ISMS for SMEs: Your pragmatic 9-point plan without bureaucracy burnout

Information security is not a corporate issue. And an ISMS doesn't have to be a nightmare.

Let's be honest: When the word ‘ISMS’ is used in a small or medium-sized IT department, there are usually two reactions. Either the IT manager looks like a tax audit has just been announced to him. Or someone from the management nods enthusiastically because they have read the term somewhere in a LinkedIn post of a hip consulting company? Set sail for fail and it will quickly become expensive.

Both are unnecessary.

An information security management system is basically everything, just not a document cemetery, not a one-time certification project and not an end in itself. It is a working principle. And for SMEs, if set up correctly, it can make the difference between ‘we knew what we were doing’ and ‘unfortunately we had no plan’. You can see that when it matters.

Here is the pragmatic 9-point plan. No enterprise overhead, no ISO certification craze. Only what really works.

1. Accept the Inconvenient Truth First

SMEs are not an uninteresting target. On the contrary: Often, central business processes depend on a terrifyingly few systems and people. If IT fails, there is not only the server room, but also sales, accounting, warehouse, sometimes the whole store.

The good news: You don't have to be a Fortune 500 company to make sense of it. All you have to do is stop thinking that this is the ‘topic of others’.

2. Start small + take it seriously

The most common error: You look at how big companies built their ISMS and try to copy that. It always ends the same way: with a system that no one cares about, no one understands and that, in an emergency, stays in a drawer.

It would be better to identify five to ten really critical assets. Typical IT candidates are:

  • Active Directory / Identity management
  • Microsoft 365 or Google Workspace
  • ERP system
  • Backups (yes, they are an asset! More on that right away)
  • Central fileshares or collaboration tools

Not everything has to be covered by day one. The most important question is: What is the first thing to do in an emergency? That's what you protect first.

3. Assess risks (but without maths Olympiad)

Risk assessment sounds like business consulting and Excel escalation. It doesn't have to be.

Three steps are enough to get you started: Low, medium, high. If you are thinking of a finely balanced 5×5 risk matrix, please do not do that. This means that you spend more time in the methodology than in the implementation. Just remember, the goal is not the perfect evaluation, but a implementable basis for decision-making.

A known, documented risk that is consciously accepted with an idea of how to respond to it is a thousand times better than an unknown risk that strikes at some point.

4. Define clear responsibilities. Because ‘all’ means no one!

In small teams, security often goes like this: Somebody cares somehow. As long as this person is there, it's going on. When she gets sick, is on vacation or leaves the company, the light quickly goes out.

An ISMS makes responsibilities explicit. It doesn't have to be complicated:

  • IT management: bears the professional responsibility
  • Admins / external service providers: implement operationally
  • management: assesses risks, makes decisions, accepts/rejects

This last point is important: Management must be involved. Not as decoration, but because risk decisions are management decisions.

5. Document only what you use

No document flood. What no one reads is useless in an emergency. To get started, these documents are sufficient:

  • Brief description of the objective and scope (half a page is enough)
  • Asset list with critical systems
  • Risk register (Can be a simple Excel spreadsheet, not a joke)
  • Prioritized list of measures (Quick&Easy, Technical, Orga, CIP)
  • Three to five core directives: Access control, backup, patch management, incident response, possibly mobile work
  • Incident log for security incidents
  • Contact list for cloud, network, IT support

A password policy doesn't have to have 10 pages. If it's on half a page, which requirements apply and why that's enough. Really!

6. The Four Processes That Really Count

An ISMS thrives on processes, not documents. And here, too, the following applies: Less is more as long as it works.

Access Management: Who has access to what? Who decides on permissions? When are rights reviewed? Historically grown admin rights under the motto ‘he's always had that’ are a classic but also an unnecessary risk.

Backup & Restore: Not only record what is secured, but also when a restore test last took place. A backup that has never been tested is certainly not safe! No restore test = no backup = no pity.

Incident response: How is a security incident detected? Who will be informed when? Which systems can be isolated? Which service providers need to go in? This must fit on one side and be understandable in case of an emergency at 2 o'clock at night, if only someone is available who sees the thing for the first time.

Patch Management: Automate where you can. Small teams simply cannot afford to make individual manual decisions on updates.

7. Setting priorities: 80 % Clean beats 100 % documented

Time is the scarce good in small IT teams. Therefore: Observe the order.

What first? The classics that are surprisingly often neglected:

  1. Backup & Restore (including test)
  2. Access control (no wild admin rights)
  3. Patch Management (remain current)
  4. Phishing & Awareness (Man is the most common attack surface)

These four points sound unspectacular. However, they regularly decide how an attack or failure will occur. No expensive tool compensates if these basics are missing.

The principle for SMEs: Preferably 80 % Cleanly lived as 100 % documented and never applied.

8. ISMS is not a project, it is an operating mode

A common misunderstanding: ISMS as a unique project with kickoff, milestones and graduation ceremony. It usually doesn't work that way.

An ISMS is alive. This does not require a huge effort, but a lived regularity:

  • Monthly: Brief review of the main risks (30 minutes are enough)
  • Quarterly: Reconciliation with the management, what has changed?
  • Annually: Verification of permissions, measures, documents

This is not a bureaucratic program. This is operational hygiene.

