Skip to content

About

Independent readiness resources for automotive information security teams

ISAREADY exists because of a pattern we kept seeing. Organisations preparing for an automotive information security assessment were not failing for lack of effort or competence. They were failing because their preparation was organised around documents rather than around operation and evidence — and the gap only became visible late, under time pressure.

We build the structure we would use ourselves: scope, gap assessment, risk treatment, implementation, evidence, internal verification and improvement, connected as one system rather than assembled as a folder of templates.

What we believe

A policy alone does not demonstrate operational readiness

Three convictions shape everything we publish.

Evidence is a design decision, not a clean-up task

The organisations that find preparation calm are the ones that decided in advance what record each activity would leave behind. Deciding afterwards costs an order of magnitude more and produces weaker evidence.

Ownership beats documentation

A requirement with a named owner and a trigger will operate. A requirement described in an excellent policy with neither will not. Most readiness gaps are organisational rather than technical.

The loop matters more than the artefact

A binder written by someone who has since left is not readiness. A cycle that produces reviewed policies, dated records and closed findings survives a change of personnel.

How we work

The method behind everything we publish

  1. 1

    Assess

    Establish scope and an honest baseline. What is actually in place, not what the documents claim.

  2. 2

    Identify Gaps

    Convert the baseline into findings with an owner, a priority and a target date.

  3. 3

    Implement

    Do the work: processes, controls and the decisions that make them stick in daily operation.

  4. 4

    Collect Evidence

    Produce the record as the activity happens. Decided in advance, not reconstructed later.

  5. 5

    Verify

    Check yourself against your own rules through internal audit before anyone else does.

  6. 6

    Improve

    Close findings at root cause and feed the outcome back into risk, controls and awareness.

Editorial policy

We separate official requirements from our own opinion

Every substantive statement in our guidance falls into one of three categories, and we label them.
Official framework information
Publicly documented by the body that owns the framework. Always verify against the current official source before acting.
Industry good practice
Widely applied in automotive information security programmes, but not itself a formal requirement.
ISAREADY recommendation
Our own methodology. Practical guidance from structuring readiness programmes — not an official requirement.
What we do not do

The lines we hold

  • We do not reproduce copyrighted assessment questionnaires. All our assessment content is original ISAREADY wording.
  • We do not claim affiliation with, or endorsement by, ENX Association, the VDA, ISO or any TISAX audit provider. We have none.
  • We do not promise assessment outcomes. No toolkit can guarantee a TISAX result, a label, an ISO certification or regulatory compliance.
  • We do not publish invented statistics, fabricated testimonials or client logos we do not have. When we have real proof, we will show it.
  • We do not use countdown timers, artificial scarcity or any other pressure tactic. The price is the price.
ISAREADY provides independent assessment-readiness resources and practical information security tools. ISAREADY is not affiliated with, endorsed by, or acting on behalf of ENX Association, VDA, ISO or any TISAX audit provider. Use of ISAREADY resources does not guarantee a TISAX assessment result, TISAX label, ISO certification or regulatory compliance.

The brand, not the individual

ISAREADY publishes as an organisation rather than under a personal byline. Articles are attributed to the ISAREADY Editorial Team. That is a deliberate choice: the guidance should stand on whether it is useful, and the toolkit should be judged on whether it works, not on whose name is attached.

If you want to talk to a person about scope, tiers or a multi-site rollout, get in touch — a person answers.

Start with an honest baseline

The free self-assessment gives an indicative readiness view across every theme we write about, with prioritised next steps and a report you can share internally.