Contact Deutsch

ISiCO GmbH
Skip navigation
  • Privacy

    Get a head start with our optimal data protection consultancy

    Secure your competitive advantage with our business-focused data protection expertise.

    • Data Protection Consulting
      • Data Protection Impact Assessment (DPIA)
      • Threat Modelling
      • Data Breaches
      • Records of Processing Activities (ROPA)
      • Communication & Procedures with Authorities
      • Employee Data Protection
      • Data Protection Management System
      • Erasure and Archiving Policies
    • External Data Protection Officer
    • Data Protection Audits
    • EU Representative
    • Whistleblower Protection Act
  • IT Security

    Reliable protection for your company

    Make use of our expertise and customised IT security solutions to protect your digital assets.

    • External Information Security Officer (ISO)
    • ISMS
      • ISMS Service Package
      • ISMS Service Package NIS2
      • ISMS Service Package ISO 27001
      • ISMS Service Package TISAX
    • ISO 27001 Certification
    • Ransomware Protection
    • Risk Management
    • IT Compliance
    • NIS2
    • DORA
    • TISAX Certification
    • IT Forensics
    • Cyber Resilience Act
  • AI Consulting

    Gain a competitive edge with the best AI advice

    Secure your competitive advantage with our business-focused AI expertise.

    • ISO 42001 Certification
    • External AI Officer
  • Data Strategy

    Make the most of your data

    We will show you how to unlock the full potential of your company's data.

    • Develop Data Strategy
    • Maturity Assessment
    • Data Governance
    • Data Product
  • Solutions

    We create solutions for all challenges

    Whether you need advice on data protection management, its implementation, or employee training, we can provide the solution you need as part of a corporate network.

    • Workshops
    • DPO Coaching
    • Privacy Solution Software caralegal
    • E-Learning from lawpilots
  • Company

    Customised, efficient and business-oriented

    ISiCO is one of the top addresses in Germany for management consultancy in data protection, information security, AI and data strategies.

    • About ISiCO
    • Team
    • Offices
    • News
    • Contact
  • Make an appointment

18.08.2026

Creating an IT security concept in 7 steps

An IT security policy sets out how your organisation systematically manages the risks to its information. It is not merely a technical matter, but rather risk management at a senior management level. We will explain its structure, the seven steps involved in drawing it up, and the current legal framework.
Arrange a no-obligation initial consultation now
Your ISiCO-Expert:
Dr Jan Scharfenberg
Partner Information Security, Managing Director

What is an IT security concept?

An IT security concept is a comprehensive planning and governance instrument that companies use to systematically ensure the security of their information processing. It documents the assessment of risks and the selection of suitable technical and organisational measures, or TOMs, in order to achieve the fundamental protection objectives of confidentiality, integrity and availability.

Unlike a one-off security setup, the security concept does not merely describe current protective measures, but also how they are embedded in processes for continuous review and improvement. It is therefore an essential component of corporate governance in the digital world.

Distinction: IT security concept vs. ISMS

A common misunderstanding is to equate the IT security concept with an ISMS, or information security management system. The two are closely connected, but differ in focus: an ISMS defines the management structures and processes for the overarching governance of information security, while the security concept describes the specific measures within this framework. A good IT security concept is therefore an operational component of an ISMS.

For which companies is an IT security concept relevant?

An IT security concept is generally necessary for every company that relies on digital systems in practice, this means almost every company. Digitalisation now affects every sector: from a craft business using cloud-based order management to an international group with connected production systems.

Why every company needs a security concept

Even for small companies, attacks on IT systems can have existential consequences: data loss, business interruption or reputational damage. The availability and integrity of data are no longer “nice to have”; they are operationally essential. A security incident does not only affect IT it always affects finance, HR, production and legal as well.

Regulatory requirements are also increasing across sectors:

  • The GDPR requires “appropriate technical and organisational measures” under Article 32 GDPR.
  • The German IT Security Act 2.0 expands obligations for critical infrastructure operators and certain other companies.
  • The NIS2 Directive will establish requirements for security measures and reporting obligations for companies across a wide range of sectors throughout Europe.
  • New EU regulations such as DORA and the Cyber Resilience Act are aimed at specific sectors, but have a strong spillover effect on general security standards.
  • Creating an IT security concept helps companies meet these requirements in a structured and traceable way while also protecting them against economic damage caused by security incidents.

Free expertise in your e-mail inbox

All the important news on data protection, information security, AI and data strategy conveniently delivered to your e-mail inbox once a month - free of charge, of course. (Currently only available in German)

What is the sum of 8 and 3?

