// CASE STUDY · AUTOMOTIVE TECHNOLOGY · STARTUP
From no compliance function to ISO 27001 ready, as fractional CISO
- vCISO engagement
- Zero to ISO 27001 ready
- Enterprise automotive customers
The problem
A startup still raising funding was already winning contracts with major automotive manufacturers. Those customers expect enterprise security posture. The company had effectively no compliance function, no policy set, and an environment that had grown the way startup environments grow.
What I did
- Acted as fractional CISO, owning the security function while the company was too early to justify a full-time hire.
- Built the policy set from nothing, aligned to ISO 27001 rather than written to look good in a questionnaire.
- Re-architected access to environments, and the network architecture underneath, so access could actually be governed and evidenced.
- Ran security reviews and worked with the engineering team on secure coding practice, so the controls held in the product rather than only on paper.
Where it landed
A company that went from no compliance function to ISO 27001 ready, able to answer enterprise automotive customer security requirements without stalling a deal.
Something similar coming up?
Engagements like this start with a call about what you are actually dealing with. No hardware, no software, and no installation is sold here, which is the independence policy in one line.