ICT & Media

How TAGGRS implemented ISO 27001 in 4 months

How do you ensure information security keeps pace with a rapidly growing scale-up? Discover how TAGGRS created structure, buy-in, and control around ISO 27001 in 4 months.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Highlights van dit succesverhaal

In 4 maanden
Naar succesvolle ISO 27001 certificering
Afname securityvragenlijsten
Meer vertrouwen bij klanten door aantoonbare informatiebeveiliging.
Volledig geborgd ISMS
Van ongedocumenteerde processen naar aantoonbare ISO 27001-structuur.
Client
TAGGRS
Standards
ISO 27001
Involved consultants

The reason

This is a body. Lorem ipsum by sit amet, consecteur adipising elite. Suspendisse varius enim in eros elementum tristique. German course, mi quis viverra ornare

TAGGRS is a rapidly growing platform that helps organizations collect and manage marketing data and tracking in a privacy-friendly way. The company operates at the intersection of data, marketing technology, and privacy, where careful handling of personal data is essential. Because TAGGRS works with sensitive customer and user data, information security and privacy (GDPR) are not just prerequisites, but the most crucial component of its service. As the company grew, it became increasingly important not only to implement this well technically, but also to demonstrably and structurally secure it in accordance with ISO 27001.

Growing pains, unwritten rules, and the call for structure

Due to TAGGRS's rapid growth, the need for structure and demonstrable information security also increased. While many processes were already running smoothly in practice, this wasn't always documented or consistently secured. Much knowledge resided within the organization itself, but not in systems or documentation. As a result, things often had to be re-explained or re-investigated, which became increasingly less scalable.

 

“There were many unwritten rules. Everything ran smoothly, but it wasn't documented anywhere,” says Edwin Remery, ISO Manager at TAGGRS.

 

At the same time, customers were increasingly asking questions about information security and privacy. Not just in the form of individual questions, but also extensive questionnaires that required demonstrable answers.

 

This created a clear need: not just to comply with ISO 27001, but to genuinely organize it in a demonstrable and structural way. An additional challenge was that the standard itself wasn't always easy to interpret. Translating requirements into concrete practical measures proved complex, especially in an organization that was rapidly evolving.

Download the ISO 27001 Checklist

The new ISO 27001:2022 requirements are clearly identified, including all Annex A components, directly applicable and free to download as a PDF.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Our approach

This is a body. Lorem ipsum by sit amet, consecteur adipising elite. Suspendisse varius enim in eros elementum tristique. German course, mi quis viverra ornare

Creating structure and buy-in in a rapidly growing scale-up

It quickly became clear to TAGGRS that they needed more than just advice or audit preparation. The organization sought a partner who could not only explain ISO 27001, but, more importantly, practically translate it into the company's daily reality. The challenge wasn't just achieving certification, but rather structurally setting up and securing processes within a rapidly growing organization.

 

“An auditor is not allowed to give advice. That's why it's good to have a party that can help with interpretation and practical guidance,” says Edwin Remery.

 

Fendix was therefore chosen as the implementation partner. The collaboration began with a GAP analysis to clearly identify the organization's current position and what steps were needed towards mature information security. From there, work proceeded step-by-step on setting up the ISMS and preparing for audits. The focus was not just on paper compliance, but primarily on how processes actually work in practice and are applied by employees.

 

From interpretation to practical implementation

During the initial phase, weekly alignment sessions of approximately one hour were held. These frequent touchpoints ensured speed, direct coordination, and the swift resolution of open questions. As the project advanced, these shifted to bi-weekly, two-hour sessions. This allowed for more in-depth discussion, the development of specific measures, and the practical testing of implementations.

 

“Texts from the standard can be quite challenging to read. It's helpful when someone can explain what it concretely means for your organization,” Edwin notes.

 

Throughout the project, Fendix remained the dedicated point of contact for interpretation and clarification. Initially, TAGGRS used Word and Excel to structure actions and tasks. This process was further professionalized during the project with the transition to Notion, enabling information security and compliance to be managed more centrally and consistently.

 

Furthermore, there was a deliberate focus on internal communication. During monthly sessions, employees were informed about new measures and their underlying rationale. This fostered greater understanding, buy-in, and engagement within the organization. Throughout the entire project, the emphasis was not merely on implementing measures, but crucially on understanding, applying, and embedding them into the organizational culture.

 

TAGGRS showed great willingness, and deadlines were taken seriously. Moreover, the team consistently brought concrete questions to the sessions, enabling us to provide highly targeted feedback and make rapid progress. According to Ruben den Dulk, who had the privilege of guiding TAGGRS as a consultant, a successful ISO 27001 project isn't solely about documentation or compliance, but primarily about fostering buy-in and ensuring practical applicability within the organization.

“You can perfectly document processes, but if employees don't understand why certain measures exist or how to work with them, information security remains merely theoretical. It's precisely that practical application that makes all the difference.”

Therefore, throughout the project, the focus was not only on implementing measures but also on making them comprehensible to the organization itself.

