
KRITIS Experts in Frankfurt
to strengthen critical infrastructure with vetted, available freelancers matched in minutesHire experts who design KRITIS security controls, coordinate risk and resilience programmes, and prepare organisations for audits and incidents. FRATCH matches you quickly and precisely with vetted, available freelancers who fit your project.
Meet FRATCH Experts in Frankfurt, who have recently used KRITIS
Reza N.
Last position:
Senior IT-Security Expert at Teambank AG
- Completed the integration of log sources into Microsoft Sentinel, including GCP workloads – centralized consolidation of all security-relevant events from Azure and GCP environments for complete end-to-end telemetry and comprehensive compliance evidence
- Developed custom rules and use cases based on the GFG Use-Case Library and the MITRE ATT&CK Matrix to cover company-specific threats and GFG-relevant scenarios with precise, mapped detection rules
- Tuned detection rules to minimize false positives, optimized detection thresholds, and modeled exceptions – enabling the SOC to work with relevant, prioritized alerts while reducing Mean Time to Detect/Respond
- Built SOAR capabilities in Sentinel by developing playbooks to automate recurring response processes such as containment, user and host isolation, and ticketing – shorter response times and 24/7 scalability
- Designed and built a log transformation solution to normalize and enrich incoming raw logs (GeoIP, CMDB, threat intelligence) and convert them into a consistent schema for high-performance KQL queries, use case logic, and correlations
- Managed Azure security through Azure Policies to enforce security and compliance standards, prevent drift, and continuously remediate deviations
- Operated the Defender XDR portal to link endpoint, identity, email, and SaaS signals with Sentinel findings, enable holistic incident triage, and orchestrate measures directly from XDR
Technologies: Microsoft Sentinel, Microsoft Defender XDR, Azure Policy, KQL, GCP, MITRE ATT&CK
Achim K.
Last position:
Portfolio Manager, Consultant, Leadership Coach at Abbvie Deutschland GmbH &Co. KG
- Management and optimization of a portfolio of about 100 projects (launches, in-field solutions, data & analytics, digital solutions, digital products)
- Optimization of the existing project standard (playbook) and alignment with the European and global organization (USA)
- Coaching project managers on setup, planning, cooperation with business, GDPR, GxP, data security and launches
- Preparing projects for works council information and project closeout communication
- Optimization of resource management (tracking, allocation, prioritization)
- Taking over individual project leads (off-/transboarding, event management, checking whether WhatsApp is allowed on a business smartphone)
- Supporting the hiring of external project managers
- Optimization of meeting structure, project controlling (KPIs), change and demand management
- Optimization of risk, issue, dependency and quality management and support during internal audits (GxP)
- Optimization of the portfolio steering tool (Smartsheet) on national, European and global level
- Design and implementation of a Business Value Complexity Scoring
- Building a strategic PMO with a sister department and optimizing cross-functional teams
- Reporting, communication and escalation at management level
- Leadership coaching for several future leaders (short-time assignment)
- Development of the concepts "PPM as a Service" and "Internal Customer Approach"
- Development and review of a concept "AI Data Governance" including roles and processes
- Selection and onboarding of the successor
Günther E.
Last position:
Senior Consultant at ISMS Rollout – Information Security Certification (ISO 27001)
- Built and successfully certified the Information Security Management System (ISMS) according to ISO 27001 in seven country organizations (Ghana, India, Bangladesh, Uzbekistan, Serbia, Kosovo, Albania).
- Full implementation of the ISMS from kick-off phase to certification, including defining the governance structure and process landscape.
- Developed and delivered target-group-specific trainings, workshops, and coaching sessions for local responsible persons on the basics of information security and ISMS operations.
- Designed and continuously improved training concepts and content to increase understanding and acceptance.