By clicking on the button, you consent to the sending of our newsletter and the aggregated usage analysis (opening rate and link clicks). You can revoke your consent at any time, e.g. via the unsubscribe link in the newsletter. More information: Privacy policy.

What makes a good IT security concept?

A convincing IT security concept is structured, complete and implementable. It should not merely exist on paper, but must be capable of being translated into concrete processes and measures.

Ideally, it includes:

  • a sound risk analysis with a traceable assessment of protection requirements,
  • the selection of appropriate security measures in line with the state of the art,
  • clear responsibilities for implementation and operation, and
  • a process for regular review and updating.

Integration into higher-level management systems is also important: an IT security concept must not remain an isolated document, but must become part of lived security management ideally embedded in an ISMS based on ISO/IEC 27001 or BSI IT-Grundschutz.

The PDCA cycle as a methodological framework

The PDCA cycle, Plan–Do–Check–Act, is a central component of professional security concepts. It enables security measures to be continuously improved and adapted to changing threat landscapes or corporate structures.

Plan

Protection requirements are analysed, threats are identified and risks are assessed. Appropriate measures are then selected on this basis. This step is strategic in nature: which risks is a company willing to accept? Which resources are available? Which legal requirements must be met?

Do

The defined measures are implemented technically and organisationally. This may include establishing a role-based authorisation system, introducing encryption technologies or firewalls, or providing awareness training for employees.

Check

Regular audits, monitoring processes and technical reviews, such as penetration tests, verify whether the measures are effective and deliver the desired level of protection. Deviations from defined standards are also identified at this stage.

Act

Based on the review results, corrective and improvement measures are initiated. The security concept is also adapted where framework conditions change for example, when new IT systems are introduced, business processes change or new legal requirements arise.

Information security that protects and thinks ahead

We don't just secure your systems; we also strengthen your structures. We provide well-thought-out IT security solutions that are tailored to your company and evolve alongside it.

Book your appointment now

Special considerations for modern technologies and threats

AI systems and IT security

The use of AI in companies raises new questions of information security. Systems used for decision automation are vulnerable to attack, in particular through manipulation of training data, known as data poisoning, or through manipulated inputs, known as adversarial inputs. The EU AI Act therefore requires companies to carry out risk assessments and documentation, especially for high-risk AI. These requirements must be reflected in the IT security concept.

Penetration testing as a control instrument

Penetration tests simulate real attacks on IT systems in order to uncover vulnerabilities in networks, applications and infrastructures. They are a central tool in the “Check” part of the PDCA cycle and are recommended or required by security standards and regulations, such as ISO 27001, NIS2 and DORA. Their results provide valuable input for the further development of the security concept.

New EU requirements: NIS2, DORA, CRA

These regulatory frameworks significantly tighten requirements for companies:

  • NIS2: reporting obligations, mandatory risk management including for supply chains, and application to many sectors.
  • DORA: stress tests, ICT risk management and mandatory monitoring of service providers in the financial sector.
  • CRA: cybersecurity obligations for manufacturers and distributors of digital products.

In future, security concepts must not only address internal IT, but also include external dependencies and software products.

Step-by-step guide to creating an IT security concept

An effective IT security concept is not created by applying checklists, but through a systematic, company-specific approach. The following steps are based on established standards such as ISO/IEC 27001, BSI IT-Grundschutz and current regulatory requirements.

1. Define the scope and organisational framework

Objective: clearly define which systems, processes and data are covered by the security concept.

Typical contents:

  • Description of the “information domain”: which IT systems, business processes, locations or organisational units are affected?
  • Definition of organisational responsibilities, for example by appointing an Information Security Officer, or ISO.
  • Publication and communication of an IT security policy by management.

Practical tip: avoid the mistake of trying to secure “everything” at once. Start with a clearly defined scope — for example, the CRM system or the HR department — and expand it iteratively.

2. Structural analysis and assessment of protection requirements

Objective: create transparency about the existing IT landscape and assess its protection requirements.

Steps:

  • Record all relevant IT systems, data flows, interfaces, servers, applications and mobile devices.
  • Assess protection requirements for each protection objective, confidentiality, integrity and availability, for each component.

Methods:

  • BSI protection requirement categories: normal, high and very high.
  • Involvement of business departments to assess operational impacts in the event of failure or compromise.

Practical tip: include real incidents or vulnerability reports from your own sector, such as CERT reports, BSI warnings or NVD databases. This increases the relevance and acceptance of the analysis.

3. Risk analysis

Objective: identify and assess threats and vulnerabilities on the basis of the protection requirements.

Approach:

  • Systematically record potential threats, such as malware, power outages, phishing or human error.
  • Analyse vulnerabilities in systems and processes.
  • Assess risk by combining likelihood of occurrence and severity of damage.

