Services

Services that build an evidence base, not a binder

From a continuous vCISO role to risk assessment and a wireless security assessment. Every service ends with a document that auditors accept as proof of implementation.

CSA · OG 14/2024GDPRNIS2
Request a quote
01 · Continuous role

vCISO: Chief Information Security Officer

CSA Art. 21 requires the implementation of risk management measures and a person accountable for them. The vCISO model gives you an appointed CISO without a new position: continuously, with proof of implementation.

Implementing measures
Implementation and oversight of measures under CSA Art. 21: policies, procedures, technical controls.
Evidence base
Preparing documentation for audits and the annual self-assessment under Art. 30.
Point of contact
Incidents, reporting to the competent CSIRT, liaison with regulators.

The scope of engagement adapts to the size and sector of your organisation. Quote on request.

02 · Assessment

CSA risk assessment

A structured risk assessment under Articles 26-31 of the Croatian Cybersecurity Act. The result is not an opinion but a matrix: domain, signal, risk level, article of the law and proposed measure.

01
Baseline
Interviews, documentation, technical review
02
Analysis
Signals across CSA domains
03
Risk matrix
Levels: critical, high, medium, low
04
Mitigation plan
Priorities with deadlines and owners
03 · Technical assessment

Wireless security assessment

A non-intrusive 10-step Wi-Fi assessment, without disrupting the network. The methodology is documented up front: contract, rules of engagement and a written authorisation before the first measurement.

Four deliverables
  • Technical report with CVSS-scored findings
  • CSA compliance matrix (Art. 21)
  • Attestation letter for the evidence base
  • Re-assessment plan
⚠ Intrusive testing: a separate engagement
Penetration testing and intrusive techniques are not part of the standard scope. They are carried out only as a separate contract, with management authorisation, expanded rules of engagement and stop criteria, in cooperation with a specialised partner.
04 · Human factor

Employee training

Staff training under CSA Art. 21(2), tied to real results. Training after each simulation wave targets exactly what the wave revealed, per school, department or organisation.

Workshops on-site and online
Tailored to your sector: healthcare, schools, public sector, manufacturing.
Micro-training after each wave
Short, targeted content right after the simulation, while the experience is fresh.
Certificate and records
Per-employee records of completion as part of the evidence base.
Next step

Not sure where to start? The gap analysis is free.

We assess the situation and propose an order of priorities. Pricing and scope for all services are defined by a quote on request.

Request a quote
Contact
ID Shield Protect Ltd. · Zagreb
📞 +385 98 470-495
📧 info@idshield.com.hr
🌐 idshield.com.hr