Research Library / Case Studies /

Technology Manufacturing (EV Batteries & Traffic Control Systems)

ISO 27001 Transformation for a $150M Tech Enterprise

A $150M technology group building EV batteries and traffic control systems needed governance to match its growth. Payatu built its ISMS from scratch across two subsidiaries and got it certified on the first attempt.
ISO/IEC 27001 Implementation, Governance Risk & Compliance (GRC), Internal Audit Readiness

At a glance

INDUSTRY

Technology Manufacturing (EV Batteries & Traffic Control Systems)

CLIENT PROFILE

A $150M technology group operating two subsidiaries under different regulatory and operational demands

SERVICES

ISO/IEC 27001 Implementation, Governance Risk & Compliance (GRC), Internal Audit Readiness

ENGAGEMENT

End-to-end ISMS build · two subsidiaries

key Numbers

100%

Audit Non- Conformities Closed

Zero

Major Non- Conformities in External Audit

2x

Improvement in Risk Visibility

Key Takeaways

  • Client – a $150M technology group spanning EV and mobile battery systems, submarine batteries, and mission-critical traffic control solutions.

  • Problem – rapid growth had outpaced governance, leaving sensitive design files, firmware, supply chain integrations, and remote service interfaces without consistent access control or risk management.

  • What Payatu did – built an ISO/IEC 27001 ISMS from the ground up across two subsidiaries, covering scoping, risk assessment, control implementation, and internal audit, then supported the client through external certification.

  • Outcome – the ISMS passed external certification on the first attempt with zero major non-conformities, closing 100% of audit findings before certification.

the challenge

Why the client called us in

Growth without governance posed long-term risk. Sensitive design files, embedded firmware, supply chain integrations, and remote service interfaces were all operating under different risk profiles with no consistent access control, data handling, or risk management practice tying them together. The client brought Payatu in to build a GRC framework that met international standards without disrupting how engineering, manufacturing, and infrastructure teams actually worked.

  • Build an ISMS from the ground up across two subsidiaries
  • Enforce consistent access control and risk management across engineering, manufacturing, and infrastructure
  • Prepare the organisation for first-attempt ISO/IEC 27001 certification

scope of engagement

What was in scope

  1. End-to-end ISO/IEC 27001 implementation across two business units
  2. Asset and risk identification across IT and OT environments
  3. Policy and control framework development
  4. Governance process implementation (access control, incident management, vendor risk)
  5. Internal audit readiness and certification support

‍

Our Approach

How Payatu ran the engagement

01

Scoping and Gap Assessment
Defined the ISMS scope and ran a gap assessment against ISO 27001 requirements, finding most foundational controls missing or inconsistently applied.

02

Risk Assessment and Risk Register
Mapped every asset and process against the CIA triad and built a comprehensive risk register with impact and likelihood ratings.

03

Control Implementation and Documentation
Designed and deployed core ISMS policies, procedures, and governance workflows, most built from scratch.

04

Internal Audit and Remediation
Ran an internal audit, documented non-conformities, and guided the client through systematic remediation.

05

External Audit and Certification
Supported the client through external audit, achieving certification on the first attempt.

Key findings

What we found

Access granted before background checks
Access restrictions were not enforced prior to completion of background verification (BGV), increasing the risk of unauthorized access by unverified personnel.
Gaps in security awareness training
Only 7 of 54 employees completed information security awareness training, well short of full coverage.
Missing vendor NDA
BGV services were outsourced without a signed NDA in place with the service provider, creating a legal and confidentiality risk.
No redundancy in processing facilities
Only one processing facility was in place, with no alternate site or redundant components, affecting availability during disruptions.

the outcome

Results and Impact

Payatu's ISMS implementation took the client from no formal governance structure to a certified, audited security program, closing every non-conformity before certification and cutting response time to security issues by nearly a third.

‍

  • 100% of audit non-conformities closed before external certification

  • Zero major non-conformities in the external audit, certified on the first attempt

  • 80% reduction in access provisioning gaps through a standardized, BGV-enforced access matrix

  • 30% decrease in operational response time to security issues

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment