Adventure Spirit d.o.o. · Zagreb, Croatia +385 95 504 1496 info@adventurespirit.hr GRC Portal
CSA / NIS2 · GDPR · DORA · ISO

Risk management.
Compliance.
Security.

We know what the regulator asks for and what proves it. We work with essential and important entities on the Croatian Cybersecurity Act, on data protection and on ISO standards - and we tell you who does what, in what order, and which piece of evidence stands behind each measure.

CSA / NIS2GDPR ISO 27001ISO 9001 ISO 14001ISO 22301 DORAVendor Risk Pen Testing
Readiness snapshot · 13 CSA measures
Sample output of a gap assessment
Categorised important entity, food industry
01
02
03
04
05
06
07
08
09
10
11
12
13
THRESHOLD 60 %
One block is 20 % of the requirements within a measure for which evidence exists. Grey columns are measures below the readiness threshold. The threshold is our internal indicator, not a statutory one.
20+
years in information security
50+
GRC and ISO projects delivered
40+
organisations in our references
9
modules in the GRC platform

Expertise that produces results

More than two decades at the intersection of information security, business processes and regulatory requirements.

Daniel Bara, PhD
Founder and Principal Consultant
  • ▸PhD - Faculty of Economics, Osijek
  • ▸MBA - Zagreb School of Economics and Management
  • ▸MSc in Transport Engineering
  • ▸PMP - Project Management Professional
  • ▸CIPP/E - Certified Information Privacy Professional/Europe
  • ▸Lecturer at RIT Croatia since 2017 (IST, Strategic Management, PM)
  • ▸Guest lectures: ZSEM, VERN, Libertas
  • ▸PMI Croatia - active member
  • ▸HAMAG-BICRO evaluator (300+ EU projects)

Over 20 years in information security and GRC

Adventure Spirit Consulting grew out of a simple proposition: organisations deserve cybersecurity and risk management expertise fitted to real operations, not to generic templates. We work with clients who know what they want, and we know what they need.

We run projects one at a time, without unnecessary exposure. What shows are the results: information security management systems in operation, business continuity plans that have actually been exercised, data protection processes that hold, and organisations that walk into certification audits with confidence. Our experience spans banking, insurance, energy, healthcare, the food industry and the public sector - everywhere data and operational resilience are a question of survival.

Principal consultant Daniel Bara, PhD, brings more than 20 years of work in information security, a doctorate in business intelligence, an MBA, the PMP and CIPP/E certifications and experience as an external evaluator on more than 300 EU-funded projects. He has lectured at RIT Croatia since 2017, with guest lectures at ZSEM, VERN and Libertas.

Areas of expertise

ISO 27001:2022ISO 9001:2015 ISO 14001:2015ISO 22301:2019 GDPR / DPOCIPP/ENIS2 / CSA DORAVendor Risk Penetration testingBIA / BCP / DRP Business IntelligenceData Architecture PL/SQLPMP

End-to-end risk and compliance management

Nine service lines, one evidence base. Where the requirements overlap, the documentation is written once.

CSA / NIS2 compliance
Implementation of all 13 risk management measures from Annex II of the Croatian Cybersecurity Regulation (OG 135/2024), at the level of implementation prescribed for your entity category - from gap assessment to a complete evidence base.
GDPR compliance
All personal data protection processes established - records of processing activities, DPIA, legitimate interest assessments, data subject request handling, DPO support and breach notification to the Croatian supervisory authority.
ISO/IEC 27001 - Information security
Gap assessment, ISMS implementation, risk assessment, Statement of Applicability and full preparation for the certification audit against ISO/IEC 27001:2022.
ISO 9001 - Quality management
QMS implementation, process documentation, definition of quality objectives and KPIs, internal audit programme and preparation for certification.
ISO 14001 - Environmental management
EMS implementation - identification of environmental aspects and impacts, legal compliance register, carbon footprint reduction and certification readiness.
ISO 22301 - Business continuity
Business impact analysis, RTO and RPO definition, business continuity and disaster recovery plans, exercising and preparation for certification against ISO 22301:2019.
DORA - Digital operational resilience
Compliance with the EU DORA regulation - ICT risk management framework, third-party risk and the register of information, resilience testing and regulatory reporting.
Vendor risk management
Third-party risk assessment, due diligence questionnaires, automated risk scoring, continuous monitoring and contractual security clauses across the supply chain.
Security audits and testing
Penetration testing, vulnerability assessment, configuration review, social engineering simulations and reports written for both technical and board-level audiences.

Sectors we cover

Entity category is determined by the sector listed in the annexes to the Act and by size, subject to a number of exceptions where size is not the criterion at all.

SOA · central cybersecurity authority NCSC-HR · incident reporting ZSIS / UVNS · state administration bodies AZOP · personal data breaches HNB / HANFA · DORA, financial sector HAKOM · digital infrastructure sector

Your GRC compliance
running in one platform

Not advisory alone. We also run our own GRC platform that digitises risk management, compliance and security processes. Your team works in a system we built out of real implementations.

  • CSA/NIS2, GDPR, ISO 27001, ISO 9001, ISO 14001, ISO 22301, DORA
  • Vendor risk management with automated risk scoring
  • AI document analysis and automated benchmarking
  • Incident management and regulatory reporting
  • BIA wizard, audit log and compliance dashboard
  • Multi-tenant architecture for consultants and their clients
Try the GRC Portal →
Adventure Spirit GRC
Compliance platform for risk management
9+
Compliance modules
AI
Document analysis
24/7
Portal availability
No account yet? Ask us for a demo →

How we work

A structured approach that delivers - from the first assessment through to certification and continuous monitoring.

