Book an Appointment

Knowledge. Practice. Orientation.

Consulting portfolio, whitepapers, studies and practical guides on current security and compliance topics — concise, well-founded, ready to use.

News & pinned posts

Partnerships, milestones and new offerings — the most important posts from the VamiSec universe.

All news
📌 PinnedGRC & Compliance24 September 2026EBA Guidelines on Third-Party Risk 2026: What Financial Entities Now Need to Know about Non-ICT Service ProvidersOn 18 September 2026 the EBA replaced its 2019 Outsourcing Guidelines with EBA/GL/2026/09. Every recurring non-ICT service that supports a function now falls within a DORA-consistent framework — complete with a register, a catalogue of contractual clauses, subcontracting rules and a two-year transitional period. We have worked through the Final Report and published an interactive knowledge page together with a CISO whitepaper.Read more →📌 PinnedGRC & Compliance24 August 2026MID-Digitale Sicherheit: 50% grant for pentests, training & baseline IT protectionNew overview page: the NRW programme funds IT security measures with a 50% grant (€4,000–15,000) — from as-is analysis with penetration testing to security training and the initial purchase of hardware & software. Awarded in a monthly lottery via NRW.BANK — we support you from expression of interest to proof of use.Read more →📌 PinnedGRC & Compliance24 August 2026MID-Digitalisierung: 50% grant for developing digital productsThe NRW programme funds external services for developing marketable digital products built on key technologies such as AI with a 50% grant (€4,000–15,000), awarded in a monthly lottery. VamiSec develops as your contractor with security by design plus CRA and AI Act conformity from the first sprint.Read more →📌 PinnedGRC & Compliance12 August 2026Up to €15,000 in grants: GRC consulting via MID-Digitale Prozesse (NRW)The NRW state programme “Mittelstand Innovativ & Digital” funds external consulting for digitalising your GRC processes — from NIS2, CRA, EU AI Act and ISO 27001 gap analyses to roadmap, tool selection and VamiGRC implementation. The grant can cover up to 100% of the consulting. 2026 call: applications from 7 Sep to 1 Dec 2026 via NRW.BANK — we guide you through the entire funding process.Read more →📌 PinnedCloud SecurityMay 1, 2026VamiSec is a Wiz Partner for Germany and EMEA — with Technical Foundations and Demo AccreditationVamiSec GmbH is an official member of the Wiz Partner Alliance for the EMEA region — listed in the Wiz Partner Alliance Directory and holding the Wiz Partner Technical Foundations Badge as well as the Wiz Partner Demo Accreditation.Read more →📌 PinnedCompanyApril 19, 2026VamiSec and softScheck — strategy meets technical depthValeri Milke also takes on the role of Managing Director at softScheck GmbH. VamiSec remains the strategic home for GRC, compliance, and management systems — complemented by softScheck’s 20+ years of product security expertise (threat modeling, pentest, SSDLC, fuzzing).Read more →
CompanySeptember 22, 2026VamiSec speaks at International Cyber Expo 2026: Agentic AI Risk Assessment with MAESTRO & AI Red Teaming30 September, Global Cyber Summit, Olympia London: Valeri Milke shows how to model agentic-AI risks with MAESTRO, test them through AI red teaming and translate them into enterprise controls that hold up. Two event days, free registration — and our talk at 15:15.Read more →GRC & ComplianceSeptember 13, 2026VamiSec on site in Tallinn: Trust Services and eID Forum & CA-Day 202615–16 September, Kultuurikatel Tallinn: ENISA, the European Commission, D-Trust and TÜV NORD Cert gather Europe's trust community — eIDAS 2.0, EUDI Wallet, European Business Wallet, CRA cross-overs and post-quantum. We are there and translate what it means for your compliance.Read more →IT Security1 August 2026VamiSec becomes a CrowdStrike partner — Falcon from a single sourceVamiSec is an authorised CrowdStrike implementation and reselling partner: licensing, rollout and 24/7 operation of the AI-native Falcon platform — from EDR/XDR to cloud security, identity protection and MDR. Full details on our CrowdStrike landing page.Read more →IT SecurityJuly 11, 2026VamiSec is an authorized KnowBe4 partner & reseller — security awareness training & human risk managementVamiSec GmbH is an authorized KnowBe4 partner & reseller, bringing the world's largest platform for security awareness training and simulated phishing to the DACH region — from licensing to a fully managed awareness program...Read more →GRC & ComplianceJune 30, 2026VamiSec is an accredited PECB Training Partner — 300+ official certifications (ISO 27001, NIS 2, EU AI Act & more)VamiSec GmbH is an accredited PECB Training Partner, delivering 300+ internationally recognized certifications — from ISO 27001 and NIS 2 to the EU AI Act — taught by active Lead Auditors who live these standards in client projects every day.Read more →IT SecurityJune 26, 2026VamiSec is an authorized OffSec Partner for the DACH region — official trainings & certifications (OSCP, OSEP, OSWE & more)VamiSec GmbH is an authorized OffSec partner, bringing official offensive-security trainings, live labs and certifications — from OSCP and OSEP to OSWE — with German-speaking guidance to companies in Germany, Austria and Switzerland.Read more →
VamiSec Beratungsportfolio 2026 — Cover
Consulting Portfolio · 2026

