The Challenge
In 2023, ContractHero aimed to achieve an even higher level of security through ISO 27001 certification. While the existing measures were already extensive, the company needed an effective way to set up a certifiable ISMS (Information Security Management System) as quickly as possible for the upcoming audit.
The Solution
ContractHero relied on Kertos’ automated compliance solution for ISO 27001 certification. In a four-month process, the company first conducted a gap analysis to identify areas for improvement. Using pre-built policy templates, ContractHero optimized its documentation, while targeted security training strengthened employee awareness. Following this, the necessary ISO 27001 controls and procedures were implemented under Kertos’ guidance. An internal audit ensured compliance before successfully completing the final external audit. Through this structured approach, ContractHero was able to efficiently achieve certification, reduce documentation efforts, and sustainably improve the company’s security culture.
The Result
With the help of Kertos, ContractHero has significantly improved its Information Security Management System (ISMS) and established a strengthened security culture within the company. By systematically implementing ISO 27001 requirements, efficient documentation, and comprehensive training, the company was able to shorten the certification process by approximately 100 hours and significantly improve data security measures. Additionally, costs were reduced due to less documentation effort. In the future, ContractHero plans to further optimize the ISMS with Kertos and continuously adapt to new security requirements.