2 Days. 10+ Experts. Countless IAM & GRC Insights. Register for NEXIS INVOLVE | September 9-10 | Regensburg

Energy

Techem Builds a Resilient Information Security and Risk Management System with NEXIS GRC

Techem implemented NEXIS GRC to build a company-wide, standardized ISMS, assess risks on a valid data foundation, and continuously advance its security maturity.
Energy

About Techem

Techem is an international leader in energy billing and energy management. In Germany, the company is the market leader in consumption-based metering and billing of heat and water for the real estate industry. Its range of services spans energy procurement, the metering and billing of heat and water consumption, and detailed analytics.

As one of the leading service partners for green and smart buildings, Techem focuses on energy efficiency across the entire real estate value chain and promotes healthy living, process efficiency, and climate protection. From its headquarters in Eschborn, the company manages its worldwide operations.

  • Headquarters: Eschborn, Germany
  • Employees: ~ 3,750
  • Presence: ~150 Locations Worldwide, in more than 20 European Countries as well as Brazil and the United Arab Emirates
  • Billing: ~ 11 Million Households

With NEXIS GRC, Techem was able to

Build a Company-Wide, Standardized ISMS

Establish a consistent approach across the entire organization that delivers comparable, valid results.

Assess Risks on a Reliable Data Foundation

Capture threats and vulnerabilities in a structured way and assess them per asset with full traceability.

Measure and Advance ISMS Maturity

Assess the controls from ISO/IEC 27001 Annex A by maturity level and derive a Statement of Applicability from them.

Fully Map ISO/IEC 27001 and 27005

Implement all information security and risk management requirements in a single solution.

Actively Involve Business Departments

Achieve high user acceptance beyond IT through workflow-supported processes that require little training.

Operate the ISMS Efficiently

Continuously monitor, document, and evidence security activities with minimal use of resources.

The Challenge

Techem wanted to build a capable information security management system to assess risks on a lasting and efficient basis. From this assessment, the company wanted to derive risk treatment measures and to measure and advance its activities based on maturity.

A central requirement was a company-wide, standardized approach that delivers comparable, valid data as a basis for decisions. The task was complex and the requirements were broad. It therefore became clear early on that professional software support is more economical and efficient than running an ISMS with in-house means or building a custom solution.

The goal was to:

  • Build a capable, company-wide standardized ISMS
  • Assess risks on a lasting and efficient basis and derive treatment measures
  • Measure activities by maturity and continuously advance them
  • Produce comparable, valid data as a basis for decisions
  • Find modern, database-supported, and flexibly adaptable software support that can be rolled out step by step across the entire organization

The approach

Techem and Nexis structured the project along the ISMS lifecycle (Plan, Do, Check, Act) and configured NEXIS GRC step by step to Techem’s requirements.

Requirements Definition and Selection of NEXIS

Techem first defined the criteria for the software selection. NEXIS GRC stood out with its database-supported web application, which already offers extensive standard content while remaining flexibly adaptable through customization. Operation with little training required, comprehensive workflow support, and a company-wide standardized methodology completed the picture.

Plan Phase: Structure and Scope

Based on ISO/IEC 27001 and ISO/IEC 27005, the teams captured the entire legal entity structure and the areas under review in NEXIS GRC. The teams imported authorized employees from Active Directory; these employees sign in via single sign-on. Techem then adopted its guidelines and policies, transferred them into the system, and linked them to the controls from ISO/IEC 27001.

Check Phase: Maturity Assessment and Statement of Applicability

The teams assessed the controls from ISO/IEC 27001 Annex A by maturity level and derived the Statement of Applicability (SoA) from them. This created a transparent basis to measure the state of information security and advance it in a targeted way.

Do Phase: Processes, Assets, and Protection Needs

The teams linked core processes with information objects and assessed them for confidentiality, integrity, and availability. These classifications determined the protection needs of the associated assets. Using customized threat and vulnerability catalogs, Techem assessed the risks per asset and documented them in a risk treatment plan.

Act Phase: Involving the Business Departments

The user-friendly workflows in NEXIS GRC require little training. They enabled a smooth involvement of the business departments in the process assessment and delivered high user acceptance beyond IT, which continuously improves the ISMS.

The Result

With NEXIS GRC, Techem introduced an information security and risk management system through which all associated activities are consistently carried out, documented, and evidenced without gaps. The insights from the implementation enable compliance- and risk-relevant decisions on a valid data foundation. The collaboration with Nexis proved trustworthy and competent across all project phases.

  • Valid data foundation: Compliance- and risk-relevant decisions rest on comparable, valid data
  • Complete traceability: All security activities are consistently carried out, documented, and evidenced
  • Resource-efficient operation: The maturity view enables continuous monitoring and a resource-conserving advancement of the ISMS
  • High user acceptance: Business departments are actively involved through workflows that require little training
  • Certification readiness: With support from the executive board, Techem prepared its ISO/IEC 27001 certification
  • Extensible: Techem is evaluating whether further topics such as quality management can be mapped in NEXIS GRC

See How Software-Supported Security Management Works in Practice

Learn how NEXIS GRC helps organizations build their ISMS on a valid data foundation, assess risks with full traceability, and continuously advance their security maturity.