30.10.2025
Blog
Cyber Security

A systematic approach to information security: Why an ISMS is essential

In an age of growing cyber threats and complex digital interdependencies, information security has long since become a strategic factor for success. Data, IT systems and networks form the foundation of modern organisations – protecting them is therefore vital to their survival. An Information Security Management System (ISMS) enables organisations to identify risks in a structured manner, implement security measures consistently and thus enhance their resilience to cyber-attacks.

Robert Stricker
Vice President, Security Consulting
Heike Abels
Corporate Communications Officer

The systematic approach to security

The current situation highlights just how urgent this issue is: according to the Bitkom study ‘Economic Security 2025’, around 80 per cent of German companies have been affected by data theft, industrial espionage or sabotage within the last twelve months. The total damage resulting from this amounts to 267 billion euros. At the same time, the market for IT security measures is growing at double-digit rates. Six out of ten companies state that cyberattacks could threaten their very existence. These figures show that information security now affects every company and every public authority – regardless of size or sector.

What is an ISMS?

An ISMS defines rules, processes and responsibilities for information security. It provides a framework for systematically identifying, assessing and controlling security risks. It combines technical, organisational and personnel measures into a unified security concept based on established standards such as ISO 27001 or the BSI IT-Grundschutz. The aim is to ensure the confidentiality, integrity and availability of information on a long-term basis. This is not just about firewalls or passwords, but about a well-thought-out interplay between people, technology and organisation. An ISMS integrates security aspects into day-to-day work and ensures that risks are addressed proactively rather than reactively.

Who needs an ISMS – and why?

An ISMS is relevant to any organisation that processes or stores information. The following are particularly affected:

  • Critical infrastructure (KRITIS), for example in the energy, healthcare or transport sectors
  • Government bodies and public institutions that handle sensitive or personal data
  • Companies in supply chains that must meet partners’ security requirements
  • SMEs, which are increasingly becoming targets of cyberattacks

Legal requirements are also increasing: the IT Security Act 2.0 and the EU NIS 2 Directive oblige many companies and public authorities to implement appropriate protective measures. The GDPR also requires organisational and technical security structures. An ISMS provides the methodological framework for this – and enables clear evidence of compliance with these requirements.

Risks without an ISMS

In the absence of structured security management, many risks remain undetected until damage occurs. The consequences can be severe:
loss of sensitive data, damage to reputation, financial losses due to business interruptions, or even fines for data protection breaches.
The trust of customers and partners also suffers when security shortcomings come to light.
Furthermore, a lack of security evidence can result in organisations no longer being considered for tenders or partnerships.

Implementing an ISMS: Steps and Process

Implementing an ISMS is a process that involves planning, implementation and continuous improvement. 

1. Analysis and preparation

First, the current situation is analysed. A so-called gap analysis identifies where security vulnerabilities exist and which measures are already in place. The scope of the ISMS is defined – that is, which sites, departments or processes are included. It is important that senior management supports the project and provides the necessary resources.

2. Security Objectives and Policies

Next, specific objectives are defined and an information security policy is drawn up. This sets out responsibilities, roles and fundamental security principles.

3. Risk Management

In this phase, risks are identified, assessed and prioritised. Based on this, appropriate measures are determined, such as access controls, backup strategies or training programmes.

4. Implementation of Measures

Technical, organisational and personnel measures are implemented. It is crucial that information security is integrated into day-to-day operations and reinforced through regular training.

5. Monitoring and Auditing

Regular audits and reviews ensure that the ISMS remains effective. Management reviews help to assess progress and identify areas for improvement.

6. Continuous improvement

An ISMS is not a one-off project, but an ongoing process. New threats, changes in legislation or technological developments mean that security measures must be continuously adapted.

Benefits of an ISMS

A well-functioning ISMS offers numerous benefits:
it creates transparency and control over security risks, promotes a security culture within the organisation and enables the organisation to provide legal evidence to regulatory authorities or partners.
It also strengthens the trust of customers and suppliers, reduces financial risks and improves the organisation’s ability to respond in the event of a crisis.

