Techem Builds a Resilient Information Security and Risk Management System with NEXIS GRC
About Techem
Techem is an international leader in energy billing and energy management. In Germany, the company is the market leader in consumption-based metering and billing of heat and water for the real estate industry. Its range of services spans energy procurement, the metering and billing of heat and water consumption, and detailed analytics.
As one of the leading service partners for green and smart buildings, Techem focuses on energy efficiency across the entire real estate value chain and promotes healthy living, process efficiency, and climate protection. From its headquarters in Eschborn, the company manages its worldwide operations.
- Headquarters: Eschborn, Germany
- Employees: ~ 3,750
- Presence: ~150 Locations Worldwide, in more than 20 European Countries as well as Brazil and the United Arab Emirates
- Billing: ~ 11 Million Households
With NEXIS GRC, Techem was able to
Establish a consistent approach across the entire organization that delivers comparable, valid results.
Capture threats and vulnerabilities in a structured way and assess them per asset with full traceability.
Assess the controls from ISO/IEC 27001 Annex A by maturity level and derive a Statement of Applicability from them.
Implement all information security and risk management requirements in a single solution.
Achieve high user acceptance beyond IT through workflow-supported processes that require little training.
Continuously monitor, document, and evidence security activities with minimal use of resources.
The Challenge
Techem wanted to build a capable information security management system to assess risks on a lasting and efficient basis. From this assessment, the company wanted to derive risk treatment measures and to measure and advance its activities based on maturity.
A central requirement was a company-wide, standardized approach that delivers comparable, valid data as a basis for decisions. The task was complex and the requirements were broad. It therefore became clear early on that professional software support is more economical and efficient than running an ISMS with in-house means or building a custom solution.
The goal was to:
- Build a capable, company-wide standardized ISMS
- Assess risks on a lasting and efficient basis and derive treatment measures
- Measure activities by maturity and continuously advance them
- Produce comparable, valid data as a basis for decisions
- Find modern, database-supported, and flexibly adaptable software support that can be rolled out step by step across the entire organization
The Result
With NEXIS GRC, Techem introduced an information security and risk management system through which all associated activities are consistently carried out, documented, and evidenced without gaps. The insights from the implementation enable compliance- and risk-relevant decisions on a valid data foundation. The collaboration with Nexis proved trustworthy and competent across all project phases.
- Valid data foundation: Compliance- and risk-relevant decisions rest on comparable, valid data
- Complete traceability: All security activities are consistently carried out, documented, and evidenced
- Resource-efficient operation: The maturity view enables continuous monitoring and a resource-conserving advancement of the ISMS
- High user acceptance: Business departments are actively involved through workflows that require little training
- Certification readiness: With support from the executive board, Techem prepared its ISO/IEC 27001 certification
- Extensible: Techem is evaluating whether further topics such as quality management can be mapped in NEXIS GRC