
BSI IT-Grundschutz Experts in Berlin
, matched in minutes from over 15,000 CVsHire experts who assess information security, define protection needs and implement BSI Standards with practical risk controls. FRATCH connects you with vetted, available freelancers through fast, precise AI matching.
Meet FRATCH Experts in Berlin, who have recently used BSI IT-Grundschutz
Andreas R.
Last position:
Freelance Consultant for Information Security at A-R-C Andreas Rühl Consulting
Development and implementation of tailored information security strategies
Introduction and further development of ISMS according to ISO 27001, BSI baseline protection, and other standards
Risk management and creation of security concepts
Consulting for KRITIS, PCI DSS, TISAX, and VdS 3473/10000
Building and improving security organizations
Creation and implementation of guidelines, policies, work instructions, and process descriptions
Audit support and certification preparation
Conducting trainings, workshops, and awareness campaigns
Selection and consulting on the introduction of IT security solutions such as SIEM, DLP, IDS/IPS, firewalls, and encryption technologies
Conducting penetration tests and vulnerability analyses
Consulting on the selection, integration, and management of security architectures in complex IT environments
Consulting on ITSM and managed security services and SOC
Leading and managing complex projects to improve information security
Process analysis, optimization, and management according to ITIL, ISO 27001, and cybernetics
Introduction and quality assurance of management, documentation, and knowledge management systems
Support in complying with regulatory information security requirements (e.g. GDPR, HIPAA, SOX, GMP, KRITIS)
Development and implementation of risk analysis procedures
Organizing initial response, forensic investigations, and organizational measures in the event of security incidents
Designing and running targeted workshops on topics such as ISMS, IT risks, and current threat scenarios
Awareness campaigns to promote security culture in companies
Special trainings on ISO 27001, BSI baseline protection, KRITIS, and other relevant standards
Simulations and exercises to prepare for information security incidents
Interim management for leading information security projects or IT security organizations
Taking on the role of an external CISO (Chief Information Security Officer)
Support in developing and implementing IT security and corporate strategies
Coaching and mentoring of managers in the field of information security
Building and leading security departments as well as recruiting and qualifying employees
Temporary assumption of management responsibility in critical situations
André B.
Last position:
External Attack Surface Assessment & Cybersecurity Readiness Checks at Graydaxe Cybersecurity GmbH
- Conducting cybersecurity readiness checks based on an in-house assessment methodology
- Analyzing the external attack surface using the Graydaxe EASM platform
- Assessing maturity levels and deriving prioritized recommendations for action
André G.
Last position:
IT Consulting Project Management / Engineering Subproject Management at T-Systems (on assignment for government agencies)
- Projects for federal networks (NdB).
- CR management, EoL change requests, design and documentation according to ITSCM.
- Data center planning.
- Project management and engineering subproject management.
- Software development for virtual server environments according to BSI.
Matthias S.
Last position:
Senior Security Consultant (freelance) at DVZ M-V
- ISMS and security concept for the Fabasoft e-file according to BSI 200-1/2, among others
- Structural analysis (A.1), modeling (A.3), and baseline protection checks (A.4)
- Preparation for OWASP penetration test, incident response plan, risk analysis
- DevOps Bitbucket, ARC42, IAM with Keycloak/AD, multi-tenant setup, DMS, SOC
- Emergency preparedness concept (BSI 200-4), operations and service concept (BSK), ITSM
Jörg H.
Last position:
Managing Director; Data Protection Officer; Information Security Officer at Datenschutz24 (brand of Sovestro GmbH)
- Drafting company agreements related to data protection
- Acting as a mediator between business interests and data subject rights in a corporate context
- Process analysis and evaluation regarding data protection and information security implications according to GDPR, BDSG, BSI baseline protection
- Support for information security audits according to ISO 27001
- Implementation of change management processes
- Analysis of IT infrastructure and deriving recommendations
- Expert support in legal proceedings and communication with supervisory authorities
- Preparation of data protection impact assessments (DPIAs) and procedure and processing documentation (VVZ)
- Training on corporate data protection and information security
- Cooperation with law firms in legal proceedings
Jan K.
Last position:
Consultant for Information Security & Auditor at Kopiasonsulting GmbH
Operational management of the company: building teams and infrastructure, developing products, analysis and implementation of IT security measures
Project assignments in the IT security environment focusing on establishing blue teaming activities (defensive processes and technologies) to defend against cyber attacks
Conducting red teaming processes, including penetration tests and security analyses for companies
Consulting on setting up Security Operation Centers and implementing SIEM systems, and building Computer Incident Response Teams (CSIRT)
Auditor for ISO 9001 and ISO 27001, § 8a, ISO 27019, § 11 1a EnWG, TISAX
Advising companies in critical infrastructures on information security and compliance with the IT Security Act
Building SIEM/SOC processes and SOC analyst work (Splunk, ELK-Stack)
Integrating data into monitoring tools (Prometheus, Grafana)
Consulting on BSI IT baseline protection, ISO 9001, ISO 27001, BCM, ITIL and risk management
Security assessments and penetration testing of IT and network architectures
Henryk O.
Last position:
Security Consultant at Daimler AG
- Development of a cloud security strategy
- Implementation of cloud security governance to comply with ISO/IEC 27017 and the CSA CCM
- Creation of a management system to control cloud security with a focus on process design as well as roles and responsibilities
- Definition of security measures to safeguard cloud solutions
- Conducting requirements analyses and defining the scope for cloud security projects
- Achievements: Established an effective NIS2-compliant cloud security governance that meets industry-specific requirements and effectively minimizes cloud security risks
Markus W.
Last position:
KRITIS Consultant at Oil Company
- Preparing an oil company for KRITIS auditing
- KRITIS consulting
- Creating necessary policies, processes, and guidelines in line with KRITIS requirements
- Tools and methodologies used: ISO/IEC 27001, BSI IT Baseline Protection, KRITIS-V
Discover over 15,000 top freelancers
Statistics of experts using BSI IT-Grundschutz
Aggregated from the professional profiles of matched freelancers.
Experience
30 years (Germany: 23 years)

