
KRITIS Experts in Munich
with precise AI matching from over 15,000 CVsHire experts who design resilient critical infrastructure processes, prepare BSI-aligned security measures and coordinate audits, incident response and continuity planning. FRATCH matches you quickly with vetted, available freelancers who fit your exact requirements.
Meet FRATCH Experts in Munich, who have recently used KRITIS
Andreas Z.
Last position:
Transformation Architect / Business Analyst at IT Consulting
- Development of a comprehensive transformation model for IT departments and ITSM organizations, from operational stabilization through structuring and optimization to strategic advancement
- Design of a transformation matrix that connects development phases with the implementation activities Position, Focus, Model, Enable, Anchor and Develop
- Development of assessment, maturity and decision-making logic to determine the operational starting point, the appropriate entry point and the prioritized areas of action
- Structuring of an end-to-end approach from current-state assessment and target vision through operating model, roadmap and service modules to implementation and integration into steady-state operations
- Derivation of combinable consulting and implementation modules, including methods, deliverables, role models, governance structures and transformation paths
- Collection, structuring and prioritization of business requirements from the perspectives of IT management, service management and operational roles
- Translation of requirements into target visions, process and role models, decision criteria and traceable deliverables
Environment / Tools: ITIL 4, IT4IT, Operating Model Canvas, SIAM, maturity models Kanban
Vicenco K.
Last position:
ITSM Project Manager (self-employed)
Unified ITSM framework
- Definition of a company-wide ITSM target picture
- Introduction of a uniform service structure across all business units
SLA and OLA management
- Building a standardized SLA framework
- Definition of service classes (Business Critical, Standard, Low Priority)
- Introduction of OLAs between internal teams
- Building meaningful SLA reporting
- Definition of KPI and service dashboards for business units
Service portfolio management
- Definition of service descriptions
- If needed, preparing possible cost and service billing
Ticketing & processes
- Incident management
- Uniform ticket categories
- Standardized prioritization
- Escalation matrix
- Automations
- Self-service optimization
Request fulfillment
- Service catalog across all business units
- Approval workflows
Problem management
- Introduction of root cause analysis
- Known error database
- Problem review process
Complete asset management concept
- Hardware lifecycle management
- Software lifecycle management
- Leasing lifecycle
- Mobile device lifecycle
- Monitor lifecycle
- Phone lifecycle
Processes
- Procurement
- Goods receipt
- Inventory
- Assignment
- Return
- Disposal
- Leasing return Goal: single source of truth for all assets
CMDB design
- Definition of all configuration items:
- Workplace
- Notebooks
- Monitors
- Mobile phones
- Printers
Infrastructure
- Servers
- Firewalls
- Switches
- WLAN
- Storage
- Backup systems
Cloud
- Azure resources
- Microsoft 365
- SaaS services
Relationships
- User ↔ Asset
- Asset ↔ Service
- Service ↔ Infrastructure
- Location ↔ Asset
- Goal: make all service dependencies visible
Software asset & license management
- License management concept
- License balancing
- Compliance reporting
- Microsoft license management
- Adobe license management
- SaaS management
- Contract management
- Renewal management
Interfaces & automation Existing systems
- Workday
- Joiner
- Mover
- Leaver
TESMA
- Leasing data
- Contract data
Matrix42
- Asset synchronization
- User synchronization
Active Directory / Entra ID
- User management
Microsoft 365
- License assignment
- Group management
Dormakaba
Access processes
Lifecycle services
Monitoring platforms
- PRTG
- Palo Alto
- Cisco
Reporting & KPI framework
- Definition of a management dashboard
- KPIs
- Ticket volume
- SLA fulfillment
- MTTR
- First resolution rate
- Asset accuracy
- License compliance
- Change success rate
- Service availability
- Degree of automation
Network redesign support
- Governance
- Support of the network redesign from an ITSM point of view
- Definition of affected services
- Change management structure
- Communication concept
CMDB integration
- Recording of all network components
- Service mapping
- Dependency analysis
Validation of documentation and knowledge base articles
- Network documentation
- Operations documentation
- Standard changes
Monitoring & event management
- Target picture
- Central monitoring concept
- Event management process
- Alerting strategy
- Escalation model
Systems
Cisco
Palo Alto
Fortinet
Rubrik
Veeam
Matrix42
Azure
Microsoft 365 Automation
Ticket creation from monitoring
Escalations
Standard actions
Audit, compliance & information security
- ISO 27001 consulting
- TISAX consulting
- NIS2 preparation - consulting
- Audit-ready processes
- Documentation structure
- Evidence tracking in Matrix42
Roadmap
- 12-month roadmap
- Prioritization of all measures
- Quick wins
- Medium-term projects
- Long-term target picture
- Documentation
Florian K.
