For ValueStreamer, as a provider of software for digital production control, one thing was clear: information security should not only be demonstrated externally, but anchored in the company in a structured way. At the same time, ISO 27001 strengthens the company's position in sales and creates an important basis for further growth, particularly with larger companies.
About the company
ValueStreamer GmbH, based in Wendlingen am Neckar, develops a SaaS solution for digital shopfloor management. With ValueStreamer®, manufacturing companies manage their key figures, tasks and deviations across sites in real time, in other words where whiteboards and Excel lists used to set the pace.
Its customers include hidden champions as well as large corporations, primarily from the manufacturing industry and the automotive sector.
Challenge
For ValueStreamer, ISO 27001 was an important step towards meeting its customers' rising information security requirements. In the procurement processes of mid-sized and large industrial companies in particular, proof of a certified information security management system is increasingly becoming standard. Security questionnaires and tenders frequently assume such structures, and can therefore determine at an early stage whether a software provider is considered in the selection process at all.
For ValueStreamer, as a provider of software for digital production control, one thing was therefore clear: information security should not only be demonstrated externally, but anchored in the company in a structured way. At the same time, ISO 27001 strengthens our position in sales and creates an important basis for further growth, particularly with larger companies.
The goal was clearly defined: not simply to obtain a certificate, but to build an ISMS of its own that suits ValueStreamer, is lived within the company and can be developed further independently over the long term. The challenge was to deliver on that ambition with a small team, alongside product development and customer support.
The solution
ValueStreamer chose SECJUR's Digital Compliance Office (DCO) and with it deliberately opted for an automation-supported approach to building its ISMS. What convinced the company: no sprawling consulting project, but its own team steering the build while drawing on a platform that already brings the logic of the standard with it.
Clear step-by-step guidance came from the ISO 27001 navigator in the DCO. Instead of working through the text of the standard, the team followed a stringent sequence: from the scope through assets and risks to controls and evidence. For a project that runs alongside day-to-day business, exactly this efficient sequencing is decisive.
The biggest time saving came from the policy generator. An ISMS comprises dozens of policies and procedures that have to fit together, cross-reference each other and be available in versioned form. Instead of writing this structure from scratch, ValueStreamer could draw on templates that conform to the standard and tailor them to its own organisation. The work thus shifted from formulating to deciding.
Added to this were the integrated training courses, through which the required evidence could be maintained systematically, without parallel lists. Where questions of interpretation regarding the standard came up, a quick email to the SECJUR expert team was enough.
The impact
The result was successful ISO 27001 certification. For a build carried out in-house, that is evidence of how robust the structure developed in the DCO was.
Just as important is what stands behind it. Today ValueStreamer has a management system that belongs to the company and that it can steer itself: policies held centrally and versioned, responsibilities assigned, training records available at any time, upcoming surveillance audits preparable from ongoing operations. In sales, the certification has an immediate effect, because security questionnaires can now be answered with accredited proof instead of self-declarations.