2 Days. 10+ Experts. Countless IAM & GRC Insights. Register for NEXIS INVOLVE | September 9-10 | Regensburg

IT Services & Digital Transformation

CANCOM Introduces an ISMS to ISO/IEC 27001 Worldwide with NEXIS GRC

For information security, risk, and data protection management, CANCOM relies on the integrated management system NEXIS GRC to steer more than 15 standards and frameworks consistently across the group.

IT Services & Digital Transformation

About CANCOM

As a Hybrid IT Integrator, service provider, and digital transformation partner, CANCOM guides companies into the digital future. The IT solution portfolio of the CANCOM Group covers consulting, implementation, services, and the operation of IT systems.

Around 4,000 employees worldwide and a capable partner network ensure market presence and customer proximity, including in Germany, Austria, Switzerland, Belgium, Slovakia, the United Kingdom, Ireland, and the USA.

  • Founded: 1992
  • Employees: ~ 4,000
  • Customers: More than 20,000
  • Locations: More than 50 across Europe and the USA

With NEXIS GRC, CANCOM was able to

Steer More than 15 Standards Centrally

Present audit information, controls, and evidence consistently across standards in one platform.

Establish a Unified Audit Platform as a Single Source

Bring together information from different sources, condense it strongly, and standardize it.

Reduce Effort through Automation

Save resources through the automatic aggregation and evaluation of information.

Involve Business Users without Training

Self-explanatory wizards conduct interviews electronically and reduce setup, travel, and onboarding times.

Use All-In-One Queries

In one process, simultaneously query the assignment to standards as well as ICS and data protection relevance.

Create Transparency over Structures

Make risks, structures, and dependencies in the group visible, especially during strong growth.

The Challenge

The internationally operating CANCOM Group works according to more than 15 standards and frameworks. Assessing this worldwide abundance of controls by maturity level and assigning the associated documents and evidence could no longer be mapped with in-house tools such as Excel.

This quickly created the need for a Unified Audit Platform. In the spirit of a single-source approach, CANCOM looked for a system that presents all information consistently across standards and, at the same time, reduces effort significantly. The focus was on the automation and standardization of processes. This standardization is essential in an international environment, because only consistent process models can keep pace with strong inorganic growth.

The goal was to:

  • Create a Unified Audit Platform as a single source
  • Present audit information, controls, and evidence consistently across standards
  • Reduce effort significantly through automation and standardization
  • Save resources through automatic aggregation and evaluation
  • Establish consistent process models for an international, fast-growing environment

The Approach

CANCOM examined the market broadly and then implemented NEXIS GRC in clearly separated phases. Around ten months were planned for the implementation.

Evaluation and Selection of NEXIS GRC

CANCOM considered a total of ten tool providers, from small to very large companies. After a pre-evaluation, five providers made the shortlist, which CANCOM compared against one another based on their USPs. Almost all of them met the basic standards requirements. For NEXIS GRC, the difference was the workflow support through integrated wizards, complemented by the convincing cost-benefit analysis and the scalability as a single-source tool.

Positioning and Acceptance

CANCOM positioned the solution so that users are actively brought on board. Quality, HR, and occupational safety managers as well as data protection officers were to work in a shared system. The message was more than "We are implementing a tool": NEXIS GRC supports a consistent path in risk, security, and data protection management.

Phase 1: Configuration

After swift scoping sessions with Nexis, the configuration began. In workshops, Nexis set up the system according to CANCOM's requirements and provided a test system.

Phase 2: Data Transfer and Go-Live

After successful testing and final adjustments, the live system went into operation in CANCOM's data center.

Phase 3: Operation and Maintenance

In ongoing operation, CANCOM connects further sources, condenses information, and generates meaningful reports. Targeted awareness activities show the added value to further departments as well and embed the solution ever more deeply in the organization.

The Result

With NEXIS GRC, CANCOM created a central platform that bundles all business processes, standards, and evidence in one place. In addition to transparency over risks and their impact, transparency over structures and dependencies in the group also emerges. This is especially beneficial for organizations that react quickly to market changes and grow strongly through acquisitions.

  • Single source of truth: more than 200 business processes, close to 600 risks, and more than 400 assets and asset groups in one platform
  • Broad coverage: more than 10 business units, more than 50 locations, and several areas under review captured
  • Central to certifications: NEXIS GRC is a fixed part of the annual certifications
  • Less effort: Automation and self-explanatory wizards reduce setup, travel, and onboarding times
  • Transparency: visibility over risks, structures, and dependencies in the group
  • High user acceptance: Business users from quality, HR, occupational safety, and data protection work in one system

See how cross-standard security and risk management works in practice

Learn how NEXIS GRC helps organizations steer many standards in a single-source platform, reduce effort, and create transparency over risks and structures.