NIS2 Experts in Austria
in minutes with vetted specialists and precise AI matchingHire experts who turn NIS2 into clear controls, gap assessments, incident processes, and supplier security reviews. They help align policies, evidence, and technical measures with the directive and the wider NIS-2 requirements, while FRATCH matches you fast with vetted, available freelancers.
Meet FRATCH Experts in Austria, who have recently used NIS2
Zoran Jovanovic
Last position:
Technical Writer – Implementation of the BNPP IT PROD SEC Service Catalog at BNP Paribas Germany
Design, authorship and finalization of the IT PROD SEC service catalog with eight standardized security services (S-ID001–S-ID008).
Development of consistent service components & deliverables, RACI assignments and SLA and KPI definitions for each service.
Integration of BaFin document requirements under DORA into the service descriptions.
Coordination with IT, compliance, risk and operations teams to validate all service descriptions.
Specifically for governance & monitoring: definition of governance cadence, evidence delivery processes, audit support and definition of measurable KPIs and measurement methods.
Ensuring that all services are standardized, measurable and documented in an audit-proof manner.
Result: Approved service catalog with eight services as a binding basis for delivery, governance and audits; transparent SLAs/KPIs for each service and DORA/BAIT/MaRisk-compliant documentation with clear responsibilities and evidence trails.
Technologies and tools: Confluence, Jira, ServiceNow, Microsoft PowerPoint, Microsoft Visio, Office 365.
Hossein Adibpouya
Last position:
Datawarehouse Consultant at LENZING AG
- Consulting on the enterprise data-warehouse and reporting practice at one of Austria's largest industrial groups.
- Designing and standardizing Power BI dashboards and data-visualization governance for company-wide enterprise reporting.
- Developing a WCAG-compliant, colorblind-safe visualization standard (Okabe-Ito palette) to harmonize dashboards across the organization.
Christian Thür
Last position:
Senior Consultant / ICS at Media-related company
- Revised the internal control system following a transformation
- Surveyed current processes and analyzed target processes
- Adjusted financial controls and conducted design and operational tests
- Provided strategic consulting at management level
- Outcome: updated ICS approved by audit bodies; follow-up projects resulting from the achieved results
- Focus areas: ICS, finance processes, governance, design and operational testing, executive consulting
Georg Oberdammer
Last position:
CIO / CDO at TroGroup
- Design and execution of the transformation journey of IT & digitization and enablement of the further development of the group
- Development of the global IT & digitization strategy (motto: “ahead of the wave”) based on group standards and USP-driven digital solutions
- Definition of the digital strategy as part of the company’s 2030 strategy with a focus on the value disciplines “operational excellence,” “customer intimacy,” “product leadership”
- Design and implementation of a business-focused, global IT organization, including existing shadow IT parts
- Digital product development with a focus on IoT, data science, AI, software development (DevOps), cloud architecture, and Azure cloud services
- Initiation and ramp-up of the CoE for artificial intelligence and data analytics, including several agentic AI projects
- Definition and global rollout of the enterprise, infrastructure, and application architecture
- Cloud transformation including setup and execution of the global S/4HANA rollout, introducing new capabilities and modules
- Global business process standardization, automation, and end-to-end digitization within and across divisions
- IT/OT integration (shop floor, CAx integration)
- P&L responsibility and further development of digital marketing & sales channels, SEO/SEA, online product configuration, PIM/DAM, eBusiness/eCommerce systems
- Implementation of a global intranet portal and several digital solutions like Workday, Concur, Softconcis, Tacto, xFlow
- Further development of Salesforce beyond CRM into a sales backbone
- Support of M&A and divestiture
- Cyber security excellence, data protection, and NIS2 preparation
- Ramp-up of nearshore and offshore locations (Poland, India)
- Evaluation and implementation of business-value–driven IT innovation like RPA, business process AI, and low-code
- IT budgeting and controlling, KPI reporting, and negotiation of large IT contracts
- Global recruiting, people retention, and development
- Stakeholder management with executive management and heads of divisions
Klaus Hoffmann-Wissenwasser
Last position:
Founder at HoWi Consulting e. U.