Position duration
2.5 years (Germany: 2.6 years)

Positions per freelancer
27 (Germany: 17)

Top business areas
Information Technology, Project Management, Quality Assurance

Top industries
Professional Services, Information Technology, Education

Certification focus areas
Information Technology, Audit, Legal
Bachelor's degree or higher
86% (Germany: 85%)
Master's degree or higher
57% (Germany: 54%)
Doctorate
14% (Germany: 9%)

Certifications per freelancer
14 (Germany: 8)

Most common languages
German, English, French

Speak two or more languages
100% (Germany: 94%)
Based on our profile pool as of 19 Sep 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Berlin are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Berlin using BSI IT-Grundschutz
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 19 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
BSI IT-Grundschutz experts industry focus
See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.
- Professional Services (100%)
- Information Technology (88%)
- Education (63%)
- Manufacturing (63%)
- Media and Entertainment (63%)
- Automotive (50%)
- Energy (50%)
- Telecommunication (50%)
Please note that freelancers can work across multiple industries, so percentages overlap.
About the technology
Framework and purpose
BSI IT-Grundschutz is the German Federal Office for Information Security methodology for establishing, operating and improving an information security management system. It combines structural analysis, protection requirements, risk assessment and documented safeguards. The approach helps organisations protect information, applications, IT systems, rooms and processes in a consistent way.
Standards and structure
The framework is built around BSI Standards such as 200-1 for the information security management system, 200-2 for the IT-Grundschutz methodology and 200-3 for risk analysis. The IT-Grundschutz Compendium provides modules with threats and requirements for common organisational and technical areas. Professionals also align the work with ISO 27001 where certification or international comparability matters.
Typical deliverables
- Security policies, scopes and information security guidelines
- Structural analyses, protection requirements and modelling
- IT-Grundschutz checks, audit evidence and remediation plans
- Security concepts for infrastructure, cloud services and business processes
The result is a traceable security baseline that management, auditors and operational teams can use.
Where companies apply it
Organisations use BSI IT-Grundschutz for public services, regulated operations, healthcare, finance, manufacturing and critical business processes. It supports new system launches, supplier assessments, cloud adoption and preparation for an audit or certification. In Berlin, specialists may combine remote delivery with on-site workshops for public-sector, research and enterprise environments.
Skills around the framework
Strong professionals connect the methodology with governance, risk and compliance, privacy, business continuity and technical security. They understand networks, identity and access management, endpoint protection, logging, backup, incident response and cloud controls. Useful adjacent knowledge includes ISO 27001, NIS2 requirements, data protection and audit preparation, without treating any one standard as a substitute for sound risk decisions.
When specialist support matters
- The organisation lacks capacity to document its security management system
- Existing controls do not map clearly to BSI modules or protection needs
- A new cloud, data centre or outsourcing arrangement changes the risk profile
- Audit findings require prioritised, evidence-based remediation
A capable specialist adapts the method to the organisation instead of producing generic documents. They interview stakeholders, test whether controls work in practice and leave maintainable evidence, ownership and improvement plans.
Frequently asked questions
