Build the management system
We help build and maintain practical management systems such as ISO/IEC 27001 and ISO 9001 — designed around how your organization already works.
From Noise to Choice
We build management systems such as ISO/IEC 27001 together with your team, implement what comes out of them, and help you navigate cybersecurity and AI compliance — using what you already have, in a way your people understand.
How we work with you
Four promises that shape how we work — from building the ISMS to a team that can carry it on its own.
We help build and maintain practical management systems such as ISO/IEC 27001 and ISO 9001 — designed around how your organization already works.
When the ISMS identifies a risk, gap, control or improvement, we help determine the right next step and implement it — process, people or technology.
We take part in the work instead of handing over a task list: workshops, working sessions, coordination and follow-up alongside your people.
We explain, train and transfer knowledge while doing the work — so your team can increasingly run and improve the ISMS itself.
Our focus
Whether you need to build a new ISMS or keep an existing one alive: this is our core expertise. Everything else builds on it.
Build a working ISMS and prepare for ISO/IEC 27001 certification — together with your team and on top of the tools you already use.
Ongoing support for an existing ISMS: risks, controls, evidence, audits and reviews that keep happening — not just before the audit.
The same logic applies whether we build a new ISMS, take over an existing one or implement a single measure.
Your organization, people, technology, existing processes and management systems.
Use what already works. Avoid unnecessary replacement and duplicate processes.
Requirements, risks, gaps, findings and improvement opportunities.
Decide what actually matters and what should be addressed first.
Work alongside your teams on practical organizational and technical measures.
Explain the system, train where useful and transfer knowledge while doing the work.
Help coordinate recurring ISMS activities where ongoing support is wanted.
Measure effectiveness, learn from incidents and findings, keep improving.
Where new capabilities are needed: existing technology, process changes, open source, European vendors, specialists and funding.
Where useful, simplify or automate repetitive management-system work with appropriate technology and AI.
FeldmannCyber App
The FeldmannCyber App is available today. We set up access after a short conversation. Every capability is clearly labelled with its status.
Plan processes, tasks, responsibilities and deadlines — with substantial Gantt and timeline functionality for implementation work.
Structure ISMS and compliance projects: work packages, activities, milestones, sign-offs and progress tracking.
Communicate around ISMS and project activities in one place — including images and videos where useful.
Explore 350+ curated cybersecurity vendors with a strong European and open-source focus, using filters instead of endless web searches.
Find funding programs for security, digitalization and AI in Germany and the EU — filtered by region, topic and type.
A private, self-hosted AI assistant that helps with ISMS work — and integrates with your existing environment.
Technology independence
European organizations should have credible technology choices and not depend unnecessarily on a small number of providers. That is why we seriously consider European vendors, open source and self-hosting for every measure — without claiming that European automatically means more secure.
350+ cybersecurity vendors in our database, with a focus on the EU/EEA.
Open tools where they fit — including a realistic plan to operate them.
Controlled environments for sensitive data and private AI.
Knowing where data lives, who can access it and what you depend on.
What an incident response plan must contain: roles, escalation, communication, NIS2 and CRA reporting deadlines, evidence and lessons learned.
Certification is not the finish line. What ISMS maintenance involves, which activities recur every year, and how to avoid the pre-audit panic.
Can an ISO 27001 ISMS use your existing tools? Yes — how wikis, document management, ticketing and project tools can carry large parts of it.
How to implement ISO 27001 step by step: scope, gap analysis, risk assessment, SoA, measures, internal audit and certification — realistically explained.
What AI governance means, what ISO/IEC 42001 is, what the EU AI Act requires after the 2026 Digital Omnibus amendment, and how both connect to an existing ISMS.
What ISO 9001 and ISO/IEC 27001 have in common, which processes an integrated management system (IMS) can share, and what remains specific to each standard.
NIS2, the Cyber Resilience Act and the EU AI Act explained: who is affected, which 2026 deadlines apply and how one ISMS covers shared requirements.
What an information security management system (ISMS) is, what it consists of, how it relates to ISO/IEC 27001 — and why it is more than a set of documents.
Tell us what you’re trying to solve. We listen, ask questions and suggest a sensible first step.