Asset & risk management depth
DataGuard ISMS
The asset register is real — owners per asset, tagging, bulk import, asset-to-risk linking and dependency visualization — and risks sit in a central matrix with mitigation tasks, status tracking and pre-built libraries. Incident handling appears as configurable workflows plus a security-incidents module, but we found no public information on a documented risk methodology, inherited protection needs across asset relations, NIS2 24h/72h reporting clocks, or risk acceptance with a named accepting owner. A workable mid-market core, not yet a certifiable risk backbone.
SECJUR Digital Compliance Office (ISMS)
The evidence markets '70% schneller zur ISO 27001' and '100% Erfolgsrate', but not one word on risk methodology, asset inventory, treatment tracking, protection-needs inheritance, or incident workflows — and a claim of 'vollständige Abdeckung aller NIS2-Anforderungen' with zero evidence of 24h/72h reporting clocks is exactly the checklist theater I reject. What is evidenced is a step-by-step assistant, central task management and a policy generator: more than a marketing chapter, less than a flat risk list with asset import.