ISO 27001 – how Vertec is committed to security every day

30.10.2024
|

The security of (customer) data is particularly important for IT companies. At Vertec, we attach great importance to information security and use an information security management system in accordance with ISO 27001, hereinafter also referred to as ISMS. But what benefit do our customers and ourselves derive from certification according to the ISO 27001 system? How Vertec handles the establishment, implementation, maintenance and continuous improvement of an ISMS is described in this article.

Vertec is certified to recognized standards.

What is ISO 27001?

One of the objectives of the ISO 27001 standard is for organizations to prevent information security risks by taking appropriate security measures. A key point of the standard is the identification of all company-internal assets (the so-called assets). At Vertec, these include things as diverse as our Cloud Suite infrastructure, our own HR or the source code of our software.
The importance of assets is assessed on the basis of three key criteria. These are:

  • Availability: How important is it that the asset is always available?
  • Confidentiality: How important is it that no unauthorized person can access the asset?
  • Integrity: How important is it that the asset cannot be adjusted?

In a second step, the risks are collected and assessed for all assets. We do this on a scenario-based basis: Typical Risks are, for example, unreadable backups or the infection of a computer with an encryption Trojan.

What specific measures are included in the standard?

In order to effectively counter the greatest risks, we adopt appropriate measures. We are committed to preventing unreadable backups by regularly restoring data from backups for testing purposes. We protect ourselves against encryption trojans by, among other things, using anti-virus software and regularly updating our clients and servers.

These risks are very real: there have been cases where customers have been unable to use their backups because they were either not made in the first place or were not readable. Some companies in our environment have also caught Trojans, resulting in all data stored on server drives being encrypted and having to be recovered from backups.

Residual risks remain even after measures have been implemented. From time to time, small risks have to be consciously accepted, because such measures would be far too expensive or too time-consuming. Once a year, existing risks are reassessed, and asset managers must explicitly state whether they want to bear their risks in this way or whether further measures should be planned.

Of course, assets and risks are constantly changing. The standard also requires that you constantly develop, review and improve your system. To this end, it is important that all employees report incidents with regard to information security. In addition, there are binding guidelines for all employees that regulate, among other things, the handling of customer data and access to customer systems.

Once a year, an external auditor checks whether Vertec implements the management system according to the settings and meets all requirements for maintaining the certificate.

What good is that for us as a company?

An ISO 27001 certification not only offers added value to our customers, we also benefit from many advantages:

  • Improving security: It shows that we identify our risks and have implemented appropriate security measures. The certification also guarantees regular review and adaptation of risks and measures.
  • Gain trust: Customers see our long-standing commitment to ISO 27001 as a quality mark and proof of security, which creates trust and is often a prerequisite for business partnerships.
  • Legal compliance: Helps you comply with legal and regulatory requirements to protect customer data.

The added value for you as a Vertec customer

Thanks to the internationally valid ISO 27001 certificate, we can guarantee our customers that their data is handled with care. It is no coincidence that the corresponding asset “customer data” is one of the most important of all for us.

For more information Regulation on order data processing how we comply with the data protection obligations under the DSGVO for EU customers and the DSG and VDSG for Swiss customers and how we process personal data in the context of the contractual relationship, please refer to our Data protection at vertec Policy.

Another significant asset for us is the security of the Vertec application itself. We regularly have the security verified by penetration tests and have implemented a variety of measures to secure our product – also with regard to the Cloud Suite. For the Cloud Suite, we have therefore also deliberately opted for Subcontractor who are also ISO 27001 certified.

Our ISMS was and still is very valuable in setting up and expanding the cloud subscription infrastructure. Since our customers’ data is stored externally and the servers belong to an external service provider, there are a multitude of risks, measures and issues that need to be clarified and implemented. The ISMS helps us to address these issues in a structured and consistent manner. What Vertec does specifically for Cloud Suite security is described in our blog article “Security in the vertec cloud suite – a look behind the scenes”.

Success factor Employee awareness

Even the most sophisticated technical security solutions are of little use if security issues are not anchored in the employees’ consciousness and they perceive the ISMS only as a burdensome duty.

A strong security culture is critical to ensuring the best possible protection of customer data. At Vertec, we not only rely on technical measures, but also regularly train our employees in many aspects of information security. These trainings familiarize employees with the relevant threats and security standards, and anchor the awareness of data security in their daily work.

We discuss current developments and security risks on a monthly basis, thereby increasing the awareness and vigilance of our employees in handling sensitive data. In this way, we reduce potential security risks and ensure that your data is well protected at all times.

Through this ongoing training, you as a customer benefit from a team that is highly aware and well prepared. Our employees can react quickly to new threats and play an active role in shaping information security at Vertec.

None
04.08.2026

The review package for future-proof Vertec installations

Make your Vertec installation future proof with our help. With the new review package.
None
21.07.2026

Environmental management at Vertec

Where does a software company have the greatest environmental impact? Ute Heimann gives insight into how Vertec uses environmental management to create transparent, gain insights and derive concrete measures.
None
15.07.2026

How to Use AI Features in Vertec with Full Sovereignty

How to leverage AI features in Vertec with models hosted in Europe.
None
11.05.2026

Has structured data died with the AI revolution?

LLMs are very good at dealing with unstructured data. Does this also happen with structured data?
None
26.03.2026

Automated AML check in Vertec

How Vertec and Legalian are revolutionizing money laundering checks in law firms
None
13.03.2026

AI in Vertec: the new LLM Client in Python 3

With the new LLM client in Python 3, attractive AI use cases are opening up in Vertec.
None
05.03.2026

Update capability and adaptability in Vertec: a technical area of tension

Vertec preserves individual customizations even across updates — but this protection requires a conscious approach to customization to ensure long-term benefit from product innovation.
Claudio Pietra, Geschäftsführer Vertec Gruppe
04.03.2026

30 years as a software entrepreneur

What I've learned in 30 years as a software entrepreneur.

Netherlands

United Kingdom