Ostendo Consulting

Resorts, Croatia

ICT security audits, penetration testing, and DORA compliance for financial institutions

Based in Ugljan, Croatia and founded in 2011, Ostendo Consulting focuses on information security risk and compliance, led by Biljana Cerin, a former board member of (ISC)2. Consultants bring decades of experience building global information security frameworks and standards, applying that background across technology, financial, health, telecom, retail, and energy clients.

The practice runs annual ICT security audits built from tailored audit plans, analyzing client ICT systems and supplier contracts as part of risk assessment. Penetration testing is delivered through a dedicated testing service aimed at digital operational resilience, with a partner firm involved in parts of that work. Where audits or tests surface weaknesses, consultants provide guidance on remediating system vulnerabilities and support clients through implementing the resulting changes.

For financial institutions, the work centers on aligning ICT risk management with DORA requirements. This includes compliance documentation, incident reporting, and regulatory communication, along with mandatory annual training for client staff. The combination of audits, testing, and remediation guidance recurs on an annual cycle rather than as a single project.

15
YEARS IN BUSINESS
2
SERVICES

Capabilities

Services

What these services involve

Penetration Testing
Penetration Testing for cybersecurity buyers. Clear scope, measurable outcomes, and reliable delivery.
Security Audits and Risk Assessment
Security Audits and Risk Assessment for cybersecurity buyers. Clear scope, measurable outcomes, and reliable delivery.

Agency details

Founded
2011 (15 years)

Directory hubs

Browse the wider directory Ostendo Consulting is listed in.