Cybersecurity you can demonstrate

We test technology and people. We build NIS2 resilience.

AI-assisted penetration testing reveals real attack paths, phishing simulations test human resilience, and our NIS2 services build a demonstrable cybersecurity capability.

20+ years of international IT experience OWASP · PTES · NIST PECB Ethical Hacker PECB NIS2 Lead Implementer Available for international projects
ATTACK PATH ANALYSIS LIVE
AI
01Attack surface47 services analysed
02Vulnerability validationManual verification in progress
03Business impact analysisPrioritising findings
12 potential findings 3 confirmed risks 0 false positives in report
Methods and frameworksOWASP WSTGPTESNIST SP 800-115ISO 27001NIS2

Three essential pillars

Technology. People. Compliance.

Security is neither documentation alone nor a single tool. We test technical resilience, employee behaviour and the organisation's ability to manage cyber risk.

01

OFFENSIVE SECURITY

AI-assisted penetration testing

We do not deliver a simple vulnerability list. We demonstrate what an attacker could actually achieve, the path they could take and what you should remediate first.

  • External and internal infrastructure
  • Web applications and APIs
  • Active Directory and identities
  • AI system security assessments
  • Social engineering scenarios
  • Retesting after remediation
Explore our approach
02

GOVERNANCE & COMPLIANCE

NIS2 compliance

From the initial gap assessment to a documented, operational and demonstrable cybersecurity risk-management system.

  • Readiness assessment and roadmap
  • Security measure implementation
  • Risk and incident management
  • Business continuity and recovery
  • Supply-chain security
  • Ongoing compliance maintenance
Arrange an initial assessment
03

HUMAN RISK

Phishing attack simulations

Controlled and ethical campaigns test how employees recognise and report realistic phishing scenarios without placing operations at risk.

  • Role- and department-specific scenarios
  • Open, click and reporting metrics
  • Risky behaviour pattern analysis
  • Targeted post-simulation training
  • Management and security team reports
  • Recurring campaigns and progress tracking
Request a phishing simulation

AI + human expertise

Artificial intelligence accelerates analysis.
An expert makes the judgement.

We use AI where it delivers measurable value: correlating large volumes of technical signals, detecting patterns and setting priorities. Every finding is manually validated by a cybersecurity professional.

Human-validated findingsNo unverified automated findings in the final report
01

Broader attack-surface analysis

Faster correlation of exposed services, technologies and known weaknesses.

02

Attack paths

Individual weaknesses are connected into realistic compromise scenarios.

03

Smarter priorities

Risks are evaluated by exploitability and actual business impact.

04

Clearer recommendations

Technical remediation steps tailored to your actual environment.

Controlled and transparent process

From scope to verified remediation

01

Scope and rules

We define systems, objectives, constraints and safe testing conditions.

02

Reconnaissance

We map the attack surface and potential entry points.

03

AI analysis

We connect technical signals with plausible attack scenarios.

04

Manual exploitation

An ethical hacker validates exploitability and the real business impact.

05

Reporting

Management receives a clear overview, while IT gets precise remediation steps.

06

Retest

We verify remediated weaknesses and close the testing cycle.

A complete security framework

Core cybersecurity services

Every service addresses a vital part of your cyber resilience — from governance and regulatory requirements to continuity, technology and employee capabilities.

vCISO

External strategic and operational information security leadership.

ISO 27001

Gap analysis, ISMS implementation and certification readiness.

GDPR

Legal, organisational and technical protection of personal data.

Risk assessment

Identification, evaluation and treatment planning for key risks.

BIA, BCP and DRP

Business continuity and recovery following serious incidents.

Supplier security

Third-party assessment, contractual requirements and risk oversight.

Security controls

SIEM, logging, IAM, cryptography and access management.

Security awareness

Continuous employee education and security-culture development.

Training and certification

Knowledge you can apply the very next working day.

As a certified PECB partner and trainer, we deliver professional training, certification programmes and internal workshops tailored to management, IT teams and employees.

Certified PECB Ethical Hacker Certified PECB NIS2 Lead Implementer Certified PECB Ethical Hacking Trainer Certified PECB NIS2 Lead Implementer Trainer
NIS2Lead Ethical HackerISO 27001AwarenessExecutive training
Request a training programme

Certified partner and trainer

Professional cybersecurity and compliance training
MV
20+years of international
IT experience

Experience behind the technology

We treat security as a business responsibility.

MIT poslovni procesi d.o.o. is a specialised cybersecurity consultancy focused on penetration testing, regulatory compliance and the development of security capabilities.

The company is led by Matija Verić, M.Sc. in Information Technology, a professional with more than 20 years of international experience in IT, cybersecurity and business development. He is a Certified PECB Ethical Hacker, Certified PECB NIS2 Lead Implementer and a certified PECB trainer in both fields.

Based in Zagreb, Croatia, we are ready to support clients across Europe and international markets beyond the Adriatic region, with remote or on-site delivery tailored to each project.

Internationalready beyond the AdriaticPECBEthical HackerPECBNIS2 Lead ImplementerPECB trainerin both fields

Let’s start a conversation

Not sure whether you need a penetration test or a compliance assessment?

In a short initial call, we will define the right scope, methodology and expected outcomes.