Information Security

What exactly is information security?

Information security is the set of measures you take to ensure that company information remains available, accurate, and confidential. We also call this the CIA classification. These three factors determine how strictly you need to secure a system or dataset. This classification is also an important part of GDPR compliance and the protection of personal data.

It is not just about your servers and laptops, but equally about data security, the contract in the filing cabinet, the database export that someone puts on a private laptop, and the employee who (un)knowingly forwards information via email.

Availability

Your information must be available the moment you need it. If your administration or order system goes down for a day, your business or process grinds to a halt. This can be caused by human error as well as by becoming infected with ransomware. Availability is therefore just as much about backups and recovery as it is about keeping attackers out.

Integrity

Information must be accurate and cannot be modified unnoticed. A modified account number on an invoice is the classic example: nothing leaks, nothing is lost, and yet the money goes to the wrong party. Integrity therefore requires checking whether anything has been changed and having logging in place so you can see what happened afterward.

Confidentiality

You should only be able to read and modify information if you are authorized to do so. That sounds obvious, but at many companies, every employee can access almost every file. This is because it was set up that way at some point and never cleaned up. Confidentiality is therefore an important element of data security and starts with restricting access rights. Who is allowed to access what, and why?

Information security versus cybersecurity

These two terms are often used interchangeably, but they do not mean the same thing. Cybersecurity is about protecting digital systems and networks from attacks. Information security is the broader umbrella: it covers all company information, digital or otherwise, as well as the agreements and behavior surrounding it.

The overlap between the two

Most of your information is digital these days, so cybersecurity largely overlaps with information security. If you have your digital side in order, you have covered the most critical part of your information security.
Access management and passwords
Incident detection and response
Logging that allows you to reconstruct what happened after the fact

Why the scope is broader than just IT

Information security doesn't stop at your network or servers. Project documents left on a train or a supplier with excessive system access—neither of these is a technical problem, yet both can cost you information or cause indirect damage. That is why people, processes, and suppliers should be just as much in scope as your technology.
People: awareness, behavior, and clear agreements
Processes: who is authorized to do what, and who oversees it
Technology: servers, laptops, email, applications, and more

Our role in your information security

Information security consists of technology, people, and processes. We focus on the area where things often go wrong in practice: the moment something happens in your environment that needs to be detected and stopped.
In addition, we provide advice on information security. We do this together with our partners.

Technical measures such as MDR and password management

MDR stands for Managed Detection & Response: we continuously monitor your systems, laptops, and users, identify suspicious behavior, and intervene before it becomes an incident. In addition, we get your password management in order with 1Password. These are two measures that address confidentiality and availability.

Policies and procedures

An information security policy defines who has access to what, how you handle incidents, and what you expect from employees. Without these agreements, technology does not align with the business. After all, an alert that no one follows up on solves nothing. We provide the practical evidence for this: every four months, we discuss what we have observed in your environment during a CyberCheck-In, allowing you to adjust your policies and procedures based on what is actually happening.

Demonstrably complying with laws and regulations

The Cyber Security Act has been in effect since August 15, 2026. Companies falling under this act are subject to registration, duty of care, and reporting obligations for serious incidents. Even if you are not directly covered by it, you may still be affected through your partners. We provide assistance so you can demonstrate what happened and how you responded.

Why you need MDR.

ISO 27001 is the international standard for information security. Certification demonstrates that your organization takes information security seriously and systematically embeds it into policies, processes, and technology.

What ISO 27001 entails

The standard is all about accountability; you know your risks, you document measures in an information security policy, and you continue to improve. In practice, this comes down to three things:
Systematic risk management and comprehensive documentation
Independent external audit and official certification
Continuous improvement of your security level

How we provide support

ISO 27001 requires demonstrable control, and part of that evidence comes from your day-to-day security. We provide advice on information security, continuous monitoring, and incident handling, including the associated reporting. This allows you to fulfill the parts of the standard related to detection, incident management, and logging, ensuring that during an audit, you have documented facts rather than just anecdotal stories.

ISO 27001:2022 A.5.28 Evidence, A6.8 Reporting
In the center of the circle is ISO 27001, surrounded by broken lines connecting the terms control, audit, risk, and policy to ISO 27001

Common information security mistakes

The incidents we see rarely start with a spectacular attack. Usually, a cyberattack begins with an employee falling for phishing, systems connected directly to the internet, or old accounts with excessive permissions. The points below are often missing and are what we see most frequently in practice.

No up-to-date overview of assets

Improper use of passwords

No incident response plan

What are the benefits of good information security?

The remaining question is what tangible benefits good information security provides when you work with us. Here is what you get in return:
ISO 27001 · A.8.15

Activity logging

Everything that happens in your environment is recorded: logins, changes in permissions, and suspicious processes. Without logging, you won't know what happened after an incident; with logging, you can investigate and prove it.
ISO 27001 · A.8.16

Monitoring of networks, applications, and systems

Your network, applications, and systems are monitored continuously, even outside office hours. You don't need to keep up with the latest threat news—we handle all new detection rules for you.
ISO 27001 · A.5.24

Incident preparation

An incident is not a matter of if, but when. That is why we establish in advance who to call, what we are authorized to isolate or shut down, and which steps to take in what order. By being prepared, we can act much faster when things go wrong.
ISO 27001 · A.6.8

Incident reporting

Reporting security incidents is just as important as detecting them. Our service provides an easy, accessible way for employees to report security incidents, enabling us to act faster and minimize impact.
ISO 27001 · A.5.27

Lessons learned

For major incidents, we work with you to analyze how it happened and what can be done to prevent it. We translate those findings into a concrete plan, allowing your company to demonstrate that you have learned from the experience.
ISO 27001 · A.5.28

Evidence

When your client, insurer, or auditor asks how your security is managed, you won't have to improvise. You can show exactly what happened, when it was detected, and how it was addressed. Demonstrability is a key component here.

Request a free cybersecurity scan

The free scan maps out your Microsoft 365 environment and monitoring, giving you a clear view of your company's security posture. Enter your email address below to get a concrete overview of all vulnerabilities and pitfalls in your detection and response.

Thanks! We will contact you within one business day to schedule your scan.
Something went wrong while sending. Feel free to email us directly.
There are no strings attached and the report is completely free.
Microsoft 365
High

Multi-Factor Authentication (MFA) not enforced for all accounts

Example finding
Resolution time: 1 day
Endpoint & monitoring
Medium

Email security not configured correctly

Example finding
Resolution time: 5 days

Frequently asked questions about information security (FAQ)

What does information security entail?

+

What is the difference between information security and cybersecurity?

+

Does Peakproteqt also help with ISO 27001?

+

What are the first steps toward good information security?

+

Is information security mandatory for my company?

+