- Identified and implemented improvements in processes and tools, including risk management for international projects.
- Optimized central ISMS core processes from the idea through pilot operation and fine-tuning to global rollout.
- Optimized knowledge management, as well as work aids and methods for the global ISMS team.
- Built and moderated cross-functional coordination with key interfaces to the ISMS.
- Microsoft Teams, Excel, SharePoint Lists, Power Apps.
Mario P.
Last position:
Senior IT Project Manager / Program Lead – Network Strategy 2030 at ALDB GmbH
- Holistic responsibility for modernizing and expanding federal networks and upgrading critical data center and telecom infrastructure in the high-security agency environment of BDBOS
- Planning and management of the expansion of national BOS network infrastructure in the VS-NfD/KRITIS environment with technical decision authority at the architecture and component level (Cisco, Layer 2/3, WAN redundancy)
- Planning, tendering (EVB-IT/UVgO) and oversight of the upgrade of security-critical telecom infrastructure for emergency call 110/112 (ACD)
- Capacity planning, rack integration, structured cabling, power supply, cooling concept (CRAC/In-Row) and DCIM monitoring for data center expansion
- Building the IT department from scratch: structures, governance, processes, team recruiting, vendor selection and long-term IT strategy
- Planning and managing infrastructure and application migrations: migration strategies, batch planning, hypercare stabilization and rollback concepts
- Creating vendor-neutral specifications (telecom systems, signature solutions) according to EVB-IT and UVgO; contract award and vendor management
- Setting up a secure IT environment according to BSI basic protection, ISO 27001 and VS-NfD; developing IT security concepts and CMDB analyses
- Hands-on program leadership: decision papers for management and steering committees, risk management, reporting and change request control
Andreas I.
Last position:
Cybersecurity Specialist Assessor at Bundesnetzagentur
- Recognition of national notified bodies
- Preparation of cybersecurity competency reports
- EU Radio Equipment Directive
Axel Z.
Last position:
Project Manager at NTT Global Data Centers
- Project management
- Coordination of the rollout of 148 firewalls (Palo Alto) for 74 buildings at more than 14 locations in EMEA
- Management of the team (8 employees)
- Communication with senior management (local) and site managers (EMEA)
- Ensuring work packages were completed on time and according to requirements, including formal acceptance
- Extensive use of the relevant Microsoft tools
- Wrike (project management)
Markus M.
Last position:
Project Manager / Senior Consultant (multiple projects) at gkv informatik
- Project manager controlling the update to ISO 27001:2022 (certification from ISO 27002:2013 to ISO 27002:2022) including gap analysis, project planning, preparation of internal and external audits, and creation and maintenance of required documentation.
- Coordination of adjusting existing measures and implementing new measures according to the new standard’s requirements, as well as continuous monitoring and adjustment of these measures.
- Regular reporting to management on progress and risks.
- Senior consultant supporting audit reviews with a focus on critical infrastructures (KRITIS), including resolving findings, creating and updating evidence documents, and amending provider contracts.
- Senior consultant reviewing all deliverables and responsibilities of the IT provider according to the existing contract: identification of over 1500 deliverables & obligations (D&O), setup of a D&O tracker (claim register), and joint expert review with service owners for various service descriptions (e.g. IT service management, workplace and print services, application and desktop services, endpoint management, email including archiving, file services, software packaging, certification, distribution).
- Senior consultant adjusting service scopes in existing service descriptions to enable end-to-end service responsibility of the provider, including identification and analysis of use cases, process analysis and optimization (incident, problem, change), as well as recording and documenting all software products in LeanIX and documenting the contract change.