Last position:
LAN Planner at Global Network AG
- As-is assessment of the current network infrastructure and its documentation, including on-site inspections
- Independent planning of new distribution and main distribution rooms in the individual district offices (components used, rack layout, connectivity), considering the BSI IT-Grundschutz and InfoSic requirements
- Planning of new copper and fiber optic cabling, including patch panels
- Coordination with building services engineering (TGA) to ensure compliance with relevant on-site requirements
- Development of detailed execution plans and high-level concepts for the rollout of the new infrastructure
- Additional support after the components go live (hypercare phase)
- Regular communication with project management and client stakeholders
Wolfgang T.
Last position:
Overall Project Manager at itzbund
Project content: The use of “Generative Pretrained Transformer” technologies (GPT) will massively change the world of work in the coming years. ITZBund is developing a base service for this, which can be used by its 200 customers. This base service is offered as an on-prem and a cloud variant. Started in 12/23, from 05/24 productive systems (based on MVP) could already be rolled out and operated successfully for several agencies and federal ministries.
Project metrics:
- Budget in 2024 approx. €20M
- approx. 70 people in the core project context
- regular (indirect) contact with approx. 80 people in the wider project environment
My main tasks:
- Overall responsible external project manager
- Project definition phase/project setup and establishment of the project organization
- Strategic and operational project planning, as well as shaping and ongoing adjustments of the project
- Ongoing coordination with project owners and stakeholders in ITZBund
- Ongoing coordination with subproject managers, agile roles and other project staff
- Responsibility for project controlling, quality management, risk management and change management
- Responsibility for providing the base service on on-prem and cloud environments and its continuous development
- Planning and leading several hypercare phases
- Collaboration and ongoing coordination with a partner project of a federal ministry and provision of an MVP
- Coordination with agile teams
- Coordination with operations, release and deployment
- Responsibility for the implementation of the first customer projects
- Responsibility for creating an AI governance
- Ensuring accessibility (BITV)
- Responsibility for setting up a subproject for marketing activities
- Support in building an efficient proposal process
- Stakeholder management
Methodology:
- V-Model XT ITZBund
- Scrum
Tools used:
- Microsoft Office, Skype, MS Project, Confluence, Jira, SharePoint, Miro
Rajan K.
Last position:
Technical Lead/BTV at BMW, Daimler (Mercedes), VW Group, Hella, Ficosa, Cariad (Audi/Porsche/Skoda)
- Directed full lifecycle of embedded software projects including LiDAR, BMS, OCU, and Cybersecurity systems.
- Coordinated internal and external stakeholders including suppliers like Bosch, Bertrandt, Magna, Continental and IAV.
- Managed cross-country teams of 12–15 engineers, conducting project onboarding and role-based training.
- Implemented change control and risk registers for safety-critical automotive platforms.
- Oversaw project schedules using MS Project, JIRA, and Azure DevOps to ensure milestone alignment and transparency.
- Extensive hands-on expertise in test planning and execution for ECUs in compliance with Automotive SPICE (SWE.4–SWE.6) and ISO 26262.
- Led digital transformation project with a cross-functional team of 15+, ensuring successful integration of systems and workflows.
- Maintained project overviews and tracking in tools like Milestones (Daimler) and MS Project, and managed status reporting to senior stakeholders.
- Coordinated with third-party transformation partners and ensured timely delivery of decision templates and risk assessments.
- Applied PRINCE2 methodology for structured delivery; facilitated agile ceremonies and maintained Confluence-based documentation.
- Strong leadership in cross-functional teams and working in agile environments (SAFe, Scrum).
