Cybersecurity · Compliance

Cybersecurity and compliance. Measurable.

vCISO and vDPO services, phishing simulations and GDPR compliance for Croatian companies, schools and institutions. An evidence base for audits, not a binder on a shelf.

CSA · OG 14/2024GDPRNIS2DORA
LureLab platformvDPO & GDPR
🏫
AZOO expert opinion
Digital Shield programme approved for primary schools
AZOP-approved solutions
Compliance confirmed by the Croatian data protection regulator
📡
Decades of experience
Telecom security and fraud management since 2012

Platform and compliance, from a single source

LureLab platform

Simulated phishing. Measurable resilience.

One platform, three modules: phishing simulations across SMS, email, voice, WhatsApp, QR and OAuth; Cyber Watch real-time SMS threat monitoring; Active Guard employee alerts triggered by the CISO.

  • EU hosting, AZOP approved
  • Simulation cycles with training after each wave
  • Resilience report as an audit-ready evidence base
Learn more about LureLab →
vDPO & GDPR compliance

Outsourced DPO with software tools

GDPR is not a project, it is a continuous process. Our outsourced Data Protection Officer service comes with tools: a DPIA wizard, ROPA records of processing, DPA templates and an audit log.

  • vDPO under GDPR Art. 37-39, liaison with AZOP
  • DPIA, ROPA, DPA agreements under Art. 28
  • Works council notification under Labour Act Art. 150
Learn more about the vDPO service →
Services

From risk assessment to continuous compliance

🛡️
vCISO and vDPO
A continuous role as your Chief Information Security Officer and Data Protection Officer. Dedicated per organisation, with an evidence base for audits.
CSA Art. 21 · GDPR Art. 37-39
📊
CSA risk assessment
A structured risk assessment under the Croatian Cybersecurity Act. Signals, risk levels and a mitigation plan mapped to the articles of the law.
CSA Art. 26-31
📡
Wi-Fi security assessment
A non-intrusive 10-step wireless assessment. Technical report with CVSS scores, a CSA compliance matrix and an attestation letter.
CSA Art. 21
🎓
Employee training
Targeted training based on simulation results. Continuous awareness, not a one-off workshop.
CSA Art. 21(2)

Pricing and scope are defined by a quote on request, based on the size and sector of your organisation.

Why ID Shield Protect

A Croatian partner, EU rules, full accountability

🇪🇺

EU hosting, EU processor

Data stays in the EU. No exposure to the US CLOUD Act or FISA 702: a risk clients carry when using US vendors.

AZOP-approved solutions

Solutions aligned with the Croatian data protection regulator. We deliver the compliance stack, we do not push it onto the client.

⚖️

CSA as the operative law

We work under the Croatian Cybersecurity Act (OG 14/2024) as the governing national law, alongside GDPR, NIS2 and DORA as parallel frameworks.

📡

Decades of experience

More than 20 years in telecom security and fraud management: T-Mobile, Deutsche Telekom Group, TELE2, DPD.

Sectors

Where CSA and GDPR matter most

🏥
Healthcare
🏫
Education
🏛️
Public sector
Energy
🏦
Finance
🏭
Manufacturing
ℹ An entity that provides services to an essential or important entity itself falls within the scope of the CSA, regardless of size (Art. 22).
Next step

Start with a free gap analysis

No obligation. We establish your current CSA and GDPR compliance status and propose a plan. Quotes are issued on request.

Request a gap analysis
Contact
ID Shield Protect Ltd. · Zagreb
📞 +385 98 470-495
📧 info@idshield.com.hr
🌐 idshield.com.hr