New: ISO 42001 and NIS2 Supply Chain available in the Compliance Tool.View standards and requirements →Careers
All customer stories
Construction & project development · ISO 27001

How VORM gained control of its information security.

ISO 27001 became a practical basis for clear responsibilities, demonstrable compliance and lasting improvement.

Customer StoryVORMBuilding & Project Development
01 · The challenge

The reason for change.

Within an organisation with several operating companies, projects and cooperation partners, documents and processes were initially separate. Clients increasingly asked for demonstrable information security, while the coherence and connection to ISO 27001 were still lacking.

02 · The approach

Software, structure and guidance.

De Compliance Afdeling started with the organization itself: objectives, working methods, client requirements and existing information. Risk analyses, policy documents and responsibilities were then set up. The Compliance Tool became the central place for policies, risk assessments, measures, tasks and evidence.

AnalysisCurrent situation and priorities.
SetupRisks, measures and ownership.
EmbeddingAudits, evidence and continuous improvement.
03 · The result

What changed in practice.

  • Processes and responsibilities are structured.
  • Information is less dependent on individual employees.
  • Audit preparation requires less searching and gives more certainty.
  • Compliance remains part of a continuous cycle.
We go into audits with much more certainty, because we know where everything is and who is responsible for it.Richard van Breugel · Coordinator ICT
Facing a similar challenge?

See how this can work for your organization.

We translate the chosen standard or obligation and your current method into a feasible approach.

No generic approach Clear ownership Lasting assurance
Interactive prototype