Company type
Kvinne GmbH
Target markets
Industries
Portfolio
Certificates
About this member
KVINNE GmbH – Information Security, Data Protection and Management Systems
Consultancy delivers value when requirements become clear and can be implemented within the organisation. We present legal, regulatory, organisational and technical requirements in such a way that you can make well-founded decisions and prioritise measures effectively.
You will gain clarity on which requirements are relevant, which existing processes can be utilised, and what realistic next steps are. Together, we clarify roles and decision-making processes, assess risks in a structured manner, link documentation to operational workflows and make better use of existing organisational knowledge.
This also includes the implementation of technical and organisational measures (TOMs), insofar as these are derived from the requirements and protection needs under consideration. The aim is to achieve an appropriate level of security that is technically sound and practical in day-to-day operations.
Our services tailored to your needs
We tailor our services to your actual requirements. We do not view information security, data protection, management systems and secure digitalisation as separate, isolated topics, but rather as integral parts of a functioning business organisation.
Establishing information security
When establishing information security, we advise you on how to systematically bring together security requirements, risks, responsibilities, processes and evidence. This includes information security management, ISMS structures, ISO/IEC 27001, IT-Grundschutz, risk management, roles and responsibilities, information security organisation and appropriate documentation.
Where possible, existing business processes form the starting point. This means you do not need to create a new parallel world from scratch. Further information can be found under ISO 27001 and external information security officers.
Managing information security on an ongoing basis
Information security is not a one-off implementation, but an ongoing management task. We support you in the further development of existing ISMS structures, in risk assessments, the monitoring of measures, training, awareness-raising, management reviews and the involvement of the relevant departments.
As external information security officers, we provide you with expert guidance, structure requirements, prepare decisions and help to continuously embed information security within your organisation.
Embedding data protection within the organisation
Data protection requires transparent, traceable and secure processing procedures. We support you with data protection consultancy, acting as an external data protection officer, data protection organisation, registers, agreements with data processors, obligations, consents, training and the further development of existing processes.
We do not view data protection as merely a collection of templates. Together, we clarify responsibilities, understand processing operations and integrate organisational measures into existing workflows. Further information can be found on our page on the EU GDPR; the official text of the Regulation is available on EUR-Lex.
Further developing management systems
Management systems help you to structure requirements, clarify responsibilities, manage measures and maintain traceable records. However, a new management system should not automatically create a new parallel organisational structure. We first examine which processes, document control, audit and corrective action procedures, as well as management routines, are already in place and can be usefully utilised going forward.
Integrating AI securely into business processes
AI can support you with structuring, documentation, organising existing knowledge, analysing existing processes, preparing drafts, quality assurance and recurring administrative tasks. Technical responsibility remains with people.
Before implementation, we clarify with you the risks, protection requirements, data classification, access rights and data flows. Particular attention is paid to confidential information. Technical options are not implemented simply because they are available, but only if they make professional sense and can be managed within the organisation. Our article ‘Approving AI Tools Safely’ also complements the secure selection of individual tools.
Our consultancy team
KVINNE GmbH employs three permanent full-time staff members. Our team combines expertise in business management, data protection, information security, audit practice and management expertise for medium-sized enterprises.
Carina Thomas – Managing Director, Auditor and Information Security Consultant
Carsten Thomas – Authorised Signatory and Consultant for Data Protection and Information Security
Richard Freund – Information Security Officer and Master’s graduate in Management of Medium-Sized Enterprises