norm·werk

// ISO 27001 · ISMS · Information security

Information security, properly built.

norm-werk builds information security management systems that fit the organisation — not the other way around. Pragmatic, plain-spoken, no paper mountain and no tool lock-in.

// ISO 27001 / ISMS / Risiko­management / Awareness / Externer ISB

// Services

Four tools. One shared goal: information security that actually holds up.

norm-werk focuses on what works day-to-day. No off-the-shelf packages, just a small set of sharply scoped services that complement each other.

01 norm·werk

ISMS consulting & implementation

From first scoping through certification readiness: we build your information security management system step by step — aligned with ISO/IEC 27001 and shaped around what your business actually needs.

  • Scope, context and stakeholder clarity
  • Risk assessment and prioritised treatment
  • Lean policies and procedures
  • Support up to the external certification audit
02 norm·werk

External ISO / ISMS officer

You need accountability, not a full-time hire. I step in as your external Information Security Officer — operationally responsible, with a clear reporting line into management.

  • Management reviews and reporting
  • Single point of contact for auditors and authorities
  • Action and risk tracking
  • Continuous improvement of your ISMS
03 norm·werk

IT & project advisory with a security lens

Security belongs in the project, not after go-live. For cloud migrations, vendor changes or new platforms, I bring the security perspective in early — before it gets expensive.

  • Requirements and architecture reviews
  • Vendor and cloud assessments
  • Hands-on support inside running IT projects
  • Sparring partner for CIO/CTO
04 norm·werk

Training & awareness

Security is behaviour, not paperwork. Tailored formats for leadership, IT teams and staff — clear, useful, and without the wagging finger.

  • Management briefings (60–90 min)
  • Team awareness workshops
  • Onboarding modules for new hires
  • Phishing and incident exercises on request

Note: I deliberately do not perform external certification audits myself — independence matters. Instead I work closely with experienced certification bodies and support you all the way up to the audit.

// How we work

Five steps from idea to structures that hold.

A clear approach is half the work. norm-werk follows a model that has proven itself in practice — lean enough for SMEs, thorough enough for certification.

  1. 01

    Intro call

    Free, no strings attached. We clarify what you need, possible paths and whether we fit. Around 30 minutes.

  2. 02

    Baseline assessment

    Where are you today? We review existing structures, documents and processes — and name gaps, risks and quick wins honestly.

  3. 03

    Roadmap

    You receive a prioritised plan with realistic effort and timing. No castles in the sky — a list you can actually work through.

  4. 04

    Implementation

    We deliver together — with your team, not around it. Responsibilities stay transparent, documents stay readable.

  5. 05

    Operation & evolution

    An ISMS is a living thing. On request I stay involved afterwards — as external ISO, in management reviews, or simply as a reliable point of contact.

// Who it fits

For organisations that take security seriously — and effort realistically.

The collaboration is a particularly good fit for:

  • 01

    Mid-sized companies with 50–500 employees that need structure without corporate overhead.

  • 02

    Organisations facing compliance demands from customers, regulators or a parent company.

  • 03

    IT departments without a dedicated security role looking for an experienced external lead.

  • 04

    Leadership teams that want to approach ISO 27001 without getting lost in tools and paperwork.

// Myths

Five persistent misconceptions about information security.

The same assumptions come up in nearly every first conversation. Here are the most common ones — and how I see them.

Mythos 01

"ISO 27001 is only for large corporations."

// Realität

The standard is deliberately written to scale. A well-tailored ISMS for an 80-person company looks different from a DAX-listed group — but it works.

Mythos 02

"We first need an expensive GRC tool."

// Realität

Tools help once the structure is in place. Without a concept they just produce expensive documents. For starting out, spreadsheets, templates and a clear head are usually enough.

Mythos 03

"This will be a year of paperwork."

// Realität

Documents are a means, not an end. norm-werk keeps policies short enough that people actually read — and live by — them.

Mythos 04

"One audit is enough — then we're secure."

// Realität

An audit is a snapshot. Security is a process. An ISMS lives on continuous care, not one-off heroics.

Mythos 05

"Information security is IT's problem."

// Realität

Responsibility sits with leadership. IT implements — but decisions, budgets and risk appetite belong at the top.

Portrait of Oliver Müller — norm-werk // portrait

// About

Behind norm-werk there is a person — not a consulting machine.

[Placeholder] For more than [X] years I have worked at the intersection of IT, project work and information security. norm-werk bundles that experience into one clear offer: consulting that lands — technically deep, plainly spoken.

[Placeholder] My standard: security has to fit the organisation, not the other way around. A good ISMS is not the one with the most documents — it is the one still in use long after the auditor has gone home.

// Qualifikation
  • [Placeholder] ISO/IEC 27001 Lead Implementer
  • [Placeholder] Further relevant qualifications
  • [Placeholder] Industry focus / specific experience

// FAQ

Questions that come up in almost every first call.

01 What is the difference between consulting and an audit?
Consulting builds, an audit checks. Both have their place — but for independence reasons they should not sit in the same hands. norm-werk deliberately stays on the consulting side and works with independent certification bodies.
02 How long does it take to be ready for certification?
Realistically six to twelve months — depending on size, maturity and the capacity you can free up internally. In the baseline assessment you get an honest estimate instead of a wish number.
03 Is ISO 27001 even worthwhile for an SME?
If customers, parent group or regulators require it: usually yes, clearly. If not, a "leaning on the standard" approach often makes more sense — using the structure of the norm without immediately chasing the certificate.
04 Do we really need external consulting — wouldn't a tool do?
Tools help, but they don't replace understanding. Without a clear concept they mostly produce documents nobody reads. Consulting pays off most where structure is missing.
05 How does the collaboration actually work?
After a free intro call you receive a clear proposal with an effort estimate. Work happens remote, hybrid or on-site — depending on need and location.

// Contact

Let's talk for 30 minutes — no commitment.

Tell me briefly where you stand and what is coming up. I usually get back within one business day.

Send an email Prefer a phone call? That works too — the number is in the footer.