DENOG17

Mathias Handsche

Mathias Handsche is an expert in IT security and network infrastructure with a strong focus on NIS2 compliance, KRITIS requirements, and ISO 27001 certification—particularly in the telecommunications sector. As the Managing Director of nGENn GmbH, he supports telecom operators and internet service providers in implementing security measures, building sustainable ISMS structures, and integrating regulatory compliance into day-to-day operations.

He is an active ISO/IEC 27001:2022 and ISO 22301:2019 lead auditor, regularly auditing organizations in critical infrastructure and telecommunications environments. His work focuses on translating regulatory requirements into lean, actionable processes that align with operational priorities.

Mathias is also an active member of the German national standards committee (DIN) contributing to the development of ISO/IEC 27001, bringing practical field experience into the evolution of international information security standards.


Session

11-11
11:30
30min
Compliance in Practice: Making NIS2 and ISO 27001 Work in Daily Operations
Mathias Handsche

With NIS2, ISO 27001 and requirements of BNetzA raising the bar for security and operational compliance, many internet providers are asking the same question: How do we meet these requirements without drowning in bureaucracy?

This talk bridges the gap between regulation and real-world implementation. Instead of focusing on theory or checklists, we’ll look at how to integrate compliance into the day-to-day work of running a network—with minimal friction.

Topics include:

  • Turning compliance into a continuous, manageable process
  • Using a Single Source of Truth (SSoT) to manage documentation, assets, and controls
  • The “document once, but right” principle: reducing duplication and inconsistency
  • Assigning and tracking responsibilities that actually get done
  • Lessons from real-life audits and what works in lean teams
  • Tooling, automation, and pragmatic templates to stay compliant while staying sane

We will demonstrate these concepts using open-source tools like:

  • NetBox for infrastructure inventory and network documentation
  • Snipe-IT for asset lifecycle management
  • Zammad for task and ticket tracking
  • Eramba for managing risk, controls, and policy compliance
  • GitLab for documentation, version control, and approval workflows

These tools help create a practical compliance framework that integrates seamlessly into daily operations and supports both audit readiness and operational efficiency.

This session is tailored for engineers, DevOps, and infrastructure managers at ISPs and hosting providers who want to build a compliant operation—without losing focus on uptime, performance, and business continuity.

You’ll walk away with concrete strategies and examples you can apply on Monday.

Saal B