KRITIS Experts in Munich
in minutes from over 15,000 CVs with the power of AI.Hire experts who know KRITIS requirements, risk analysis, incident response, and audit-ready documentation. They support critical services, security controls, and continuity plans with fast, precise matching of vetted, available freelancers.
Meet FRATCH Experts in Munich, who have recently used KRITIS
Vicenco Kenk
Last position:
ITSM Project Manager (self-employed)
Unified ITSM framework
- Definition of a company-wide ITSM target picture
- Introduction of a uniform service structure across all business units
SLA and OLA management
- Building a standardized SLA framework
- Definition of service classes (Business Critical, Standard, Low Priority)
- Introduction of OLAs between internal teams
- Building meaningful SLA reporting
- Definition of KPI and service dashboards for business units
Service portfolio management
- Definition of service descriptions
- If needed, preparing possible cost and service billing
Ticketing & processes
- Incident management
- Uniform ticket categories
- Standardized prioritization
- Escalation matrix
- Automations
- Self-service optimization
Request fulfillment
- Service catalog across all business units
- Approval workflows
Problem management
- Introduction of root cause analysis
- Known error database
- Problem review process
Complete asset management concept
- Hardware lifecycle management
- Software lifecycle management
- Leasing lifecycle
- Mobile device lifecycle
- Monitor lifecycle
- Phone lifecycle
Processes
- Procurement
- Goods receipt
- Inventory
- Assignment
- Return
- Disposal
- Leasing return Goal: single source of truth for all assets
CMDB design
- Definition of all configuration items:
- Workplace
- Notebooks
- Monitors
- Mobile phones
- Printers
Infrastructure
- Servers
- Firewalls
- Switches
- WLAN
- Storage
- Backup systems
Cloud
- Azure resources
- Microsoft 365
- SaaS services
Relationships
- User ↔ Asset
- Asset ↔ Service
- Service ↔ Infrastructure
- Location ↔ Asset
- Goal: make all service dependencies visible
Software asset & license management
- License management concept
- License balancing
- Compliance reporting
- Microsoft license management
- Adobe license management
- SaaS management
- Contract management
- Renewal management
Interfaces & automation Existing systems
- Workday
- Joiner
- Mover
- Leaver
TESMA
- Leasing data
- Contract data
Matrix42
- Asset synchronization
- User synchronization
Active Directory / Entra ID
- User management
Microsoft 365
- License assignment
- Group management
Dormakaba
Access processes
Lifecycle services
Monitoring platforms
- PRTG
- Palo Alto
- Cisco
Reporting & KPI framework
- Definition of a management dashboard
- KPIs
- Ticket volume
- SLA fulfillment
- MTTR
- First resolution rate
- Asset accuracy
- License compliance
- Change success rate
- Service availability
- Degree of automation
Network redesign support
- Governance
- Support of the network redesign from an ITSM point of view
- Definition of affected services
- Change management structure
- Communication concept
CMDB integration
- Recording of all network components
- Service mapping
- Dependency analysis
Validation of documentation and knowledge base articles
- Network documentation
- Operations documentation
- Standard changes
Monitoring & event management
- Target picture
- Central monitoring concept
- Event management process
- Alerting strategy
- Escalation model
Systems
Cisco
Palo Alto
Fortinet
Rubrik
Veeam
Matrix42
Azure
Microsoft 365 Automation
Ticket creation from monitoring
Escalations
Standard actions
Audit, compliance & information security
- ISO 27001 consulting
- TISAX consulting
- NIS2 preparation - consulting
- Audit-ready processes
- Documentation structure
- Evidence tracking in Matrix42
Roadmap
- 12-month roadmap
- Prioritization of all measures
- Quick wins
- Medium-term projects
- Long-term target picture
- Documentation
Thomas Martin
Last position:
Lead AI-/Agentic-Engineering at AI-/Agentic-Engineering (Own research)
AI-supported development and PM acceleration with agentic workflows; deep reinforcement learning; fully automated 24/7 setup.
