About the company
For more than 65 years, Löttco has been developing and manufacturing complex wire, tube, stamped and welded components as well as hybrid components made of metal and plastic in Neuenrade. A large share of these are safety-relevant parts.
Around 90 employees serve more than 80 customers from Neuenrade and the second plant in Bystrice, Czech Republic, mostly OEMs as well as system and module suppliers to the international automotive industry. Design, tool making and prototyping are handled in-house, and quality management is certified to IATF 16949. Löttco therefore accompanies components from the first idea through to volume production.
Challenge
The requirement came from the market, the ambition from the company itself.
Without a TISAX® label, suppliers are no longer even considered in many tenders and supplier assessments in the automotive industry. For Löttco, the label was therefore a clear factor in winning contracts. At the same time, the reason ran deeper. As a development partner, Löttco works with customer drawings, specifications, prototype and series start-up data every day. Protecting this information reliably is not a formality, but part of the service for which customers choose Löttco.
From the outset, management was therefore clear about what the project should not become: a collection of Word documents that is pulled out for the assessment and filed away again afterwards. What the company was looking for was an information security management system that works in day-to-day operations, fits into the existing quality organisation and creates recognisable value of its own. The partner had to lead not only to the label, but to a robust system behind it.
Solution
Löttco chose SECJUR's Comfort Self Service and with it a hybrid model of self-service platform and intensive expert support, a combination that suits a mid-sized company that wants to keep responsibility in-house while drawing on experienced guidance.
The VDA ISA catalogue was mapped in full on the InfoSec platform, maturity levels were maintained, and implementation descriptions and evidence were stored in a structured way. Policies, procedural instructions and operating procedures were given a central place with clearly governed access rights and responsibilities.
Two points were decisive for Löttco:
Routine operation instead of an annual exercise: Recurring tasks, status displays and clearly defined responsibilities make sure the ISMS is lived and developed further in day-to-day work. Laborious preparation ahead of the recurring assessments is no longer necessary.
Interlocking with the existing quality management: Löttco has worked with IATF 16949 structures for years: document control, internal audits, action tracking, evidence of effectiveness. The ISMS was deliberately built into this existing logic rather than set up alongside it. For employees, this did not create a second, unfamiliar set of rules, but an extension of what they already know. That made acceptance in production and administration considerably easier.
Impact
At the end of the project stood a fully completed VDA ISA list whose achieved maturity level exceeds the required threshold. The internal audit with SECJUR and the subsequent external assessment were both successful.
More important than the label, however, is what remained afterwards. Responsibilities are assigned, evidence is held centrally and kept up to date, customer and supplier enquiries can be answered without searching, and information security topics run in the same rhythm as the other management processes. Löttco now approaches automotive enquiries with confidence and uses TISAX® deliberately as proof of trust in new customer projects.