- Successfully led and supported IT and transformation projects, including those in regulated sectors (e.g., KRITIS or energy sector).
- Represented or supported overall project leadership in large-scale transformation programs.
- Maintained and updated complex project plans (Gantt charts, milestone tracking, and resource allocation).
- Coordinated workstreams and interdisciplinary teams; ensured timely delivery of all work packages.
- Acted as central communication point between project team, senior management, external vendors, and transformation partners.
- Prepared and delivered concise status reports, steering committee presentations, and decision memos.
- Identified project risks, maintained risk registers, and led mitigation planning.
- Assessed resource needs and supported reallocation based on project priorities and constraints.
- Proficient in JIRA, Milestones, Confluence, MS Project, MS PowerPoint, and Excel.
- Used both Agile (Scrum) and Waterfall (PRINCE2, PMI) methodologies.
- Created and tracked action lists, meeting protocols, and backlog items.
- Conducted critical analysis of project progress, resource bottlenecks, and deliverable timelines.
- Ensured alignment of transformation goals with enterprise IT architecture and business objectives.
Volker R.
Last position:
Architect and Senior System Administrator at International Trading Company
- Analysis and optimization of the VMware environment for operation in a critical infrastructure environment
- Planning and execution of updates for the VMware and hardware environment in a critical infrastructure environment
- Deployment of Skyline Health Diagnostics
- Review of existing documentation
- Training and onboarding of new internal staff
- Support for migration and upgrade projects
- Preparation for moving scripts in the virtualization environment to GitLab
- Ticket handling with ServiceNow
Patrick U.
Last position:
Interim Management | Consulting & Implementation | Data Deletion in SAP at BSR (Berliner Stadtreinigung)
- Topics: Business Analysis, Data Privacy, Data Management, Stakeholder Management, Conceptualization
- This project focuses on developing and implementing a strategic approach for data deletion in SAP systems. The goal is to identify the relevant data and structures during system migration to ensure both data privacy and IT system efficiency. At the same time, downtime should be minimized and regulatory requirements met.
- Development of a comprehensive approach for data deletion in SAP systems, considering data privacy and business requirements.
- Ensuring efficient and structured data transfer to the new system.
- Optimizing system efficiency and reducing downtimes during migration.
- Creating functional and technical concepts to ensure compliant and sustainable data management.
- Topic preparation: Detailed study of the "data deletion" area to lay the foundation for a structured data migration.
- Definition of project structure: Setting roles, interfaces and the project's organizational structure.
- Regulatory requirements: Analysis of data privacy regulations and business requirements to define deletion criteria.
- Approach: Developing possible scenarios and methods for data cleansing and deletion.
- Deletion concepts: Creating functional and technical deletion concepts that structure the implementation and provide clear guidelines.
- Setting deletion criteria: Defining which data and structures to delete or transfer.
- Responsibilities: Clarifying responsibilities within the project team and among stakeholders.
- Analysis of ongoing activities: Identifying and collecting existing activities in the "data deletion" area.
- Effort, cost and timeline planning: Creating estimates for resources, effort and budget.
- Implementation initiatives: Developing and executing concrete measures to apply the defined deletion strategies.
- IT system efficiency: Analyzing the existing IT infrastructure to identify optimization potential for data deletion and transfer.
- Technology trends: Evaluating new technologies and tools that can support the data cleansing process.
- Cost-benefit analysis: Assessing the financial impact of data cleansing and the introduction of new solution approaches.
- Risk management: Identifying potential risks during implementation and developing appropriate mitigation measures.
- This project lays the foundation for a sustainable and compliant data transfer to a new SAP system. With a clear approach to data deletion, it meets data privacy requirements, reduces downtimes and increases the efficiency of the new system. The results and recommendations will help companies develop a future-proof data strategy that meets legal and business needs.
Alexander N.
Last position:
Security Expert at DAK-Gesundheit
- Pentesting of mobile applications
- Code review
- Gematik audit
- Development of secure software development methods
- Creation of security and test concepts
- Penetration testing of software and architecture
- Vulnerability analysis
- Automation and information security
- Use of Confluence and Jira
- Working with databases, J2EE, JavaServer Faces, Liquibase, Apache, Maven, Mercurial, Oracle Financials
- Documentation and creation of security policies
- Management of software systems, SharePoint, PrimeFaces, Git
- Compliance with security regulations and .NET, AWS, API
- Tools: MobSF, Frida, Android Studio, Drozer, Objection, Azure
Volker J.
