Codepurple Logo Codepurple Logo Codepurple Logo
  • Services
  • Blog
  • About us
  • Contact
  • de
  • /

  • en
  • Language:

  • de
  • /

  • en

IT Security Officer / CISO

Are you looking for support in developing an information security strategy? With our extensive training and experience, we support you from defining an information security policy through the planning and implementation of an Information Security Management System (ISMS) to successful execution.

Contact Codepurple

How can we support you?

With more than 20 years of experience in IT, spanning both software development and business, combined with a solid background in management, we take a holistic view of organizations. This enables us to connect the different parts of a business, identify interdependencies, and see the bigger picture.
We bring our experience and an external perspective to the table, serving as a trusted sparring partner who challenges ideas, provides fresh insights, and helps you make well-informed decisions.

Support in the implementation of standards

In information security, there are numerous standards and frameworks that organizations can use to strengthen their security posture. The most widely adopted include ISO/IEC 27001, the NIST Cybersecurity Framework (NIST CSF), the ICT Minimum Standard, and the BSI IT Baseline Protection (IT-Grundschutz).

The individual standards have different levels of detail but are largely overlapping. The choice of which standard to adopt depends on the specific goals of the company.

Advantages:

  • Improving information security
  • Increasing resilience
  • Establishing processes
  • Empowering the company

What does an IT Security Officer do?

The primary responsibilities of an IT Security Officer include:

  • Develop and maintain the information security policy.
  • Develop information security strategies.
  • Analyze security risks
  • Train employees
  • Review and assess the effectiveness of implemented security measures
  • Handle security incidents.

How is information security positioned within your organization? To establish a baseline and identify concrete quick wins, we assess the current state of your organization. This assessment does not only focus on technical aspects but also places strong emphasis on the supporting processes.

Why does that help me?

If you lack resources or experience, our specialists can bring their input to your company. We focus on your needs and work with you to find the right format to tackle the issues.

Establishing security processes vs. Implementing security measures

Processes define the “how” by establishing binding guidelines, responsibilities, roles, and contingency plans for the organization.
Measures protect the “now” by reducing existing risks through the use of technologies, configurations, and controls.
Only when theory (processes) and practice (measures) seamlessly work together can true resilience be achieved.

What is the result?

Together with you, we develop an information security policy that serves as the foundation for all further IT security processes. We support you in defining processes, creating documentation, implementing processes, monitoring and reviewing their effectiveness, continuously improving them, and training employees.

Support in establishing an ISMS

Are you planning to set up an information security management system or are you already on the way to doing so? We can support you with valuable input and experience. We not only understand the management view and processes, but also the technical side with all its complexity.

Contact Codepurple

In cybersecurity, the rule is simple: later is too late.

Source: Codepurple

Do you have any questions or would you like an appointment?

Kathrin Müller is looking forward to hearing from you and will be happy to organize a meeting according to your needs.

Contact

nanio GmbH (Codepurple)
Moosweg 24
5606 Dintikon

+41 79 823 45 30
rhino@codepurple.ch

Follow us

Linekdin

Imprint| Privacy| © Codepurple 2026. All rights reserved