Skip to main content
Back to case studiesCyber Security

ISO 27001 Readiness: Technical Controls and Risk Register

The organization operated at 800 employees with fragmented tooling and unclear ownership between security, platform, and application teams. Incidents were detec…

Client profile

Sector
Healthcare
Scale
800 employees

Challenge

The organization operated at 800 employees with fragmented tooling and unclear ownership between security, platform, and application teams. Incidents were detected late; changes lacked measurable acceptance criteria.

Engineering approach

Arekan mapped trust boundaries, data flows, and failure modes before writing code or rules. We ran staged pilots with rollback plans, defined SLOs for detection or retrieval quality, and aligned deliverables to audit evidence requirements.

Solution

We implemented production-ready components using ISO 27001, NIST CSF, Policy templates with infrastructure-as-code, monitored rollouts, and handover runbooks. Customer identities remain confidential; this case reflects a composite of anonymized enterprise engagements.

Implementation process

  1. 1.Discovery and asset inventory
  2. 2.Architecture design and threat modeling
  3. 3.Pilot implementation in staging
  4. 4.Production rollout with canary validation
  5. 5.Handover, training, and continuous improvement roadmap

Results

-62% average reduction
Detection / response MTTR
-41% in first 90 days
False positive triage volume
-55% manual effort
Audit evidence preparation time
99.97% maintained
Platform availability during migration

Technologies

ISO 27001NIST CSFPolicy templatesWazuh

Stack selected for interoperability, operability, and audit evidence.

Customer identities are confidential. Metrics represent anonymized composite outcomes from Arekan delivery work.

AI, Cybersecurity & Enterprise Software Engineering

Secure. Scale. Innovate.

We build secure, AI-powered digital platforms for ambitious companies across Europe, the Middle East and the Gulf region.