How vent.io got ISO 27001 certified in half the time
“Working with consulting firms could have taken 50-80% more time to setup an ISMS. With DataGuard, we felt cared for and supported, even in challenging times.”
Georgios Gkekas, vent.io
This digital and innovation subsidiary of Deutsche Leasing AG used DataGuard to halve the estimated time for ISO 27001 certification and boosted information security awareness across the whole organisation. Here’s how.
Top 3 benefits for vent.io
They saved an estimated 50-80% time using DataGuard instead of consultants Document templates - Ready-to-use policy documents that vent.io could share with DataGuard experts, collaborate offline and save unnecessary meetings
They nailed their ISO audit first time and saved 100+ hours negotiating contracts following certification Audit preparation - Internal audit by DataGuard experts helped vent.io prepare for external audits and pass the ISO audit first time
They levelled up information security knowledge across the business DataGuard Academy - Used consistently as a top resource by vent.io team members to keep up with all the latest compliance practices
Help! I’ve got information security gaps in my vendor assessments...
Security is always a big deal for companies working in or around the Financial Services sector due to the sensitivity of the customer data. A fact not lost on vent.io – a digital and innovation subsidiary of Deutsche Leasing AG. The vent.io team had already built robust security practices around their software development offering, but they’d also found gaps in vendor assessments and risk management processes.
“Working with consulting firms could have taken 50-80% more time to setup an ISMS . With DataGuard, we felt cared for and supported, even in challenging times.”
Georgios Gkekas, CTO, vent.io
Always looking for proactive ways to improve, vent.io set to work on its ISO 27001 certification journey in 2023. There were two main strategic reasons: Not only would this fortify its overall security practices, but it would demonstrate vent.io’s commitment to excellence and position them as a trustworthy entity in the market.
Certification would also strengthen the bond of trust with its parent company, Deutsche Leasing, and safeguard project pipeline and revenue goals.
Why DataGuard?
Georgios Gkekas, Chief Technology Officer at vent.io, was already convinced of the need to secure ISO 27001 certification as early as possible. It would help protect the organisation from these risks and signal vent.io’s information security credentials to the market and other key stakeholders.
But why choose to partner with DataGuard?
There are several reasons, it turns out. But high on the list was the flexible nature of the DataGuard service. “The holistic approach of combining a secure platform with the support from real-life experts made us faster in this process,” says Georgios.
This created a ‘Goldilocks zone’ not offered by other consultants and one that was effective and manageable. The result? “We felt cared for and supported, even in challenging times,” Georgios says.
The benefits of partnering with DataGuard
The certification brought significant time savings in contractual negotiations. Georgios reckons ISO certification reduced contract negotiations by 20-30%. The time savings for more complex contracts could exceed 100 hours because of reduced reliance on security questionnaires and the resulting back-and-forth between stakeholders.
“ISO certification reduced time spent on contract negotiation by 20-30%”
The certification also made conversations with its parent company easier and positioned vent.io favourably in the broader market, where some customers demand the certification before agreeing to do business.
And people across the organisation have a better understanding of information security at vent.io - and the vital role they play in supporting it.
“With the advanced risk management, DataGuard has helped build a holistic view of all our 3rd party risks.”
Georgios Gkekas, CTO, vent.io
Continuous infosec improvement
This is just the beginning. “The effectiveness of security measures doesn’t solely rest on the shoulders of a few individuals with extensive knowledge,” says Georgios. Instead, it hinges on the collective awareness and understanding of security practices across the entire team and company. Not just today – but on an ongoing basis.
“Always assume a data breach,” Georgios reminds us. “Even the most advanced companies acknowledge the inevitability of potential attacks.” In future, the key lies in being prepared to react swiftly to security incidents, minimising downtime and swiftly restoring systems. “With the advanced risk management, DataGuard has helped build a holistic view of all our 3rd party risks.”
And we look forward to continuing to help vent.io to get compliant and stay compliant as it grows in the future.
About vent.io
As the digital and innovation subsidiary of Deutsche Leasing AG, vent.io develops and tests digital business models, products, and services. vent.io focuses on the areas of Asset Finance and Asset-related Services. Its goal is to support the growth of companies and make the business models of clients future-proof in times of digitization. Two approaches are pursued: vent.io collaborates with and invests in B2B startups, and concurrently develops digital customer and partner interfaces, implementing solutions with artificial intelligence.
INDUSTRY
Finance & Technology
NUMBER OF EMPLOYEES
10-50
LOCATION
Frankfurt
DATAGUARD PRODUCT
Infosec-as-a-service
It's time to get compliance right
We help your compliance run like clockwork with pragmatic, needs-based advice.
Get a quote
More Customer Success Stories
Don't just take our word for it
“Getting ISO 27001 certified was a critical step to demonstrate our commitment to the market that we manage data in the most efficient and secure way.”
“Working with consulting firms could have taken 50-80% more time to setup an ISMS. With DataGuard, we felt cared for and supported, even in challenging times.”
“Trying to find the right solution was a complete minefield. There was no understanding or empathy. We are dealing with sensitive data and needed extra help. Nobody took the time to really understand...
“Caring about data privacy is just common courtesy. It shows that you care just as much about your customers themselves as you do about them spending money with your company. If we only cared about...
“E-commerce is all about people. We do more than just store personal data: we monetize it. This makes it critical for us to stay on the safe side of data protection law. DataGuard helps us do exactly...
“DataGuard's team of privacy experts is what makes the difference. They don't just tell us "do it like this", they also explain why it should be done in a specific way – which helps broaden my team's...
“Parconomy’s solution is aimed primarily at parking garage operators and mobility providers – both municipal and commercial. Data privacy is a top priority for these target groups – and that's a good...
"Strong data protection practices are a great argument in favour of a company. People really care about this. And if customers care about it, then businesses need to care about it, too. With the help...
"The requirements with regard to data privacy and information security recently increased massively with our automotive customers, similarly to our industrial customers from other industries."
"With DataGuard, there’s a certain amount of hours included in our package. It covers the amount of questions that I have and gives me peace of mind that I won’t get a huge invoice at the end of the...
“We were introduced to DataGuard and they were able to provide us with the perfect solution at the time we needed it. DataGuard gives us peace of mind and helps us sleep well at night. If you want to...
“We chose a professional solution that covers a spectrum which an individual internal data protection officer cannot provide – neither in terms of expertise nor in terms of time."
“As a non-profit, we often work with so much personal data – names, email addresses, phone numbers, and more. We have to be on the safe side when it comes to privacy.”
“DataGuard allows us to automate responses which saves time and money. And if we ever have a question, they have a team of experts standing by to help. It is like having a pain reliever."
“Previously, all data privacy queries ended up on my desk. Now, the platform is the linchpin. Colleagues can find all their necessary to-dos, templates, documentation, and training courses easily and...
Use our web-based platform wasdeveloped to be used by anyone, even privacy novices. Work on compliance at your own pace, with the support of our experts always just a click away.