30.10.2025
Blog
Cyber Security

A systematic approach to information security: Why an ISMS is essential

In an age of growing cyber threats and complex digital interdependencies, information security has long since become a strategic factor for success. Data, IT systems and networks form the foundation of modern organisations – protecting them is therefore vital to their survival. An Information Security Management System (ISMS) enables organisations to identify risks in a structured manner, implement security measures consistently and thus enhance their resilience to cyber-attacks.

Robert Stricker
Vice President Security Consulting
Heike Abels
Referentin für Unternehmenskommunikation

The systematic approach to security

The current situation highlights just how urgent this issue is: according to the Bitkom study ‘Economic Security 2025’, around 80 per cent of German companies have been affected by data theft, industrial espionage or sabotage within the last twelve months. The total damage resulting from this amounts to 267 billion euros. At the same time, the market for IT security measures is growing at double-digit rates. Six out of ten companies state that cyberattacks could threaten their very existence. These figures show that information security now affects every company and every public authority – regardless of size or sector.

What is an ISMS?

An ISMS defines rules, processes and responsibilities for information security. It provides a framework for systematically identifying, assessing and controlling security risks. It combines technical, organisational and personnel measures into a unified security concept based on established standards such as ISO 27001 or the BSI IT-Grundschutz. The aim is to ensure the confidentiality, integrity and availability of information on a long-term basis. This is not just about firewalls or passwords, but about a well-thought-out interplay between people, technology and organisation. An ISMS integrates security aspects into day-to-day work and ensures that risks are addressed proactively rather than reactively.

Who needs an ISMS – and why?

An ISMS is relevant to any organisation that processes or stores information. The following are particularly affected:

  • Critical infrastructure (KRITIS), for example in the energy, healthcare or transport sectors
  • Government bodies and public institutions that handle sensitive or personal data
  • Companies in supply chains that must meet partners’ security requirements
  • SMEs, which are increasingly becoming targets of cyberattacks

Legal requirements are also increasing: the IT Security Act 2.0 and the EU NIS 2 Directive oblige many companies and public authorities to implement appropriate protective measures. The GDPR also requires organisational and technical security structures. An ISMS provides the methodological framework for this – and enables clear evidence of compliance with these requirements.

Risks without an ISMS

In the absence of structured security management, many risks remain undetected until damage occurs. The consequences can be severe:
loss of sensitive data, damage to reputation, financial losses due to business interruptions, or even fines for data protection breaches.
The trust of customers and partners also suffers when security shortcomings come to light.
Furthermore, a lack of security evidence can result in organisations no longer being considered for tenders or partnerships.

Implementing an ISMS: Steps and Process

Implementing an ISMS is a process that involves planning, implementation and continuous improvement. 

1. Analysis and preparation

First, the current situation is analysed. A so-called gap analysis identifies where security vulnerabilities exist and which measures are already in place. The scope of the ISMS is defined – that is, which sites, departments or processes are included. It is important that senior management supports the project and provides the necessary resources.

2. Security Objectives and Policies

Next, specific objectives are defined and an information security policy is drawn up. This sets out responsibilities, roles and fundamental security principles.

3. Risk Management

In this phase, risks are identified, assessed and prioritised. Based on this, appropriate measures are determined, such as access controls, backup strategies or training programmes.

4. Implementation of Measures

Technical, organisational and personnel measures are implemented. It is crucial that information security is integrated into day-to-day operations and reinforced through regular training.

5. Monitoring and Auditing

Regular audits and reviews ensure that the ISMS remains effective. Management reviews help to assess progress and identify areas for improvement.

6. Continuous improvement

An ISMS is not a one-off project, but an ongoing process. New threats, changes in legislation or technological developments mean that security measures must be continuously adapted.

Benefits of an ISMS

A well-functioning ISMS offers numerous benefits:
it creates transparency and control over security risks, promotes a security culture within the organisation and enables the organisation to provide legal evidence to regulatory authorities or partners.
It also strengthens the trust of customers and suppliers, reduces financial risks and improves the organisation’s ability to respond in the event of a crisis.

In the long term, an ISMS also contributes to increased efficiency, as processes become clearer, responsibilities more clearly defined and security measures more predictable.

