Municipalities manage large amounts of sensitive data every day, from residents' personal data to critical administrative processes. Within these decentralised organisations, a wide range of disciplines work with a great variety of information systems, which quickly makes information security complex.

Base27 helps municipalities give information security a central, guiding role. With one clear system, you stay in control of risks, comply with the relevant frameworks, and demonstrably account for your actions. 

Calamiteitenplannen

100% EU based 

Your data is in safe hands. Fully GDPR-compliant with local support. 

Beleid en organisatie

250+ Happy customers

Join a growing network of organisations that trust us to keep them secure. 

Operationele planning

50% time saved

Speed up your workflows and free up yout team to focus on what really matters.

What information security requirements apply to municipalities?  

As a municipality, you face specific obligations in the area of information security. The most important is the BIO (Baseline Information Security for Government), the mandatory standard for all government bodies. The BIO has since been updated to version 2.0. This BIO2 aligns with current international frameworks such as ISO 27001 and ISO 27002. In addition, the GDPR sets clear requirements for the processing of personal data, and the Cybersecurity Act (NIS2) requires municipalities to take additional measures in the area of digital resilience.

As a municipality, you are required to account for your information security every year through ENSIA, the national accountability method that municipalities use to report on information security in a uniform way. This requires a continuous audit cycle and up to date insight into the status of your measures.

informatiebeveiliging certificeringen - normenkaders - isms 1
mockup-axxemble2

Using ISMS software at municipalities  

CISOs, DPOs and other specialists involved work simultaneously across multiple systems to achieve consistent and effective information security. Policies end up scattered across documents, risks are tracked separately, and responsibilities are not always formally documented. The result? A lack of overview and insight, exactly when these are most essential.

According to the 2025 ENSIA report, only 52.6% of municipalities indicate that the municipal executive has full visibility into risks for which no or insufficient measures have been taken. This shows a clear need for a structured approach.

An ISMS, such as Base27, brings overview and insight together in one central environment. You draw up policies, communicate them to everyone involved, and maintain them through a fully supported PDCA cycle. You also manage information systems, plan internal checks and external audits, and can access all the information needed for required accountability and management reporting at the touch of a button.

Dashboards &
Reports

  • Comprehensive reports giving you insight into the status of your information security at all times;
  • Dashboards for quick and easy insight into the status of your information security;
    • Insight by department, or across the board;
    • Filters and sorting;
    • Exports to Microsoft Excel or Word;
    • Analysis in pivot tables.

 

NL - Dashboard

Planning

  • See at a glance which information security maintenance tasks need to be performed throughout the year and what the status is;
  • Easily assign tasks and monitor progress;
  • The plan can be flexibly expanded and repeated annually.

 

operational-planning-Base27

Processes & KPIs

  • Establish overview of processes and related information systems;
  • Set and manage critical success factors and KPIs (Key Performance Indicators);
  • Compliance with standards is automatically made transparent.

 

process-kpi-base27

Single Sign-on

  • Base27 is excellent for integrating within your organisation, for example by using SAML, to allow your employees to access the application without logging in again;
  • REST interface to link data from other sources. Through this capability, incidents from for example your ITSM can be read in or updates sent.

 

RESTAPI-Base27-Single-Sign-On

You don't need to be an expert to get started with Base27

Thanks to pre-filled structures, clear explanations and logical workflows, anyone can easily get started with Base27. Our system guides you step-by-step through identifying potential risks, establishing appropriate measures and assigning responsibilities. Exactly at the level that suits your municipality.

NENPersoon (1)-modified
Inkesta
logo-provincie-Zeeland

Complete ISMS, excellent support and helpful with internal audits

Sanne Muskens

Base27 is the first ISMS that truly aligns seamlessly with the ISO 27001 standard and is very user-friendly

mockup-axxemble2

Why Base27? 

Base27 is developed by an international team and runs entirely on European servers. This is not only relevant for GDPR compliance, but also makes you digitally independent from major US tech companies.

From risk analyses and policies to supplier management, incident registration and internal audits, Base27 brings it all together in one clear platform. All parties within the municipality, from CISOs and DPOs to IT specialists and end users, work together from a single environment. This helps everyone work more efficiently, provides a clear overview, and keeps your municipality demonstrably in control.

Automatically up to date with the latest version of BIO2 and GDPR.
Time savings through structured workflows and a pre filled policy framework.
100% European hosting, fully in line with GDPR requirements.
Support with ENSIA accountability and ISO 27001 certification.

ISMS for municipalities

Base27 monitors and manages your processes from one central place. It serves as both an information security management system (ISMS) and a privacy management system (PMS), giving you a firm grip on the many complex aspects of information security and privacy protection.

From policy development and communication to risk analysis, controls and asset registration, Base27 covers it all.

Try Base27 free for 30 days and discover how information security can finally become clear and organized.

Establishment and communication of policy
Description of processes and procedures
Protection of personal data
Conducting risk assessments and treatment plan
Managing suppliers and partners
Registration of assets
Incident registration and handling
Maintaining calamity plans
Planning improvement activities and internal audits
Monitoring and reporting

Frequently asked questions

Why is information security complex for municipalities?

Municipalities work with a wide variety of information systems and diverse disciplines. On top of that, they must account for their performance through a continuous audit cycle and keep pace with changing frameworks. This makes information security a multifaceted challenge in which overview and insight are essential.

Which frameworks apply to municipalities?

The most important is BIO2 (Baseline Information Security for Government), a mandatory standard for all government organisations. In addition, the GDPR applies to the processing of personal data, the Cybersecurity Act (NIS2) applies to digital resilience, and international frameworks such as ISO 27001 and ISO 27002 also apply. Base27 supports all these frameworks from one central platform.

What is ENSIA and how does Base27 help with this?

ENSIA (Uniform Standards for the Single Information Audit) is the national accountability method municipalities use to report annually on information security, based on BIO2. Base27 helps you keep track of the required information in a structured way, so you can meet your accountability obligations towards the municipal council and national regulators with minimal effort.

What is the difference between an ISMS and regular security software?

Regular security software, such as antivirus programs, protects your system technically from external threats. An ISMS goes further: it brings policies, risk analysis, measures and responsibilities together in one system. This means you not only work more securely, but can also demonstrate that information security is structurally in order. This is especially valuable for municipalities, given their complex organisational structure.

Can I get support with implementation?

Absolutely. Implementing an ISMS follows a fixed approach: from establishing your information security policy and carrying out a risk analysis, to raising awareness among employees and preparing for an external audit. Base27 guides you through this process with a pre filled policy framework, structured workflows and clear steps, so you always know where you stand and what still needs to be done.

What are the consequences of a data breach at a municipality?

Under the GDPR, you are required to report a data breach to the Dutch Data Protection Authority. Failing to do so risks a fine. A data breach can also lead to reputational damage and a loss of trust among residents and partners. For municipalities, which handle sensitive personal data of residents on a daily basis, prevention is better than cure.