Fast-growing software companies move quickly.
New teams. New clients. New cloud environments. New markets.
But while the business scales, security often can grow in pieces.
That was the reality for an international software development company with more than 620 employees operating across Belgium, Germany, Poland, the United States, and India.
Different offices followed different security practices. Cloud environments expanded rapidly. Development teams shipped fast, but security controls were not always consistent across the organization.
At the same time, enterprise clients increasingly required ISO 27001 certification before signing contracts, while regulations like GDPR, NIS2, and the Indian DPDP Act added even more pressure.
The company didn’t have a lack of talent or technology.
It had a lack of structure.
What followed was a complete transformation of how security was managed across the business, from governance and cloud security to secure software development and international compliance.
This case study explores how the company unified security across five countries and successfully achieved ISO 27001:2022 certification.
Where it started: rapid growth without consistency
Like many fast-scaling technology companies, each office had gradually developed its own way of working.
Some teams had mature security practices. Others relied heavily on informal processes.
The initial assessment revealed several critical challenges:
Inconsistent security practices across locations
The Belgian headquarters maintained formal change management processes, while other offices operated with varying levels of structure.
The Indian development center relied largely on informal peer review. The US office selectively applied SOC 2 principles, while Germany and Poland lacked a documented security framework entirely.
Gaps in the Secure Development Lifecycle (SDLC)
Although development teams used agile methodologies and CI/CD pipelines, security was not formally embedded into the software development lifecycle.
There were:
- No mandatory secure coding standards
- No structured vulnerability management process
- No required security testing gates
- Limited security validation before deployments
Cloud sprawl and excessive privileges
The organization used both AWS and Azure environments spread across multiple accounts and subscriptions.
The assessment identified:
- 23% of cloud accounts with excessive permissions
- 11 instances of hardcoded credentials stored inside repositories
- inconsistent cloud monitoring and hardening practices
International data transfer risks
Because customer data was processed by teams in India, GDPR-compliant transfer mechanisms were required.
Existing Standard Contractual Clauses had not been supplemented with Transfer Impact Assessments following Schrems II requirements, creating legal and compliance exposure.
Client audit fatigue
The absence of a recognized certification created a significant operational burden.
The company responded to approximately:
- 14 security questionnaires per year
- 6 client audits annually
This consumed large amounts of leadership, legal, and engineering time.
The organization needed more than isolated fixes.
It needed a unified security structure that could scale globally.
Our approach: centralized governance with localized execution
Rather than forcing a one-size-fits-all model across five countries, a centralized ISMS was designed with localized execution.
The goal was clear:
Create consistent governance while respecting operational and regulatory differences across jurisdictions.
Phase 1 – Multi-site discovery and gap analysis (Weeks 1–8)
A complete assessment was performed across all five countries through a combination of on-site workshops and remote interviews involving:
- Developers
- DevOps engineers
- Project managers
- Country managers
- Executive leadership
The existing environment was mapped against ISO 27001:2022 Annex A controls and applicable privacy regulations.
The assessment identified:
- 167 total gaps
- 89 core ISO 27001 control gaps
- 41 governance and measurement gaps
- 37 detection and response weaknesses
For the first time, leadership had a complete and consolidated view of organizational security maturity.
Phase 2 – ISMS architecture and governance (Weeks 6–16)
A hub-and-spoke governance model was introduced.
The Belgian headquarters managed:
- policies
- risk methodology
- management reviews
- Statement of Applicability
- centralized governance
At the same time, local ISMS representatives were assigned in each country to ensure operational alignment.
To simplify global operations, a tiered documentation structure was developed:
Level 1 – Global policies
28 company-wide policies applied consistently across all locations.
Level 2 – Regional requirements
Country-specific supplements addressed:
- GDPR obligations
- US privacy laws
- Indian DPDP requirements
Level 3 – Operational procedures
Team-specific work instructions aligned security requirements with day-to-day workflows.
A Global Security Steering Committee was also established, creating regular collaboration between all regions.
Phase 3 – Secure development lifecycle integration (Weeks 10–24)
One of the most important transformations involved integrating security directly into the software development process.
Instead of treating security as a separate control function, it became part of the developer workflow itself.
A formal Secure SDLC framework was implemented, including:
- Threat modeling during sprint planning
- SAST integrated into CI/CD pipelines
- Automatic blocking of deployments with critical findings
- Software Composition Analysis (SCA) for open-source dependencies
- DAST testing in staging environments
- Mandatory peer security code reviews
At the same time, a centralized vulnerability management platform was deployed to aggregate findings from all scanning tools and enforce SLA-driven remediation timelines.
This significantly improved visibility and accountability across engineering teams.
Phase 4 – Cloud security and data transfer controls (Weeks 14–26)
A full cloud security posture assessment was conducted across AWS and Azure environments.
The remediation program addressed:
- 156 cloud misconfigurations
- 23 over-privileged IAM roles
- all 11 hardcoded credentials found in repositories
To maintain long-term visibility, Cloud Security Posture Management (CSPM) tooling was introduced with continuous compliance monitoring against CIS Benchmarks.
At the regulatory level, compliant international data transfer mechanisms were implemented through:
- updated Standard Contractual Clauses
- Transfer Impact Assessments
- supplementary encryption and pseudonymization controls
- stricter access restrictions
This ensured that security improvements aligned not only with ISO 27001, but also with evolving international privacy obligations.
Phase 5 – Internal audits and certification (Weeks 28–38)
Internal audits were performed across all five countries through a combination of on-site and remote assessments.
A centralized evidence package was created, reducing certification preparation efforts by approximately 50%.
The organization successfully achieved ISO 27001:2022 certification with a multi-site scope covering all international operations under a single certification body.
The result: measurable security and business improvements
The transformation produced both operational and commercial impact.
Security improvements
- Secure SDLC coverage increased from ad hoc adoption to 100% of projects
- Critical and high vulnerabilities in production dropped from approximately 18 per quarter to fewer than 3
- Cloud misconfigurations decreased from 156 identified issues to fewer than 10 under continuous monitoring
- Hardcoded credentials in repositories were completely eliminated
Operational improvements
- Client questionnaire response times decreased from 3–4 weeks to 2–3 days
- Bespoke client audit preparation reduced from 6 audits annually to just 1
- The ISO 27001 certification was accepted by 89% of clients in place of separate assessments
Commercial impact
Most importantly, the certification directly enabled three enterprise contracts that had previously been blocked due to the absence of ISO 27001 certification.
One of these included a major German financial services client worth €1.2 million annually.
What made the difference
Several factors played a critical role in the success of the transformation:
Centralized governance with local ownership
The hub-and-spoke model ensured consistency without ignoring cultural and operational differences between regions.
Developer-focused security integration
By embedding security directly into CI/CD pipelines and agile workflows, adoption became part of normal development operations rather than an external burden.
Business-driven security strategy
Leadership was able to clearly measure the commercial value of certification by tracking previously blocked sales opportunities and reduced audit overhead.
How Dadir can support your organization
Many growing technology companies face similar challenges:
rapid expansion, distributed teams, increasing regulatory pressure, and inconsistent security practices across locations.
Dadir helps organizations establish structured, scalable, and internationally aligned cybersecurity programs that support both operational resilience and business growth.
We support organizations with:
- ISO 27001 implementation and certification
- Secure SDLC integration
- Cloud security governance
- GDPR and international data transfer compliance
- Multi-site ISMS governance
- Risk management and operational security maturity
Because for international software companies, security is no longer only a technical requirement.
It has become a business requirement.



