A team is working together in the conference room.

IT Security Consulting

Security Strategy and Implementation
from a Single Source

We protect your IT infrastructure according to the highest standards—NIS2-compliant, with experience in KRITIS, and over 50 years of expertise in secure data center operations.

SECURITY STRATEGY & CONSULTING

Your strategy. Tailored to your needs. Put into practice.

Today, information security must accomplish two things simultaneously: respond quickly to new threats and meet growing regulatory requirements such as NIS2, DORA, and KRITIS.

When it comes to business-critical processes, sensitive data, or regulated industries, a one-off measure is quickly no longer sufficient.

With GRASS-MERKUR’s IT security consulting, you’ll receive a security strategy tailored to your actual risk profile.

From the initial analysis through the design phase to actual implementation, we provide you with comprehensive support—ensuring robust, practical IT security.

Challenges

Challenges in Modern Information Security

Many companies today are facing similar questions:

  • What impact will NIS2, DORA, or KRITIS have on our company?
  • How do we assess our current security risks?
  • Are our processes sufficiently defined and prioritized?
  • What measures are actually required—and in what order?
  • How do we ensure transparency for customers, auditors, and regulatory authorities?
  • How can we sustainably increase our cyber resilience?

Our IT security consulting provides the necessary answers—serving as the foundation for informed decisions.

Georg and Jens Ahlbrand in conversation.

SECURITY STRATEGY & CONSULTING

Why IT Security Consulting?

IT security consulting is ideal for companies that want to view their information security not in isolation, but within the broader context of business processes, systems, and risks.

It is particularly well-suited for companies that want to secure business-critical processes, comply with regulatory requirements, or systematically enhance an existing security infrastructureregardless of industry or company size.

At a Glance

  • Customized Risk Assessment Instead of a Standard Approach
  • A holistic view of technology, organization, and processes
  • Practical, actionable recommendations
  • Experience in regulated industries since 1971
  • Clear prioritization with a realistic roadmap
  • Vendor-neutral consulting
  • Close integration with data center, cloud, and managed services operations
  • Scalable for companies of all sizes

Key Areas of Expertise

Information Security That Grows With You

Three building blocks for information security you can count on.

Security and Maturity Assessment

A clear picture of the status quo, weaknesses and need for action in your information security.

What's included:

  • Security and maturity assessments
  • Protection requirement and risk analyses
  • Prioritized security strategies and roadmaps
More on Security Assessment

Building and Developing an ISMS

Structured setup or further development of an ISMS that fits your organization.

What's included:

  • ISMS design
  • Systematic risk management
  • Clear documentation structures
More on Building an ISMS

Cyber Risk Management

Systematic identification and assessment of risks as a basis for decisions.

What's included:

  • Risk analyses and threat assessments
  • Business impact analyses
  • Prioritized measures and reporting
More on Risk Management

For Whom

For Which Companies Is IT Security Consulting Suitable?

Our IT-Security Consulting is designed for companies of all sizes that want to approach information security strategically rather than case by case.

This includes mid-sized companies as well as banks, insurance companies, the public sector and operators of critical infrastructure.

Typical areas of application include

  • Preparation for NIS2 requirements
  • Establishment or further development of an ISMS
  • Conducting risk analyses
  • Preparation for certifications
  • Support with audit and compliance requirements
  • Developing an information security strategy
  • Strengthening cyber resilience

Contact

Request IT Security Consulting

Tell us about your project — we will get back to you with a concrete assessment.

I'm interested in

Direct Line

GRASS-MERKUR GmbH & Co. KG
Rothwiese 5
30559 Hannover

Your contact will advise you personally — by phone or on site.
Your GRASS-MERKUR contact: Georg Ahlbrand - Business Development & Sales

Georg Ahlbrand

Business Development Manager