Identify vulnerabilities, assess risks, prioritize protective measures

KRITIS Vulnerability Assessment and Risk Analysis

A systematic vulnerability assessment and risk analysis forms the foundation for effective protective measures in critical infrastructures.

  • 01Complete identification of technical and organisational vulnerabilities
  • 02Risk assessment according to ISO 27005 and BSI IT-Grundschutz
  • 03Prioritisation of protective measures by criticality and probability
  • 04Compliance with KRITIS regulation, BSI Act and NIS2 Directive
11+Years of experience
120+Employees
540+Projects
ISO 27001certified

What does a KRITIS vulnerability assessment cover?

Vulnerability assessment and risk analysis is a central component of KRITIS compliance. Operators of critical infrastructures must take appropriate precautions under Section 8a BSIG. This includes systematic identification of vulnerabilities in IT and OT systems as well as assessment of the resulting risks to service continuity.

We conduct a comprehensive vulnerability assessment and risk analysis covering all aspects of your critical infrastructure. From asset inventory through technical scans to threat modelling, we deliver concrete recommendations for improving your security posture.

2 service modules

What we take on for you

Bookable individually or as an end-to-end programme.

01

Asset Inventory & System Classification

Complete capture and classification of all critical assets and systems as the foundation for vulnerability analysis.

  • Systematic capture of all IT and OT systems
  • Classification by criticality and protection requirements
  • Documentation of dependencies and interfaces
  • Establishment of a central asset register
02

Technical Vulnerability Analysis

Comprehensive technical analysis to identify vulnerabilities in IT and OT systems.

  • Automated vulnerability scans
  • Manual penetration tests and code reviews
  • Analysis of network architectures and access controls
  • Assessment of configurations and patch status

5 phases

Our Approach

We conduct a systematic and comprehensive vulnerability analysis that considers both technical and organizational aspects.

  1. Complete capture and classification of all critical assets

  2. Systematic identification of technical and organizational vulnerabilities

  3. Development of realistic threat scenarios

  4. Quantitative assessment of probabilities and impacts

  5. Derivation of prioritized action recommendations

Sarah Richter

Your contact

Sarah Richter

Head of Information Security, Cyber Security

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Why ADVISORI for your KRITIS vulnerability assessment?

  • 01Over 11 years of experience advising critical infrastructure operators
  • 02Proven methods based on ISO 27005, BSI IT-Grundschutz and IEC 62443
  • 03Cross-sector experience in energy, water, finance and transport
  • 04Practical recommendations with clear prioritisation

Important for KRITIS operators

From July 2026, the KRITIS Umbrella Act tightens requirements for physical security. Combined with NIS2, operators must systematically analyse and address both cyber and physical risks.

Certificates, partners and more

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance