Intro
Sven Dessel:
DataGuard makes our work enormously easier. It gives us centralized risk management, and I can link it to the management systems we already have in place—systems specialized in different areas, like rolling stock operations, quality management, or sustainability and certification, all of which are areas we work in.
I'm the Coordinator for Data Protection, Information Security, and Regulatory Affairs at Railpool. We lease locomotives across Europe, and in that role I coordinate regulatory requirements with our business processes.
What compliance challenges are you facing right now?
NIS2 applies to us, and so do the Cyber Resilience Act and the EU AI Act. We're dealing with the Data Act as well—basically the full range of regulations. That left us with the challenge of finding a partner flexible enough to go into all these different regulations with us, advise us, and also provide a system platform where we could map it all out. And map it in a way—this was the real challenge—that connects regulatory content that sometimes complements and sometimes overlaps, so we don't end up generating duplicate regulations and policies.
What did you need from a partner and a platform?
What we asked of DataGuard here was, first, a system platform that brings all of these topics together—all the regulations, policies, and risk management—in one central place. That means we don't have to worry about administering the entire framework, or frameworks, and the management system.
The second decisive factor was having consultants on hand, including for topics we haven't focused on as much yet. When NIS2 first appeared on the horizon, we could pass those questions to the consultants, and they carried the answers into the company.
And I think the third important aspect is that DataGuard has grown along with us and with its product.
How did DataGuard support you in implementing NIS2?
With NIS2, the challenge wasn't only implementing regulations. Other organizational challenges came up as well—there were much more direct requirements around supply chain management and around management accountability. That's where we saw the advantage of the DataGuard platform: we could take ISO 27001, which we already had in place, and simply extend the relevant risks to cover NIS2, add to them and classify them, so we could keep the different regulations in a single system, tiered by class. Essentially, we got a solid foundation for whatever regulations come next—the confidence that we're working in a secure, compact system that helps us keep managing all of this.
What value does the DataGuard platform add to your day-to-day work?
Above all, DataGuard keeps me from starting at zero every time. When a new regulation comes in that we have to look at, I'm not starting from scratch—I can build on the platform and add the new regulation there.
What has been the biggest highlight of working with DataGuard?
The big highlight is definitely having a technology platform where we can integrate everything we've built so far. We don't have to stop and ask ourselves where to put a new regulation—we just build on what's already there. And I think the other big thing is that from day one, the consultants helped us build a regulatory system that isn't rigid—not something that merely gets you through an audit, but a system you can actually live with. Short, concise documentation, concise policies. Especially in information security, it mattered to me that we describe our own processes, not just what the standard prescribes.
We also went our own way a bit. In line with the standard, of course. But I think that was the real highlight—that we found our own way of doing it.