# ISMS in the mid-market: build information security, prepare for ISO 27001 and TISAX

> An information security management system that fits your size: scope, risks, policies, evidence and the route to certification when customers require it.

URL: https://techport.ai/en/it-beratung/sicherheit-und-resilienz/isms-und-zertifizierung

---

1.  [IT Consulting](/en/it-beratung)/
2.  [Security and Resilience](/en/it-beratung/sicherheit-und-resilienz)/
3.  Building information security

[Security and Resilience](/en/it-beratung/sicherheit-und-resilienz)

# Building information security

By Redaktion techport.ai, IT-Beratung · Last updated on 21 August 2026

An information security management system sounds like a corporate structure with a dedicated officer and cabinets full of policies. In practice it comes down to something simple: knowing which information and systems are worth protecting, which risks exist, which measures work against them and whether they actually work.

In the mid-market the trigger is rarely your own conviction. It is usually customers demanding evidence, or statutory duties. Both lead to the same task, and that task is worthwhile regardless of the trigger.

## How you notice it

*   A customer requests a certificate or a completed questionnaire, and the answers have to be worked out first.
*   There are security measures but no system by which they were decided.
*   Policies exist but are years old and unknown in daily work.
*   Nobody checks whether the measures introduced still work.

## Why this happens

Security measures in the mid-market usually arise as reactions: to an incident, to a provider's recommendation, to a report in the press. Each is sensible on its own, but the common framework is missing that would show where gaps remain and where more is being done than necessary. Without that framework it is also impossible to establish whether the level of security is rising or only the number of tools.

## How we go about it

1.  **Set the scope and the assets.** We determine which areas, sites and processes are included and which information and systems are particularly worth protecting. A narrow, well implemented scope is worth more than a wide one on paper.
2.  **Assess the risks.** We record threats and weaknesses for those assets, assess them by likelihood and impact, and decide per risk whether it is reduced, transferred, avoided or knowingly accepted. That decision is made by management, not by IT.
3.  **Introduce measures and policies.** We implement the measures that follow from the risk assessment and write only the policies genuinely needed, in language that is understood on the shop floor.
4.  **Check effectiveness and improve.** We set up recurring reviews, internal and where necessary external, and make sure that incidents, review findings and changes in the company feed back into the risk assessment.

## What you gain

*   Answers to customer questionnaires in hours rather than weeks.
*   Security measures that follow from an assessment rather than from individual events.
*   A basis on which certification is possible when it is demanded.

## From our projects

The most common mistake is too wide a scope. Including the whole company at the first attempt produces documents rather than security and loses internal support after a few months. We recommend starting with the processes that interest customers or that are covered by law, and extending afterwards. The second recurring finding: the effort for the initial certification is overestimated and the effort for maintaining it is underestimated. A certificate is valid for three years with annual surveillance, and that annual work has to be planned from the start.

## Good to know

Several routes exist for mid-sized companies. Certification to ISO 27001 is internationally recognised and the one customers most often request. The German Federal Office for Information Security offers certification to ISO 27001 on the basis of IT-Grundschutz, which is more concrete in its requirements. For getting started there are staged approaches such as the basic protection level of IT-Grundschutz. In the automotive industry, manufacturers regularly require TISAX, an assessment and exchange mechanism based on the requirements of the German automotive industry association. Which route fits is decided less by content than by what your customers accept.

## Häufige Fragen

Do we need our own information security officer?

A named role yes, a dedicated post in most mid-sized companies no. What matters is that the person is independent enough to name risks even when they are inconvenient, and that they have direct access to management. In smaller companies the role is frequently filled externally and complemented by a contact person in house.

What does a certification cost?

The cost of the certifying body is usually the smaller part. The larger part is the internal work for building, documenting and implementing the measures, spread over six to twelve months. Solid figures are only possible once the scope has been set, because scope drives effort more than company size does.

## Let us talk about Building information security

In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.

[Arrange an initial call](/en/kontakt)[Our consulting](/en/so-funktionierts)

## Further reading

[Security and ResilienceNIS2 and cyber securityWhether your company falls under the new German BSI Act, which duties follow, how risk management, reporting and supply chain are implemented, and what applies personally to management.](/en/it-beratung/sicherheit-und-resilienz/nis2-und-cybersicherheit)[IT Governance and ComplianceIT obligations at a glanceWhich IT related obligations affect your company, who owns them, which evidence is needed and how a register of obligations gets you prepared for every audit.](/en/it-beratung/it-governance-und-recht/it-compliance)[Security and ResilienceTraining and awarenessHow awareness works instead of annoying: show real attack patterns, train short and often, build a reporting culture, involve managers and make the effect measurable.](/en/it-beratung/sicherheit-und-resilienz/awareness-und-schulung)[KnowledgeIT maturity checkKnow where your IT stands in ten minutes.](/en/it-beratung/reifegrad-check)[KnowledgeIT glossaryTerms from IT, software and security, briefly explained.](/en/it-beratung/glossar)

Back to the field [Security and Resilience](/en/it-beratung/sicherheit-und-resilienz)

## Sources

*   [ISO 27001 certification on the basis of IT-Grundschutz, BSI (in German)](https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Zertifizierung-und-Anerkennung/Zertifizierung-von-Managementsystemen/ISO-27001-Basis-IT-Grundschutz/iso-27001-basis-it-grundschutz_node.html)
*   [IT-Grundschutz, BSI (in German)](https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/IT-Grundschutz/it-grundschutz_node.html)
*   [TISAX, ENX Association](https://www.enx.com/en-US/TISAX/)

Rt

Written by

[Redaktion techport.ai](/ueber-uns), IT-Beratung

Mehr als 15 Jahre Erfahrung in IT-Projekten des Mittelstands, Auswahl und Einführung von Unternehmenssoftware, Aufbau von IT-Betrieb und Informationssicherheit in wachsenden Organisationen.

This page reflects the position at the date given and does not replace legal advice. For specific questions we work together with your legal advisers.

[More about us](/en/ueber-uns)

More from techport.ai

[

Software

Custom process software for mid-sized companies.

](/en/loesungen)[

HR consulting

People processes and the systems behind them.

](/en/hr-beratung)[

IT maturity check

Ten minutes to a clear position.

](/en/it-beratung/reifegrad-check)[

HR maturity check

24 statements, a result per field.

](/en/hr-beratung/reifegrad-check)[

Funding

BAFA grant plus more than 50 programmes for delivery.

](/en/foerderung)[

Process in practice

How workflows become reliable software.

](/en/sop-praxis)[

Data and AI

Analysis, forecasts and assistance systems.

](/en/daten-ki)[

About us

The people behind techport.ai.

](/en/ueber-uns)
