Compliance

Achieving Two ISO 27001 Certifications in 11 Months: Onet’s Success Story

85,000 employees, two business units to be certified simultaneously—one of which required building an ISMS from scratch—and a timeline deemed impossible even by the auditor. Find out how Onet rose to this challenge: the obstacles encountered, the key decisions made, and what truly made the difference on audit day.

Download
20 days
saved per year on Operational Maintenance
60%
time saved on data consolidation
3x
faster to produce your compliance reports
“Without Tenacy, we would have had to address the three major non-conformities and undergo another audit in three months. The tool was instrumental in demonstrating to the auditor that our approach was structured and sustainable, even within such a short timeframe.”
Hervé Comes
Group Chief Information Security Officer at Onet

With this case study, you will be able to

Follow the entire process of an ISO 27001 certification project month by month under real-world conditions, from the initial scoping workshops to the auditor’s final decision.
Understand how to centralize documentation, evidence, and action plans within a GRC platform to turn a stressful audit into a manageable process.
Identify the key factors that have enabled Onet to turn cybersecurity into a genuine business driver and a means of expanding into new markets, rather than merely a regulatory requirement.

Key points of the case study

A project launched under intense pressure

Two entities with vastly different levels of cybersecurity maturity (one starting from scratch), an audit process that was modified along the way, and a central IT department under pressure: Onet had to synchronize an entire decentralized ecosystem in less than a year—a task that takes most organizations twice as long.

Tenacy as the central platform on audit day

During Phase 2, the auditors took their investigations far beyond what was originally planned, particularly with regard to risk analysis; it was the ability to instantly generate time-stamped evidence directly from the platform—including the CEO’s approval logs—that downgraded three major non-conformities to minor ones and prevented the need for a follow-up audit.

A certification that serves as the foundation for a long-term strategy

For Hervé Comes (Group CISO), the end of the audit is not the end of the story: the tool is now at the heart of day-to-day cybersecurity management, with the goal of expanding its use to other business units and shifting from a compliance-focused approach to a performance-focused approach to cybersecurity.

About Tenacy

Tenacy is a cyber GRC platform designed for security teams looking to streamline their compliance processes, automate their management, and demonstrate measurable results to senior management.

More than 200 organizations in 32 countries rely on Tenacy to streamline their risk management and multi-compliance efforts (NIS 2, DORA, ISO 27001, etc.).

Find out how Tenacy can transform your organization’s cybersecurity management with a personalized demo: book your demo today.