Customer story

CSN Solutions: Less evidence stress. More time for the actual ISMS.

CSN Solutions
Photo: CSN Solutions, data center in Schleswig-Holstein
Image credit: Photo: CSN Solutions, data center in Schleswig-Holstein
Company size
Commercial
Headquarters
EMEA
Industry
IT services
Use cases
ISO 27001
Evidence
Tasks
Risks
Audit

About CSN Solutions

CSN Solutions is the external IT department for mid-sized companies, public authorities and corporations. With its own data centers in Schleswig-Holstein, a clear focus on 100 % green IT and tailored managed services, CSN looks after highly sensitive, business-critical IT infrastructure. Information security is the foundation: CSN has been continuously certified to ISO/IEC 27001 for more than ten years.

csn-solutions.de

Challenge

An ISMS certified for more than ten years ran on SharePoint, Excel, tickets and network drives. As the company grew, those tools stopped scaling with it.

Solution

Kopexa connects controls, policies, tasks and evidence in one system and guides the team through daily ISMS work along clear audit trails.

Outcome

Continuous audit readiness during day-to-day operations and a recertification report that explicitly documents the use of Kopexa as a strength.

of ISO 27001 history, carried over without nonconformities
10+ years
of ISO 27001 mapped in Kopexa
100 %
additional in-house measures integrated
~100
until evidence sits on the right control
Seconds

Audit report

Documented as a strength by the auditor

Excerpt from the official audit report: Audit report, ISO/IEC 27001:2022 recertification

2.2 Strengths: the requirements of the standard(s) are exceeded

StandardRequirementTopicFindingRating
ISO 27001:20225.1Management processesManagement provides a tool (Kopexa) for documenting compliance and risk management.Strength

Details

The starting point: the ISMS worked, but it demanded too much attention

When a company has been certified for more than a decade, the challenge is not understanding the standard. The team around Information Security Officer Gunnar Mentzel knew every control question, every audit cycle and every required piece of evidence inside out.

Over the years, however, the ISMS had grown with the tools already installed on every computer: Microsoft SharePoint, Excel, Outlook and network drives.

That worked reliably for a long time. But with a growing customer base, new customer systems and more and more evidence, the setup reached its limits. A spreadsheet does not know who has to do what today. A folder does not know which control a piece of evidence belongs to. And as the security officer, you end up making sure everything fits together. CSN did not have a compliance problem. It had a scaling problem.

Where the ISMS wasted time every day

Even in a well-run security environment, the separate tools created noticeable friction:

  1. The classic evidence dilemma: Colleagues in IT operations produced important evidence every day, such as backup restore tests, firewall reviews or approvals. Yet the same questions kept coming up: Which subfolder does the file go into? How should it be named? Which spreadsheet row needs the link? As a result, evidence stayed on desktops or ended up in the wrong place.
  2. Tasks and evidence were disconnected: To-dos ran through tickets, emails or calendars. The evidence lived somewhere in SharePoint. There was no logical bridge between "What needs to be done?" and "Where is the valid evidence?".
  3. A lot of chasing for the security officer: Because the filing structure only existed in people's heads, Gunnar spent a lot of time following up with colleagues, renaming files and fixing outdated spreadsheet links.
  4. Audit preparation as a separate project: Before every recertification or surveillance audit the same routine repeated itself: verify document versions, reconcile approval dates, gather evidence.
  5. An administrative bottleneck: Simply managing files took up time that was missing for actual security work and risk assessment.

Why now? Growing compliance complexity

The trigger for the switch was not an acute audit problem but a look ahead.

As a modern managed service provider, CSN faces a steadily growing range of requirements. Alongside the existing ISO 27001, CSN plans to build out business continuity management (BCM), prepare for the NIS2 directive and bring in quality management (QMS).

The team knew: if managing a single standard already takes noticeable time, running several standards in separate spreadsheets and folders would only add more admin work.

