Blog

News about information & data security, as well as about TEN Information Management GmbH

I hear this phrase more often than I’d like during initial consultations. And it highlights the exact problem: Most CEOs are familiar with ISO 27001—but don’t understand what it could really mean for their company....
Not the budget. Not the tools. But leadership.Two companies, similar in size, with the same goal: to implement ISO 27001and get certified. Company 1️⃣Goal: “Get certified in 5 months!”Tone: “We just have to do it.”Typical...
In many companies, information security is still treated as an IT issue. As a result, it gets delegated. → To the IT department.→ To external service providers.→ To “someone who takes care of it.” What...
The wiper blades on my leased vehicle were worn out.The car had been sitting for six months before I took delivery—low mileage,visibility is now limited. Lease includes maintenance & wear and tear; wiper blades are...
A few weeks ago, I attended a blind dinner.A full menu – served in complete darkness. Everything was there: food, drinks, cutlery, service.Just not visible. Suddenly, completely new questions arose:How do I drink without knocking...
“IT takes care of security.”One of the most common and dangerous misconceptions in companies. Information security is not an isolated IT project.It is a company-wide management issue. So who is actually responsible?Information security protects the...
Recently at an NIS 2 workshop with a client’s management team.Topic: Reporting requirements for IT security incidents. The central BSI portal for reporting security incidents has recently been launched – which is good and right....
In recent weeks, I have heard the same thing repeatedly in conversations with customers: The industry surrounding NIS-2 and ISO 27001 is currently a gold mine, and many are acting accordingly. The general sentiment can...
About a year ago, a prospective customer said to me:“You know, Mr. Neeff, everything we need for our ISO 27001 ISMS documentation is now available for free on the internet. And I’ll do the rest...
Many believe that the core of effective information security lies in a particularly “good” or “beautiful” implementation of ISO 27001 or NIS-2. But the real success factor is something else: an honest assessment of the...