Tools:

  • Risk matrix, qualitative or quantitative.
  • BSI catalogue of standard threats or your own scenarios.

Practical tip: include real incidents or vulnerability reports from your own sector, such as CERT reports, BSI warnings or NVD databases. This increases the relevance and acceptance of the analysis.

4. Planning measures

Objective: develop a tailored and effective catalogue of security measures.

Principles:

  • Select suitable technical and organisational measures, or TOMs, for each identified risk.
  • Align measures with the state of the art, for example two-factor authentication or zero-trust concepts.
  • Prioritise: which measures can be implemented quickly and with high impact?

Examples:

  • Firewalls and network segmentation.
  • Encryption, both in transit and at rest.
  • Access controls based on the least-privilege principle.
  • Emergency concepts and backup strategies.
  • Awareness training for employees.

Practical tip: document the objective, owner, deadline and success indicator for each measure. This makes monitoring easier and creates transparency for auditors.

5. Implementation and integration into ongoing operations

Objective: transfer the measures plan into day-to-day business.

Success factors:

  • Secure resources: personnel, budget and external support.
  • Clearly define and document responsibilities.
  • Involve relevant stakeholders, including IT, business departments, data protection and the works council.
  • Train employees where necessary.

Practical tip: use project management methods for implementation, such as agile sprints for measure packages. A transparent roadmap increases acceptance within the company.

6. Control, review and incident management

Objective: ensure that the measures are effective and can be adjusted where necessary.

Measures:

  • Internal audits in accordance with ISO/IEC 27001 or BSI requirements.
  • Continuous monitoring of security-relevant systems, for example through SIEM.
  • Documentation and analysis of security incidents.
  • Regular penetration testing.

Practical tip: avoid merely “working through” compliance requirements. Develop a reporting system that presents the security situation to executives in an understandable way with KPIs, incident statistics and areas requiring action.

7. Continuous improvement, PDCA cycle

Objective: continuously adapt the security concept to technological developments, new threats and organisational changes.

Points of reference:

  • Evaluation after security-relevant projects, such as a new cloud architecture.
  • Lessons learned from security incidents.
  • Response to new regulatory requirements, such as DORA or NIS2.

Practical tip: plan fixed review cycles, for example annually or semi-annually. Define when the concept must be updated at a minimum — for example in the event of system changes, new business areas or external audits.

Responsibilities within the company

An IT security concept only works if responsibilities are clearly defined:

Function Responsible for
Management Strategic decisions, resources, security objectives
Information Security Officer, ISO Development, implementation and maintenance of the security concept
IT department Technical implementation, system hardening, network security
Data Protection Officer Alignment of TOMs with GDPR requirements, data protection impact assessments
Employees Implementing policies in day-to-day work, reporting security incidents

Legal and normative framework

An IT security concept should take the following standards and requirements into account:

  • Article 32 GDPR: security of personal data through appropriate technical and organisational measures.
  • German IT Security Act 2.0: minimum standards and obligation to implement attack detection for certain companies.
  • ISO/IEC 27001: certifiable ISMS and international standard.
  • BSI IT-Grundschutz: detailed catalogues of measures and structures for German organisations.
  • EU requirements: NIS2, DORA, CRA and the AI Act broadly influence security requirements.

Conclusion: IT security concepts are a strategic necessity

An IT security concept does not merely protect technical systems; it is an integral part of modern corporate governance. It combines legal certainty with operational resilience and creates the basis for trust both internally and externally.

Companies that build a structured, up-to-date and practical concept at an early stage secure a sustainable advantage. Those who ignore security risks, by contrast, expose themselves and others to incalculable dangers.

Recommendation: think about IT security strategically. And make the security concept a permanent part of your company’s DNA.

Information security that protects and thinks ahead

We don't just secure your systems; we also strengthen your structures. We provide well-thought-out IT security solutions that are tailored to your company and evolve alongside it.

Book your appointment now

Back to the news overview

Berlin
Köln
München

Ready for the next step?

+49 30 21300285-0
info@isico.de

Directly to get to know us

 

Outstanding work

ISiCO is also an active member of the German Association for Data Protection and Data Security (GDD) and the German Association for Information Technology, Telecommunications and New Media (Bitkom).

Top-Links
Skip navigation
  • External Data Protection Officer
  • Data Protection Management System
  • Data Strategy
  • Data Breaches
  • ISMS
Find out more
Skip navigation
  • About ISiCO
  • Contact

Language

DE EN

© ISiCO GmbH | Contact | Imprint | Privacy | Privacy Settings