Recruitment Services Digital Economy

Critical Infrastructure in the Public Sector: What Structures Employers Must Now Put in Place

New Legal Framework Makes Infrastructure Resilience a Leadership and Management Responsibility Date: August 7, 2026

With the KRITIS Framework Act, a uniform nationwide legal framework for the physical security and resilience of critical infrastructure came into effect for the first time on March 17, 2026. The law implements the European CER Directive and requires operators of critical facilities to systematically protect themselves against natural disasters, sabotage, technical failures, human error, and other hazards.

For public employers, this means more than just additional security plans. KRITIS is becoming an organization-wide management task—and thus an issue for agency leadership, human resources departments, municipal enterprises, and public institutions.

KRITIS is not solely the responsibility of the IT department

The overarching KRITIS Act focuses on the physical resilience of critical infrastructure. At the same time, the new BSI Act—which has been in effect since December 6, 2025, as a result of the NIS 2 implementation—regulates cyber and information security. Affected organizations must therefore consider both dimensions of protection together: the security of IT systems and networks, as well as the operational functionality of buildings, facilities, control centers, supply chains, and business processes.

Consequently, this responsibility cannot be delegated to a single IT specialist or an external data center operator. What is needed is a binding KRITIS governance framework that integrates information security, technical infrastructure, building security, emergency preparedness, data protection, procurement, and crisis management.

Which public employers may be affected

Whether a government agency or municipal institution falls directly under the KRITIS umbrella law depends on the facility it operates, the critical service it provides, its sectoral classification, and the applicable thresholds. The law covers, among other areas, energy, transportation, finance, healthcare, drinking water, wastewater, information technology, telecommunications, and public administration.

The issue is therefore of particular relevance to municipal utilities, public transit agencies, hospitals, municipal data centers, water and wastewater utilities, waste management companies, control centers, technical departments, and other public enterprises.

However, even public authorities that are not themselves directly classified as operators of a critical infrastructure must review their dependencies. This is because public services often depend on external data centers, energy suppliers, telecommunications companies, cloud providers, technical service providers, and specialized suppliers.

Establishing Responsibility at the Management Level

The first organizational step does not involve new software or a technical security product. Public employers must first determine who is responsible for KRITIS, resilience, and business continuity.

The leadership of the agency, utility, or business should establish binding objectives, responsibilities, resources, and escalation procedures. This also includes deciding which services must continue to operate or be restored particularly quickly even in the event of a serious incident.

KRITIS thus becomes a management responsibility. Security measures must be prioritized, funded, reviewed, and enforced organization-wide.

Establish Central KRITIS Coordination

Depending on the size and complexity of the organization, central responsibility can be structured as a staff unit, functional area, division, or program management.

Suitable job profiles include, for example:

These positions are not required to implement all technical measures themselves. Their primary responsibility is to coordinate responsibilities, assess risks, manage projects, and ensure implementation by internal departments, data centers, and external service providers.

Establishing Cross-Functional Governance Structures

An effective KRITIS organization requires more than a single designated representative. It makes sense to establish a permanent steering team with representatives from IT, information security, technical operations, facilities management, data protection, legal, human resources, procurement, communications, and disaster response.

This committee should meet regularly to prioritize risks and monitor the status of implementation. At the same time, clear decision-making and escalation procedures must be established for emergencies.

Particularly in the public sector, care must be taken to ensure that responsibilities are not merely described in formal terms but are also backed by actual decision-making authority and sufficient resources.

Identify Critical Services and Dependencies

The starting point for every KRITIS organization is the question of which services must be maintained under exceptional conditions.

This applies not only to servers and networks. Buildings, control centers, technical facilities, power supply, communication channels, key personnel, supply chains, service providers, and alternative operating locations must also be identified.

A motor vehicle registration office, for example, may depend on traffic control centers, digital specialized procedures, communication networks, data center services, and technical traffic infrastructure. The failure of individual components can have significant impacts on traffic control, hazard prevention, and public safety.