Last position:
Interim CISO (Germany, Austria, US, APAC), Auditor at Vetter Pharma-Fertigung GmbH & Co. KG
- Planned and initiated BIA/BCM assessment to identify risk mitigation measures and process optimization, and provide risk transparency to the general management
- Evaluated KRITIS/NIS-2 status and implemented requirements
- Created comprehensive digital roadmap and ISO 27001/NIS-2/Data Privacy KRITIS roadmap
- Enhanced crisis management process and documentation
- Integrated information security clauses into customer and supplier contracts to ensure compliance with internal and regulatory requirements
- Ensured organizational readiness for audits by the Landesbehörde für Aufsicht (LBA) and supported audit processes
- Improved asset management processes and classification of sensitive data to strengthen overall security
- Planned and ordered regular penetration tests (internal, external) to identify vulnerabilities and improve security measures
- Performed compliance checks against EU CER requirements and reporting
- Created management status and risk reports to ensure transparent communication of risks and security posture
- Managed registration with the German Federal Office for Information Security (BSI) and provided ongoing status updates
- Conducted risk assessment of supply chain, enhanced evaluation and reporting processes
- Improved IT/OT network segmentation to enhance security and reduce potential audit risks
- Strengthened cyber resilience by proactive measures and enhanced security frameworks and KPI reporting
- Onboarded SIEM/SOC/EDR to improve cybersecurity monitoring and response
- Planned and conducted awareness trainings for employees, administrators, and management
- Enhanced incident reporting processes to ensure timely and accurate reporting of cybersecurity events
- Created AI policy in cooperation with the Legal department to secure use and governance of Artificial Intelligence within the organization
- Scoped and implemented ISO 27001:2022 requirements as part of the Information Security Management System
- Served as interim InfoSec team lead
- Introduced information security to global KAM and Sales organization
- Improved admission and access management including privileged access
- Conducted internal audits in collaboration with internal audit department
Discover over 15,000 top freelancers
Statistics of experts using KRITIS
Aggregated from the professional profiles of matched freelancers.
Experience
20 years (Germany: 23 years)

Position duration
2.1 years (Germany: 2.2 years)

Positions per freelancer
15 (Germany: 18)

Top business areas
Information Technology, Project Management, Quality Assurance

Top industries
Information Technology, Automotive, Professional Services

Certification focus areas
Information Technology, Project Management, Human Resources
Bachelor's degree or higher
71% (Germany: 89%)
Master's degree or higher
43% (Germany: 47%)

Certifications per freelancer
5 (Germany: 8)

Most common languages
German, English, French

Speak two or more languages
89% (Germany: 94%)
Based on our profile pool as of 19 Sep 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Munich are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Munich using KRITIS
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 19 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
KRITIS experts industry focus
See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.
- Information Technology (89%)
- Automotive (78%)
- Professional Services (67%)
- Government and Administration (67%)
- Banking and Finance (56%)
- Aerospace and Defense (44%)
- Insurance (44%)
- Manufacturing (44%)
Please note that freelancers can work across multiple industries, so percentages overlap.
About the technology
What KRITIS covers
KRITIS refers to critical infrastructures whose disruption can affect public life, safety or essential services. In Germany, the term is closely linked to BSI requirements, sector-specific regulation and the protection of information technology that supports vital operations. KRITIS work connects cybersecurity, operational resilience, governance and dependable service delivery.
Typical applications
Companies use KRITIS expertise to protect and operate essential systems across energy, healthcare, transport, water, finance, telecommunications and public services.
- Assess critical services, assets and dependencies
- Create security and resilience concepts
- Prepare evidence for audits and supervisory reviews
- Improve incident response and continuity planning
- Coordinate suppliers and outsourced IT services
Ecosystem and tooling
KRITIS specialists work with the BSI framework, ISO 27001, sector-specific security requirements and risk management methods. Depending on the environment, their work includes SIEM and monitoring tools, identity and access management, vulnerability management, backup systems, network segmentation and industrial control environments. They also connect technical controls with policies, processes and management reporting.
When freelance expertise helps
External professionals are useful when a company must establish a KRITIS program, close audit findings or prepare for a new regulatory obligation. They can provide an independent assessment, strengthen documentation or support a major infrastructure change without taking over permanent operational ownership.
- A regulated service is adding new systems or suppliers
- Security responsibilities are unclear across business and IT
- Incident, recovery or crisis procedures need testing
- Internal teams need temporary expertise for an audit
What strong professionals deliver
Strong KRITIS experts translate business-critical services into practical protection measures. They understand risk analysis, asset inventories, network architecture, access controls, logging, detection, recovery and evidence management. They communicate clearly with management, technical teams, auditors and operators, and they document decisions so controls remain usable after the project ends.
Munich project considerations
In Munich, KRITIS work often involves closely regulated industries, technology providers, healthcare organizations and public-sector environments. Local collaboration may matter for workshops, site assessments or crisis exercises, while much of the documentation and analysis can be completed remotely. German communication skills may be important when coordinating with authorities, auditors and operational teams.
Frequently asked questions
Need clarity? These are the questions we hear most often about KRITIS.
KRITIS is used to protect services and systems that are essential to public life, such as energy supply, healthcare, transport, water, finance and telecommunications. The work covers risk management, cybersecurity, continuity, incident response and reliable operation.
KRITIS focuses on the resilience of essential services and the consequences of their disruption, not only on protecting information. It combines cybersecurity with operational technology, supplier dependencies, emergency procedures, regulatory evidence and service continuity.
A strong KRITIS specialist often combines information security with risk analysis, ISO 27001, BSI guidance, audit preparation and business continuity. Experience with cloud environments, industrial control systems, identity management, monitoring or incident response can be important depending on the sector.
The right KRITIS freelancer depends on the assignment rather than a fixed career length. A documentation review may need focused compliance expertise, while designing resilience for a complex operational environment requires experience with dependencies, technical controls, crisis processes and stakeholder coordination.
Much of KRITIS work can be delivered remotely, including assessments, policy design, evidence reviews and workshops. On-site collaboration may still be needed for sensitive environments, facility assessments, operational technology reviews or exercises, so the working model should be agreed before the engagement begins.
Before hiring a KRITIS expert, define the critical services, systems in scope, regulatory context and expected deliverables. Companies should also clarify access requirements, confidentiality, language needs and whether the assignment involves offices, data centers, production sites or operational facilities in and around Munich.
Quality in KRITIS work is visible in a clear link between critical services, risks, controls and evidence. Strong deliverables identify ownership, dependencies, residual risks and practical next steps rather than presenting generic security checklists. References to comparable sectors and a structured review method are useful indicators.
KRITIS is often considered alongside ISO 27001, BSI guidance, business continuity management and sector-specific security frameworks. These approaches are not interchangeable: KRITIS establishes the critical-infrastructure context, while the other frameworks can provide methods for governance, controls, audits and continuity planning.
The average hourly rate of freelancers in Munich, Germany who have used KRITIS in their recent projects is 108 €, which corresponds to a daily rate of about 860 € based on an 8-hour working day.
Of the freelancers in Munich, Germany who have used KRITIS in their recent projects, 71% hold at least a Bachelor's degree and 43% hold at least a Master's degree.
On average, freelancers in Munich, Germany who have used KRITIS in their recent projects have 20 years of professional experience, with a single engagement typically lasting around 2.1 years.
The most common languages among freelancers in Munich, Germany who have used KRITIS in their recent projects are German (100%), English (89%), and French (22%).
The most common industries among freelancers in Munich, Germany who have used KRITIS in their recent projects are Information Technology (89%), Automotive (78%), and Professional Services (67%).
The most common business areas among freelancers in Munich, Germany who have used KRITIS in their recent projects are Information Technology (100%), Project Management (100%), and Quality Assurance (67%).
Main locations of FRATCH Experts, who have recently used KRITIS
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Countries:
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Frankfurt
Dusseldorf