9. Certification: Can, need not

As soon as the topic of ISMS is on the table, the question of ISO 27001 inevitably arises. Sometimes this makes sense, as customers, partners or tenders increasingly require formal proof.

But: Certification does not automatically make a company safer. It confirms that a framework is documented and verifiable. That's not the same thing.

For most SMEs, the better way is to: Build a lean, functioning ISMS, anchor internally and live in everyday life. This helps enormously to answer customers' security questions substantially and to better deal with the real risks.

Whether a certification follows depends on the business model and the cost-benefit ratio, not on a reflex.


Bonus: Tools & Resources

Tips to speed things up without having to reinvent the wheel.

No one has to build all this from scratch on the green field. Here are the tools and templates that will take your real job. Sorted from ‘free and immediately usable’ to ‘makes sense if you want to continue’.

PlanA: Directly from the BSI (free, serious, often underestimated)

IT-Grundschutz-Compendium (BSI) The central work of the BSI with more than 110 building blocks is available free of charge on the BSI website. Sounds like a mammoth project, but it is modular. For SMEs, it is advisable to start with the Basic hedging because it covers the most critical requirements, is explicitly designed for smaller companies and the beginning. Conveniently, it already covers many of the NIS-2 requirements. And let's be honest, who works with public authorities should know what's in it anyway. → BSI IT-Grundschutz-Compendium

Checklists for the IT-Grundschutz-Compendium With these checklists, the current implementation status of IT basic protection modules can be easily documented. For each building block, the individual requirements are listed; Free text fields record status, target date and responsibility. Practical: This is basically your risk register and your list of measures in one. Finished template, don't make anything yourself. → BSI Checklists Download

IT basic protection modules as Word/PDF The building blocks of Edition 2023 are available as ZIP, optionally PDF or MS-Word, as well as cross-reference tables in Excel format. The Word format means: directly edit, customize, use as a template for your own policies. Massively underestimated as a starting point for your own documentation. → BSI Building Blocks Download

PlanB: No one in charge of the house or too little visibility?

CyberRiskCheck according to DIN SPEC 27076 This is the fastest structured entry there is. An IT service provider interviews your company about IT security in a one- to two-hour interview.
27 requirements from six subject areas will be reviewed. From access control to patch management to emergency processes, everything is important. The result is a clear report with prioritized recommendations for action, broken down by urgency.
Not a month-long project, not a huge budget. At the federal level, the check is already subsidised with 50 percent via the ‘go-digital’ programme – so anyone who already has or is looking for an IT service provider starts here. → BSI CyberRiskCheck


Tools for daily ISMS work

For the absolute low-budget entry: Excel / Confluence / Wiki Yeah, really. A cleanly structured table with the columns Asset, Threat, Valuation, Strategy, Responsible and Status is completely sufficient for the start. No tool in the world replaces the will to actually maintain the list.

Verinice (Open Source) For those who don't want a SaaS subscription: Verinice is an established open source tool for IT basic protection and ISO 27001, which is used by many German authorities and SMEs. Learning curve available, with the (older) single-user version also no ongoing license costs. → verinice.com

FOURS It is also a 100 % Open source ISMS software from DSS GmbH. It supports the construction and management of information security according to ISO 27001, BSI IT-Grundschutz and NIS-2, completely without proprietary components, can be self-hosted, but also offers paid support if required → it-security.gmbh

isms4kmo A German software tool that was developed especially for SMEs and reflects the BSI IT basic protection standard 200-1. Also interesting for automotive suppliers, as it also depicts TISAX. Guided process, in German, with built-in online manual. For those who want more structure than Excel, but don't need an enterprise ISMS tool. → isms4kmo.com

Compliance aspects More automation: preset ISMS concept model with typical enterprise infrastructure, automatic allocation of IT basic protection requirements, built-in risk matrix according to BSI 200-3. It makes sense for SMEs that are already a little bit further or are actually heading for certification. → compliance-aspects.de

PlanC: Sample guideline for direct starting

If you do not know where to start or/and are looking for a ready-made template for the information security guideline (i.e. the document describing the objective and scope of the ISMS), ask-datenschutz.de offers a free, updated model guideline based on the BSI IT basic protection, designed for SMEs and municipalities. Download, customize, have the management sign, build on it. → Model Guideline Information Security (free of charge)

An honest assessment at the end: No tool replaces the decision as to which measures really make sense in your context. Tools are accelerating, yes. But they don't take away your thinking. Anyone who buys a tool and hopes that the ISMS is ‘done’ has misunderstood the principle.


Conclusion: An ISMS as a tool, not a monument

An ISMS for SMEs is not an end in itself and not a prestige project. It is a tool for prioritization. It creates overview, enables clear decisions and reduces the dangerous dependence on individual knowledge.

It doesn't matter how thick the folder is. The decisive factor is whether the ISMS is used + whether it makes it capable of acting in an emergency.

And this can also be done without certification, without enterprise overhead and without six months of project duration. You just have to start.