What CSN needed: less searching, more steering

CSN did not want just a better document store. It was looking for a system that guides you and your team through daily ISMS work in a structured way. Five points made the difference:

  • Everything connected in one place: Policies, controls, operational evidence and responsibilities must not live in silos. Every piece of evidence should land in the right context.
  • Guidance instead of folder hunting: The software leads the user. Instead of memorizing folder paths, owners follow clear audit trails straight to the right action.
  • Capture evidence in seconds: The barrier for colleagues in IT operations has to be minimal. Evidence goes onto the control in a few clicks.
  • Built-in task management: Recurring controls hang as tasks directly on the respective control, with clear due dates, assignments and direct evidence upload.
  • Multi-standard capability: Besides the full ISO 27001, around 100 in-house measures and further standards in the future should fit on the same foundation.

CSN chose Kopexa.

“Because everything in Kopexa is linked and task management is built in, the system practically guides you through. For me, the real value is the focus I've gained: I no longer get lost in evidence management, and I have a clear head to assess risks more soundly and drive strategic topics like BCM, NIS2 and QMS.”
Gunnar MentzelInformation Security Officer, CSN SolutionsTranslated from the German original.

The switch: carry over what exists instead of starting from scratch

You do not change a management system lightly. It was essential that data center and support operations kept running seamlessly. Existing content was not reinvented but moved into a connected structure:

  1. Structure and standard mapping: The policies and controls built up over ten years were fully mapped in Kopexa, complemented by around 100 company-specific measures.
  2. Task management switched on: Recurring audit duties and security controls were set up as fixed tasks with named owners and due dates.
  3. Bringing the team on board: Colleagues in IT operations now upload evidence right when they complete a task. The security officer needs to chase far less, because Kopexa guides everyone through the necessary steps.
  4. The audit inside the platform: Instead of assembling folder bundles before the audit, CSN navigated through Kopexa together with the auditor.

The real test: recertification in the new system

The first ISO/IEC 27001:2022 recertification with Kopexa immediately showed how the new way of working holds up in an audit:

  • A guided audit: Auditor and security officer navigated directly through the relevant controls. Because evidence is linked to tasks and policies, it was available without delay.
  • Evidence filed in seconds: Without confusing file paths, the barrier for the team dropped noticeably. Today evidence lands on the right control within seconds when a task is completed.
  • Accountability in daily work: Everyone sees their open tasks, due dates are tracked and evidence lands in the intended place right away.
  • Less audit preparation: Because evidence is filed continuously during normal operations, far less searching, sorting and reconciling is needed before recertification.

That Kopexa makes daily work easier is not just internal feedback. In the official recertification report, the auditor recorded the use of Kopexa under "Strengths: the requirements of the standard(s) are exceeded". So in the audit, Kopexa was not just a tool. It was explicitly rated a strength.

What really changed

The biggest lever is not just the time saved maintaining the ISMS, but the quality of security management.

Today Gunnar does not just know where a piece of evidence is. Thanks to the connected view of controls, measures, responsibilities and evidence, he keeps track of the actual security posture and can assess risks in daily operations on a sounder basis.

At the same time, the platform delivers more impact with the same resources:

  • More standards on the same foundation: CSN's next topics, BCM, NIS2 and QMS, do not have to be built as new isolated solutions but can build on the same organizational structure.
  • Relief for IT operations: Security management turns from an annoying extra project into a guided routine running in the background.
  • Security that works day to day: The ISMS does not just live in documents and folders. It is part of daily IT operations and therefore traceable in the audit.

Before and after

Staff & IT operations

BeforeUnclear paths, searching, hesitating where to file

With KopexaFiling in seconds: evidence lands on the control when a task is completed

Security officer & governance

BeforeManual chasing, maintaining static spreadsheets

With KopexaBetter risk assessment: a reliable overview and more focus on BCM, NIS2 and QMS

External auditor

BeforeTedious evidence matching across scattered folders

With KopexaOfficially audited as a strength: auditors navigate the system in a structured way

Capabilities

Read more

See the capabilities CSN Solutions works with.