SERVICES TAILORED TO YOUR BUSINESS NEEDS
SecWed helps businesses manage information security and data protection compliance.
INFORMATION SECURITY
Our services cover information security and cybersecurity audits, training, development and implementation, as well as ongoing information security management services. We also support businesses with ISO 27001 certification and implementation, as well as ensuring compliance with the NIS2 Directive.
Information Security Assessments
We help businesses identify gaps in information security and cybersecurity and implement the measures needed to strengthen and maintain their security posture.
- Information security current-state assessment
- Practical risk analysis
- Information security maturity assessment
- Development roadmap and action plan
Information Security Management System (ISO 27001 ISMS)
We help businesses put information security management into practice through concrete, hands-on measures.
- Information security development project management and expert services
- Implementation and documentation of an information security management model
- Project scheduling and progress monitoring
- Making the benefits tangible
- Quality assurance
Information Security and Cybersecurity Management as an Ongoing Service
For many businesses, information security management does not require a full-time role.
We provide a tailored information security officer service based on your business needs.
- Information security officer as a service, from a few days per month
- Incident management
- Risk assessment and management
- Establishing and maintaining an information security management model
- Annual information security management cycle
- Onboarding, training and development of security awareness
- Information security support in development projects and partner relationships, including contract management
DATA PROTECTION
Data protection audits, development and management, as well as training to meet the requirements of the General Data Protection Regulation (GDPR).
Data Protection Pre-Assessment
A preliminary assessment of your organisation’s data protection practices.
- Data protection self-assessment and onboarding
- Collection and documentation of preliminary information related to the processing of personal data
- Identification and assessment of the organisation’s data protection capabilities
Data Protection Current-State Analysis and Situation Overview
The current-state analysis includes the following activities:
- Analysis of the pre-assessment and self-assessment, including compliance gaps and deviations from requirements
- Data protection maturity assessment
- Data protection risk analysis
- Classification of findings and identified gaps
- Prioritisation and scheduling of corrective measures
- Documentation model for maintaining an up-to-date data protection situation overview
- Action plan for the data protection management model
Data Protection Management Model
- Project management and mentoring
- Implementation and documentation of data protection management
- Annual data protection management cycle and data protection report
- Data protection self-monitoring
- Management of data subject rights
- Data protection training, onboarding and awareness development
- Taking data protection into account in supplier relationships and contracts
Implementing Privacy Information Management System (ISO 27701 PIMS)
For many businesses, data protection management does not require a full-time role. We provide a tailored Data Protection Officer service based on your specific needs.
- Data Protection Officer as a service, from a few days per month
- Incident management and reporting
- Data protection risk assessment and management, including
- Data Protection Impact Assessments (DPIAs)
- Implementation of a data protection management model
- Onboarding, training and development of data protection awareness
- Data protection impact assessments in development projects and partner relationships, including contract management
Jarkko Aula
M.Sc. | CISSP | ISO 27001 Lead
Auditor/Implementer | CIMP
I’m Jarkko Aula, a certified expert in information security, cybersecurity, data protection and IT management with extensive international experience. Throughout my 30+ year career, I’ve held a range of international roles and successfully delivered client engagements. My primary focus is always on creating tangible business value for my clients.
My Motto:
Admitting what you don’t know is a virtue.
SecWed Oy
Business ID: 2767912-1
Email: info (at) secwed.fi