This is a body. Lorem ipsum by sit amet, consecteur adipising elite. Suspendisse varius enim in eros elementum tristique. German course, mi quis viverra ornare
  • 01

  • 02

  • 03

  • 04

  • 05

  • 06

  • 07

  • 08

This is a body. Lorem ipsum by sit amet, consecteur adipising elite. Suspendisse varius enim in eros elementum tristique. German course, mi quis viverra ornare

Next-Gen Consultant speaking

“You can perfectly document processes, but if employees don't understand why certain measures exist or how to work with them, information security remains merely theoretical. It's precisely that practical application that makes all the difference.”

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Ruben
den Dulk
Information Security and Privacy Consultant

The results

This is a body. Lorem ipsum by sit amet, consecteur adipising elite. Suspendisse varius enim in eros elementum tristique. German course, mi quis viverra ornare

Fewer security questionnaires, more customer trust

Within approximately four months, TAGGRS made significant progress in professionalizing information security and structurally embedding ISO 27001. One of the most immediate effects was seen in customer interactions. Thanks to the improved information security framework, the number of extensive security questionnaires noticeably decreased, as TAGGRS could now demonstrably (through ISO 27001 certification) show how its processes and measures are structured.

 

“Customer trust has genuinely increased. You notice that you have to explain far less, because everything is simply in place.”

 

Internally, a clear step towards professionalization was also achieved. Processes have been documented, such as employee onboarding and offboarding,  

security measures have been expanded, and the organization is better equipped to work consistently according to agreed standards.

 

At the audit level, progress became tangibly visible. The number of identified deficiencies decreased from five during the initial certification audit to two during the latest surveillance audit, demonstrating the organization's active commitment to continuous improvement.

“An auditor is not allowed to give advice. That's why it's so helpful to have a party that can assist with interpretation and practical guidance.”

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Edwin Remery
Information Security Officer
“An auditor is not allowed to give advice. That's why it's so helpful to have a party that can assist with interpretation and practical guidance.”

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Edwin Remery
Information Security Officer
This is a body. Lorem ipsum by sit amet, consecteur adipising elite. Suspendisse varius enim in eros elementum tristique. German course, mi quis viverra ornare

Continuous improvement as a standard operating procedure

For TAGGRS, information security is no longer just a small, separate project for IT to handle. It has become an integral part of the organization and its way of working. And that is precisely where the strength of the ISO 27001 framework lies: not in a one-time certification, but in the continuous, structured evaluation and improvement of processes, measures, and responsibilities within the organization.

 

At TAGGRS, this is achieved through periodic management reviews, internal audits, evaluations of measures, and recurring sessions with employees, among other things. As a result, information security is not limited to documentation or compliance, but becomes part of daily practice.

 

Furthermore, TAGGRS's continued growth ensures that requirements and risks are constantly evolving. This is precisely why it's crucial to have a structure that is flexible enough to adapt without losing its foundation.

 

Within this context, Fendix remains involved as a sparring partner and guide, including for annual internal audits and further optimization of the ISMS. This ensures that information security not only stays in order but also continues to develop towards an increasingly mature level.

 

“Due to the company's growth, requirements are constantly changing. Now we have a structure that allows us to adapt to those changes.”

 

Is your organization also growing rapidly, and are you tired of security questionnaires? Then an ISO 27001 implementation will help you, just like it helped TAGGRS. We have successfully assisted 100% of our clients. Feel free to contact Fendix to discuss the possibilities.

Involved consultants

Ruben
Renter
Marketing Specialist
This is a body. Lorem ipsum by sit amet, consecteur adipising elite. Suspendisse varius enim in eros elementum tristique. German course, mi quis viverra ornare

Kilian Houthuijzen

Commercial Manager

Kilian

Houthuijzen

Commercial Manager & Partner

Is your organization also growing rapidly, and are you tired of security questionnaires?

Contact us for a free introduction.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Other success stories

Healthcare
GGZ Western Noord-Brabant

How GGZ Westelijk Noord-Brabant structured information security

NEN 7510
AVG/GDPR
Enterprise
Heras

Heras achieves ISO 27001 certification within one year with worry-free implementation

ISO 27001
Enterprise
Total Energies

How Total Energies Charging Solutions Netherlands obtained more than one certificate with the implementation of ISO 27001

ISO 27001
ICT & Media
Nedscaper

With Nedscaper to an ISO 9001 and ISO 27001 certificate in 12 weeks

ISO 27001
ISO 9001
Healthcare
Stap & Care Group

Towards ISO 27001 and NEN 7510 certification with Stap & Care Group

ISO 27001
NEN 7510
Enterprise
Goose VPN

Interactive cybersecurity week at GOOSE VPN

ISO 27001
ICT & Media
Now Online

NowOnline's Choice for an Interim Security Officer from Fendix

ISO 27001
ICT & Media
SPL

From start-up to ISO 27001 and NEN 7510 certificate in 6 months

ISO 27001
NEN 7510