Information Security – Guidance for Decision-Makers
Holistic approach to protecting sensitive company data
Related topics
Information security is not a project – it is a continuous commitment.
Information security is not an IT project that is completed once, but a state that a company must permanently establish and demonstrate. Anyone who wants to win contracts today, fulfil regulatory obligations, and succeed in supply chains can no longer do without robust security structures.
This page contextualises the topic: what information security encompasses, which standards and regulations are relevant – and how the individual building blocks (ISMS, NIS2, TISAX, CADIS®) are interconnected. From here, we will guide you specifically to the topics that matter to your company.
Sustainable Information Security as a Competitive Factor
What information security means
Information security protects information regardless of whether it is digital, on paper, or in the minds of employees. Three core security objectives form the basis:
- Confidentiality – Information is only accessible to authorised persons.
- Integrity – Information is correct and unadulterated.
- Availability – Information will then be available when it is needed.
What is important is the distinction from pure IT security: IT security considers technology and systems. Information security is a more comprehensive concept – it includes processes, organisation, people, and physical factors. Technology alone does not protect information if responsibilities, rules, and awareness are lacking.
Technology alone does not protect information if responsibilities, rules, and awareness are lacking.
Why Information Security is a Top Management Issue Today
The pressure is coming from several sides at once – and it's increasingly affecting senior management personally, not just the IT department.
Regulatory framework. With NIS2, the legislator is significantly expanding the number of organisations affected and establishing obligations that extend to the liability of senior management. Those who were previously exempt are often no longer so.
Supply chains. Major clients pass their security requirements down the supply chain. In the automotive industry, a TISAX®Today, labelling is often a prerequisite for even entering the tender phase. Security becomes market access.
Threat assessment. Attacks involving ransomware, phishing and compromised suppliers have become an everyday occurrence. An incident does not just mean downtime; it also poses a risk to reputation and liability.
Integration and Growth. It is particularly following acquisitions and in post-merger situations that heterogeneous, complex IT landscapes emerge. In such cases, a robust security strategy determines whether integration is a success or becomes a risk.
An overview of the four areas of action
Information security cannot be implemented in a one-size-fits-all manner – it takes shape in different components depending on the objectives and requirements. Four of these are relevant to most organisations:
-
ISMS – the foundation
-
NIS2 – the obligation
-
TISAX® – market access in the automotive industry
-
CADIS® – Security for the Defence Sector
An Information Security Management System (ISMS) forms the methodological backbone. It makes security manageable: through policies, clear roles, risk management and continuous improvement – certifiable to ISO/IEC 27001. Anyone wishing to tackle NIS2 or TISAX® seriously must build on an ISMS.
The EU NIS2 directive requires significantly more companies to implement concrete security measures – with deadlines, reporting obligations, and personal responsibility for management. The first step is the impact assessment: Is your company affected?
TISAX standardises the demonstration of information security to car manufacturers and their suppliers, based on the VDA ISA catalogue. Without a valid certification, many suppliers are denied access to the market.
CADIS® is DEKRA’s certification process for requirements in the defence and security sector. A specialised field with high standards – and little room for compromise.
How the building blocks are connected
These four topics do not stand in isolation; they build on one another. The ISMS forms the methodological foundation – TISAX and NIS2 are based on the same fundamental principles (risk management, policies, defined responsibilities). Anyone who establishes a robust ISMS does not have to start from scratch for TISAX or NIS2, but can build specifically on what is already in place.
This connection is the real key: rather than tackling each issue in isolation and approaching every audit from scratch, a common foundation is created that meets several requirements at once.
Information security as part of successful integration
For bitformer, information security is not a stand-alone product, but an integral part of our overarching theme: shaping secure digital integration. It is precisely where IT landscapes are brought together – following mergers, acquisitions or as part of modernisation – that security determines whether complexity can be transformed into a viable whole.
We support organisations across all four areas of focus – from setting up the ISMS, through the NIS2 scoping assessment, to TISAX preparation. For TISAX, Ralph Dörfler is available as a designated specialist with practical experience of conducting assessments.
Our approach: no scaremongering, no off-the-shelf packages. Instead, an honest assessment of what your business actually needs – and a way to achieve it that integrates seamlessly with your existing IT infrastructure.
Your entry
Not sure which issue is most relevant to you at this stage? That’s a good place to start. The process often begins with a realistic assessment of the current situation: where does your organisation stand, what challenges lie ahead, and what is the most pragmatic first step?
Arrange your no-obligation initial consultation on information security now.
RALPH DÖRFLER
Head of IT Security

