
How KPS is strengthening and unifying infosec management across multiple offices using ISMS.online
Digital transformation experts KPS provide the software, tools, and strategies its clients need to create high-quality customer experiences on their own websites. KPS specialises in supporting mid-to-high-end retailers, including many household names. KPS’s security-conscious clients, who deal with vast amounts of customer financial and personal data, expect a high standard of information security from KPS.
The Challenge
KPS decided to pursue ISO 27001 certification primarily because it is becoming a critical requirement for both existing and potential clients. But achieving certification was extra challenging because of KPS’s decentralised set-up — with four offices across three countries using different systems and processes due to past acquisitions.
KPS faced several challenges which hampered information security management and oversight at enterprise level:
- Varying levels of information security maturity across multiple sites
- Decentralised, siloed data held across various spreadsheets, emails, and people’s heads
- Inefficient review and approval processes via email chains
Initially, the KPS team considered using spreadsheets and SharePoint to manage the ISO certification process — but soon realised the complexity involved. They decided to invest in a specialised solution to help them efficiently implement and manage a robust information security management system, including embedding a culture of compliance.
“The main challenge was aligning three regional offices that are used to operating fairly independently and varied significantly in risk management and compliance practices — and within a tight timeframe. We had to unify everybody into a standard way of working for ISO 27001 accreditation.”
Risk and Compliance Manager, KPS
The Solution
After demoing different tools, KPS chose ISMS.online for its ease of use, compatibility with KPS’s existing single sign-on app, and comprehensive resources to help achieve ISO 27001 accreditation.
Implementing ISMS.online was straightforward. KPS staff find it easy to learn and use — even for non-native English speakers.
“ISMS.online does exactly what we need it to do. The single sign-on through our current identity management provider — rather than having to install an extra app — was a big plus which other solutions didn’t offer.”
Risk and Compliance Manager, KPS
ISMS.online provides guidance, content, control attributes, risks, and suggested controls, all ready for KPS to adopt, adapt, or add to, as required — all in one centralised, user-friendly platform. Digital signatures streamline approval processes.
“ISMS.online’s setup is great because it pushes you to be compliant straight out of the box: you need to do this, this, and this. ARM is very helpful because it guides you through each step of the ISO process in an organised way, so you can achieve certification relatively quickly but also to the required standard.”
Risk and Compliance Manager, KPS
The Result
Just three months into their ISO 27001 certification journey, KPS has already seen significant improvements in data management efficiency. Using ISMS.online has streamlined workflows, improved visibility, and fostered easier collaboration, making it simpler to manage and track tasks across different locations.
KPS is bolstering its market position simply by working towards certification — landing two new contracts thanks to this.
“We’ve already won a couple of contracts based on the understanding that we will be ISO 27001 compliant by the end of this year.”
Risk and Compliance Manager, KPS
ISMS.online is playing a critical role in increasing accountability within KPS. The platform’s real-time progress tracking, clear assignment of tasks, and automated reminders ensure everybody knows what they need to do — and oversight is much easier.
“ISMS.online is great for organising work. Having a centralised, web-based tool means staff can access it from anywhere, and it’s straightforward to see who’s responsible for what and who has tasks outstanding.”
Risk and Compliance Manager, KPS
Adopting ISMS.online has catalysed a cultural shift towards stronger information security compliance and risk management within KPS — sparking important internal conversations and highlighting existing strengths.
“A major benefit of implementing ISMS.online is that it’s forced us to have a lot more conversations internally around risk management and compliance, which historically we’ve seldom done as a group. Reassuringly, it’s also highlighted the brilliant work already going on. It’s been an eye opener.”
Risk and Compliance Manager, KPS
What’s Next?
With their eyes firmly set on achieving certification by the end of 2024, the KPS team is now focusing on implementing policy packs for staff and suppliers. Monitoring compliance is straightforward with digital signatures in ISMS.online.
Despite working to an ambitious deadline, having ISMS.online is boosting KPS’s audit confidence.
“Having ISMS.online is going to be a massive benefit during the audit process. Instead of giving the auditors large binders stuffed with documents, everything will be web-based, and easy to find and view.”
Risk and Compliance Manager, KPS
For more information, visit our ISO 27001 solutions page or contact us to see how we can help your business.
Based
United Kingdom, Germany, Spain
Company Size
501 - 1,000
Industry
Information Technology & Services
Compliance Frameworks
ISO 27001
Increased customer trust
Already won two contracts on the strength of pending ISO 27001 certification
Embedding culture of compliance
Increased internal focus on risk management and security
ISO 27001 audit confidence
On track for a successful audit despite an ambitious timeframe
Get a personalised demo
Get certified up to 5 x faster
See how you can get certified 5 x faster with our pre-built templates and step-by-step guidance. Book your personalised platform demo today and start your ISO 27001 journey!