- Focused services: managed software service, application and desktop service, workplace and print services, web server service, container service, M365, SAP/Oscare, output management systems (OMS), telephony and omnichannel management service.
- Project manager steering a benchmark based on the existing IT contract, including coordination of the entire benchmark process between the benchmarker, IT provider and client, review of benchmark results, and preparation and conduct of price negotiations with the IT provider.
Peter S.
Last position:
IT Project Manager at PAS Provider for Hospital
Overall responsibility for managing a clinical digitization project in a regulated hospital environment.
Design and implementation of a patient call and management system (PASO) for the orthopedics department of a large hospital.
- Project management, planning, and control
- Process analysis and optimization, and managing implementation and rollout
- Coordination with clinical departments, IT, and external service providers
- Ensuring integration into existing IT and process landscapes
Project scope: 310 person-days, team size: 21 members.
Peter W.
Last position:
ISO 27001 Auditor for health insurance archive system at Health insurance company
The replacement of the existing archive system (document management system – DMS) on a host-based platform is well advanced.
The internal audit is meant to ensure the company's quality standards.
GDPR
ISO 27001 ff.
BSI
DORA
Patient data regulations
Host / Cloud / S3 / Container / highly scalable / Nuxeo
Budget: 50,000
Team: 1
Felix T.
Last position:
Quality and Process Manager Trading – Systems Focus at Mainova AG
- Ensuring stable operation of business-critical applications in the energy environment (KRITIS-adjacent systems), coordinating with IT operations on certificates, permissions, and security-relevant logging
- Continuous monitoring of interfaces, processes, and system states including analysis of deviations and performance issues
- Development and setup of secure interfaces including authentication and access concepts
- Incident management: prioritization, root cause analysis, coordination of issue resolution with IT operations, business units, and external service providers
- Change and release management including coordination, test coordination, go-live, and post-live support
- Product owner for operational systems in day-to-day operations (forecasts, schedule management, market data import and export, contract management, regulatory reporting)
- Documentation of operational processes, changes, and incidents to ensure traceability and auditability
- Automation and digitization of operational processes
- Introduction and use of AI-supported analysis and monitoring approaches and agents with Microsoft 365 Copilot
Thoralf T.
Last position:
Consultant Digital Operational Resilience Act (DORA) at Swisslife Deutschland GmbH
- Auditing CIS evidence of the SOC providers T-Systems Austria and Cancom GmbH
- Mapping of VAIT, ISO:IEC 27002 and CIS 7.0 requirements for the IT realignment strategy of the German subsidiaries in threat intelligence and zero trust
- Reviewing SIEM evidence, reporting, incident management and security breaches
- Reviewing IT asset management regarding ITSCM and BCM processes
- Employee awareness and compliance training focused on CEO fraud
- Advising the chief information security officer
Falk W.
Last position:
SVP IT & Organisation / Deputy SVP Finance & Controlling Infrastructure at B+S Card Service / Payone
- Modernised post-merger regulated payment-processing infrastructure (KRITIS).
- Established cloud-enabled platform and ensured PCI and regulatory compliance.
Daniel S.
Last position:
Business and IT consulting at Business and IT Consulting (freelance)
- Process consulting
- Project management
- Creating and aligning functional and technical specifications
- Portfolio management
- Stakeholder management
- Data cleansing
- Test, quality, and requirements management
- Rollout management
- Financial planning
- Marketing and sales consulting
- IT architecture and strategy consulting
- Trainer for IT, project management, and eBusiness
Discover over 15,000 top freelancers
Statistics of experts using KRITIS
Aggregated from the professional profiles of matched freelancers.
Experience
19 years (Germany: 23 years)