Checklist for ISMS implementation

  1. Secure management commitment
  2. Define the scope
  3. Carry out a current state analysis and risk assessment
  4. Establish security policies and objectives
  5. Assign responsibilities
  6. Plan and implement measures
  7. Launch training and awareness programmes
  8. Carry out internal audits
  9. Evaluate and document results
  10. Establish a process of continuous improvement

Conclusion

In the face of growing cyber threats and stricter legislation, an ISMS is becoming a central component of modern corporate governance. It helps to manage risks, build trust and demonstrate compliance. Organisations that act early gain a clear advantage – not only in terms of security, but also in competitiveness and reputation. Conversely, those that do without an ISMS risk losing data, trust and business opportunities. Information security is not a static state, but a process – and an ISMS is the tool for successfully managing this process.

Further information: Information security and ISMS

Robert Stricker
Vice President Security Consulting

Robert Stricker ist Vice President Security Consulting bei Materna.

Heike Abels
Referentin für Unternehmenskommunikation

Heike Abels arbeitet bei Materna als Referentin für Unternehmenskommunikation. Sie betreut redaktionell verschiedene Formate für die externe Kommunikation. Thematischer Schwerpunkt ist der Bereich Cross Market Services. Dazu zählen Enterprise Service Management, Customer Service und Cyber Security.

Related articles

Event
Frankfurt am Main
18.11.2026
BMC Helix Roadshow 2026

Meet Materna at the BMC Helix Roadshow 2026 on 18 November in Frankfurt and discover how modern service management, Agentic AI and compliance requirements work together successfully. Look forward to exclusive insights into the BMC Helix roadmap, the…

Read more
Event
Dortmund
05.11.2026
XCS Day (Xchange in Cyber Security)

At XCS Day, experts from the business and public sectors will once again come together to discuss current challenges and strategies relating to cyber security and regulation. Find out how organisations are strengthening their resilience to cyber…

Read more
Event
Dortmund
03.11.2026
FMS Information Day

On 3 November 2026, we will update you on the latest developments relating to the Federal Government’s FMS and encourage mutual exchange. The keen interest you show in every issue demonstrates that the FMS is, and will remain, a key element of…

Read more
Event
Wien
13.10.2026
Agentic AI Roundtable in Vienna

How does Agentic AI deliver real added value for IT and service organisations? At the Agentic AI Roundtable in Vienna, Materna, BMC Helix and other experts will discuss specific use cases, current challenges and next steps for businesses. Look…

Read more
Event
Berlin
13.10.2026 - 15.10.2026
Smart Country Convention (SCCON)

Come and meet us in Hall 27 at Stand 206 at the leading event for the digital state and public services. SCCON is a must-attend event for all stakeholders actively driving and shaping digital transformation. At our stand, you’ll find a use case…

Read more
Event
Amsterdam
06.10.2026 - 08.10.2026
Atlassian Team ’26 Europe

From 6 to 8 October 2026, Atlassian will be bringing the community together for ‘Team ’26 Europe’ in Amsterdam. Look forward to hands-on sessions covering AI, new products and features, live demos and certification opportunities. You’ll also have the…

Read more
Event
Berlin
01.10.2026
Open Insurance Dialog 4.0 (#OID4.0)

Open Insurance Dialog 4.0: FiDA, Identity and New Opportunities for Insurers

The insurance industry is facing a profound transformation: FiDA (Financial Data Access) and Open Insurance are creating new opportunities for data-driven services,…

Read more
Event
Online
30.09.2026
Webcast: ‘Understanding the mainframe, accelerating migration: How banks and insurers are harnessing hidden knowledge’

Mainframe and legacy systems contain decades of business logic – often inadequately documented and difficult to access. From 10.00 to 11.30, Materna and Nomain will demonstrate how AI-powered analyses can make business logic, dependencies and…

Read more
Event
Düsseldorf
30.09.2026
27th NRW ÖV Symposium

Artificial intelligence, digital sovereignty, the cloud, the data economy and cyber security form the framework for the digital transformation of public administration in North Rhine-Westphalia. This popular platform for information and dialogue on…

Read more
Event
Public Sector
Online
24.09.2026
Webcast: ‘From a jungle of registers to a digital ecosystem.’

How register modernisation, the ‘once-only’ principle and NOOTS are bringing about lasting change in public administration. Find out what challenges public authorities face, which strategies are proving effective, and how a future-proof register…

Read more