Establish Risk Analyses and Resilience Plans

Operators of critical facilities must conduct their own risk analysis and risk assessment at least every four years. Based on this, proportionate technical, security-related, and organizational measures must be developed.

The law specifies, among other things:

These measures must be documented in a resilience plan, implemented, and updated based on risk analyses and as needed to reflect relevant changes.

Jointly Managing KRITIS and Cybersecurity

At the same time, the new BSI Act requires affected organizations to implement comprehensive risk management measures for information security. These include, among other things, incident management, backup and recovery, crisis management, supply chain security, access controls, and securing the development, procurement, and maintenance of information technology systems.

Public employers should therefore avoid establishing separate, parallel structures for physical security, IT security, and emergency management. A more appropriate approach is an integrated management model with clearly defined interfaces.

New Positions Require Management and Project Expertise

The growing demand for personnel is not limited to traditional IT security specialists. There is an increasing need for specialists and managers who can combine technical, organizational, and administrative expertise.

Skills in the areas of digitalization, process management, information security, risk analysis, business continuity, technical infrastructure, data protection, and project and service provider management are particularly relevant.

For many public-sector employers, establishing such structures will only be possible through targeted recruitment. However, the job market for experienced IT security, KRITIS, and resilience experts is tight. Job profiles must therefore be realistically defined, clearly delineated in terms of technical scope, and accompanied by an attractive scope of responsibility.

Resilience Requires Organization and Qualified Personnel

The KRITIS umbrella law does not require every government agency to immediately establish a new department. However, it does increase the pressure to clearly define responsibilities and build effective structures.

Public employers should therefore assess:

After all, critical infrastructure is not protected by technology alone. What is crucial are clear lines of responsibility, robust processes, and qualified employees who permanently embed security and resilience within the organization.

Request offer Arrange call back Send enquiry
Critical Infrastructure in the Public Sector: What Structures...
Critical Infrastructure in the Public Sector: What Structures Employers Must Now Put in Place

KRITIS Framework Act 2026: Public-sector employers must reorganize their approach to accountability, resilience, and IT security. What structures, …

August 7, 2026
Head of the Digitalization Division at the Department of Motor...
Head of the Digitalization Division at the Department of Motor Vehicles

Public Service, Frankfurt am Main: The Road Traffic Authority is seeking an experienced Head of Digitalization and KRITIS IT (m/f/d) for a permanent, …

July 29, 2026
Success Story: IT management for operations & digitalization...
Success Story: IT management for operations & digitalization in a municipal environment successfully filled

Success Story: Kontrast Personalberatung GmbH fills a hard-to-find IT management position in the public sector/municipal operation in NRW. After …

February 13, 2026
Executive search successful: Head of Sales Public Sector / Bid...
Executive search successful: Head of Sales Public Sector / Bid Management filled

Headhunting Public Sector: Kontrast Personalberatung as headhunter filled by executive search "Head of Sales Public Sector / Bid Management" for …

December 16, 2025
IT project manager wanted
IT project manager wanted

The Episcopal Vicariate General is looking for a Project Manager (m/f/d) for Digitalization & System Integration. Management of digitalization …

October 2, 2025
Vacancies IT Project Manager (m/f/d) for Hospital Information...
Vacancies IT Project Manager (m/f/d) for Hospital Information Systems

Hospital IT Specialist - Medical IT Specialist wanted for project development HIS/KAS and future orientation of the clinic

August 18, 2023
Headhunters with Expertise in Recruiting Female Managers
Headhunters with Expertise in Recruiting Female Managers

Kontrast Personalberatung GmbH provides suitable candidate selection

October 15, 2021
We Are Successful in Filling Engineering Vacancies
We Are Successful in Filling Engineering Vacancies

With many years of experience and a strong candidate pool we find suitable engineers

August 17, 2021