Skip to main content
Strategic IT Consulting

Legal Security. Cost-Effectiveness. Compliance with Common Sense.

We bridge the gap between IT technology, legal requirements and business reality. From audit defense through contract optimization to NIS2 implementation.

Governance & Risk

Strategic Consulting

We advise at C-level to minimize risks and secure long-term strategies.

Audit Defense

The fire department when the vendor is on fire. We take over communication during audits (Oracle, SAP, Microsoft) and defend against unjustified claims.

Contract Engineering

Contracts that work technically. We check license contracts for operational feasibility and cost traps before you sign.

Regulatory (NIS2 / DORA)

Minimize liability risks. We translate EU directives into concrete IT measures for mid-market companies – pragmatically, without bureaucratic overhead.

CIO Advisory

Your external right hand. We support strategic make-or-buy decisions and aligning IT with business goals.

The Strategic Connector

The 360° Strategy Approach.

Consulting is not a silo. It is the foundation on which your operational units work safely. The biggest risk in IT is the interface: When lawyers speak in paragraphs but don't understand the technology.

Novartum acts as your translator. We bring technical facts to the table in a way that they can be decided legally sound and commercially sensible.

Consulting + Procurement

Procurement negotiates the price, consulting defines the content. We provide the arguments, scenarios and benchmarks your procurement needs to enforce best prices.

Consulting + SAM

SAM provides data. Consulting assesses the legal risk. We interpret 'gray areas' in the terms and conditions to your advantage (e.g., virtualization, second-use rights).

Consulting + ITSM

Regulation (NIS2) must not paralyze operations. We design compliance requirements so that they are directly automated in your ITSM workflows.

Current Threats

Risk Radar

These topics are currently occupying IT decision-makers the most. We have the answers.

Liability Risk

NIS2 Directive

Häufige Risiken
  • Personal Liability of Management
  • Fines up to €10M or 2% Revenue
  • Reporting Obligation for Incidents within 24h
Die Novartum Lösung

Conducting a gap analysis, defining critical assets and creating a pragmatic action plan to achieve 'state of the art' compliance.

Beratung anfragen
Financial Risk

Audit Defense

Häufige Risiken
  • Estimates by Vendor
  • Freezing of Discounts
  • Unplanned Cash-Out in Millions
Die Novartum Lösung

Single-Point-of-Contact Strategy. We channel all communication, validate all data before release in a sandbox and negotiate the 'Commercial Settlement'.

Beratung anfragen
Operational Risk

Contract Gaps

Häufige Risiken
  • Price-Uplifts without Upper Limit (Cap)
  • Missing Exit Clauses / Lock-in
  • Indirect Use Uncovered
Die Novartum Lösung

Red-lining your contracts. We strike critical passages and add protective clauses (e.g., for divestitures, M&A or cloud exit).

Beratung anfragen
Methodology

The 'Safe Harbor' Process

Our standardized approach creates security in crisis situations.

Our Standard

  • Discretion & Confidentiality
  • Legally Validated Approach
  • Result Orientation
01

Assess

Initial risk assessment. Analysis of the audit letter or inventory of NIS2 status.

02

Stabilize

Immediate measures for damage limitation. Imposition of a data stop (audit) or closing critical gaps.

03

Strategize

Development of negotiation or implementation strategy. Simulation of various scenarios (best/worst case).

04

Execute

Leading negotiations with the vendor or implementing compliance measures.

05

Proof

Final report and legally secure documentation (audit-proof) to defend against future claims.

Negotiating Power

We know the leeway of vendors and enforce your interests.

Risk Minimization

We identify risks before they become problems.

C-Level Language

We prepare technical topics in a decision-ready manner for management.

Our Approach

Why IT Projects Often Fail.

The biggest risk in IT is not the technology itself, but the interface. Lawyers speak in paragraphs, technicians speak code and procurement speaks budget. When these worlds are not synchronized, contract gaps, security risks and exploding costs arise.

Novartum acts as your translator and strategist. We bring technical facts to the table in a way that they can be decided legally sound and commercially sensible.

€0Accepted Penalties
100%Compliance Rate
NIS2Ready Check
Knowledge at a Glance

FAQ

Antworten auf die wichtigsten Fragen rund um Lizenzmanagement, Audits und Compliance. Optimiert für schnelle Informationsfindung.

Noch Fragen offen?

Unsere Experten beraten Sie gerne unverbindlich.

Yes, NIS2 tightens liability (Art. 20). Management must approve and monitor cybersecurity measures. Ignorance does not protect from punishment. We train your management and document the fulfillment of the duty of care.
No, never unchecked! Vendor scripts often collect more data than contractually agreed (data protection risk) or incorrectly interpret configurations as license-required. Let Novartum check the scripts in a sandbox before you send data.
No, we complement them. Lawyers know the law, we know the technology and license metrics. We provide your legal counsel with the technical fact base ('Technical Fact Finding') so they can win the case legally.
In disputes, vendors often claim usage that technically did not occur. We forensically analyze logs, configurations and architectures to technically refute these claims.
Yes. Many contracts contain lock-in clauses that make switching expensive. We design exit strategies and negotiate contract clauses that secure your data sovereignty and switching options.