VamiSec Consulting Portfolio 2026

Trusted · Holistic · Engineered

Our complete service portfolio in one deck — from ISO 27001, NIS2, DORA and CRA to IT- & Cloud Security, AI Governance, Managed Services and the Vami IMS Framework. 27 pages, compact.

📄 27 pages·2.7 MB · PDF·EN

All whitepapers at a glance

Hands-on whitepapers from our consulting work — each with its own page and direct download form, sorted by our five knowledge areas.

GRC – Governance, Risk & ComplianceTLPT per DORA: How to Truly Protect Your Crown JewelsView whitepaper page →GRC – Governance, Risk & ComplianceBSI Grundschutz++ Methodology & ISO 27001 Upgrade PathView whitepaper page →GRC – Governance, Risk & ComplianceCRA Reality Check — Zero-Days, Supply Chain & AIView whitepaper page →GRC – Governance, Risk & ComplianceDORA Reality Check — Third-Party Risk & Agentic AIView whitepaper page →GRC – Governance, Risk & ComplianceNIS2 Reality Check — Registration, Supply Chain & LiabilityView whitepaper page →GRC – Governance, Risk & ComplianceAI Act Reality Check — High-Risk Deadlines, GPAI & Agentic AIView whitepaper page →GRC – Governance, Risk & ComplianceThird-Party Risk für CISOs — EBA Non-ICT Guidelines 2026View whitepaper page →PDFIT SecurityIoT Penetration Testing — How to truly secure connected devicesView whitepaper page →Agentic AI SecurityAI OWASP LLM PenTesting: How to Truly Secure Your AI SystemsView whitepaper page →Agentic AI SecurityLLM Pentesting & Prompt Injection: How to Truly Protect AI Systems from ManipulationView whitepaper page →Agentic AI SecurityEU AI Act — Compliance Guide for CompaniesView whitepaper page →Secure Software & Product DevelopmentEU Cyber Resilience Act — Practical guide for digital productsView whitepaper page →Secure Software & Product DevelopmentCI/CD Pipeline Security: How Attackers Take Over Your Pipeline — and How You Take It BackView whitepaper page →Secure Software & Product DevelopmentOWASP Top 10 CI/CD Security Risks — Practical Guide with Compliance CrosswalkView whitepaper page →Secure Software & Product DevelopmentSecure Coding in the AI Era: The CWE Top 25 (2025) and Secure-by-DesignView whitepaper page →Secure Software & Product DevelopmentAI-Powered Security in the CI/CD PipelineView whitepaper page →Secure Software & Product DevelopmentAutomotive Threat Matrix — ATT&CK for VehiclesView whitepaper page →

Looking for Individual Advice?

Our experts are happy to support you in implementing the content from our whitepapers in your organization.

Free Initial Consultation →