A board-level route in which NIS2, the Governance Code Social Work, internal control and supplier management are brought together.

The organisation

A medium-sized social organisation in the social care and community services works with residents, clients, municipalities, health and welfare organisations and various cooperation partners. The organisation has over a hundred employees and fulfils a public and social mission.

The reason

Within the organisation, attention was already paid to privacy, information and technical security. The central question, however, was wider:

How do we ensure that information security becomes a demonstrable part of governance, oversight, internal control and daily implementation?

Step 1: Boardroom session for Board and Supervisory Board

Kynexis Information Security started an interactive boardroom session on the board-level significance of NIS2, governance and oversight responsibilities, continuity and reputation risks, chain dependencies and connection to the Social Work Governance Code 2025.

Governance Code Social Work as a board-level framework

The code provided leads for social legitimacy, role purity, risk management, digital transformation, cybersecurity, data, AI, supplier dependencies and periodic accountability.

Step 2: GAP analysis information security and governance

The GAP analysis combined relevant elements of the Social Work Governance Code 2025 with selected topics from ISO 27001. The analysis focused on board-level responsibility, policy, roles, risk management, privacy, suppliers, incident management, continuity, awareness and reporting.

What went well?

  • a recognisable mission in society;
  • staff involved and short lines;
  • basic technical measures;
  • attention to privacy and information;
  • a movement towards ISO 9001;
  • awareness and quality management initiatives.

The main finding

Many subjects were given attention in practice, but coherence, ownership, prioritisation and reporting were not sufficiently clearly defined. As a result, measures and decision-making remained too personal.

An executable order for the improvement actions

1. Critical business processes

First, it was determined which processes are crucial for service, personal data, continuity, file registration, supplier dependencies and incident handling.

2. Information security policy

A compact policy followed with scope, principles, roles, procedures and reporting lines.

3. RACI and mandates

By process, application, supplier and incident route it had to be made clear who is responsible, executive, advisory, decision-making and controlling.

4. Asset registration

The organisation needed to gain insight into applications, equipment, data collections, suppliers and links.

5. Cyber Risk Analysis

Per risk, it was necessary to choose between mitigation, acceptance, transfer or avoidance.

6. Incident response and continuity

RTO, RPO, recovery sequence, escalation, communication, supplier roles and restoration tests were identified as necessary follow-up steps.

7. Suppliers Management

Supplier assessment had to become a permanent part of procurement, contracting, renewal and annual evaluation.

Temporary CISO support

Temporary CISO support was advised for programme management, basic policies, manuals, risk analysis, supplier assessment, incident response and board-level reporting.

The result

  • a shared board-level conceptual framework;
  • a GAP analysis on governance and information security;
  • 20 priority management actions;
  • a route of implementation for the first 12 months;
  • recommendations for critical processes, policies and RACI;
  • an approach to asset registration and risk analysis;
  • Improvement points for suppliers, incident response and continuity;
  • a proposal for temporary CISO direction.

Why this approach worked

First, board-level involvement was created, then it was examined where the organisation really stood and then a realistic order was determined.

Also perform a GAP analysis information security?

  • Boardroom sessions for Board and Supervisory Board
  • GAP Information Security Analyses
  • Governance code Social work
  • Information security risk analysis and risk analysis
  • RACI, Supplier Management and CISO as a Service