01
Gap assessment
We score the current state against every measure and control and list the evidence that is missing. The result is a number, not an impression.
2 to 3 weeks
02
Remediation plan
A prioritised compliance roadmap with owners, deadlines, resource estimates and a measurable target for each requirement.
1 to 2 weeks
03
Implementation
Policies, procedures, risk register and the records that stand behind each measure, together with staff training and management review.
3 to 9 months
04
Platform and certification
We walk through the documentation the way an auditor or certification body will, before they arrive. Everything lives in the GRC platform for continuous monitoring.
Ongoing
What you actually get
Gap assessment report with scoring by measure, sub-measure and control
Information asset register and a threat catalogue tailored to your sector
Risk register, assessment matrix and a risk treatment plan with defined risk appetite
Policies and procedures behind every measure, ready for board approval
Compliance roadmap with priorities, owners, deadlines and resource estimates
Internal review report that simulates the audit or certification process
Mapping of your existing certifications and standards onto CSA, DORA and GDPR requirements
Every deliverable recorded in the GRC platform, with an audit trail and deadline tracking

Organisations that trust us

We have worked with organisations across financial services, insurance, energy, healthcare, the food industry, IT and sport - implementing ISMS, BCMS, GDPR, DORA, NIS2 and ISO certifications.

40+
organisations across banking, insurance, energy, IT, the food and pharmaceutical industries, logistics and sport

What the rules ask for and what proves it

Articles on the Croatian Cybersecurity Act, ISO standards and risk management. Every claim carries the article of the law or standard behind it, where one exists.

What clients ask us most

Answers carry the article of the law or standard behind them, where one exists.

The category is determined by sector and by the size of the entity, subject to exceptions. Essential entities are subject to an independent cybersecurity audit, while important entities carry out a self-assessment. You are notified of the categorisation in writing by the competent authority. Size is not the criterion for state administration bodies and operators of the state information infrastructure (essential), for local and regional self-government and the education system (important), nor for trust service providers, DNS service providers and the national domain registry. In addition, Article 11 allows any entity to be categorised regardless of size if it is the sole provider of an essential service or if its disruption would significantly affect public safety, security or health.

Cybersecurity Act, OG 14/2024

The Croatian Cybersecurity Regulation breaks the statutory duties down into 13 cyber risk management measures, set out in 99 sub-measures across three levels of implementation: basic, medium and advanced. The level that applies to you depends on your entity category and on your risk assessment. The scope runs from security policy and risk management through to cryptography, supply chain security and physical protection. Every control requires written evidence.

Cybersecurity Regulation, OG 135/2024, Annex II

A twelve-month period runs from the delivery of the categorisation notice, not from the date the Act entered into force. The competent authority must deliver that notice within 30 days of the categorisation. After the compliance period ends, conformity is verified - by independent audit for essential entities, by self-assessment for important ones. In practice organisations lose the first quarter waiting for an internal owner to be appointed, so we recommend starting the gap assessment as soon as the notice arrives.

Cybersecurity Act, OG 14/2024, Art. 26

An early warning to the competent CSIRT within 24 hours of becoming aware, an incident notification within 72 hours and a final report within 30 days. If the incident also involves a personal data breach, a parallel notification to the Croatian data protection authority runs within 72 hours under Article 33 GDPR. The deadlines do not add up - they run in parallel, so the reporting process has to be prepared in advance rather than improvised during the incident.

Cybersecurity Act, OG 14/2024 · GDPR, Art. 33

For the financial sector DORA is the more specific regime governing ICT risk management, resilience testing and oversight of ICT service providers. Entities subject to DORA do not thereby cease to be subject to other rules. The good news is that the evidence base overlaps heavily: the same asset register, the same risk register, the same register of third-party contracts and the same incident records. You do the work once and report it in several directions.

DORA, EU 2022/2554

Not automatically, but a large part of the work is already done. ISO/IEC 27001:2022 covers a substantial share of the 13 measures - security policy, risk management, asset management, access control, supply chain security and business continuity. What ISO does not cover are the specifics of the Act: entity categorisation, the deadlines and format for reporting incidents to the competent CSIRT, and the content of the self-assessment. We therefore map your existing controls onto the measures and only fill the gap, instead of building a second set of documentation in parallel.

ISO/IEC 27001:2022, Annex A

Two to three weeks for a mid-sized organisation. The result is a scored assessment against every measure and control, a list of the evidence that is missing, a risk register and a compliance roadmap with priorities, owners and resource estimates. Everything is recorded in our GRC platform straight away, so you track progress continuously and with an audit trail rather than once a year in a spreadsheet.

We perform internal audits of management systems, compliance reviews and a documentation review that simulates the audit process. We do not perform ISO certification - by definition that is carried out by an accredited certification body, and whoever built a system may not certify it. The independent cybersecurity audit of essential entities under the Act is carried out by a provider holding the prescribed authorisation, and for state administration bodies by the competent authority.

What we perform ourselves, and what we do not

We do perform internal audits of management systems, compliance reviews against the Croatian Cybersecurity Act and data protection law, and a documentation review that simulates the audit process before an external auditor arrives. We also act as external DPO and external CISO.

We do not perform ISO certification - by definition that is carried out by an accredited certification body, and nobody who built a system may also certify it. That separation is not a formality but protection for you: what we tell you is ready is ready for someone who has no interest in it being so.

Get in touch

Need a compliance assessment, an ISO implementation, DORA or NIS2 preparation, or a demo of the GRC platform? Write to us - we reply within 24 hours.

Emailinfo@adventurespirit.hr