Privacy, Security and Quality Management

Ubikon offers services in Privacy, Quality and Security Consulting, with our focus being on:

enabling our customers to understand, reach and maintain various standards, laws and regulations

conducting security reviews on company IT systems and processes from both information security and privacy standpoints

setting up or migrating Quality Management Systems (QMS) and Information Management Systems (ISMS) on behalf of our customers

guiding process development, internal auditing and documentation practices

Standards & Regulations

The primary general standards we cover are: ISO9001 for Quality Management, ISO270001 and NIS2 for Information Security Management, and GDPR for Privacy regulations. In addition to this, we offer services for consulting on multiple automotive standards – IATF16949, Automotive SPICE (ASPICE), TISAX and ISO26262

We approach our work on the standardization front from an engineering perspective, aiming towards finding functional solutions that are a good fit for a specific customer and work together to ensure that the solutions fit the natural existing operating practices of a given company. Our primary goals are for our customers to reach the standards they are aiming for, on a realistic schedule and in a way that ensures that the standards support the customers’ core operations, instead of becoming extra overhead.

Security Reviews

Our security reviews focus on going through the full set of systems utilized by a company, mapping out their dependencies, drilling down into security details & practices for each service, assessing the overall handling of personal information and collecting the information mandated by GDPR.

This type of review provides a solid standing point for a company starting work towards NIS2, ISO27001 or TISAX and prepares the company for setting up their ISMS by having collected a large portion of the requisite information into a single source.

QMS & ISMS Setup & Migration

We are flexible on the choice of QMS / ISMS solution, whether it be through a commercial framework (e.g. Cyberday) or handling the relevant documentation in the customers’ own knowledge management system (e.g. Confluence or SharePoint).

In this type of project we gather the relevant information, processes and details from our customer, draft the needed documentations, ensure that the practices fulfill the needs of the relevant standards and iterate together with our customer, working in an agile methodology.