require both - integrated is more efficient than separate.

What is audit readiness and evidence management?

It means evidence is not scrambled together just before the audit but arises continuously, in a structured and traceable way. This saves effort and makes examinations predictable.

Do exercises really help?

Yes. ENISA names missing testing as a central implementation problem. Only exercises - from tabletop to simulation - reveal whether plans actually hold when it counts, and deliver concrete improvement points.