Prioritized cybersecurity measures for optimal protection

CIS Controls

The CIS Controls offer a prioritized approach to cybersecurity with the most important security measures. We support you in the effective implementation of these proven practices.

  • Prioritized implementation of the most effective security measures
  • Measurable improvement of cyber resilience
  • Cost-efficient allocation of security resources
  • Compliance with modern cybersecurity standards

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

  • Your strategic goals and objectives
  • Desired business outcomes and ROI
  • Steps already taken

Or contact us directly:

Certifications, Partners and more...

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

CIS Controls: Prioritized Cybersecurity with Impact

ADVISORI in Numbers

11+

Years of Experience

120+

Employees

520+

Projects

We follow a structured approach to CIS Controls implementation that takes both technical and organizational aspects into account.

Our Approach:

Assessment of the current security posture and CIS readiness

Prioritization of controls based on Implementation Groups

Phased implementation from Basic through Foundational to Organizational Controls

Establishment of monitoring and measurement systems

Continuous improvement and maturity advancement

"We support companies in the effective implementation of the CIS Controls — with a structured approach and practical consulting. This enables security gaps to be closed in a targeted manner, priorities to be set correctly, and cybersecurity to be strengthened in a measurable and sustainable way."
Sarah Richter

Sarah Richter

Head of Information Security, Cyber Security

Expertise & Experience:

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Our Services

We offer you tailored solutions for your digital transformation

CIS Controls Assessment

Comprehensive assessment of your current security status against the CIS Controls.

  • Detailed gap analysis of all 20 CIS Controls
  • Assessment of Implementation Groups (IG1, IG2, IG3)
  • Risk assessment and prioritization matrix
  • Individual implementation roadmap

CIS Controls Implementation

Structured implementation of the prioritized CIS Controls in your organization.

  • Phased implementation according to Implementation Groups
  • Technical implementation and tooling integration
  • Process definition and documentation
  • Training and change management

Our Competencies

Choose the area that fits your requirements

CIS Controls Implementation: All 18 Controls v8

The 18 CIS Critical Security Controls v8 address over 90% of the most common attack vectors. We guide you through the complete implementation — from gap analysis and Implementation Group prioritization to technical integration into your existing security architecture.

More Services in Regulatory Compliance Management

Frequently Asked Questions about CIS Controls

What are the CIS Controls and how do they differ from other frameworks?

The CIS Controls are 18 prioritised security measures from the Center for Internet Security based on real-world attack data. Unlike ISO 27001 or NIST CSF, which describe comprehensive management systems, the CIS Controls focus on concrete technical and organisational measures with measurable impact. Version 8 contains 153 individual safeguards prioritised through Implementation Groups (IG1�IG3) according to organisation size and risk profile. Studies show that IG1 alone addresses approximately 85% of the most common cyber attacks.

How do the Implementation Groups (IG1, IG2, IG3) work?

The Implementation Groups tier the 153 safeguards by complexity and resource requirements. IG1 encompasses 56 foundational safeguards for every organisation — even without a dedicated security team. IG2 expands to 130 safeguards for organisations with IT security staff and sensitive data. IG3 covers all 153 safeguards and targets organisations with a high risk profile, such as those in regulated industries like financial services or critical infrastructure. Each group builds cumulatively on the previous one.

What are the 18 CIS Controls in version 8?

The 18 controls in CIS v8 are: 1) Inventory and Control of Enterprise Assets, 2) Inventory and Control of Software Assets, 3) Data Protection, 4) Secure Configuration of Enterprise Assets and Software, 5) Account Management, 6) Access Control Management, 7) Continuous Vulnerability Management, 8) Audit Log Management, 9) Email and Web Browser Protections, 10) Malware Defenses, 11) Data Recovery, 12) Network Infrastructure Management, 13) Network Monitoring and Defense, 14) Security Awareness and Skills Training, 15) Service Provider Management, 16) Application Software Security, 17) Incident Response Management, and 18) Penetration Testing.

How does a CIS Controls implementation with ADVISORI work?

Our implementation follows five phases: First, we conduct an assessment that evaluates your current security posture against the CIS Controls and identifies gaps. Then we prioritise controls based on your risk profile and the appropriate Implementation Group. In the third phase, we carry out phased implementation — from basic controls through foundational to organisational controls. Next, we establish monitoring and measurement systems for ongoing operations. The fifth phase ensures continuous improvement and maturity advancement.

How can CIS Controls be mapped to ISO 27001 and NIST CSF?

The CIS Controls map directly to ISO 27001 Annex A controls and NIST CSF 2.0 categories. The Center for Internet Security provides official mapping documents linking each safeguard to corresponding controls in other frameworks. For organisations that have already implemented ISO 27001 or NIST CSF, this means many CIS requirements are already covered. ADVISORI performs cross-framework mapping, identifies overlaps and gaps, and thereby reduces the overall effort for multiple compliance requirements.

Which industries benefit most from the CIS Controls?

The CIS Controls are applicable across industries but are particularly relevant for financial services (regulatory requirements, DORA, PCI DSS), healthcare (patient data, medical devices), critical infrastructure (NIS2), manufacturing (OT security, supply chain) and the public sector. In regulated industries, the CIS Controls serve as demonstrable security standards for regulators. ADVISORI tailors implementation to industry-specific needs and takes sectoral regulation into account.

How much does a CIS Controls implementation cost and how long does it take?

Duration and effort depend on the target Implementation Group, current maturity level and organisation size. An IG1 implementation for a mid-sized company typically takes three to six months. IG2 requires six to twelve months, IG3 twelve to eighteen months. ADVISORI works with risk-based prioritisation and quick wins: the most effective controls are implemented first to achieve immediate security improvements. An initial gap analysis delivers a reliable effort estimate within two to four weeks.

Let's

Work Together!

Is your organization ready for the next step into the digital future? Contact us for a personal consultation.

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance