CJ2 is a hosting organization that has been operating for over twenty years based on a clear conviction: data needs to be close by. Not only because of speed and accessibility, but increasingly from the perspective of data sovereignty and control over the entire chain. The organization delivers hosting services, online workplaces, applications, and websites to a broad customer base, ranging from small associations to healthcare institutions with hundreds of employees working entirely in the cloud.
What sets CJ2 apart is that the entire infrastructure is end-to-end managed in-house. From the network to connections and hosting: everything remains under its own control. In doing so, a conscious choice is made for open-source technology and in-house network management, keeping dependency on external parties to a minimum.
To further professionalize its information security and support its ISO and NEN certifications, CJ2 is collaborating with our partner Nestor Security and Warpnet. While Nestor Security supports the organization in the areas of governance, risk management, and certification, Warpnet provides objective testing of technical security through independent penetration tests. Together, they help CJ2 continuously improve its information security. In this customer case study, representatives from CJ2, Nestor Security, and Warpnet discuss what this collaboration looks like and the insights and improvements it has yielded.
Information security as the core of the operation
Information security within CJ2 is intertwined with the entire operation. The organization is ISO27001 and NEN7510 certified and has been working structurally on improving its security maturity since 2017. Carlos de Boer, CEO of CJ2, explains: “The importance of information security has only increased over the years, partly due to growth, customer expectations, and new regulations, such as NIS2. That is super important to us. We manage everything, so it is essential that we also have everything under control. That is also why we have those certificates.”
As the organization grew, so did the volume of documentation and processes surrounding information security. What once started out as manageable became increasingly complex due to the sheer volume of policies, documents, and interdependencies. Internally, the first phase of certification was looked back upon as a period in which the standard was the primary guiding factor. “We were already doing a lot technically, but we actually started with the idea that we had to check off everything listed in the standard. Only later do you realize that you also just need to look at: what are we already doing, and how do we record that properly,” Carlos says. That shift became important: instead of adapting the organization to fit the standard, the standard was increasingly translated to fit the reality of the organization itself.
Bringing structure to complexity
To support that movement, an external security officer was brought in via Nestor Security. Her role mainly focused on redesigning risk management and guiding the recertification process. From the very beginning, the sheer volume of documentation was striking. “CJ2 had an immense amount of documentation surrounding the ISO 27001 standard. An important next step is to further structure that documentation so that everything is easily accessible and consistent,” says Wendy Sikkema, Security Officer at Nestor Security.
Therefore, simplification was chosen. Topics were restructured, policies were revised, and where possible, references were used instead of duplication. In addition, a fixed consultation structure was introduced. “We sit down together every week. This ensures that expectations remain constantly clear and allows you to respond more quickly when something changes. What we are trying to do is actually bring the standard closer to the organization. So that it becomes something you can use rather than something you merely have to comply with.”
Independent validation in practice
In addition to audits, CJ2 has penetration tests performed annually to have the technical side of information security independently tested. Warpnet was engaged for a configuration review and pentest on a new identity provider and open source platform components. Because the system was still in development, a large part of the process consisted of interactive sessions in which choices, setup, and architecture were discussed together. “CJ2”s employees were very good at explaining their choices. They were motivated and they also asked many questions in return, making it a truly interactive process," says Nikhil John Thomas, Pentester at Warpnet.
The outcome of the pentest was predominantly affirmative. A few recommendations were made, but no critical vulnerabilities were found. “We do not report findings in the sense of ‘you are not doing a good job’, but recommendations. It is about what you can improve on what is already there.” CJ2 primarily saw this as confirmation of their existing course.
Experience with collaboration and process
Patrick Hulshof, Security Engineer at CJ2, shares more about the collaboration with Warpnet: “The entire process was experienced as accessible and transparent. The intake was clear, the collaboration during the test was open, and there was plenty of room for mutual understanding. The report was also seen as an important part of the value: not only technically complete, but above all easy to follow and practical to use.”
For CJ2, the added value of the collaboration with Nestor Security lies not only in their substantive knowledge, but also in the way it is communicated. Whereas the organization was previously mainly focused on compliance, Nestor Security helped view information security from their own practical perspective. In doing so, existing choices were critically evaluated and sharpened where necessary. As Carlos himself points out: “The consultants at Nestor Security help us to describe things as clearly as possible, but in a realistic way. In the beginning, they really held up a mirror to us. As a result, we started looking at our processes and policy differently.”
Insights from audits and pentests are actively fed back into the organization and serve as input for further maturity in risk management. The focus is increasingly shifting toward gathering risks from within the organization itself. Wendy explains: “I visit every team to see where they perceive risks. I take those back with me, and then we perform a risk analysis on them.”
Continuous improvement
The collaboration has since evolved into a structural way of working in which information security grows along with the organization. Through the combination of external expertise, internal involvement, and independent validation, a mature approach has emerged in which compliance is not the endpoint, but a logical consequence of well-designed processes. This feeling is ultimately summarized by Carlos as follows: “You benefit from it. You become more professional. And that is something that lasts. Digital dependency is increasing and cyber threats are becoming more frequent; handling sensitive data with care is therefore simply a priority.”