Curious about BSI IT-Grundschutz? Here are the answers that come up again and again.
BSI IT-Grundschutz is used to create and operate a structured information security management system. It helps organisations analyse their information assets, define protection needs, select safeguards and prepare reliable evidence for audits or certification.
BSI IT-Grundschutz provides a detailed German methodology with modules, threats and recommended safeguards, while ISO 27001 defines requirements for an information security management system. They can work together: IT-Grundschutz adds practical implementation guidance, and ISO 27001 supports international recognition.
A strong BSI IT-Grundschutz specialist should understand governance, risk management, privacy, business continuity and audit preparation. Technical familiarity with networks, identity, cloud services, logging, backup and incident response is also important because the framework must reflect real systems.
The right level depends on the scope, complexity and maturity of the organisation. A smaller assessment may need focused methodology knowledge, while a full ISMS, certification preparation or complex infrastructure requires someone who has led stakeholder interviews, modelling, control design and remediation.
BSI IT-Grundschutz can be applied to cloud environments when responsibilities between the organisation and provider are clearly mapped. A specialist should assess identity, configuration, data locations, interfaces, monitoring, resilience and supplier evidence rather than copying controls designed for on-premises systems.
BSI IT-Grundschutz work can often be delivered remotely through interviews, document reviews and collaborative modelling. On-site workshops in Berlin can still help when teams need to inspect facilities, clarify operational processes or align stakeholders who work across public-sector and enterprise environments.
Look for clear scope, traceable protection requirements, justified control choices and evidence that owners can maintain after the engagement. A good BSI IT-Grundschutz professional explains assumptions, distinguishes gaps from risks and connects every recommendation to an accountable process or system.
A BSI IT-Grundschutz freelancer usually starts by defining the information security scope, stakeholders and existing documentation. Early outputs may include a structural analysis, protection-needs assessment, project plan and prioritised findings, giving the organisation a sound basis for detailed modelling and implementation.
The average hourly rate of freelancers in Berlin, Germany who have used BSI IT-Grundschutz in their recent projects is 115 €, which corresponds to a daily rate of about 917 € based on an 8-hour working day.
Of the freelancers in Berlin, Germany who have used BSI IT-Grundschutz in their recent projects, 86% hold at least a Bachelor's degree, 57% hold at least a Master's degree, and 14% hold a doctorate.
On average, freelancers in Berlin, Germany who have used BSI IT-Grundschutz in their recent projects have 30 years of professional experience, with a single engagement typically lasting around 2.5 years.
The most common languages among freelancers in Berlin, Germany who have used BSI IT-Grundschutz in their recent projects are German (100%), English (100%), and French (25%).
The most common industries among freelancers in Berlin, Germany who have used BSI IT-Grundschutz in their recent projects are Professional Services (100%), Information Technology (88%), and Education (63%).
The most common business areas among freelancers in Berlin, Germany who have used BSI IT-Grundschutz in their recent projects are Information Technology (100%), Project Management (88%), and Quality Assurance (88%).
Main locations of FRATCH Experts, who have recently used BSI IT-Grundschutz
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Countries:
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Munich
Cologne
Frankfurt
Dusseldorf