
QFINITY · News · Insights & Events
What is driving the regulated quality of tomorrow.
Articles and analysis from our own work across GxP, pharma, quality management, GAMP and AI. They cover what is changing in the regulated environment, what it means in practice, and what is happening inside our company.
Latest articles




IT Quality Management for Secure System Restoration: Recovery from Ransomeware attack in GxP-Regulated Environments
After a ransomware attack, a drug-discovery company had to recover GxP-relevant systems and data – fully documented. QFINITY guided the recovery from an IT quality management perspective: from forensically grounded quality planning through integrity-assured data migration to validated release.
Problem statement
The client is an international company in pharmaceutical active ingredient research. Its services include researching and developing new active ingredients and building software platforms for specialized methods in this environment. The company became the target of a ransomware attack that encrypted large parts of its infrastructure, systems, and data, making them inaccessible. Because some of these data and systems were GxP-relevant, the restoration of IT services and functions had to be closely overseen – and fully documented from an IT quality management perspective.
To achieve this objective, the client required:
Project execution
At the start of the project, QFINITY recorded the recovery activities defined by the project team and evaluated their regulatory relevance. The results of the forensic analysis of the ransomware attack fed into this work, serving to review the effectiveness of existing quality management processes and optimize them where necessary. Based on this analysis, QFINITY developed a quality plan covering the following activities and areas:
Implementing this plan and the associated activities required intensive coordination with all departments to enable a fast, secure release of IT services and systems in full regulatory compliance.
Results and benefits
The project was completed successfully on schedule and within the planned budget because analysis, documentation, and release activities were appropriately scaled and efficiently coordinated. The restored IT systems and associated data fully meet all internal and regulatory requirements. Throughout the recovery, internal quality assurance continuously monitored the documentation in close coordination with the IT quality function, ensuring complete regulatory compliance and adherence to the highest internal quality standards. The resulting IT infrastructure meets the most stringent requirements for security, data integrity, and operational reliability.
Global QMS concept for an international pharmaceutical company: design and implementation
Grown through acquisitions, an international pharmaceutical company needed a harmonized global QMS. QFINITY designed and implemented it along GAMP 5 and ITIL – across infrastructure, software development, and computerized system validation – including a training concept and a worldwide rollout.
This case study focuses on the design and implementation of a global QMS concept for an international pharmaceutical company.
Problem Statement
The client is an international company in pharmaceutical active ingredient research. Its services range from researching and developing new pharmaceutical compounds to building software platforms for specialized methods in this domain.
After years of significant growth through acquisitions, the company needed to consolidate its various quality management approaches into a harmonized global Quality Management System (QMS).
To achieve this objective, the client required:
Project Execution
In the initial phase, QFINITY analyzed the organization’s existing quality management systems and evaluated them against regulatory requirements and industry standards.
QFINITY then developed a new QMS concept covering the following areas:
As part of the implementation, QFINITY developed all necessary policies, directives, SOPs, work instructions, and document templates. It also created training materials for all relevant areas and planned and ran training sessions for the respective employee groups and departments.
Results and Benefits
The project was completed successfully on time and within the planned budget. Appropriately scaling the analysis, development, and rollout activities – and coordinating them efficiently – made this possible. Potential bottlenecks were identified early and avoided, keeping the overall project timeline on track.
The implemented global QMS significantly improved both efficiency and compliance. Globally harmonized processes and approaches ensured consistent compliance with regulatory requirements across the entire organization. Process efficiency increased substantially, and the company established a unified global understanding of quality.
The company’s internal quality assurance function reviewed the QMS approach and related documentation, and any inconsistencies identified were resolved promptly before rollout.
For more information about QFINITY’s case studies, check out our Project News.
ISPE EU Annual Conference | April 20-22, 2026
Meet QFINITY on site at the ISPE EU Annual Conference 2026 in Copenhagen and learn how to bring digital compliance, AI, and GxP requirements together in a safe, future-proof, and practical way.
QFINITY’s Contribution to ISPE Europe 2026
The digital transformation of the pharmaceutical industry is progressing rapidly. Artificial intelligence, cloud technologies, and data-driven automation are now integral to GxP-critical processes. At the same time, regulatory requirements for data integrity, transparency, and patient safety remain uncompromising.
Oliver Herrmann, CEO of QFINITY, is a member of the event’s Program Team. He also serves as Track Lead for the Digital Compliance track, together with Josef Trapl and Niels de Blende. In this role, he is responsible for the track’s structure, technical depth, and overall content direction.
Content Focus: Digital Compliance
The Digital Compliance track addresses one central question:
How do you ensure lasting GxP compliance in AI-enabled, cloud-based, and continuously evolving system landscapes?
1. GxP Principles in the Age of AI
2. From Document-Based to Data-Driven Validation
3. Data Integrity, Trust, and Decision-Making
4. Next Generation Digital Compliance
For more information about the event and to register for the ISPE EU Annual Conference, please visit the ISPE website.