Position duration
2.5 years (Germany: 2.2 years)

Positions per freelancer
15 (Germany: 18)

Top business areas
Information Technology, Operations, Project Management

Top industries
Banking and Finance, Information Technology, Automotive

Certification focus areas
Information Technology, Project Management, Product Development
Bachelor's degree or higher
100% (Germany: 89%)
Master's degree or higher
33% (Germany: 47%)

Certifications per freelancer
5 (Germany: 8)

Most common languages
German, English, French

Speak two or more languages
100% (Germany: 94%)
Based on our profile pool as of 19 Sep 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Frankfurt are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Frankfurt using KRITIS
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 19 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
KRITIS experts industry focus
See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.
- Banking and Finance (85%)
- Information Technology (85%)
- Automotive (54%)
- Healthcare (54%)
- Transportation (54%)
- Professional Services (46%)
- Energy (38%)
- Insurance (38%)
Please note that freelancers can work across multiple industries, so percentages overlap.
About the technology
KRITIS in practice
KRITIS refers to critical infrastructures whose disruption can seriously affect public life, safety or economic stability. In Germany, the term covers sectors such as energy, water, healthcare, transport, finance, telecommunications and food supply. KRITIS work connects cyber security with operational resilience, governance and dependable service delivery.
Systems and sectors
KRITIS specialists support environments where digital systems and physical operations must remain dependable. Their work may cover control networks, data centres, clinical systems, payment services, cloud platforms, communication networks and industrial plants. In Frankfurt, financial services, transport infrastructure and connected business services create a strong need for security and resilience expertise.
Core ecosystem
The work often combines BSI guidance with established security and continuity practices. Relevant tools and standards can include:
- BSI requirements, risk assessments and incident processes
- ISO 27001, business continuity and crisis management
- SIEM, SOC workflows, vulnerability management and identity controls
- IEC 62443 for industrial automation and control environments
When specialists help
Companies bring in freelance KRITIS professionals when an audit is approaching, a regulated service is changing or internal capacity is limited. They can map assets and dependencies, assess risks, define security measures, document evidence and rehearse incident response. External specialists are also useful during mergers, cloud migrations, supplier reviews and remediation programmes.
Project deliverables
A strong engagement produces clear, usable results rather than policy documents alone. Typical deliverables include protection concepts, network and asset inventories, risk registers, continuity plans, recovery procedures, audit evidence, supplier requirements and tested response playbooks. Specialists may also align security teams, operations, legal stakeholders and executive decision-makers.
Choosing strong expertise
Look for professionals who can explain technical risks in operational and business terms. They should understand dependencies between IT, OT, facilities, suppliers and essential services, while working confidently with BSI expectations and recognised standards. For remote collaboration, clear German and English documentation, structured workshops and disciplined handling of sensitive information matter as much as technical depth.
Frequently asked questions
Everything clients usually want to know about KRITIS, in one place.
KRITIS describes critical infrastructures and the security, resilience and continuity measures that protect them. It is used to organise risk management for essential services such as energy, healthcare, transport, finance, water and telecommunications.
KRITIS focuses on services whose failure can have serious consequences for society or the economy. General cyber security may protect any organisation, while KRITIS work adds stronger attention to operational continuity, dependencies, incident reporting, resilience and regulatory expectations.
A capable KRITIS professional often combines information security with business continuity, risk management, incident response and supplier assurance. Depending on the environment, useful adjacent knowledge includes cloud security, industrial control systems, identity management, data protection and audit preparation.
The right depth depends on the service, system complexity and stage of the programme. A smaller assessment may need focused experience with risk and controls, while a transformation or remediation programme requires a professional who has coordinated operations, security, compliance and crisis planning across several stakeholders.
KRITIS projects can often be delivered remotely for documentation, risk workshops, control design and evidence reviews. On-site work may still be needed for facilities, industrial environments, secure areas or operational exercises; teams should agree access rules, language expectations and handling procedures at the outset.
German KRITIS engagements commonly refer to BSI guidance and sector-specific requirements. Depending on the organisation, professionals may also work with ISO 27001, business continuity practices, IEC 62443 and European requirements such as NIS2, while confirming the exact obligations with the responsible compliance team.
A KRITIS specialist should first establish scope, critical services, assets, dependencies, owners and existing controls. A concise current-state assessment and prioritised action plan give the organisation a defensible basis for remediation, investment decisions and later audit evidence.
Ask the KRITIS professional to explain how they would connect a service failure to business impact, technical controls and recovery actions. Strong evidence includes clear deliverables, relevant sector experience, practical incident scenarios, sound documentation and the ability to work with both operational teams and senior stakeholders.
The average hourly rate of freelancers in Frankfurt, Germany who have used KRITIS in their recent projects is 116 €, which corresponds to a daily rate of about 932 € based on an 8-hour working day.
Of the freelancers in Frankfurt, Germany who have used KRITIS in their recent projects, 100% hold at least a Bachelor's degree and 33% hold at least a Master's degree.
On average, freelancers in Frankfurt, Germany who have used KRITIS in their recent projects have 19 years of professional experience, with a single engagement typically lasting around 2.5 years.
The most common languages among freelancers in Frankfurt, Germany who have used KRITIS in their recent projects are German (100%), English (100%), and French (8%).
The most common industries among freelancers in Frankfurt, Germany who have used KRITIS in their recent projects are Banking and Finance (85%), Information Technology (85%), and Automotive (54%).
The most common business areas among freelancers in Frankfurt, Germany who have used KRITIS in their recent projects are Information Technology (100%), Operations (85%), and Project Management (85%).
Main locations of FRATCH Experts, who have recently used KRITIS
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Countries:
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Munich
Dusseldorf