- Project management IT & business process design digitalization
- Delivered 10+ successful projects (see project list)
- Business analysis
- Business organization
- Data management
Peter Wallner
Last position:
Head of ICT Department at St. Pölten University Hospital
Overall management of ICT infrastructure and services at the St. Pölten University Hospital
Ensuring a highly available, secure, and high-performance IT environment
Planning, controlling, and continuously optimizing IT processes
Adapting and evolving the IT strategy in line with clinical requirements
Main point of contact for alignment between ICT, hospital management, and clinical departments
Interface between the regional health agency and local management
Ensuring efficient cross-department collaboration
Building, maintaining, and developing relationships with internal and external stakeholders
Representing the ICT department in interdisciplinary committees and projects
Leading digitization, innovation, and infrastructure projects
Managing IT projects with regard to cost, time, and quality
Ensuring compliance with data protection, security, and compliance requirements (e.g. NIS/NIS2)
Implementing and monitoring security measures to minimize risks
Analyzing, optimizing, and automating IT-supported workflows
Introducing innovative solutions to increase efficiency
Planning, controlling, and monitoring IT budgets and resources
Efficient allocation of personnel and financial resources
Developing and implementing long-term ICT strategies at the hospital
Identifying and integrating new technologies to improve patient care
Leading, motivating, and developing a high-performing ICT team
Promoting an innovation-friendly and collaborative work culture
Advising clinical and administrative departments on technology solutions
Supporting digital transformation and the introduction of new IT services
Sascha Leitner
Last position:
CEO at SEComply
- Founder & creator of a cutting-edge Governance, Risk & Compliance SaaS solution.
- Developing and executing business development strategies to identify new opportunities and expand market presence.
- Providing information security consulting services.
- Specializing in governance, risk, and compliance (GRC) topics such as risk management, ISO 27005, ISO 27001, NIS 2, DORA, PCI DSS, EU-GDPR, and more.
- Past projects:
- Kyndryl Austria GmbH: delivered IAM blueprint, conducted risk assessments, developed transformation strategy and roadmap for client projects, and provided support in pre-sales activities to align solutions with client needs.
- Cashpoint Sportwetten GmbH: conducted ISO 27001:2022 gap analysis, enhanced ISMS processes, updated security training, aligned with ISO 27001:2022 standards, and improved vulnerability management practices through regular assessments and remediation planning.
- Hornbach Baumarkt AG: supported the CISO in achieving ISO 27001 compliance, implementing a secure software development lifecycle (SDLC), strengthening vulnerability management practices, and enhancing risk management frameworks.
- MHP Management- und IT-Beratung GmbH: created and reviewed security concepts aligned with ISO 27001 standards.
- Stromnetz Berlin GmbH: developed a comprehensive security concept based on ISO 27001 requirements.
- dmTech GmbH: conducted IT security training for employees, fostering awareness and adherence to security best practices.
- Finanz Informatik GmbH: managed PCI DSS-related tasks, including compliance assessments and control implementations.
- TIPS Messtechnik GmbH: conducted NIS2 gap analysis, developed a comprehensive compliance roadmap, and provided supportive actions to address identified gaps and ensure alignment with regulatory requirements.
Anton Laza
Last position:
CISO & Interim DPO at Finmatics GmbH
- Built the company’s entire security function from zero to ISO-aligned, audit-ready operation (ISO 27001, GDPR, NIS2).
- Delivered enterprise-grade security posture enabling regulated customer onboarding and due-diligence success.
- Embedded automated security controls (SAST, DAST, secrets, vuln scanning) into CI/CD for a growing SaaS engineering team, removing security as a deployment bottleneck.
- Cut third-party risk exposure by ~70% by replacing manual vendor reviews with an automated, LLM-driven risk scoring and approval pipeline.
- Led board-level security, customer audits, and live incident response.
Peter Klosa
Last position:
Sabbatical
Discover over 15,000 top freelancers
Statistics of experts using NIS2
Aggregated from the professional profiles of matched freelancers.
Experience
22 years
Position duration
2.6 years
Positions per freelancer
12
Top business areas
Information Technology, Project Management, Strategy
Top industries
Information Technology, Banking and Finance, Manufacturing
Certification focus areas
Project Management, Information Technology, Audit
Bachelor's degree or higher
100%
Master's degree or higher
75%
Doctorate
25%
Certifications per freelancer
6
Most common languages
German, English, Spanish
Speak two or more languages
100%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Austria are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Austria using NIS2
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
What NIS2 covers
NIS2 is the EU cybersecurity directive that raises the bar for risk management, reporting, and governance. It affects many essential and important entities, plus the suppliers they rely on. In practice, it shapes how companies document controls, handle incidents, and prove accountability.
