Roles & responsibilities
Who leads, who decides, who communicates — including deputies.
Cybersecurity & compliance
When a security incident happens, there is no time to figure out who decides what. We develop your incident response plan together with IT, management and other stakeholders — clear, tested and connected to your ISMS.
Who leads, who decides, who communicates — including deputies.
When an event becomes an incident, and when an incident becomes a crisis.
A simple scheme to assess severity and priority quickly.
Internal and external communication, including templates.
Internal contacts and external partners such as IT providers, insurers, forensics, legal counsel and authorities.
Regulatory reporting timelines (e.g. NIS2, CRA, GDPR) mapped to clear steps.
What to record during an incident and how to preserve evidence.
A structured review that feeds back into risks and corrective actions.
Systems, dependencies, existing processes, service providers and obligations.
Workshops with IT, management and other stakeholders to agree on roles and decisions.
A concise plan and playbooks for likely scenarios — usable under stress.
Tabletop exercises to walk through realistic scenarios where appropriate.
Link to the ISMS: risk assessment, corrective actions, awareness and reviews.
What we do — and what we do not replace
We help you plan and prepare. We are not a 24/7 emergency response team and do not replace your IT department, security operations center, forensics provider or legal counsel. A good plan defines exactly when and how you involve them.
Incidents as a source of improvement
The plan does not end with recovery. It closes the loop back into the management system.
At minimum: scope and definitions, roles and responsibilities, escalation and decision rules, a classification scheme, communication paths and contacts, reporting obligations and deadlines, documentation and evidence requirements, and a lessons-learned process. Scenario playbooks help for the most likely incident types.
ISO/IEC 27001 requires planned incident management. NIS2 requires incident handling and reporting; affected entities must submit an early warning within 24 hours. The Cyber Resilience Act sets reporting obligations for manufacturers. In practice, a plan is the only way to meet these deadlines reliably.
Our focus is preparation and improvement. During an acute incident you need your IT, specialized emergency responders and — where relevant — forensics and legal counsel. Your plan should name them in advance.
Build a working ISMS and prepare for ISO/IEC 27001 certification — together with your team and on top of the tools you already use.
Awareness training connected to your ISMS, policies and systems — so employees understand not only what to do, but why.
Understand which cybersecurity regulations apply, identify the gaps and implement practical technical and organizational measures.
What an incident response plan must contain: roles, escalation, communication, NIS2 and CRA reporting deadlines, evidence and lessons learned.
Recap of the IHK Darmstadt IT managers meeting: FeldmannCyber on IT security monitoring along the Cyber Kill Chain — scans, monitoring and SIEM.
Certification is not the finish line. What ISMS maintenance involves, which activities recur every year, and how to avoid the pre-audit panic.
Let us build one with your team before you need it.