Een vrijblijvend adviesgesprek plannen
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript


How TAGGRS implemented ISO 27001 in 4 months
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript
Highlights van dit succesverhaal

The reason
TAGGRS is a rapidly growing platform that helps organizations collect and manage marketing data and tracking in a privacy-friendly way. The company operates at the intersection of data, marketing technology, and privacy, where careful handling of personal data is essential. Because TAGGRS works with sensitive customer and user data, information security and privacy (GDPR) are not just prerequisites, but the most crucial component of its service. As the company grew, it became increasingly important not only to implement this well technically, but also to demonstrably and structurally secure it in accordance with ISO 27001.
Growing pains, unwritten rules, and the call for structure
Due to TAGGRS's rapid growth, the need for structure and demonstrable information security also increased. While many processes were already running smoothly in practice, this wasn't always documented or consistently secured. Much knowledge resided within the organization itself, but not in systems or documentation. As a result, things often had to be re-explained or re-investigated, which became increasingly less scalable.
“There were many unwritten rules. Everything ran smoothly, but it wasn't documented anywhere,” says Edwin Remery, ISO Manager at TAGGRS.
At the same time, customers were increasingly asking questions about information security and privacy. Not just in the form of individual questions, but also extensive questionnaires that required demonstrable answers.
This created a clear need: not just to comply with ISO 27001, but to genuinely organize it in a demonstrable and structural way. An additional challenge was that the standard itself wasn't always easy to interpret. Translating requirements into concrete practical measures proved complex, especially in an organization that was rapidly evolving.



Download the ISO 27001 Checklist
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript
Our approach
Creating structure and buy-in in a rapidly growing scale-up
It quickly became clear to TAGGRS that they needed more than just advice or audit preparation. The organization sought a partner who could not only explain ISO 27001, but, more importantly, practically translate it into the company's daily reality. The challenge wasn't just achieving certification, but rather structurally setting up and securing processes within a rapidly growing organization.
“An auditor is not allowed to give advice. That's why it's good to have a party that can help with interpretation and practical guidance,” says Edwin Remery.
Fendix was therefore chosen as the implementation partner. The collaboration began with a GAP analysis to clearly identify the organization's current position and what steps were needed towards mature information security. From there, work proceeded step-by-step on setting up the ISMS and preparing for audits. The focus was not just on paper compliance, but primarily on how processes actually work in practice and are applied by employees.
From interpretation to practical implementation
During the initial phase, weekly alignment sessions of approximately one hour were held. These frequent touchpoints ensured speed, direct coordination, and the swift resolution of open questions. As the project advanced, these shifted to bi-weekly, two-hour sessions. This allowed for more in-depth discussion, the development of specific measures, and the practical testing of implementations.
“Texts from the standard can be quite challenging to read. It's helpful when someone can explain what it concretely means for your organization,” Edwin notes.
Throughout the project, Fendix remained the dedicated point of contact for interpretation and clarification. Initially, TAGGRS used Word and Excel to structure actions and tasks. This process was further professionalized during the project with the transition to Notion, enabling information security and compliance to be managed more centrally and consistently.
Furthermore, there was a deliberate focus on internal communication. During monthly sessions, employees were informed about new measures and their underlying rationale. This fostered greater understanding, buy-in, and engagement within the organization. Throughout the entire project, the emphasis was not merely on implementing measures, but crucially on understanding, applying, and embedding them into the organizational culture.
TAGGRS showed great willingness, and deadlines were taken seriously. Moreover, the team consistently brought concrete questions to the sessions, enabling us to provide highly targeted feedback and make rapid progress. According to Ruben den Dulk, who had the privilege of guiding TAGGRS as a consultant, a successful ISO 27001 project isn't solely about documentation or compliance, but primarily about fostering buy-in and ensuring practical applicability within the organization.
“You can perfectly document processes, but if employees don't understand why certain measures exist or how to work with them, information security remains merely theoretical. It's precisely that practical application that makes all the difference.”
Therefore, throughout the project, the focus was not only on implementing measures but also on making them comprehensible to the organization itself.
- 01
- 02
- 03
- 04
- 05
- 06
- 07
- 08
Next-Gen Consultant speaking

Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript

The results
Fewer security questionnaires, more customer trust
Within approximately four months, TAGGRS made significant progress in professionalizing information security and structurally embedding ISO 27001. One of the most immediate effects was seen in customer interactions. Thanks to the improved information security framework, the number of extensive security questionnaires noticeably decreased, as TAGGRS could now demonstrably (through ISO 27001 certification) show how its processes and measures are structured.
“Customer trust has genuinely increased. You notice that you have to explain far less, because everything is simply in place.”
Internally, a clear step towards professionalization was also achieved. Processes have been documented, such as employee onboarding and offboarding,
security measures have been expanded, and the organization is better equipped to work consistently according to agreed standards.
At the audit level, progress became tangibly visible. The number of identified deficiencies decreased from five during the initial certification audit to two during the latest surveillance audit, demonstrating the organization's active commitment to continuous improvement.
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript


Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript

Continuous improvement as a standard operating procedure
For TAGGRS, information security is no longer just a small, separate project for IT to handle. It has become an integral part of the organization and its way of working. And that is precisely where the strength of the ISO 27001 framework lies: not in a one-time certification, but in the continuous, structured evaluation and improvement of processes, measures, and responsibilities within the organization.
At TAGGRS, this is achieved through periodic management reviews, internal audits, evaluations of measures, and recurring sessions with employees, among other things. As a result, information security is not limited to documentation or compliance, but becomes part of daily practice.
Furthermore, TAGGRS's continued growth ensures that requirements and risks are constantly evolving. This is precisely why it's crucial to have a structure that is flexible enough to adapt without losing its foundation.
Within this context, Fendix remains involved as a sparring partner and guide, including for annual internal audits and further optimization of the ISMS. This ensures that information security not only stays in order but also continues to develop towards an increasingly mature level.
“Due to the company's growth, requirements are constantly changing. Now we have a structure that allows us to adapt to those changes.”
Is your organization also growing rapidly, and are you tired of security questionnaires? Then an ISO 27001 implementation will help you, just like it helped TAGGRS. We have successfully assisted 100% of our clients. Feel free to contact Fendix to discuss the possibilities.
Involved consultants

Kilian Houthuijzen
Commercial Manager
Kilian
Houthuijzen
Commercial Manager & Partner

Is your organization also growing rapidly, and are you tired of security questionnaires?
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript
























