Scope & context
What does the ISMS cover, which interested parties and requirements matter, and what are your security objectives?
Management systems
We help you build an information security management system (ISMS) that fits how your organization already works — and prepare it for ISO/IEC 27001 certification. We do not stop at the gap analysis: we work alongside your team to implement what the ISMS identifies — and help your people understand and run it.
ISO/IEC 27001 is not hard because of its length. It becomes hard when the ISMS lives next to the organization instead of inside it.
Everything an ISMS needs for ISO/IEC 27001 — structured so that your team can keep it running.
What does the ISMS cover, which interested parties and requirements matter, and what are your security objectives?
Where do you stand today against ISO/IEC 27001 — and what is already there that we can build on?
An asset inventory and a risk assessment method that people can actually apply, plus a risk treatment plan.
Selecting and justifying Annex A controls, and a Statement of Applicability that reflects reality.
Clear, short policies and procedures written for the people who follow them — not for the shelf.
Who owns which risk, control and process — agreed with the people involved.
Measurable security objectives and a small set of meaningful indicators.
Evidence structure, internal audit, management review and support through the certification audit.
Integrated ISMS support
An ISMS continuously produces work: requirements, risks, findings, objectives. Our support follows what your management system identifies — from the requirement to a measure that is implemented, evidenced and reviewed.
Many consultants would write “implement stronger authentication” into a report and leave. This is what it can look like with us instead:
This is not a closed catalogue. If an activity, risk, control or improvement comes out of your ISMS, there is a good chance we can help you address it.
We do not claim to provide every specialist service ourselves — for example 24/7 SOC, MDR, penetration testing, digital forensics, emergency incident response or legal advice. Where these are needed, we help you define the requirement, find suitable specialists or solutions and integrate the result into your ISMS.
How deep we get involved
Every engagement is different. Most combine these three kinds of support — and shift over time as your team takes over.
We explain what is required, what the problem is, which options exist and what we recommend.
We work with your team to design processes, create structures, prepare documentation, run workshops and close gaps.
We help coordinate recurring activities, follow up on actions, review risks, prepare audits and reviews — and keep the momentum.
Part of the team — not a transfer of responsibility
Working alongside you does not mean we take over your management responsibilities. Risk ownership, process ownership, decisions and legal responsibilities stay with your organization unless something specific is agreed. Our role: help you do the work — and do it well.
We learn how your organization works: people, processes, systems, existing documentation and tools.
We compare the current state with ISO/IEC 27001 and agree on a realistic roadmap and responsibilities.
Risks, controls, policies and processes are developed in workshops with your team — inside your existing systems where possible.
We explain the why behind each part and train the people who will run the ISMS day to day.
We run or support the internal audit and management review and close the remaining gaps.
We support you through the certification audit and — if you like — the operation afterwards.
Your ISMS should belong to your organization — not your consultant
We document in your systems, explain every decision and hand over knowledge step by step. The goal is an ISMS your team understands and can run — with us as long as it helps, without us when you are ready.
You are starting from scratch or with first steps and want to introduce an ISO/IEC 27001 ISMS and get certified.
Your ISMS exists — maybe certified — but day-to-day operation takes too much effort or no longer matches reality.
Organizational adoption
An ISMS can be perfectly documented and still fail — if people see it as bureaucracy, believe security belongs to IT, or only act right before the audit. That is why adoption is part of every implementation we do.
Over time your people become increasingly able to manage their responsibilities, recognize risks and changes, maintain processes and evidence, prepare audits and suggest improvements. We can keep supporting you — but your own ISMS maturity should grow.
An information security management system (ISMS) is the set of policies, processes, responsibilities and controls an organization uses to manage information security risks systematically. ISO/IEC 27001 is the international standard that describes the requirements for such a system.
It depends on size, scope and starting point. Many small and mid-sized organizations need roughly six to twelve months from kick-off to certification readiness. After the gap analysis we give you a realistic plan instead of a generic promise.
Very often, yes. If you already have a knowledge base, document management, ticketing or project tool, large parts of the ISMS can live there. We only suggest additional software where it clearly helps — including our own app.
No. Certification is carried out by an independent, accredited certification body. We prepare you for the audit and can accompany you through it — keeping consulting and certification separate is what makes the certificate credible.
We help you do the work — we coordinate, prepare, facilitate, implement and follow up alongside your team. Management responsibility, risk ownership, process ownership and decisions stay with your organization, unless something specific has been agreed in the contract. That is also what makes an ISMS work: the people who own the risks understand them.
Then we help you define the requirement, find suitable specialists, vendors or open-source options, and integrate the result back into the ISMS. We do not claim to provide every specialist service ourselves (such as 24/7 SOC, penetration testing or forensics), but we make sure the measure is chosen well and the ISMS keeps moving.
The ISMS has to keep working: risks are reviewed, controls monitored, internal audits and management reviews repeated, and surveillance audits follow each year. We can support this through ISMS maintenance.
Yes. NIS2 requires risk management measures that overlap substantially with ISO/IEC 27001. An ISMS gives you the structure to implement and evidence them. It does not automatically cover every NIS2 obligation, such as registration or specific reporting duties.
Ongoing support for an existing ISMS: risks, controls, evidence, audits and reviews that keep happening — not just before the audit.
Combine quality, information security and AI governance in one integrated management system with shared processes.
Awareness training connected to your ISMS, policies and systems — so employees understand not only what to do, but why.
Related in the FeldmannCyber App: Vendor Intelligence
Certification is not the finish line. What ISMS maintenance involves, which activities recur every year, and how to avoid the pre-audit panic.
Can an ISO 27001 ISMS use your existing tools? Yes — how wikis, document management, ticketing and project tools can carry large parts of it.
How to implement ISO 27001 step by step: scope, gap analysis, risk assessment, SoA, measures, internal audit and certification — realistically explained.
Tell us where you stand. We will give you an honest view of the effort and a sensible first step.