Wolfgang Tomaschek
Last position:
Overall Project Manager at itzbund
Project content: The use of “Generative Pretrained Transformer” technologies (GPT) will massively change the world of work in the coming years. ITZBund is developing a base service for this, which can be used by its 200 customers. This base service is offered as an on-prem and a cloud variant. Started in 12/23, from 05/24 productive systems (based on MVP) could already be rolled out and operated successfully for several agencies and federal ministries.
Project metrics:
- Budget in 2024 approx. €20M
- approx. 70 people in the core project context
- regular (indirect) contact with approx. 80 people in the wider project environment
My main tasks:
- Overall responsible external project manager
- Project definition phase/project setup and establishment of the project organization
- Strategic and operational project planning, as well as shaping and ongoing adjustments of the project
- Ongoing coordination with project owners and stakeholders in ITZBund
- Ongoing coordination with subproject managers, agile roles and other project staff
- Responsibility for project controlling, quality management, risk management and change management
- Responsibility for providing the base service on on-prem and cloud environments and its continuous development
- Planning and leading several hypercare phases
- Collaboration and ongoing coordination with a partner project of a federal ministry and provision of an MVP
- Coordination with agile teams
- Coordination with operations, release and deployment
- Responsibility for the implementation of the first customer projects
- Responsibility for creating an AI governance
- Ensuring accessibility (BITV)
- Responsibility for setting up a subproject for marketing activities
- Support in building an efficient proposal process
- Stakeholder management
Methodology:
- V-Model XT ITZBund
- Scrum
Tools used:
- Microsoft Office, Skype, MS Project, Confluence, Jira, SharePoint, Miro
Volker Reisberger
Last position:
Architect and Senior System Administrator at International Trading Company
- Analysis and optimization of the VMware environment for operation in a critical infrastructure environment
- Planning and execution of updates for the VMware and hardware environment in a critical infrastructure environment
- Deployment of Skyline Health Diagnostics
- Review of existing documentation
- Training and onboarding of new internal staff
- Support for migration and upgrade projects
- Preparation for moving scripts in the virtualization environment to GitLab
- Ticket handling with ServiceNow
Alexander Nagy
Last position:
Security Expert at DAK-Gesundheit
- Pentesting of mobile applications
- Code review
- Gematik audit
- Development of secure software development methods
- Creation of security and test concepts
- Penetration testing of software and architecture
- Vulnerability analysis
- Automation and information security
- Use of Confluence and Jira
- Working with databases, J2EE, JavaServer Faces, Liquibase, Apache, Maven, Mercurial, Oracle Financials
- Documentation and creation of security policies
- Management of software systems, SharePoint, PrimeFaces, Git
- Compliance with security regulations and .NET, AWS, API
- Tools: MobSF, Frida, Android Studio, Drozer, Objection, Azure
Rajan Kumar
Last position:
Technical Lead/BTV at BMW, Daimler (Mercedes), VW Group, Hella, Ficosa, Cariad (Audi/Porsche/Skoda)
- Directed full lifecycle of embedded software projects including LiDAR, BMS, OCU, and Cybersecurity systems.
- Coordinated internal and external stakeholders including suppliers like Bosch, Bertrandt, Magna, Continental and IAV.
- Managed cross-country teams of 12–15 engineers, conducting project onboarding and role-based training.
- Implemented change control and risk registers for safety-critical automotive platforms.
- Oversaw project schedules using MS Project, JIRA, and Azure DevOps to ensure milestone alignment and transparency.
- Extensive hands-on expertise in test planning and execution for ECUs in compliance with Automotive SPICE (SWE.4–SWE.6) and ISO 26262.
- Led digital transformation project with a cross-functional team of 15+, ensuring successful integration of systems and workflows.
- Maintained project overviews and tracking in tools like Milestones (Daimler) and MS Project, and managed status reporting to senior stakeholders.
- Coordinated with third-party transformation partners and ensured timely delivery of decision templates and risk assessments.
- Applied PRINCE2 methodology for structured delivery; facilitated agile ceremonies and maintained Confluence-based documentation.
- Strong leadership in cross-functional teams and working in agile environments (SAFe, Scrum).
- Successfully led and supported IT and transformation projects, including those in regulated sectors (e.g., KRITIS or energy sector).
