Grundfos achieves ISO 27001 certification through strategic collaboration and business-focused change management
With help from kaastrup|andersen’s experienced project manager and consultant, Grundfos achieves ISO 27001 certification within a tight timeframe.
The project enhances information security, drives organisational improvements, and ensures compliance. The project’s great success is largely due to the focus not only on technology and systems but also on creating real business value through close collaboration, honest advice, and strategic change management.
Challenge: A complex project with high ambitions
In late 2022, Grundfos decided to implement ISO 27001 as part of its digital strategy. The goal is to strengthen the company’s information and cybersecurity and meet the increasing customer demands for compliance.
The task is to establish an Information Security Management System (ISMS) that encompasses the entire organisation, including governance, policies, and processes related to information and cybersecurity. Additionally, policies and processes
must be implemented within the certification scope.
The certification scope includes: Development, operation, maintenance, and support of digital products and solutions.
Success criteria:
- Build on existing frameworks: Deliverables must be based on existing policies and business processes and integrated with Grundfos’ existing management systems (Integrated Management System and Quality Management System)
- Scalability: It is essential to create a practical and scalable solution that is applicable in daily operations and can be implemented across a larger portion of the company in the future
- Real improvements: The certification must lead to tangible improvements that strengthen maturity and security, rather than being merely a compliance exercise
- Strict timeline: The certification must be achieved by the end of 2024
Challenges:
- Cross-organisational task: Grundfos’ size and global organisation make the project complex. The size and cross-organisational nature of the stakeholder landscape require engagement and alignment at the management level, as well as extensive follow-up and coordination at the operational level for success
- Resource availability: The availability of internal key resources is a limiting factor and must be considered when creating the project plan
Grundfos asks kaastrup|andersen for help in the form of an experienced project manager and an ISO 27001 specialist to ensure the success of the project.
"Under kaastrup|andersen’s leadership and guidance, we have made significant progress in improving our information security framework. Their strategic vision, structured approach, and ability to tackle challenges have truly been remarkable."
Jonas Åkeson
Vice President, Digital Development, Grundfos
Solution: A holistic approach to project management
kaastrup|andersen’s experienced project manager and ISO 27001 specialist drive the project with an approach that focuses just as much on people and business processes as on technology. They know that achieving success requires more than simply selecting the right systems. It necessitates changes in Grundfos’ way of working, the defined roles and responsibilities, and, not least, changes in people’s behaviour.
A tailored project methodology:
Overall, the project manager from kaastrup|andersen uses PRINCE2 as the project framework. However, the project plan is largely built around the requirements of the ISO 27001 standard, taking into account the organisation’s level of information security, available resources, and, not least, the ambition level.
The goal of achieving certification by the end of 2024 requires a flexible plan, but strict control. Planning is a complex process that requires a deep understanding of Grundfos’ organisation, stakeholders, and business processes.
With a clear project plan, comprehensive stakeholder management, and continuous project risk management, the project manager from kaastrup|andersen, in collaboration with Grundfos, ensures that the solutions both meet the ISO 27001 standard and create real business value.
"It is absolutely crucial to the success of the project that we maintain a strong focus on people and change management to ensure that all employees understand the purpose of the ISO 27001 certification. The goal is to foster a culture where information security becomes a natural part of daily operations. Implementing ISO 27001 changes the way the organisation works, making it essential to ensure that all employees comprehend the purpose, rationale, and significance of these changes."
Peter Budolfsen
Senior Project Manager, kaastrup|andersen a/s
The preparatory work involves:
- Establishing an overview of the organisational context, including a stakeholder analysis and clarification of roles and responsibilities
- Forming a steering committee and developing a business case and project scope
- Conducting a GAP analysis
- Assembling a project team
The plan in brief:
- Establishing a risk management process and identifying information assets (assets)
- Conducting risk assessments and adjusting information security policies based on all 93 controls in the ISO 27001 standard
- Gradual implementation of policy requirements into business processes, ensuring flexibility in the plan and distributing the workload among key personnel over time
- Ongoing internal audits to evaluate the implementation effort and ensure proper prioritisation
"Establishing a project team and a steering committee in a complex organisation with distributed responsibilities is a challenging task. Roles and responsibilities often overlap across organisational units and management levels, resulting in an extensive stakeholder landscape and a correspondingly large steering committee with diverse interests."
Peter Budolfsen
Senior Project Manager, kaastrup|andersen
Multiple iterations
A task of this nature requires constant change readiness from the project manager and the organisation’s stakeholders, as well as revisiting previous assumptions and making adjustments accordingly.
This creates a need for:
- Continuous training and education for employees and managers
- Ongoing adjustments to governance, roles, and responsibilities both horisontally and vertically
- Continual adaptation of business processes and procedures
"We challenge Grundfos’ existing processes when necessary and provide honest and bold advice. Our goal is to deliver the best possible solutions that are both practical and value-creating."
Thomas Hæstrup
Senior Consultant, Specialist in the ISO 27001 standard, kaastrup|andersen a/s
Result: A certification that creates value
Certification without remarks
In November 2024, following two external audits, Grundfos achieves their goal of ISO 27001 certification for “Development, operation, maintenance, and support of digital products and solutions.”
"The implementation of ISO 27001 helps us comply with regulatory requirements, build trust with stakeholders, and gain a competitive advantage.
The certification enhances our brand reputation, reduces the likelihood of costly security breaches, and fosters a culture of security within the organisation.
It also increases awareness of the purpose and importance of information and cyber security across the organisation, while establishing a shared language and forums to address these matter effectively across all levels."
Jonas Åkeson
Vice President, Digital Development, Grundfos
The core of the certification
ISO 27001 certification signifies that Grundfos adheres to the highest international standards for managing information security. It demonstrates Grundfos’ commitment to protecting sensitive data, managing risks effectively, and continuously improving security practices.
The certification ensures that Grundfos’ development processes, digital products, and solutions are built with security at their core. It enhances the Secure Software Development Lifecycle (SDLC), ensuring that Grundfos’ digital products and solutions are secure from the design phase and effectively safeguard customer data.
It also supports the ongoing improvement of Grundfos’ security practices to adapt to the evolving threat landscape, making their digital products and solutions more reliable and trustworthy.
"For our customers, achieving ISO 27001 certification provides assurance that their data is handled with the utmost care and security.
It builds trust and confidence, demonstrating that we prioritise their privacy and are committed to protecting their information against potential threats."
Jonas Åkeson
Vice President, Digital Development, Grundfos
At kaastrup|andersen, we understand that projects are more than just technology and systems. They are about people and creating value across the organisation. We ensure that your company experiences a predictable and successful process with a focus on business success.
We make it easier and smarter for your organisation to adopt new systems by prioritising change management and collaboration. With us as your partner, you can confidently navigate complex digital projects and achieve results that truly make a difference.