Typical delivery work
- Scope checks and gap assessments against NIS2
- Security policies, incident playbooks, and evidence packs
- Supplier and third-party risk reviews
- Board reporting and responsibility mapping
- Support for audits, remediation, and control rollout
Skills that matter
Strong NIS2 specialists know cybersecurity governance, risk management, and compliance documentation. They often work with ISO 27001, incident response, asset inventories, vulnerability handling, and business continuity. They also need to translate legal text into practical technical and process steps.
When companies bring help in
Many teams ask for freelance NIS2 expertise when they need a fast baseline, an external view, or focused support for remediation. Common triggers are unclear scope, weak evidence, missing incident processes, or supplier contracts that do not reflect current security duties. External specialists help turn pressure into a workable plan.
NIS2 in Austria
In Austria, NIS2 projects often involve mixed teams across security, legal, procurement, and operations. Remote work is common for assessments and documentation, while workshops and leadership sessions may benefit from on-site time. Clear German or English communication is often expected, depending on the organisation.
What good professionals deliver
The best NIS2 professionals do more than cite the directive. They map obligations to real systems, identify gaps that matter, and leave behind usable policies, registers, and action plans. They know how NIS2, the NIS-2 Directive, and the Network and Information Security Directive 2 are used in practice, not just in legal text.
Frequently asked questions
Key details about NIS2, drawn from the questions we get asked most.
NIS2 is used to structure cybersecurity governance, incident handling, and risk controls around the EU directive. Companies use it to understand what they must protect, what they must report, and how they should document their security posture. It is most useful when compliance and operational security need to be aligned.
NIS2 is a legal and regulatory requirement, while ISO 27001 is a management system standard. Many companies use both, but they solve different problems: NIS2 defines obligations, and ISO 27001 helps organise controls and evidence. A strong specialist knows how to map one to the other without forcing them to be the same.
A strong NIS2 freelancer usually brings cybersecurity governance, risk assessment, and incident response knowledge. Useful adjacent skills include supplier risk management, business continuity, control testing, and policy writing. In many projects, legal and procurement awareness matters as much as technical depth.
For a small gap assessment or policy update, a seasoned NIS2 specialist can move quickly with limited internal support. For a full implementation, you usually want someone who has handled both documentation and operational rollout. The more regulated or distributed the environment, the more practical experience matters.
Most NIS2 work can start remotely, especially scope reviews, document analysis, and gap assessments. On-site time in Austria can help when teams need workshops, leadership alignment, or access to internal stakeholders and systems. Many engagements use a mix of both.
With NIS2, quality shows up in concrete outputs: clear scope, traceable obligations, usable policies, and remediation that fits the business. Be wary of generic templates that do not reflect your systems, suppliers, or incident processes. Good work should be easy for internal teams to maintain after the freelancer leaves.
Often yes, because NIS2 combines legal interpretation, governance, and technical controls. Internal teams may know the environment well, but a specialist can spot missing evidence, unclear ownership, or gaps between policy and practice. External support is especially useful when timelines are tight or the scope is uncertain.
Yes. NIS2 is the common shorthand for the NIS-2 Directive, also referred to as the Network and Information Security Directive 2. Searchers use all three forms, but they point to the same EU cybersecurity framework.
The average hourly rate of freelancers in Austria who have used NIS2 in their recent projects is 128 €, which corresponds to a daily rate of about 1,021 € based on an 8-hour working day.
Of the freelancers in Austria who have used NIS2 in their recent projects, 100% hold at least a Bachelor's degree, 75% hold at least a Master's degree, and 25% hold a doctorate.
On average, freelancers in Austria who have used NIS2 in their recent projects have 22 years of professional experience, with a single engagement typically lasting around 2.6 years.
The most common languages among freelancers in Austria who have used NIS2 in their recent projects are German (100%), English (100%), and Spanish (22%).
The most common industries among freelancers in Austria who have used NIS2 in their recent projects are Information Technology (67%), Banking and Finance (56%), and Manufacturing (56%).
The most common business areas among freelancers in Austria who have used NIS2 in their recent projects are Information Technology (100%), Project Management (89%), and Strategy (89%).
Main locations of FRATCH Experts, who have recently used NIS2
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Countries:
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
