How we work

We work with your team — not around it

No report with a task list after which we disappear. We understand what you have, implement what is needed together, and transfer knowledge until your team carries the management system itself.

Illustration: two colleagues sitting together at a computer, discussing a task

We don’t just tell you what needs to be done. We help you do it.

The classic consulting model

  1. Consultant analyses the company
  2. Creates a report
  3. Produces a task list
  4. Customer does everything
  5. Consultant returns later

How we work

  1. FeldmannCyber + your team
  2. Understand & prioritize
  3. Plan together
  4. Implement together
  5. Operate together
  6. Transfer knowledge
  7. Improve

How we work

The same logic applies whether we build a new ISMS, take over an existing one or implement a single measure.

  1. Understand

    Your organization, people, technology, existing processes and management systems.

  2. Integrate

    Use what already works. Avoid unnecessary replacement and duplicate processes.

  3. Identify

    Requirements, risks, gaps, findings and improvement opportunities.

  4. Prioritize

    Decide what actually matters and what should be addressed first.

  5. Implement together

    Work alongside your teams on practical organizational and technical measures.

  6. Enable

    Explain the system, train where useful and transfer knowledge while doing the work.

  7. Operate

    Help coordinate recurring ISMS activities where ongoing support is wanted.

  8. Improve

    Measure effectiveness, learn from incidents and findings, keep improving.

  9. Extend

    Where new capabilities are needed: existing technology, process changes, open source, European vendors, specialists and funding.

  10. Automate

    Where useful, simplify or automate repetitive management-system work with appropriate technology and AI.

Our principles

Integrate before you replace

We work with what you already have: knowledge bases, document systems, ticketing and project tools, identity and cloud environments.

Use what works. Improve what doesn’t.

No reinvention on principle. We add where there is a real gap.

Fit to your organization

Your management system should fit your organization — not the other way around.

Knowledge transfer, not dependency

Explain, implement together, document, train, hand over — your ISMS belongs to you.

How knowledge is transferred

  1. Explain
  2. Implement together
  3. Document
  4. Train
  5. Transfer knowledge
  6. Operate together
  7. Improve

How deep we get involved

From advice to working alongside you

Every engagement is different. Most combine these three kinds of support — and shift over time as your team takes over.

Advise

We explain what is required, what the problem is, which options exist and what we recommend.

Implement together

We work with your team to design processes, create structures, prepare documentation, run workshops and close gaps.

Operate & improve together

We help coordinate recurring activities, follow up on actions, review risks, prepare audits and reviews — and keep the momentum.

Part of the team — not a transfer of responsibility

Working alongside you does not mean we take over your management responsibilities. Risk ownership, process ownership, decisions and legal responsibilities stay with your organization unless something specific is agreed. Our role: help you do the work — and do it well.

Integrated ISMS support

An ISMS should create action — not just documentation

An ISMS continuously produces work: requirements, risks, findings, objectives. Our support follows what your management system identifies — from the requirement to a measure that is implemented, evidenced and reviewed.

  1. Requirement, risk or finding
  2. Action required
  3. Organizational or technical measure
  4. Implementation
  5. Evidence
  6. Effectiveness review
  7. Improvement

Example: a risk assessment identifies weak authentication

Many consultants would write “implement stronger authentication” into a report and leave. This is what it can look like with us instead:

  1. Requirement understoodWhich systems, users and access paths are affected — and what does “strong enough” mean for this risk?
  2. Existing environment reviewedYour identity provider, VPN, cloud services and applications — often the capability is already licensed.
  3. Options evaluatedSettings in existing tools, organizational rules, open-source or European alternatives if something is missing.
  4. Decision by youYou choose the solution based on a clear comparison of effort, cost and risk reduction.
  5. Implementation supportedRollout plan, coordination with IT and service providers, exceptions handled.
  6. Responsibilities & peopleOwners defined, employees informed or trained where necessary.
  7. Evidence & reviewEvidence collected, effectiveness checked, risk and control status updated in the ISMS.

Examples of what we can help with

This is not a closed catalogue. If an activity, risk, control or improvement comes out of your ISMS, there is a good chance we can help you address it.

Structure

  • Risk and asset management
  • Controls and Statement of Applicability
  • Policies, procedures and process design
  • Information classification
  • Access-control processes
  • Evidence structures

Steering

  • Security objectives and KPIs
  • KPI monitoring
  • Internal audit preparation
  • Management review preparation
  • Corrective actions
  • Documentation maintenance

People

  • Responsibilities and competence
  • Awareness and employee training
  • Incident response planning
  • Workshops and working sessions
  • Supplier security and assessments

Beyond the ISMS

  • Security technology research
  • Vendor, open-source and European alternatives
  • Funding opportunity research
  • AI governance and secure AI
  • Other measures that arise from the ISMS

We do not claim to provide every specialist service ourselves — for example 24/7 SOC, MDR, penetration testing, digital forensics, emergency incident response or legal advice. Where these are needed, we help you define the requirement, find suitable specialists or solutions and integrate the result into your ISMS.

Organizational adoption

A management system should not just exist. People should use it.

An ISMS can be perfectly documented and still fail — if people see it as bureaucracy, believe security belongs to IT, or only act right before the audit. That is why adoption is part of every implementation we do.

  1. “I have to do this because ISO says so.”
  2. “I understand why this process exists.”
  3. “I understand my role.”
  4. “I understand how this protects our organization.”
  5. “This is part of how we work.”

Adoption comes from more than training

  • Involving process owners when processes are designed
  • Explanations during the work, not only in formal sessions
  • Understandable responsibilities and useful documentation
  • ISMS tasks integrated into existing workflows and tools
  • Less duplicate work and less bureaucracy
  • Management involvement and recurring communication
  • Feedback from employees — and acting on it
  • Automation of repetitive work where it helps

Stronger internal team

Over time your people become increasingly able to manage their responsibilities, recognize risks and changes, maintain processes and evidence, prepare audits and suggest improvements. We can keep supporting you — but your own ISMS maturity should grow.

From requirement to a stronger internal team

From requirement to a stronger internal team
  1. Understand
  2. Build the ISMS
  3. Identify risks & gaps
  4. Prioritize

People

  • Awareness
  • Training
  • Adoption
  • Knowledge

Process

  • Policies
  • Procedures
  • Incident response planning
  • Controls

Technology

  • Existing tools
  • Open source
  • European vendors
  • Other solutions
  1. Implement together
  2. Operate together
  3. Measure effectiveness
  4. Improve
  5. Transfer knowledge
  6. Stronger internal team

Sounds like the kind of collaboration you’re looking for?

Tell us what you’re working on.

contact@feldmanncyber.com · +49 (0)151 6275 6121