For IT service providers, a certified Information SecurityagSystem (ISMS) according to ISO 27001 is more important than ever. Implementation not only presents challenges but also opens up new opportunities – for greater structure, security, and trust. In this articleag we look back on our own journey and openly share what we would do differently today.
At Netstream the introduction of our Information SecurityagSystem (ISMS) in 2022 was rather a rushed process. Nevertheless, we managed to implement the ISMS in just under three months. After our first recertification audit – which takes place every three years – we look back andagourselves: Would we do it the same way again today? Not quite.
Our initial expectations were anything but optimistic. When we first considered ISO 27001 certification, we anticipated costs in the six-figure range – and a project duration of one to two years. No wonder the topic was shelved for a while.
With increasing market demand and rising information security requirements, we finally decided to address the issue proactively. Our goal was clear: to implement ISO 27001 certification efficiently and sustainably – in a way that suits us as an SME.
Steps towards our ISMS setup: Implementation and insights
1. Assess your budget realistically
Frankly, we initially had no clear idea of the actual costs we would incur when implementing an ISMS. Previous estimates seemed far too high. Therefore, we opted for aagapproach: Instead of working with a fixed budget, we considered the fundamental value of taking the step towards ISO 27001 certification – and continuouslyagthis benchmark.
For many,ag a project without a fixed budget might seem daunting. But especially with a small team and short decision-making processes, this flexible framework helped us to invest strategically – without losing control.
2. Accept help
We knew from the start that it would be difficult without professional support. So we set out to find a consulting partner who understood our situation and could help us build an ISMS that suited us –ag, efficient and feasible in everydayag.
3. ISMS in the right dimension
We didn't want to create a system that looked good on paper but was practically unusable. Therefore, from the outset, we made sure our ISMS remainedag– without compromising our commitment to fulfilling the ISO 27001 requirements seriously and transparently.
4. Involve the team – don't just inform them
Don't make the mistake of simply throwing the decision to implement an ISMS over the fence. Ultimately, it's the employees who have to live and breathe the system.
Therefore, it was important for us to involve key people early on, rather than just informing them. We spoke openly about fears and reservations, but also incorporated ideas from the team and integrated them into the implementation.
5. Clarify tools and structure early on
Our first version of the ISMS was scattered across various tools and platforms: Word, Excel, Confluence and countless folders.
While specialized software is not strictly necessary, it can be extremely helpful, especially in areas such as riskagor policy management.
Today we rely on a central ISMS solution, but supplement it strategically with tools like Confluence and Jira – because they have proven their worth in our dailyag . What also helps: a clear and simple guideline for employees on where to find which content.
6. Define the scope of application consciously
What exactly is included in our ISMS? To be honest, at the beginning we didn't have a clear answer toag.
Today we know that a well-defined scope of application not only simplifies the documentation, but also the entire certification process. Back then, we approached it step by step.
7. Identify risks correctly – and don't get lost in them
Our first risk analysis was a cluttered Excel spreadsheet that regularly gave us headaches. We were often unsure ourselves what we were actually evaluating.
It quickly became clear: We need a solution that helps us to record risks in a structured and comprehensible way – while also maintaining the necessary overview.
Switching from Excel was more complex than expected, but it was worth it. Today we work with a specialized SaaS tool that supports us in both assessing and tracking risks.
8. Develop guidelines that can actually be lived by
A guideline is quickly written, but that doesn't automatically make it helpful.
We realized early on that it is crucial toagourselves about every policy: Is it truly relevant? Is it understandable? And above all: Can we implement it in everydayag ?
The danger is great of getting bogged down in details and ultimately creating a system that is formally correct, but nobody actually uses. Our goal has therefore always been: as much as necessary, as little as possible.
9. Document, document, document
A key, yet tedious aspect of the ISMS. If documentation isn't considered from the outset, it will come back to haunt you later. Auditors ultimately want to see evidence.
ISO 27001 doesn't prescribe how documentation must be done – and that's precisely where the opportunity lies. We've chosen a method that suits our workflow: Today, we rely on Jira, supplemented by Confluence, and document directly where we already work. This saves time and provides clarity.
10. Not everyone needs to know the Cryptographic Policy
One of the biggest misconceptions when implementing an ISMS is that everyone now needs to know everything. They don't. Instead of distributing entire collections of guidelines, we carefully considered: Who needs what knowledge? A well-placed piece of information is more effective than 40 pages of policy that nobody reads.
11. Audit without panic? Preparation helps.
During our first audit in early 2022, everything went wrong: pandemic, online audit, and half the team out sick. The audit was conducted via video call – with screen sharing, spontaneousag, and the expectation that all documents would be immediately accessible. While we had stored everything somewhere, finding specific pieces of evidence at that moment was… let'sagsay: challenging.
Today we know what helps: Compile all relevant evidence, policies, reports, and links beforehand – ideally sorted by standard chapter. This keeps your heart rate down, even when the camera is rolling.
12. After certification comes the next certification
Once you have the certificate in your hand, you might think: done. But in reality, the real work only begins afterwards.
Since our initial certification, we've completely overhauled our ISMS more than once – rethinking, reorganizing, and rebuilding it. Not for fun, but because we've realized: an ISMS has to fit the company, not the other way around.
We take a more relaxed view of it today: The ISMS is not a finished project, but a living part of our business. And if you approach it correctly, even a quite useful one.
Conclusion
Our entry into the world of information security was rather bumpy – with manyag, a few detours and some spontaneous decisions.
Today, three years later, we have an ISMS that suits us: livable, effective and continuously evolving.
What did we learn? That perfection shouldn't be the goal. An ISMS can grow, adapt, and even be rethought from time to time – the main thing is that it remains practical.
And yes: The investment has paid off. Not only because we are now certified, but because we better understand risks, have structured our processes more clearly – and the trust of our customers and partners has been strengthened.
For everyone facing this decision: Startag, stay flexible – and don't see the ISMS as a mandatory exercise, but as an opportunity to better position the company.






