Information security is on the agenda for many medium-sized companies due to ISO 27001 or NIS2. And external pressure is growing: customers want to know if their data is protected, insurance companies require proof, and management realizes that this topic can no longer be delegated. But even though the importance of information security is rarely questioned today, it often remains unclear what role it should actually play within the company.
Anyone who honestly asks themselves, "What is the state of information security in my company?" often encounters the same challenge. The topic sits with the IT department and stays there. As soon as the next audit is due, it is dragged out for everyone again.
The crux of the matter is not whether a company has an ISMS (Information Security Management System), but how information security is understood, organized, and practiced. Ultimately, that determines the real impact an ISMS can have.
In practice, there are many variations: small companies organize information security differently than large ones, and manufacturing companies have different priorities than service providers. The role of the information security officer also depends heavily on the maturity level, history, and corporate culture. Nevertheless, many approaches can be broken down into three basic models:
Here, information security is primarily understood as a necessary duty. The ISMS exists to get certificates on the wall, prepare for audits, and maintain policies for the next inspection. The system exists, but it doesn't live.
A typical sign of this is that information security exists separately from daily work. Policies are maintained because an audit is coming up, and risk analyses are created only because a standard requires it. Employees, and especially managers, often see information security as an annoying extra task rather than a necessity or a safeguard for their daily work.
The result: The potential of an ISMS remains untapped. Because if information security only becomes visible shortly before an audit, its impact ends as soon as the audit conversation is over.
Here, those involved have understood that an ISMS offers advantages for the company that go beyond mere compliance. The realization that information security serves not just for documentation, but for protection, is a real step forward!
However, problems arise when information security is held directly responsible for the security of the entire organization – and this responsibility lands solely with the IT department. After all, IT managers do not carry out most business processes themselves. Nevertheless, they are expected to assess risks that arise in departments where they have no direct insight.
This leads to unrealistic expectations: the IT department becomes overwhelmed, the departments feel controlled, and the desired impact fails to materialize. Instead of working together on secure processes, a divide emerges between IT managers and the rest of the staff. Yet even ISO 27001 establishes as a core requirement that the sole responsibility for implementing an ISMS must not be transferred entirely to IT.
In this model, information security management is understood as what it is: a management system that enables the organization to deal with information risks consciously. While the ISMS alone does not create security, it acts as the most important tool that makes security in the company possible in the first place. In this model, the responsibility for secure processes remains where they are carried out: in the departments. The role of the ISMS is to provide orientation, supply methods, create transparency, and enable improvements. The most important metric is then not "audit passed," but "security posture improved."
When a company views information security as a driving force for greater security, the next question immediately arises: Which management system best supports this role?
Management systems can be interpreted in very different ways. Some are merely collections of documents, while others are ambitious integration projects. Ideally, a management system should encompass the sum of all the rules a company follows when handling information. Here, too, we distinguish between three typical approaches:
The initial impulse in many companies to house information security in its own dedicated system is understandable. After all, quality management, data protection, risk management, and compliance all have their own structures, documents, and responsibilities.
While this may look neat and clearly defined at first glance, in practice it leads to the creation of information silos. The same processes are viewed from different angles without the insights ever converging. This weakens not only the effectiveness of the ISMS but also that of all other management systems. To truly understand the connections, you need the big picture, not just fragments.
To avoid scattered data silos, you need an integrated system. Quality management and information security management often look at the same workflows from different perspectives. ISO 9001 asks: How well does this process work? While ISO 27001 wants to know: How secure is the information within this process?
However, many integrated systems stop halfway. They bring technical topics together into one system but still form a parallel world to the organization. The structure follows an artificially created order rather than the lived reality. As a result, the documentation is integrated but ineffective. Employees cannot relate to it, and managers do not use it for steering the business.
An effective management system does not start with standards—it starts with the reality of the company. The foundation for this is formed by processes as central hubs where information is created, processed, shared, and stored. This is why processes are the ideal anchor for an ISMS.
When processes are at the center, different perspectives can be meaningfully connected. A process description then shows:
In this way, many individual facets combine to form a holistic picture. And this is exactly where impact is created: employees use the management system because it helps them in their daily work, and managers use it because it provides guidance. This is how information security fulfills its intended purpose as a central contribution to the company's stability.
Companies do not need to reinvent information security. But they must decide what impact they hope to achieve. This only happens when the ISMS enables the company to deal with information risks systematically—along the actual processes that people use to do their jobs.
Real impact is seen in everyday life—not in an audit. It happens when employees know which information in their process needs protection and when managers identify risks before they become incidents. If an organization is well-prepared for an emergency, even a cyberattack does not have to lead to a total shutdown.
What this requires is a new approach to information security management: empowerment instead of parallel documentation and IT control. Only with this understanding can an ISMS fulfill its purpose as the living set of rules by which a company handles its information.
The first step is an honest look at where your company currently stands. Ask yourself the following questions:
Looking to the future is just as important. Think about what role you want information security to play for you in the future. Do you view it...
Once you have found the answers to these questions, you are ready for the next step.
Sign in to get in touch with Carsten directly.
