ISO/IEC 27001:2022 Lead Auditor (TÜV).
Certified qualification to conduct ISMS audits under the current ISO/IEC 27001:2022 standard.
From first gap analysis to a certification-ready ISMS: end-to-end ISO 27001 and TISAX® consulting led by Josef Floesser, a certified ISO/IEC 27001:2022 Lead Auditor (TÜV) — with the hands-on Head of IT experience to actually implement what the standard requires, not just document it.
The standard path from current state to certification-ready ISMS — scoped to your company size, not a generic template.
Your current security posture assessed against the ISO/IEC 27001:2022 Annex A controls — what already meets the standard, and what is missing.
Building the Information Security Management System: scope, risk register, policies, and the Statement of Applicability the certification body will review.
Rolling out the missing controls, training staff on the new policies, and running an internal audit before any external assessor sees the ISMS.
Preparation and direct support through the certification body's Stage 1 (documentation review) and Stage 2 (on-site/remote audit).
Certification is a trust business — verifiability matters more than marketing claims.
A consultant should disclose their own qualifications as transparently as they expect from your ISMS.
There's often a gap between audit paperwork and real system administration — practical Head of IT experience closes it.
Many consultants are platform-agnostic generalists — specific expertise in Apple MDM environments is rare and relevant for Mac-first companies.
Experience with international teams and locations helps with globally operating clients, such as in the automotive industry.
The facts, verified from the current CV — no embellishment.
Certified qualification to conduct ISMS audits under the current ISO/IEC 27001:2022 standard.
Certified qualification to advise companies preparing for TISAX® assessments.
Independent consulting practice in information security and Apple Enterprise Architecture.
Hands-on IT leadership for an architecture firm (since 2024) and a film production company (since 2021) — both documented as references on this site.
Studied Information Technology and Media Studies at the University of Offenburg, complemented by exchange semesters at the University of Liechtenstein and Universidade Europeia in Lisbon (PROMOS scholarship). Afterwards Scientific Assistant (2019–2022) and Research Fellow at the Affective & Cognitive Institute (2022–2024).
Yes — the ISO/IEC 27001:2022 Lead Auditor certification (TÜV) is complete. He additionally holds certification as an Information Security Consultant for TISAX® with the TÜV Rheinland Group.
The combination of formal auditor certification and hands-on Head of IT experience at real companies (UNDPLUS, Rekorder) — not just advisory work but actual implementation practice, plus specialization in Apple enterprise environments.
Yes, ISO 27001 and TISAX® consulting is fundamentally platform-agnostic. The Apple enterprise focus is an additional specialization, not a requirement for other environments.
A good ISO 27001 consultant should hold the Lead Auditor certification themselves — someone who has been trained to audit an ISMS against the standard understands what a certification body will actually check far better than someone who has only read about it. JF Agency is led by a certified ISO/IEC 27001:2022 Lead Auditor (TÜV) who has also held hands-on Head of IT roles at real companies, meaning the gap analysis and ISMS build-out come from someone who has implemented security controls operationally, not only documented them on paper.
Apple's security platform and on-device AI, mapped to Annex A.
What to check before your TISAX assessment.
Enterprise Architecture for design studios.
Security consulting for campaigns and world premieres.
Apple Certified Technical Partner for enterprise environments.