IT Advisory for Public Sector & Government
Public authorities, municipalities and public institutions operate inside a double frame of security and digitalisation law.
IT in Public Sector
The recast German BSI Act has applied since 6 December 2025 and governs federal administration bodies in a chapter of its own: section 43 BSIG makes the head of the body responsible for information security management, section 44 BSIG makes the specifications and minimum standards of the BSI binding, and section 45 BSIG requires an information security officer with a deputy at every body.
Registration with the BSI and the reporting of significant incidents under section 32 BSIG apply here too — initial report within 24 hours, follow-up report within 72 hours, final report within one month. The BSI Act does not bind municipalities directly; for them the federal states legislate separately. Hospitals additionally fall under section 75c of the German Social Code Book V: since 1 January 2022 they must maintain appropriate organisational and technical measures reflecting the state of the art and update them at least every two years, in practice via the sector-specific standard B3S for hospital care.
On the digitalisation side, the amended Online Access Act has required end-to-end digital procedures and the removal of written-form requirements since 24 July 2024; the legal right to electronic access to federal services takes effect four years after promulgation, and business-related services move to electronic-only after five years. BSI IT-Grundschutz remains the benchmark for procurement and audit.
Technically this meets historically grown estates: fragmented directory services without consistent rights management, applications that assume local administrator rights, backups without a tested recovery, and logs that cannot be evaluated inside a 24-hour window. Alendris approaches this in stages. For a critical infrastructure operator in healthcare we achieved NIS2 compliance on time: gap analysis, a prioritised action plan, Microsoft Defender XDR as the central security platform, all signals integrated into Microsoft Sentinel, Entra ID Governance with recurring access reviews, Conditional Access for compliant devices — plus the policies, processes and incident response plans an auditor asks to see. For data sovereignty we design Microsoft 365 and Azure architectures with data residency in German and EU regions, plus Microsoft Purview for classification and data loss prevention.
Typical pain points
- BSI Grundschutz mandates with detailed building blocks and audit obligations
- Digital government platform integration with heterogeneous legacy systems
- Public procurement law complicates agile sourcing — long tender processes
- Data sovereignty: cloud usage requires hosting in Germany / EU
- Limited cybersecurity personnel capacity amid escalating threats