Integration · Automation · Security
Two things to protect: the business, and everyone who trusted it.
A breach is rarely only your problem. The people whose details you hold — customers, staff, guests, patients — did not choose your systems, and they carry the consequence anyway.
What this actually is
Making it hard to get in, quick to notice if someone does, and possible to say afterwards what happened. In practice that is unremarkable work: who can sign in and how, what happens when a laptop is lost, whether the backup would actually restore, who still has access who left last year.
Very little of it is exciting, and that is the point. The measures that prevent the overwhelming majority of real incidents are the dull ones, applied consistently, and kept working after the week they were installed.
Where you need to show it rather than simply have it — for a board, an insurer, a tender, a customer's questionnaire — that is the same work with the evidence kept as you go, rather than reconstructed in a panic afterwards.
What it looks like where you are
Small business
You are not a target because of who you are; you are a target because you are reachable. Almost all of it is opportunistic, which is also why almost all of it is stoppable with a handful of unglamorous measures.
Enterprise
You have the controls written down. The question is whether the control described in the document is the control actually running this morning, and who would notice if it stopped.
Government
The question is rarely whether something is secure. It is whether that can be procured, assured, and defended afterwards — to an auditor, to a minister, and to the public.
Where the standards come in
ISO/IEC 27001 is the international standard for managing information security; ISO/IEC 42001 is the equivalent for managing the use of artificial intelligence. They matter when someone else needs to be satisfied — a board, an insurer, a procurement process — and they are overkill when nobody does. We will tell you which situation you are in.
Joerg Micheel holds BSI Training Academy certifications as ISO/IEC 27001 Lead Auditor and Lead Implementer, ISO 19011 Management Systems Internal Auditor, and ISO/IEC 42001 Lead Implementer. These are personal professional credentials. Kaimai Security Limited is not itself a certified organisation, and does not claim to be.
What we will not pretend
Nothing here makes a business unbreachable, and anyone who says otherwise is selling something. What good work buys you is that the common attacks stop being viable, the uncommon ones get noticed, and the bad day is survivable rather than existential.
We are also a small team and we do not offer a callout service or a published response time. What we offer instead is the work that means you are far less likely to need one. If round-the-clock response is what you actually need, we will say so plainly and it will not be us.