Services

From management system to implemented measure

The information security management system is at the centre. Whatever it uncovers — risks, gaps, improvements — we implement together with your team. The services below are examples, not a closed catalogue.

Management systems

Building, operating and integrating management systems — our core expertise.

Cybersecurity & compliance

Understanding regulatory requirements and turning them into effective measures for people, processes and technology.

AI

Governing and securing the use of AI — embedded in existing governance.

Advisory & intelligence

When measures need technology or financing: market knowledge instead of guesswork.

Integrated ISMS support

An ISMS should create action — not just documentation

An ISMS continuously produces work: requirements, risks, findings, objectives. Our support follows what your management system identifies — from the requirement to a measure that is implemented, evidenced and reviewed.

  1. Requirement, risk or finding
  2. Action required
  3. Organizational or technical measure
  4. Implementation
  5. Evidence
  6. Effectiveness review
  7. Improvement

Example: a risk assessment identifies weak authentication

Many consultants would write “implement stronger authentication” into a report and leave. This is what it can look like with us instead:

  1. Requirement understoodWhich systems, users and access paths are affected — and what does “strong enough” mean for this risk?
  2. Existing environment reviewedYour identity provider, VPN, cloud services and applications — often the capability is already licensed.
  3. Options evaluatedSettings in existing tools, organizational rules, open-source or European alternatives if something is missing.
  4. Decision by youYou choose the solution based on a clear comparison of effort, cost and risk reduction.
  5. Implementation supportedRollout plan, coordination with IT and service providers, exceptions handled.
  6. Responsibilities & peopleOwners defined, employees informed or trained where necessary.
  7. Evidence & reviewEvidence collected, effectiveness checked, risk and control status updated in the ISMS.

Examples of what we can help with

This is not a closed catalogue. If an activity, risk, control or improvement comes out of your ISMS, there is a good chance we can help you address it.

Structure

  • Risk and asset management
  • Controls and Statement of Applicability
  • Policies, procedures and process design
  • Information classification
  • Access-control processes
  • Evidence structures

Steering

  • Security objectives and KPIs
  • KPI monitoring
  • Internal audit preparation
  • Management review preparation
  • Corrective actions
  • Documentation maintenance

People

  • Responsibilities and competence
  • Awareness and employee training
  • Incident response planning
  • Workshops and working sessions
  • Supplier security and assessments

Beyond the ISMS

  • Security technology research
  • Vendor, open-source and European alternatives
  • Funding opportunity research
  • AI governance and secure AI
  • Other measures that arise from the ISMS

We do not claim to provide every specialist service ourselves — for example 24/7 SOC, MDR, penetration testing, digital forensics, emergency incident response or legal advice. Where these are needed, we help you define the requirement, find suitable specialists or solutions and integrate the result into your ISMS.

How deep we get involved

From advice to working alongside you

Every engagement is different. Most combine these three kinds of support — and shift over time as your team takes over.

Advise

We explain what is required, what the problem is, which options exist and what we recommend.

Implement together

We work with your team to design processes, create structures, prepare documentation, run workshops and close gaps.

Operate & improve together

We help coordinate recurring activities, follow up on actions, review risks, prepare audits and reviews — and keep the momentum.

Part of the team — not a transfer of responsibility

Working alongside you does not mean we take over your management responsibilities. Risk ownership, process ownership, decisions and legal responsibilities stay with your organization unless something specific is agreed. Our role: help you do the work — and do it well.

The big picture

From requirement to a stronger internal team

From requirement to a stronger internal team
  1. Understand
  2. Build the ISMS
  3. Identify risks & gaps
  4. Prioritize

People

  • Awareness
  • Training
  • Adoption
  • Knowledge

Process

  • Policies
  • Procedures
  • Incident response planning
  • Controls

Technology

  • Existing tools
  • Open source
  • European vendors
  • Other solutions
  1. Implement together
  2. Operate together
  3. Measure effectiveness
  4. Improve
  5. Transfer knowledge
  6. Stronger internal team

Your topic isn’t listed?

If it comes out of your ISMS, there is a good chance we can help — or we will tell you honestly who is a better fit.

contact@feldmanncyber.com · +49 (0)151 6275 6121