ISO 27002 Experts in Germany
matched in minutes with vetted specialistsHire experts who can turn ISO 27002 into practical controls, clear policies, and audit-ready evidence. Bring in specialists for risk treatment, control design, internal reviews, and gap assessments, with fast, precise matching to vetted, available freelancers.
Meet FRATCH Experts in Germany, who have recently used ISO 27002
Florian Schröder
Last position:
Information Security Officer / Designated InfoSec Officer at Oil Company
- Complete overhaul of the ISMS according to ISO 27001
- Conducted a comprehensive gap analysis
- Reduced ISMS documentation by 30% through consolidation and process optimization
- Introduced a full PDCA cycle for continuous improvement
- Established the ISMS within the company
- Implemented the necessary processes
- Managed and conducted internal and external audits
- Developed and implemented a company-wide risk management system
- Deployed an ISMS tool including process design and training
- KRITIS compliance: Prepared and provided required evidence, liaised with regulatory authorities, planned, documented, and implemented an attack detection system (SIEM), co-led the BCMS/ITSCM implementation subproject
- NIS-2 implementation: Gap analysis, risk assessments, training for executives and staff
- Led a cybersecurity team of 3 members
- Conducted various internal and external audits, managed providers, introduced continuous improvement
- Project consulting: closely coordinated with business and system owners, launched an online shop, a mobile app, and a customer portal
- Redesigned the security architecture, reducing administrative efforts by 20%
- Implemented ITIL processes (e.g., change management)
- Revised service agreements with internal and external providers
- Developed a security awareness strategy, ran social engineering tests, introduced and monitored phishing simulations, created various awareness materials, gave presentations
- Managed a budget of one million euros
Peter Dittkuhn
Last position:
Security Consultant at Public Institution of the City Administration
- Requirements management, process planning, interface role, ISMS implementation and documentation
- Implementation and establishment of an ISMS according to ISO 27001 as well as setup of emergency management / ITSCM
- Coordination of conditions with the authority-affiliated IT service provider
- Consideration of KRITIS relevance in the scope and implementation of a B3S
- Development of guidelines for document control and the continuous improvement process (KVP)
- Creation of relevant project documents
- Analysis of existing processes and development of guidelines
- Collection of requirements for ISMS and ITSCM and coordination with the IT service provider including definition of interfaces
- Analysis of communication processes and escalation paths
- Review of documents for risk management, ISMS, emergency preparedness and emergency response
- Development of a complete rebuild of all documentation and creation of new relevant documents
- Development of necessary rules, policies and concepts
- Interface function between customer and service provider to ensure document quality
- Coordination of protection needs with departments, especially regarding KRITIS relevance, and planning resulting measures
- Development of preventive measures to minimize data center outages for various scenarios such as pandemics or ransomware attacks
- Defining the test strategy for IT emergency exercises
- Initiation of necessary training measures for raising awareness in departments
- External Information Security Officer (ISB)
- Introduction of document control
Markus Marschollek
Last position:
Project Manager / Senior Consultant (multiple projects) at gkv informatik
- Project manager controlling the update to ISO 27001:2022 (certification from ISO 27002:2013 to ISO 27002:2022) including gap analysis, project planning, preparation of internal and external audits, and creation and maintenance of required documentation.
- Coordination of adjusting existing measures and implementing new measures according to the new standard’s requirements, as well as continuous monitoring and adjustment of these measures.
- Regular reporting to management on progress and risks.
- Senior consultant supporting audit reviews with a focus on critical infrastructures (KRITIS), including resolving findings, creating and updating evidence documents, and amending provider contracts.
- Senior consultant reviewing all deliverables and responsibilities of the IT provider according to the existing contract: identification of over 1500 deliverables & obligations (D&O), setup of a D&O tracker (claim register), and joint expert review with service owners for various service descriptions (e.g. IT service management, workplace and print services, application and desktop services, endpoint management, email including archiving, file services, software packaging, certification, distribution).
- Senior consultant adjusting service scopes in existing service descriptions to enable end-to-end service responsibility of the provider, including identification and analysis of use cases, process analysis and optimization (incident, problem, change), as well as recording and documenting all software products in LeanIX and documenting the contract change.
- Focused services: managed software service, application and desktop service, workplace and print services, web server service, container service, M365, SAP/Oscare, output management systems (OMS), telephony and omnichannel management service.
- Project manager steering a benchmark based on the existing IT contract, including coordination of the entire benchmark process between the benchmarker, IT provider and client, review of benchmark results, and preparation and conduct of price negotiations with the IT provider.
Sergey Komarov
Last position:
Managing Director Cybersecurity at CBA-Cybersecurity and Business Advisory GmbH
- Development of comprehensive services in cybersecurity, IT governance, and AI
- Building and delivering strategic security solutions such as vCISO service, ISMS, SOC-as-a-Service (SIEM, SOAR, use cases, playbooks, threat hunting, incident response), AI-driven risk and compliance tools, and frameworks for outsourcing and third-party risks
- Supporting companies in meeting regulatory requirements and certifications (ISMS, NIS-2, DORA, CRA, KRITIS, ISO 27001, TISAX, BSI IT Baseline Protection, EU AI Act)
- Promoting innovations in cybersecurity automation, AI governance, and secure digital transformation
- Responsible for company growth, client relations, and strategic partnerships
Norbert Stilling
Last position:
Self-Employed Consultant and Project Manager at Self-Employed Consultant and Project Manager
- 21 projects ≥ 6 months at large and medium-sized companies
- 13 projects as project or subproject manager
- 6 international projects with English as project language
Ralf Lembke
Last position:
Chief Information Security Officer at Stadtwerke Krefeld Holding AG
- Building an information security management system for the entire group
- Supporting 2 KRITIS subsidiaries
Klaus-Dieter Krause
Last position:
Executive Partner at iAP-Independent Audit Professionals GmbH
Discover over 15,000 top freelancers
Statistics of experts using ISO 27002
Aggregated from the professional profiles of matched freelancers.
