Cybersecurity & compliance

From identified gap to the right security measure

An ISMS, audit or risk assessment tells you what is missing. It rarely tells you what to do next. We help you find the most appropriate response — which is not always a new product.

Why consulting should not stop at documentation

  • The risk treatment plan says “implement logging” — but how, with what, and who operates it?
  • Vendors each claim to solve everything
  • Existing tools already have the capability, but nobody knows
  • Open-source options are dismissed or adopted without a plan for operation
  • Purchases are made without checking whether they address the actual risk

What we help with

Requirement clarification

What exactly does the risk, finding or regulation require — and what is the minimum effective measure?

Existing stack review

Which capabilities do your current systems already offer, licensed but unused?

Process options

Where an organizational or process measure is sufficient or better.

Open-source options

Credible open-source tools — including what it takes to operate them.

Vendor shortlists

Relevant vendors from our curated database, with a strong European focus.

Decision support

Comparing options by risk reduction, effort, cost, operation and dependencies.

How we find the right measure

  1. Requirement

    Start from the risk, finding or regulatory requirement.

  2. Existing stack

    Check what your current technology can already do.

  3. Organizational measure

    Consider whether a process or organizational change is sufficient.

  4. Open source & EU vendors

    Research open-source and European options where appropriate.

  5. Decision & implementation

    Choose, plan the implementation and document it in the ISMS.

Not “find another product to buy”

Our goal is the most appropriate measure for the identified requirement. Sometimes that is a new tool. Often it is a setting, a process or a capability you already pay for. We have no reseller model that would bias our recommendation.

The right measure

Five questions before anything is bought

We work through these questions in order. Often the answer is found at question one or two.

  1. Can your existing technology solve the problem?

  2. Is an organizational or process measure sufficient?

  3. Is an open-source solution appropriate?

  4. Is a European cybersecurity provider appropriate?

  5. Is another commercial product necessary?

What you get out of it

  • Measures that address the actual risk
  • Better use of the technology you already have
  • Transparent decisions that hold up in the next audit

Frequently asked questions

Do you sell security products?

No. We advise on measures and help you evaluate options. That keeps our recommendations independent from product margins.

Do you only recommend European vendors?

No. We give European and open-source options serious consideration because technology independence matters. But the best measure for the requirement comes first — and European does not automatically mean more secure.

Related services

Related in the FeldmannCyber App: Vendor Intelligence

Related reading

Have a finding and no clear next step?

Tell us what the requirement is. We help you find the measure that fits.

contact@feldmanncyber.com · +49 (0)151 6275 6121