Knowledge. Practice. Orientation.
Consulting portfolio, whitepapers, studies and practical guides on current security and compliance topics — concise, well-founded, ready to use.
Knowledge by topic
Our knowledge is organized into five topic areas. Each topic area has its own knowledge page with in-depth content, related pages and the matching whitepapers for download.
GRC – Governance, Risk & Compliance
ISO 27001, BSI IT-Grundschutz, DORA, NIS2, the EU CRA and the EU AI Act — governance, risk management and audit-ready compliance.
Explore topicIT Security
Penetration testing, secure coding, threat modeling and a secure SDLC — technical security across the entire lifecycle.
Explore topicAgentic AI Security
LLM & agentic-AI pentesting, prompt injection, OWASP LLM Top 10 and AI threat modeling — securing AI systems.
Explore topicCloud Security
CSPM & CNAPP (partner: Wiz), sovereign cloud architecture, BSI C5, ISO 27017 and the EU Cloud & AI Act (CADA) — cloud security, compliance and sovereignty as one.
Explore topicSecure Software & Product Development
Secure coding, SSDLC, CI/CD security, supply chain (SLSA, SBOM) and product regulation from CRA to IEC 62443 — security across the entire product lifecycle.
Explore topicNews & pinned posts
Partnerships, milestones and new offerings — the most important posts from the VamiSec universe.
VamiSec is a Wiz Partner for Germany and EMEA — with Technical Foundations and Demo AccreditationVamiSec GmbH is an official member of the Wiz Partner Alliance for the EMEA region — listed in the Wiz Partner Alliance Directory and holding the Wiz Partner Technical Foundations Badge as well as the Wiz Partner Demo Accreditation.Read more →VamiSec and softScheck — strategy meets technical depthValeri Milke also takes on the role of Managing Director at softScheck GmbH. VamiSec remains the strategic home for GRC, compliance, and management systems — complemented by softScheck’s 20+ years of product security expertise (threat modeling, pentest, SSDLC, fuzzing).Read more →All whitepapers at a glance
Hands-on whitepapers from our consulting work — each with its own page and direct download form, sorted by our five knowledge areas.
GRC – Governance, Risk & ComplianceTLPT per DORA: How to Truly Protect Your Crown JewelsView whitepaper page →
GRC – Governance, Risk & ComplianceBSI Grundschutz++ Methodology & ISO 27001 Upgrade PathView whitepaper page →PDFIT SecurityIoT Penetration Testing — How to truly secure connected devicesView whitepaper page →
Agentic AI SecurityAI OWASP LLM PenTesting: How to Truly Secure Your AI SystemsView whitepaper page →
Agentic AI SecurityLLM Pentesting & Prompt Injection: How to Truly Protect AI Systems from ManipulationView whitepaper page →
Agentic AI SecurityEU AI Act — Compliance Guide for CompaniesView whitepaper page →
Secure Software & Product DevelopmentEU Cyber Resilience Act — Practical guide for digital productsView whitepaper page →
Secure Software & Product DevelopmentCI/CD Pipeline Security: How Attackers Take Over Your Pipeline — and How You Take It BackView whitepaper page →
Secure Software & Product DevelopmentOWASP Top 10 CI/CD Security Risks — Practical Guide with Compliance CrosswalkView whitepaper page →
Secure Software & Product DevelopmentSecure Coding in the AI Era: The CWE Top 25 (2025) and Secure-by-DesignView whitepaper page →
Secure Software & Product DevelopmentAI-Powered Security in the CI/CD PipelineView whitepaper page →Looking for Individual Advice?
Our experts are happy to support you in implementing the content from our whitepapers in your organization.
Free Initial Consultation →