Many organisations, especially Critical Infrastructures, are facing an increasingly severe cyber threat situation and are continuously improving their IT-security. We present the state of the art of sector specific security operation of CI operators with the German health sector as an example. To improve the situation we propose several spheres of activity with practical exemplary measures, e.g. for relevant protocols. In this way we help to prepare a CI sector governance with sourcing options for security operation for all relevant actors: from the responsible authorities in the country via a single point of contact in the health sector to hospital centres and the medical practice.