CANCOM Introduces an ISMS to ISO/IEC 27001 Worldwide with NEXIS GRC
For information security, risk, and data protection management, CANCOM relies on the integrated management system NEXIS GRC to steer more than 15 standards and frameworks consistently across the group.
About CANCOM
As a Hybrid IT Integrator, service provider, and digital transformation partner, CANCOM guides companies into the digital future. The IT solution portfolio of the CANCOM Group covers consulting, implementation, services, and the operation of IT systems.
Around 4,000 employees worldwide and a capable partner network ensure market presence and customer proximity, including in Germany, Austria, Switzerland, Belgium, Slovakia, the United Kingdom, Ireland, and the USA.
- Founded: 1992
- Employees: ~ 4,000
- Customers: More than 20,000
- Locations: More than 50 across Europe and the USA
The Challenge
The internationally operating CANCOM Group works according to more than 15 standards and frameworks. Assessing this worldwide abundance of controls by maturity level and assigning the associated documents and evidence could no longer be mapped with in-house tools such as Excel.
This quickly created the need for a Unified Audit Platform. In the spirit of a single-source approach, CANCOM looked for a system that presents all information consistently across standards and, at the same time, reduces effort significantly. The focus was on the automation and standardization of processes. This standardization is essential in an international environment, because only consistent process models can keep pace with strong inorganic growth.
The goal was to:
- Create a Unified Audit Platform as a single source
- Present audit information, controls, and evidence consistently across standards
- Reduce effort significantly through automation and standardization
- Save resources through automatic aggregation and evaluation
- Establish consistent process models for an international, fast-growing environment
The Result
With NEXIS GRC, CANCOM created a central platform that bundles all business processes, standards, and evidence in one place. In addition to transparency over risks and their impact, transparency over structures and dependencies in the group also emerges. This is especially beneficial for organizations that react quickly to market changes and grow strongly through acquisitions.
- Single source of truth: more than 200 business processes, close to 600 risks, and more than 400 assets and asset groups in one platform
- Broad coverage: more than 10 business units, more than 50 locations, and several areas under review captured
- Central to certifications: NEXIS GRC is a fixed part of the annual certifications
- Less effort: Automation and self-explanatory wizards reduce setup, travel, and onboarding times
- Transparency: visibility over risks, structures, and dependencies in the group
- High user acceptance: Business users from quality, HR, occupational safety, and data protection work in one system