A board-level route in which NIS2, the Governance Code Social Work, internal control and supplier management are brought together.
The organisation
A medium-sized social organisation in the social care and community services works with residents, clients, municipalities, health and welfare organisations and various cooperation partners. The organisation has over a hundred employees and fulfils a public and social mission.
The reason
Within the organisation, attention was already paid to privacy, information and technical security. The central question, however, was wider:
How do we ensure that information security becomes a demonstrable part of governance, oversight, internal control and daily implementation?
Step 1: Boardroom session for Board and Supervisory Board
Kynexis Information Security started an interactive boardroom session on the board-level significance of NIS2, governance and oversight responsibilities, continuity and reputation risks, chain dependencies and connection to the Social Work Governance Code 2025.
Governance Code Social Work as a board-level framework
The code provided leads for social legitimacy, role purity, risk management, digital transformation, cybersecurity, data, AI, supplier dependencies and periodic accountability.
Step 2: GAP analysis information security and governance
The GAP analysis combined relevant elements of the Social Work Governance Code 2025 with selected topics from ISO 27001. The analysis focused on board-level responsibility, policy, roles, risk management, privacy, suppliers, incident management, continuity, awareness and reporting.
What went well?
- a recognisable mission in society;
- staff involved and short lines;
- basic technical measures;
- attention to privacy and information;
- a movement towards ISO 9001;
- awareness and quality management initiatives.
The main finding
Many subjects were given attention in practice, but coherence, ownership, prioritisation and reporting were not sufficiently clearly defined. As a result, measures and decision-making remained too personal.
An executable order for the improvement actions
1. Critical business processes
First, it was determined which processes are crucial for service, personal data, continuity, file registration, supplier dependencies and incident handling.
2. Information security policy
A compact policy followed with scope, principles, roles, procedures and reporting lines.
3. RACI and mandates
By process, application, supplier and incident route it had to be made clear who is responsible, executive, advisory, decision-making and controlling.
4. Asset registration
The organisation needed to gain insight into applications, equipment, data collections, suppliers and links.
5. Cyber Risk Analysis
Per risk, it was necessary to choose between mitigation, acceptance, transfer or avoidance.
6. Incident response and continuity
RTO, RPO, recovery sequence, escalation, communication, supplier roles and restoration tests were identified as necessary follow-up steps.
7. Suppliers Management
Supplier assessment had to become a permanent part of procurement, contracting, renewal and annual evaluation.
Temporary CISO support
Temporary CISO support was advised for programme management, basic policies, manuals, risk analysis, supplier assessment, incident response and board-level reporting.
The result
- a shared board-level conceptual framework;
- a GAP analysis on governance and information security;
- 20 priority management actions;
- a route of implementation for the first 12 months;
- recommendations for critical processes, policies and RACI;
- an approach to asset registration and risk analysis;
- Improvement points for suppliers, incident response and continuity;
- a proposal for temporary CISO direction.
Why this approach worked
First, board-level involvement was created, then it was examined where the organisation really stood and then a realistic order was determined.
Also perform a GAP analysis information security?
- Boardroom sessions for Board and Supervisory Board
- GAP Information Security Analyses
- Governance code Social work
- Information security risk analysis and risk analysis
- RACI, Supplier Management and CISO as a Service


