You will be ISO 27001 certified. We guarantee it.
Large customers and public buyers want to see ISO 27001 before they sign. Secured by FM CyberSecurity takes on the whole job: our own SOC around the clock, a vCISO who keeps you on track, and a full package of security products. One vendor, one contract, one price.
How it works
You do not need your own security team. We set up the tools, run them and tell you what to do next.
- 01
Onboarding
We set up CrowdStrike, Tenable and Aikido in your organization. The setup follows the ISO 27001 requirements.
- 02
You get access
The tools are yours to look into. You see the same as we do: alerts, vulnerabilities and status, whenever you want.
- 03
We run them
FM CyberSecurity operates the platforms for you. Our own SOC, built on CrowdStrike, monitors and responds around the clock.
- 04
Advice and reporting
Your vCISO gives advice and helps you with tenders. Every month you get a report on status and what we recommend next.
What you get
The whole package, delivered as one service.
Our own 24/7 SOC
Our own SOC monitors and responds around the clock. Built on CrowdStrike, run by FM CyberSecurity.
Exposure management
Tenable finds and prioritizes vulnerabilities across your systems. You see what needs fixing first.
Application security
Aikido secures the code you build. FM CyberSecurity produces pentest reports you can show your customers.
vCISO
A senior security advisor who knows your business and sets priorities with you.
Monthly reports
Every month you get a report: status, incidents, vulnerabilities and what we recommend next.
GRC tool
One place for controls, evidence and audit trail. Everything the auditor needs to see, ready for the audit.
How the guarantee works
ISO 27001 is the proof customers and tenders ask for. We build the management system, the documentation and the controls together with you. If the audit does not go through within the agreed time, we cover the next attempt.
*Gross negligence on the customer side voids the guarantee.
The work counts twice: the same controls are the documentation you need for NIS2.
Built for organizations that want to win bigger contracts
- Organizations with around 100 employees or fewer.
- You lose tenders because you lack ISO 27001 certification.
- You do not have your own security team, and you do not need to build one.
- You are covered by NIS2, or you supply someone who is.
Certification-ready in roughly four weeks
Four weeks is a typical run. The pace depends on your organization.
- Week 1
Onboarding
We map your organization and set up CrowdStrike, Tenable and Aikido.
- Week 2
Up and running
The tools are live. Controls and documentation take shape in the GRC tool.
- Week 3 to 4
Certification-ready
The management system is in place. You are ready for the audit.
- After that
The audit
An accredited certification body performs the audit. This is where the guarantee applies.
Common questions
- Who monitors our systems at night?
- Our own SOC at FM CyberSecurity monitors and responds around the clock, built on CrowdStrike. Your vCISO takes the findings forward with you.
- What happens if the audit does not pass?
- Then FM CyberSecurity covers your next certification attempt. Gross negligence on the customer side voids the guarantee.
- What does it cost?
- One price covers the tools, the operations, the vCISO and the certification work. Send us a message and we will price it for your organization.
- How fast can we get certified?
- A typical run is certification-ready in roughly four weeks. The audit itself is performed by an accredited certification body after that.