Business Continuity Management
BCM training platform for a German resilience consultancy
A German business continuity management consultancy sold crisis exercises as on-site workshops — labor-intensive, hard to scale, with no product character. Today it operates its own training platform under its own brand.
Multi-tenant
one platform, many end clients
Browser & VR
shared live exercises
Managed
set up with an EU provider, continuously maintained
Starting point
Crisis exercises depended on on-site facilitation: every session tied up consultants, every protocol was written by hand, and nothing remained with the client between exercises. The consultancy wanted to offer its proven exercise methodology as a product of its own — with audit-grade records and clean GDPR documentation, as its clients in regulated industries expect.
Solution
We built a multi-tenant training platform where teams run branching crisis scenarios live: decisions, votes, chat, and a shared whiteboard — in the browser or via VR headset, both in the same exercise. Every exercise automatically produces an audit-grade protocol.
- Branching live scenarios with decisions and votes
- Audit-grade exercise protocol at the push of a button
- AI-assisted scenario authoring for subject-matter experts
- Anonymized, GDPR-compliant KPI reporting
- White-label branding under the consultancy's brand
- Role and permission model with two-factor authentication
Results
Today the consultancy sells crisis exercises as a recurring product: its clients train regularly on the platform, while the consultants focus on methodology instead of logistics. We set up the hosting with a European provider and deliver maintenance, support, and ongoing development from a single source.
- Recurring platform revenue instead of individual workshop dates
- Audit-ready exercise records without manual protocol work
- Complete GDPR documentation as part of the delivery
- Differentiation: an own product under an own brand
Cybersecurity / Compliance
NIS2 compliance platform for an IT security consultancy
The NIS2 Directive hits the European mid-market — which cannot afford six-figure consulting projects. A German IT security consultancy therefore translated its audit expertise into a self-service platform with us.
18 sectors
parametric requirements library
AI assistant
grounded in the regulatory texts
Lead funnel
free assessment with CRM sync
EU hosting
privacy by design, EU AI Act considered
Starting point
Most affected companies don't even know whether NIS2 applies to them — let alone how to derive concrete measures from the legal text. The consultancy, at home in ISO 27001 and BSI IT-Grundschutz for over a decade, wanted to productize that knowledge: from applicability check to auditable implementation plan, without requiring a consultant for every step.
Solution
We built a multi-tenant platform covering the full compliance lifecycle. A free applicability check serves as the entry point and feeds sales through a CRM integration. At its core is a parametric requirements library: every requirement is linked to sectors and company sizes and is maintained by the consultants themselves — no developers needed.
- Free applicability check as a measurable lead magnet
- Individual action plans from a central requirements library
- Task board with roles, history, and a complete audit trail
- AI assistant that answers from the actual regulatory texts
- Real-time collaboration across the whole team
- EU hosting and cookieless analytics
Results
A decade of audit experience now lives in a reusable requirements library that serves any number of customers — instead of being re-delivered one engagement at a time. Because every action is logged, audit-ready evidence emerges as a by-product of daily work.
- Consulting knowledge scales as a product instead of billable days
- Measurable acquisition funnel from check to registration
- Regulatory evidence exportable at any time
- AI answers anchored in the real legal texts