Requirement clarification
What exactly does the risk, finding or regulation require — and what is the minimum effective measure?
Cybersecurity & compliance
An ISMS, audit or risk assessment tells you what is missing. It rarely tells you what to do next. We help you find the most appropriate response — which is not always a new product.
What exactly does the risk, finding or regulation require — and what is the minimum effective measure?
Which capabilities do your current systems already offer, licensed but unused?
Where an organizational or process measure is sufficient or better.
Credible open-source tools — including what it takes to operate them.
Relevant vendors from our curated database, with a strong European focus.
Comparing options by risk reduction, effort, cost, operation and dependencies.
Start from the risk, finding or regulatory requirement.
Check what your current technology can already do.
Consider whether a process or organizational change is sufficient.
Research open-source and European options where appropriate.
Choose, plan the implementation and document it in the ISMS.
Not “find another product to buy”
Our goal is the most appropriate measure for the identified requirement. Sometimes that is a new tool. Often it is a setting, a process or a capability you already pay for. We have no reseller model that would bias our recommendation.
The right measure
We work through these questions in order. Often the answer is found at question one or two.
No. We advise on measures and help you evaluate options. That keeps our recommendations independent from product margins.
No. We give European and open-source options serious consideration because technology independence matters. But the best measure for the requirement comes first — and European does not automatically mean more secure.
Requirement-driven vendor selection with curated intelligence on 350+ cybersecurity vendors and a strong European and open-source focus.
Build a working ISMS and prepare for ISO/IEC 27001 certification — together with your team and on top of the tools you already use.
Identify relevant funding programs for cybersecurity, digitalization and AI projects in Germany, the federal states and the EU.
Related in the FeldmannCyber App: Vendor Intelligence
Can an ISO 27001 ISMS use your existing tools? Yes — how wikis, document management, ticketing and project tools can carry large parts of it.
Funding for digital and cybersecurity projects in Hesse: Distr@l, RKW consulting grants, DIGI grant, push!, Prototype Fund and the de minimis rule.
Recap of the IHK Darmstadt IT managers meeting: FeldmannCyber on IT security monitoring along the Cyber Kill Chain — scans, monitoring and SIEM.
Tell us what the requirement is. We help you find the measure that fits.