# ISO 27001, guaranteed | Secured by FM CyberSecurity

> Large customers and public buyers want to see ISO 27001 before they sign. We take you all the way, with a guarantee. One vendor, one contract, one price.

Source: https://fmcybersecurity.com/en/secured/
Locale: English
Other locale: https://fmcybersecurity.com/secured/

Large customers and public buyers want to see ISO 27001 before they sign. Secured by FM CyberSecurity takes on the whole job: our own SOC around the clock, a vCISO who keeps you on track, and a full package of security products. One vendor, one contract, one price.

## How it works

You do not need your own security team. We set up the tools, run them and tell you what to do next.

- Onboarding: We set up CrowdStrike, Tenable and Aikido in your organization. The setup follows the ISO 27001 requirements.
- You get access: The tools are yours to look into. You see the same as we do: alerts, vulnerabilities and status, whenever you want.
- We run them: FM CyberSecurity operates the platforms for you. Our own SOC, built on CrowdStrike, monitors and responds around the clock.
- Advice and reporting: Your vCISO gives advice and helps you with tenders. Every month you get a report on status and what we recommend next.

## What you get

The whole package, delivered as one service.

- Our own 24/7 SOC: Our own SOC monitors and responds around the clock. Built on CrowdStrike, run by FM CyberSecurity.
- Exposure management: Tenable finds and prioritizes vulnerabilities across your systems. You see what needs fixing first.
- Application security: Aikido secures the code you build. FM CyberSecurity produces pentest reports you can show your customers.
- vCISO: A senior security advisor who knows your business and sets priorities with you.
- Monthly reports: Every month you get a report: status, incidents, vulnerabilities and what we recommend next.
- GRC tool: One place for controls, evidence and audit trail. Everything the auditor needs to see, ready for the audit.

## How the guarantee works

ISO 27001 is the proof customers and tenders ask for. We build the management system, the documentation and the controls together with you. If the audit does not go through within the agreed time, we cover the next attempt.

*Gross negligence on the customer side voids the guarantee.

The work counts twice: the same controls are the documentation you need for NIS2.

## Built for organizations that want to win bigger contracts

- Organizations with around 100 employees or fewer.
- You lose tenders because you lack ISO 27001 certification.
- You do not have your own security team, and you do not need to build one.
- You are covered by NIS2, or you supply someone who is.

## Certification-ready in roughly four weeks

Four weeks is a typical run. The pace depends on your organization.

- Week 1, Onboarding: We map your organization and set up CrowdStrike, Tenable and Aikido.
- Week 2, Up and running: The tools are live. Controls and documentation take shape in the GRC tool.
- Week 3 to 4, Certification-ready: The management system is in place. You are ready for the audit.
- After that, The audit: An accredited certification body performs the audit. This is where the guarantee applies.

## Common questions

- Who monitors our systems at night? Our own SOC at FM CyberSecurity monitors and responds around the clock, built on CrowdStrike. Your vCISO takes the findings forward with you.
- What happens if the audit does not pass? Then FM CyberSecurity covers your next certification attempt. Gross negligence on the customer side voids the guarantee.
- What does it cost? One price covers the tools, the operations, the vCISO and the certification work. Send us a message and we will price it for your organization.
- How fast can we get certified? A typical run is certification-ready in roughly four weeks. The audit itself is performed by an accredited certification body after that.

---

For the full documentation index, see https://fmcybersecurity.com/llms.txt
For the complete corpus as a single document, see https://fmcybersecurity.com/llms-full.txt
