CIS Controls
The CIS Controls offer a prioritized approach to cybersecurity with the most important security measures. We support you in the effective implementation of these proven practices.
- ✓Prioritized implementation of the most effective security measures
- ✓Measurable improvement of cyber resilience
- ✓Cost-efficient allocation of security resources
- ✓Compliance with modern cybersecurity standards
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
- Your strategic goals and objectives
- Desired business outcomes and ROI
- Steps already taken
Or contact us directly:
Certifications, Partners and more...










CIS Controls: Prioritized Cybersecurity with Impact
ADVISORI in Numbers
11+
Years of Experience
120+
Employees
520+
Projects
We follow a structured approach to CIS Controls implementation that takes both technical and organizational aspects into account.
Our Approach:
Assessment of the current security posture and CIS readiness
Prioritization of controls based on Implementation Groups
Phased implementation from Basic through Foundational to Organizational Controls
Establishment of monitoring and measurement systems
Continuous improvement and maturity advancement
"We support companies in the effective implementation of the CIS Controls — with a structured approach and practical consulting. This enables security gaps to be closed in a targeted manner, priorities to be set correctly, and cybersecurity to be strengthened in a measurable and sustainable way."

Sarah Richter
Head of Information Security, Cyber Security
Expertise & Experience:
10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security
Our Services
We offer you tailored solutions for your digital transformation
CIS Controls Assessment
Comprehensive assessment of your current security status against the CIS Controls.
- Detailed gap analysis of all 20 CIS Controls
- Assessment of Implementation Groups (IG1, IG2, IG3)
- Risk assessment and prioritization matrix
- Individual implementation roadmap
CIS Controls Implementation
Structured implementation of the prioritized CIS Controls in your organization.
- Phased implementation according to Implementation Groups
- Technical implementation and tooling integration
- Process definition and documentation
- Training and change management
Our Competencies
Choose the area that fits your requirements
The 18 CIS Critical Security Controls v8 address over 90% of the most common attack vectors. We guide you through the complete implementation — from gap analysis and Implementation Group prioritization to technical integration into your existing security architecture.
More Services in Regulatory Compliance Management
Frequently Asked Questions about CIS Controls
What are the CIS Controls and how do they differ from other frameworks?
The CIS Controls are 18 prioritised security measures from the Center for Internet Security based on real-world attack data. Unlike ISO 27001 or NIST CSF, which describe comprehensive management systems, the CIS Controls focus on concrete technical and organisational measures with measurable impact. Version 8 contains 153 individual safeguards prioritised through Implementation Groups (IG1�IG3) according to organisation size and risk profile. Studies show that IG1 alone addresses approximately 85% of the most common cyber attacks.
How do the Implementation Groups (IG1, IG2, IG3) work?
The Implementation Groups tier the 153 safeguards by complexity and resource requirements. IG1 encompasses 56 foundational safeguards for every organisation — even without a dedicated security team. IG2 expands to 130 safeguards for organisations with IT security staff and sensitive data. IG3 covers all 153 safeguards and targets organisations with a high risk profile, such as those in regulated industries like financial services or critical infrastructure. Each group builds cumulatively on the previous one.
What are the 18 CIS Controls in version 8?
The 18 controls in CIS v8 are: 1) Inventory and Control of Enterprise Assets, 2) Inventory and Control of Software Assets, 3) Data Protection, 4) Secure Configuration of Enterprise Assets and Software, 5) Account Management, 6) Access Control Management, 7) Continuous Vulnerability Management, 8) Audit Log Management, 9) Email and Web Browser Protections, 10) Malware Defenses, 11) Data Recovery, 12) Network Infrastructure Management, 13) Network Monitoring and Defense, 14) Security Awareness and Skills Training, 15) Service Provider Management, 16) Application Software Security, 17) Incident Response Management, and 18) Penetration Testing.
How does a CIS Controls implementation with ADVISORI work?
Our implementation follows five phases: First, we conduct an assessment that evaluates your current security posture against the CIS Controls and identifies gaps. Then we prioritise controls based on your risk profile and the appropriate Implementation Group. In the third phase, we carry out phased implementation — from basic controls through foundational to organisational controls. Next, we establish monitoring and measurement systems for ongoing operations. The fifth phase ensures continuous improvement and maturity advancement.
How can CIS Controls be mapped to ISO 27001 and NIST CSF?
The CIS Controls map directly to ISO 27001 Annex A controls and NIST CSF 2.0 categories. The Center for Internet Security provides official mapping documents linking each safeguard to corresponding controls in other frameworks. For organisations that have already implemented ISO 27001 or NIST CSF, this means many CIS requirements are already covered. ADVISORI performs cross-framework mapping, identifies overlaps and gaps, and thereby reduces the overall effort for multiple compliance requirements.
Which industries benefit most from the CIS Controls?
The CIS Controls are applicable across industries but are particularly relevant for financial services (regulatory requirements, DORA, PCI DSS), healthcare (patient data, medical devices), critical infrastructure (NIS2), manufacturing (OT security, supply chain) and the public sector. In regulated industries, the CIS Controls serve as demonstrable security standards for regulators. ADVISORI tailors implementation to industry-specific needs and takes sectoral regulation into account.
How much does a CIS Controls implementation cost and how long does it take?
Duration and effort depend on the target Implementation Group, current maturity level and organisation size. An IG1 implementation for a mid-sized company typically takes three to six months. IG2 requires six to twelve months, IG3 twelve to eighteen months. ADVISORI works with risk-based prioritisation and quick wins: the most effective controls are implemented first to achieve immediate security improvements. An initial gap analysis delivers a reliable effort estimate within two to four weeks.
Let's
Work Together!
Is your organization ready for the next step into the digital future? Contact us for a personal consultation.
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
Ready for the next step?
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
Prefer direct contact?
Direct hotline for decision-makers
Strategic inquiries via email
Detailed Project Inquiry
For complex inquiries or if you want to provide specific information in advance