- Represented or supported overall project leadership in large-scale transformation programs.
- Maintained and updated complex project plans (Gantt charts, milestone tracking, and resource allocation).
- Coordinated workstreams and interdisciplinary teams; ensured timely delivery of all work packages.
- Acted as central communication point between project team, senior management, external vendors, and transformation partners.
- Prepared and delivered concise status reports, steering committee presentations, and decision memos.
- Identified project risks, maintained risk registers, and led mitigation planning.
- Assessed resource needs and supported reallocation based on project priorities and constraints.
- Proficient in JIRA, Milestones, Confluence, MS Project, MS PowerPoint, and Excel.
- Used both Agile (Scrum) and Waterfall (PRINCE2, PMI) methodologies.
- Created and tracked action lists, meeting protocols, and backlog items.
- Conducted critical analysis of project progress, resource bottlenecks, and deliverable timelines.
- Ensured alignment of transformation goals with enterprise IT architecture and business objectives.
Volker Jung
Last position:
Interim CISO (Germany, Austria, US, APAC), Auditor at Vetter Pharma-Fertigung GmbH & Co. KG
- Planned and initiated BIA/BCM assessment to identify risk mitigation measures and process optimization, and provide risk transparency to the general management
- Evaluated KRITIS/NIS-2 status and implemented requirements
- Created comprehensive digital roadmap and ISO 27001/NIS-2/Data Privacy KRITIS roadmap
- Enhanced crisis management process and documentation
- Integrated information security clauses into customer and supplier contracts to ensure compliance with internal and regulatory requirements
- Ensured organizational readiness for audits by the Landesbehörde für Aufsicht (LBA) and supported audit processes
- Improved asset management processes and classification of sensitive data to strengthen overall security
- Planned and ordered regular penetration tests (internal, external) to identify vulnerabilities and improve security measures
- Performed compliance checks against EU CER requirements and reporting
- Created management status and risk reports to ensure transparent communication of risks and security posture
- Managed registration with the German Federal Office for Information Security (BSI) and provided ongoing status updates
- Conducted risk assessment of supply chain, enhanced evaluation and reporting processes
- Improved IT/OT network segmentation to enhance security and reduce potential audit risks
- Strengthened cyber resilience by proactive measures and enhanced security frameworks and KPI reporting
- Onboarded SIEM/SOC/EDR to improve cybersecurity monitoring and response
- Planned and conducted awareness trainings for employees, administrators, and management
- Enhanced incident reporting processes to ensure timely and accurate reporting of cybersecurity events
- Created AI policy in cooperation with the Legal department to secure use and governance of Artificial Intelligence within the organization
- Scoped and implemented ISO 27001:2022 requirements as part of the Information Security Management System
- Served as interim InfoSec team lead
- Introduced information security to global KAM and Sales organization
- Improved admission and access management including privileged access
- Conducted internal audits in collaboration with internal audit department
Discover over 15,000 top freelancers
Statistics of experts using KRITIS
Aggregated from the professional profiles of matched freelancers.
Experience
23 years
Position duration
2.4 years (Germany: 2.3 years)
Positions per freelancer
15 (Germany: 17)
Top business areas
Information Technology, Project Management, Quality Assurance
Top industries
Information Technology, Automotive, Manufacturing
Certification focus areas
Information Technology, Project Management, Product Development
Bachelor's degree or higher
83% (Germany: 93%)
Master's degree or higher
50%
Certifications per freelancer
4 (Germany: 9)
Most common languages
German, English, French
Speak two or more languages
100% (Germany: 95%)
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Munich are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Munich using KRITIS
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
What KRITIS covers
KRITIS stands for Kritische Infrastrukturen, the critical services that must keep running when systems fail. In practice, it covers sectors where outages have direct impact, so companies need clear security, resilience, and reporting processes. Strong experts turn legal requirements into workable controls.
Typical work
- Map systems and services against KRITIS scope
- Prepare security concepts, risk reviews, and evidence packs
- Support business continuity and incident handling
- Align technical measures with compliance teams and auditors
These tasks often sit between IT security, operations, and governance. In Munich, that matters for companies with regulated environments, industrial operations, and interconnected service chains.
Ecosystem and standards
KRITIS work often touches the BSI framework, the KRITIS regulation, ISO 27001, and internal control catalogs. Experts also work with network segmentation, logging, identity controls, backup concepts, and supplier checks. Good professionals know how these parts fit together without overengineering the process.
When companies bring in specialists
Companies usually need freelance KRITIS experts when they face a scope check, an audit, a new system rollout, or a gap in documentation. They also step in after an incident, during reorganizations, or when internal teams need quick support for a deadline. Fast access is useful when local coordination in Munich is needed but the work can be done partly remote.
What strong experts do differently
Strong KRITIS specialists ask about assets, dependencies, recovery targets, and reporting lines before they talk solutions. They write in plain language, connect legal duties to technical tasks, and keep evidence easy to maintain. They know when to focus on minimum viable compliance and when a deeper control design is needed.
How to work with them
KRITIS projects benefit from experts who can work with security, legal, operations, and management. Look for clear documentation, calm incident handling, and practical advice that fits your environment. If your team needs German-language coordination, Munich-based collaboration can help, while many reviews and remediation tasks still work well remotely.
Frequently asked questions
Need clarity? These are the questions we hear most often about KRITIS.
KRITIS refers to critical infrastructure that must stay reliable under pressure. For a company, that means clear responsibilities, documented controls, tested recovery steps, and evidence that security measures are actually in use. The exact scope depends on the sector and the systems involved.
KRITIS is the common shorthand people use for the critical infrastructure rules and requirements in Germany. In practice, searchers often mean the BSI framework, the KRITIS regulation, or Kritische Infrastrukturen as a whole. A strong specialist should understand the legal context and the operational impact, not just the wording.
A KRITIS specialist often delivers scope checks, gap analyses, security concepts, continuity plans, and audit-ready documentation. They may also support incident processes, supplier reviews, and internal workshops with operations and compliance teams. The goal is usable evidence, not paperwork for its own sake.
KRITIS and ISO 27001 overlap, but they are not the same thing. ISO 27001 gives a broad management system for information security, while KRITIS focuses on critical services, resilience, and sector-specific duties. Many companies need both views connected in one practical setup.
A good KRITIS expert usually also understands risk analysis, incident response, business continuity, supplier management, and security documentation. Familiarity with BSI guidance, audit preparation, and technical controls like logging or network segmentation helps a lot. Clear communication matters just as much as framework knowledge.
A KRITIS project needs someone who has worked through real reviews, not just read the rules. Simple scope checks may need lighter support, while audits, remediation, or incident follow-up need deeper expertise. Ask for concrete examples of similar environments and deliverables.
KRITIS work is often a mix. Document reviews, control design, and preparation work are usually fine remotely, while workshops, site checks, and leadership alignment can benefit from being on-site in Munich. A flexible specialist should handle both without slowing the project down.
A strong KRITIS freelancer explains the scope clearly, asks about your systems and dependencies early, and turns complex requirements into practical steps. Look for clean documentation, realistic recommendations, and comfort working with both technical and non-technical stakeholders. If the answer is vague or overly theoretical, keep looking.
The average hourly rate of freelancers in Munich, Germany who have used KRITIS in their recent projects is 99 €, which corresponds to a daily rate of about 790 € based on an 8-hour working day.
Of the freelancers in Munich, Germany who have used KRITIS in their recent projects, 83% hold at least a Bachelor's degree and 50% hold at least a Master's degree.
On average, freelancers in Munich, Germany who have used KRITIS in their recent projects have 23 years of professional experience, with a single engagement typically lasting around 2.4 years.
The most common languages among freelancers in Munich, Germany who have used KRITIS in their recent projects are German (100%), English (100%), and French (43%).
The most common industries among freelancers in Munich, Germany who have used KRITIS in their recent projects are Information Technology (86%), Automotive (71%), and Manufacturing (57%).
The most common business areas among freelancers in Munich, Germany who have used KRITIS in their recent projects are Information Technology (100%), Project Management (100%), and Quality Assurance (86%).
Main locations of FRATCH Experts, who have recently used KRITIS
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Frankfurt
Dusseldorf