Information security policy
The top-level document signed off by management: what we protect, against what, and who is accountable. Under NIS2 the board must be able to stand behind it.
A policy downloaded from the internet looks convincing until someone asks who approved it, when it was last reviewed and how you know staff have read it. We write the documentation from the way your business runs day to day, so it stands up to auditors, customers and your own teams.
The scope depends on what the documents must cover: GDPR, NIS2, a customer asking for an ISAE 3402 report, D-mærket or simply your own governance. Most sets end up at 10-15 documents.
The top-level document signed off by management: what we protect, against what, and who is accountable. Under NIS2 the board must be able to stand behind it.
A readable view of threats and consequences that decides which controls you need and which you can leave out with a stated reason.
Rules for granting, changing and removing rights, tied directly into onboarding and offboarding.
Home working, passwords and MFA, personal devices, backup, supplier management and incident handling.
One or two pages for staff in plain language. Nobody reads thirty pages about passwords.
Templates for an incident log, periodic access reviews and proof of awareness training. These are what an auditor asks to see.
Documentation is only worth having if people can follow it. A procedure that fights the real workflow will be ignored within a week.
Over Teams we talk to management, the IT lead and HR about current practice: onboarding, access, suppliers and incidents.
We write the documents and walk through the wording with you, so every rule is realistic to keep.
Management approves, staff get a short online introduction, and read receipts are stored.
We book an annual review and update the set whenever systems or the organisation change significantly.
NIS2 makes security a board matter. Senior management has to approve risk management and understand it well enough to oversee it. A policy that no director has read is therefore not just weak paperwork, it is a governance problem. We give your leadership a short, clear briefing as part of the project.
That depends on your sector and size. Many mid-sized firms in energy, transport, health, manufacturing and digital infrastructure are in scope, and others feel it indirectly because customers push requirements down to suppliers. We help you read the rules, but the final call is yours.
Certification is issued by an accredited certification body, not by us. We write the documents along ISO 27001 lines, so they can serve as the base if you later pursue certification or an ISAE report.
A named person in your organisation. Alongside the texts you get an annual calendar showing what to review when and which records to keep. Without an owner, documentation goes stale within a year.
The D-mærket criteria on IT security and responsible data use overlap heavily with what we write, so the material supports your application. The label itself is awarded by the D-mærket secretariat.
Tell us what the documents need to cover: GDPR, NIS2, a customer demand or internal governance. We will propose a scope and a timeline.
Thank you for getting in touch
One of our consultants already has it. Expect a reply within the working day; anything urgent goes straight to an engineer.
That city is not on our list. Check the spelling or pick the nearest larger town.