Welcome to Protify.

In accordance with cookie legislation and our privacy policy, we only place strictly necessary functional cookies. 😊

For visitor analysis, we use Google Analytics (also cookieless). May we also place some Google Analytics analytical cookies to gain a better understanding?

DialogueTrainer: An ISO 27001 Implementation

Written by Protify

ISO 27001 is people work

The practical case study of The DialogueTrainer

A SaaS company that trains communication skills with digital simulations is by definition dependent on the trust it receives from its customers and users. But how do you demonstrate that information security does not only feel right, but is also structurally secure?

In this practical casestudy, DialogueTrainer shows how ISO 27001 helped to document existing choices more clearly, answer customer questions more quickly and make AI a controlled part of the ISMS.

About DialogueTrainer

DialogueTrainer developed a platform where people can practice realistic conversations. Users open a scenario, talk to an avatar and receive feedback on choices and responses. This allows organizations to train communication skills in a way that is measurable and repeatable. DialogueTrainer originated from Utrecht University and works for large organizations in areas such as business, health care and education.

The organization consists of about twenty people. Within the ISO 27001 process, Michiel Hulsbergen, one of the founders, and Jan Nederhorst, customer support manager and operational security officer, played a central role. Jan had a major impact on the success of the process.

Together with a colleague on the technical side, Jan is responsible for the security officer role within DialogueTrainer. For him, the ISO 27001 certification project did not only mean creating policy, but above all ensuring that information security became part of daily work. Assessing new suppliers, reporting incidents, following up on tasks, checking documents and keeping colleagues involved. All while the regular work also continued.

The activities now feel normal. Sometimes it is still a matter of finding where the time comes from, but the more often you do it, the more routine it becomes. Jan Nederhorst, DialogueTrainer

The reason

DialogueTrainer had already been consciously working on information security for some time. Still, the step toward ISO 27001 certification was necessary because market demand changed. Customers increasingly asked explicitly for an ISO 27001 certificate. Where DialogueTrainer could previously explain that it worked in accordance with ISO, customers now increasingly wanted to see independent evidence.

Michiel: “DialogueTrainer processes a lot of data. Then you need to be able to build trust. ISO 27001 was therefore not an administrative exercise, but a logical step in the professionalization of the platform and the organization.”

The use of AI made the need for ISO 27001 even greater. DialogueTrainer previously mainly used fixed answer options in simulations. The platform now also uses AI to make open conversations, also called AI deeptalks, possible. As a result, participants can respond more freely and simulations become more realistic. The value here lies mainly in the feedback users receive. The feedback tells you where your improvement points are. By then doing the conversation again, you work concretely and directly on your learning points. In light of ISO 27001, AI requires additional focus on risk analysis, data processing, retention periods, monitoring and evidence.

From well organized to demonstrably organized

During the implementation of ISO 27001, it became clear that DialogueTrainer had already thought through many matters well in substance. The biggest step was not in rethinking everything, but in structuring, documenting and demonstrating.

Jan described the start of the project as logical and clear, but also intensive. The structure of the ISMS, ProActive Compliance Tool (PCT), helped us make visible which topics required attention. According to Jan, that gave direction to the process: “In your head, you often know it. But now describe it across all the different areas.”

Processes that had always felt self evident now had to be described explicitly. Who does what? Where is data stored? Which suppliers are involved? Which risks are associated with that? Which retention periods apply? And how does the organization prove that agreements are followed?

A concrete example is the process for selecting suppliers. Previously, DialogueTrainer first chose a solution that worked functionally. After that, the team looked at data, risks and conditions. Because of ISO 27001, the organization reversed that process. The team first assesses data storage, risks and the supplier. After that, it is assessed whether the application meets the functional requirements.

The role of Jan

In many ISO 27001 processes, the way roles are filled determines success. That was also the case at DialogueTrainer. Jan combined his role as customer support manager with the operational side of information security. Together with a colleague who handled the technical side, he further shaped the security role.

That role required a lot. Jan not only had to complete documents, but above all had to ensure that ISO 27001 became part of daily practice. Assessing new suppliers, reporting incidents, following up on tasks, preparing audits, involving colleagues and collecting evidence. That made him an important driver of the process.

Michiel indicated that he mainly safeguarded the framework himself, while Jan was much more intensively involved in daily execution.

Jan describes the development pragmatically:

The activities now feel like normal work. Sometimes it is still a matter of finding where the time comes from, but the more often you do it, the more routine it becomes.”

Protify’s approach

Protify helped DialogueTrainer make ISO 27001 practical. Not by making the standard heavier than necessary, but by translating it to the organization.

Jan and Michiel experienced the guidance from Tim of Protify as very positive. His availability, his thinking along with them and the way Tim took the team along step by step were important points for them.

“It is not just about answering your question, but also about thinking more broadly.”

Michiel especially emphasized the tone of the guidance:

“Tim is not busy making ISO sound grand. He is busy making ISO normal. I think that is very important.”

That also fits DialogueTrainer. The organization works in a playful and flexible way, but applies clear quality criteria. Protify connects to that by providing structure without making the organization rigid.

The results

ISO 27001 helps DialogueTrainer very directly in customer conversations. When security now comes up, DialogueTrainer can indicate that it is ISO 27001 certified. That helps enormously.

That is also the commercial effect DialogueTrainer was looking for with the certification. Customers increasingly ask for demonstrability. A data processing agreement alone is often no longer enough. With the ISO 27001 certificate, DialogueTrainer can show that processes have been set up and that information security is structurally followed up.

Jan described the effect toward customers as follows:

“Customers no longer have to take our word for it. We can show that our processes are in order.”

Internally, the process created more sharpness. Processes became tighter and better planned. Supplier selection became more conscious. Retention periods, incidents, tasks and risks became more clearly visible. Information security is no longer a separate project, but part of daily work.

The most important lessons

The first lesson is that ISO 27001 only works when the foundation is right. Michiel expressed that as advice to other SaaS organizations:

“Ask yourself: Is what you are doing right? Then you will be able to do this too.”

The second lesson is that management must be actively involved. During our audit, the auditor noted positively that two management team members were present and took ownership. With that, DialogueTrainer showed that information security was not placed with one person, but was truly carried by the organization.

The third lesson is that an audit is not a reckoning, but a moment of assessment. Yes, an auditor asks critical questions. That can create tension, but it also helps to substantiate choices more sharply. DialogueTrainer learned not to take critical questions personally, but to use them to improve itself.

Why Protify?

With Protify, DialogueTrainer chose a partner that made ISO 27001 workable. Protify brought structure, asked the right questions and helped make existing choices demonstrable. The approach matched a small, fast moving SaaS organization that wants to work professionally without unnecessary complexity.

Ultimately, the core of the process was not only in policy, processes and evidence. It was in people taking responsibility. In Michiel, who saw the importance of trust and demonstrability. In Jan, who led the daily safeguarding and thereby had a major impact on the process. And in Protify, which made ISO 27001 understandable and executable.

Michiel says about this: “ISO 27001 is people work.”

Do you also want to take the step toward ISO 27001?

And do you want to approach this in a practical and workable way?

Contact us for a non binding introductory meeting. Together, we ensure that your organization works on information security in a demonstrable and sustainable way. Schedule a no obligation introductory meeting.

Avatar photo

Protify

For more information, please follow us on LinkedIn

Where AI Regulation and ISO 27001 Intersect

Aragorn: practical case ISO 27001 in SMEs