In the long term, an ISMS also contributes to increased efficiency, as processes become clearer, responsibilities more clearly defined and security measures more predictable.

Checklist for ISMS implementation

  1. Secure management commitment
  2. Define the scope
  3. Carry out a current state analysis and risk assessment
  4. Establish security policies and objectives
  5. Assign responsibilities
  6. Plan and implement measures
  7. Launch training and awareness programmes
  8. Carry out internal audits
  9. Evaluate and document results
  10. Establish a process of continuous improvement

Conclusion

In the face of growing cyber threats and stricter legislation, an ISMS is becoming a central component of modern corporate governance. It helps to manage risks, build trust and demonstrate compliance. Organisations that act early gain a clear advantage – not only in terms of security, but also in competitiveness and reputation. Conversely, those that do without an ISMS risk losing data, trust and business opportunities. Information security is not a static state, but a process – and an ISMS is the tool for successfully managing this process.

Further information: Information security and ISMS

Robert Stricker
Vice President, Security Consulting

Robert Stricker is Vice President of Security Consulting at Materna.

Heike Abels
Corporate Communications Officer

Heike Abels works at Materna as a Corporate Communications Officer. She is responsible for the editorial content of various formats used for external communications. Her work focuses on Cross Market Services, which includes Enterprise Service Management, Customer Service and Cyber Security.

Related articles

Short News
Think ahead
Cyber Security
26.08.2026
Quantum computers: The end of encryption as we know it

Why post-quantum readiness extends far beyond cryptography and is becoming a key prerequisite for digital sovereignty – for public administration, critical infrastructure, industry and all organisations with data that requires long-term protection.

Read more
Blog
Cyber Security
11.08.2026
Detecting and intercepting drones: the solutions are already available

How well are critical infrastructures protected against drone attacks? The security incident at Leipzig/Halle Airport has sent shockwaves through…

Read more
Blog
Cyber Security
11.08.2026
Cyber Security 2026: These trends are shaping both the business sector and public administration

In 2026, cyber security will be more of a focus than ever for businesses, government agencies and public institutions. According to the Lünendonk…

Read more
Short News
Corporate
Cyber Security
31.07.2026
From Rising Star to Leader: Materna has been recognised as a Leader in Strategic Security Services in the ISG Provider Lens™ Cyber Security – Services and Solutions 2026

ISG has recognised Materna as a leading provider of cyber security consultancy in Germany.

Read more
Blog
Cyber Security
28.07.2026
Security by Design: Why secure software isn’t just created just before going live

In many software projects, security is still viewed as a final testing step. Once the application is almost complete, security scans, penetration…

Read more
Blog
Cyber Security
21.07.2026
Information security: Clear lines of responsibility strengthen cyber resilience

Information security rarely fails due to a lack of awareness alone – it is often unclear lines of responsibility, a lack of coordination and…

Read more
Blog
Cyber Security
13.05.2026
KRITIS Framework Act: These new requirements now apply to KRITIS operators

The protection of critical infrastructure has been a key issue for many businesses and public authorities for years. With the new KRITIS framework law…

Read more
Blog
Cyber Security
24.03.2026
Cyber resilience in small and medium-sized enterprises: Why cyber security today determines the future

Cyber resilience in small and medium-sized enterprises is no longer merely an optional IT issue, but a strategic necessity. Whilst large corporations…

Read more
Blog
Cyber Security
30.10.2025
A systematic approach to information security: Why an ISMS is essential

In an age of growing cyber threats and complex digital interdependencies, information security has long since become a strategic factor for success.…

Read more
Blog
Data & AI
Cyber Security
28.10.2025
Prompt Injection – How AI can be misled by hidden commands

Imagine this: you ask a chatbot to summarise a web page. At first glance, the text seems completely harmless, but hidden somewhere in the small print…

Read more