Experience
35 years
Position duration
5 years
Positions per freelancer
15
Top business areas
Information Technology, Project Management, Operations
Top industries
Manufacturing, Aerospace and Defense, Information Technology
Certification focus areas
Information Technology, Audit, Legal
Bachelor's degree or higher
100%
Master's degree or higher
25%
Doctorate
25%
Certifications per freelancer
10
Most common languages
German, English, Spanish
Speak two or more languages
100%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using ISO 27002
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
Control guidance
ISO 27002 is the code of practice that helps teams choose and apply security controls from ISO/IEC 27001 and the wider ISO 27000 family. It is used to shape policies, procedures, and control sets that fit the way a company actually works.
What specialists do
- Map security controls to business risks and systems
- Write or refine policies, standards, and control guidance
- Support internal audits and certification preparation
- Review gaps across suppliers, cloud services, and endpoints
Where it fits
Companies bring in ISO 27002 specialists when they need a clear baseline for information security, not vague advice. It is common in regulated environments, in SaaS and IT service firms, and in German organizations that work with enterprise customers asking for strong security controls.
Related standards
ISO 27002 is often used together with ISO/IEC 27001, ISO 27005, and the rest of the ISO 27000 series. Strong professionals know how these documents connect, so controls, risk handling, and evidence all line up instead of staying separate.
Signs you need help
- Security controls exist, but nobody owns them clearly
- Policies are outdated or too generic to pass review
- An audit found missing evidence or weak control design
- A supplier, cloud setup, or new process changed the risk picture
What good experts bring
Strong ISO 27002 professionals translate the standard into plain language and practical actions. They understand control intent, implementation detail, and how to document decisions so teams in Germany can work with security, legal, and audit stakeholders without confusion.
Frequently asked questions
Need clarity? These are the questions we hear most often about ISO 27002.
ISO 27002 is used to select and explain information security controls in a practical way. It helps teams decide how to handle access, logging, supplier security, incident response, and other core topics. Most companies use it as the control guide behind ISO/IEC 27001 work.
ISO 27002 gives guidance on how to implement controls, while ISO/IEC 27001 defines the requirements for an information security management system. In simple terms, 27001 is the rule set and 27002 is the playbook. Many projects need both because controls without governance stay incomplete.
A strong ISO 27002 specialist should know control design, risk thinking, and policy writing. Look for someone who can connect the standard to real systems such as identity, cloud, endpoints, and supplier management. Good work also includes clear evidence and documentation that auditors can follow.
The best ISO 27002 professionals usually bring knowledge of ISO/IEC 27001, risk management, internal audit, and security governance. Cloud security, identity and access management, and vendor risk review are also useful. In Germany, working fluency in English is often important because source material and audits may use both languages.
A ISO 27002 project can be small or broad, but it usually needs someone who has seen real control work before. If the task is only a policy refresh, a focused specialist may be enough. If it covers an ISMS, audit readiness, and multiple teams, you want deeper experience with structured security programs.
Most ISO 27002 work can be done remotely because it centers on review, writing, workshops, and document alignment. On-site time helps when the specialist needs to meet control owners, inspect processes, or support an audit in person. In Germany, many companies use a hybrid setup for this reason.
Look for practical examples, not just familiarity with the standard. A good ISO 27002 expert can explain why a control exists, how it should work, and how to prove that it works. Clear gap analysis, sensible priorities, and audit-ready documents are strong signs of quality.
ISO 27002 and ISO/IEC 27002 are commonly used to mean the same guidance standard. The longer form is the formal publication name, while the shorter form is the search term many people use. When hiring, both terms point to the same kind of specialist.
The average hourly rate of freelancers in Germany who have used ISO 27002 in their recent projects is 123 €, which corresponds to a daily rate of about 984 € based on an 8-hour working day.
Of the freelancers in Germany who have used ISO 27002 in their recent projects, 100% hold at least a Bachelor's degree, 25% hold at least a Master's degree, and 25% hold a doctorate.
On average, freelancers in Germany who have used ISO 27002 in their recent projects have 35 years of professional experience, with a single engagement typically lasting around 5 years.
The most common languages among freelancers in Germany who have used ISO 27002 in their recent projects are German (100%), English (100%), and Spanish (14%).
The most common industries among freelancers in Germany who have used ISO 27002 in their recent projects are Manufacturing (86%), Aerospace and Defense (71%), and Information Technology (71%).
The most common business areas among freelancers in Germany who have used ISO 27002 in their recent projects are Information Technology (100%), Project Management (100%), and Operations (86%).
Main locations of FRATCH Experts, who have recently used ISO 27002
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
