Trust for Enterprise Customers: How Theobald Software Achieved ISO 27001 Certification with a Lean Team

About the company

What began in Stuttgart in 2004 has grown into a specialist for demanding SAP data integration. Theobald Software builds solutions that let companies move their SAP data seamlessly into a wide range of target systems, from Microsoft environments and analytics platforms to cloud and database solutions.

With around 50 employees, the team serves customers worldwide and brings data from cloud, on-premises and hybrid landscapes to wherever it is needed.

 

Challenge

As a provider in the enterprise space, information security had long been more than an IT topic for Theobald Software. Without a certified ISMS according to ISO 27001, however, the company lacked the formal proof that large customers increasingly expected in tenders and security reviews.

Internally, information security rested primarily with one person who had completed basic training, while know-how, time and a clear roadmap to certification were limited. In the summer of 2025, uncertainty about the actual status of the project and the next steps prevailed. With the Stage 1 and Stage 2 audits scheduled and future requirements in view, the pressure grew to build information security in a structured way and make it sustainable beyond the certification itself.

With our small InfoSec team, ISO 27001 certification was a challenge at first. The SECJUR platform gave us the structure to set up risks, assets and policies properly, and the experts guided us safely through the audits. Thanks to the successful certification process, we live conscious information security in our company and can clearly document that to our customers and stakeholders.
Michael Bässler
Chief Product & Technology Office

Solution

Theobald Software started building its ISMS with the "SECJUR Comfort Self Service" and used the DCO platform as its central working tool.

Risks were identified, assessed and linked to the relevant assets via the risk register and a systematically maintained asset register. Controls and the accompanying Statement of Applicability were backed with tasks so that solid evidence could be presented in the audit. In parallel, the team established training and document confirmations through the training module.

When it became clear that internal know-how and time resources would not be sufficient, Theobald moved to an extended expert setup: SECJUR experts joined recurring meetings, supported the risk register, reviewed the asset register, conducted an internal audit and advised on how to interlock the ISMS with data protection.

 

Impact

With ISO 27001 certification achieved on 16 April 2026 and the Stage 1 and Stage 2 audits passed, Theobald Software now has an established ISMS that brings risks, assets, policies and training together in one consistent structure.

The role of internal information security has become considerably sharper. What started as a single employee with basic training has become a solid InfoSec function that works with auditors, management and product teams as an equal. Building on the existing ISMS, Theobald can now develop information security continuously, optimise processes and make sure security requirements are anchored in the company for the long term.