Cybersecurity · IT audit · GRC

Clarity wheresecurity, regulationand operations meet.

Euridica provides cybersecurity, IT audit and GRC services for regulated organizations across Southeast Europe. We assess risks and controls, with clear recommendations for remediation.

Assessment approach
01 Risk02 Evidence03 ControlsConclusion
Assessment conclusions supported by evidence and control testing.
Banja Luka · Southeast EuropeA clearer view of risk

Financial-sector experience. Independent assessments.

SWIFT CSP

Independent control assessments

Financial institutions

IT audit & cybersecurity experience

Southeast Europe

Cross-border project experience

Security should hold up under scrutiny.

A weakness in an IT system can disrupt a critical service or expose a gap in regulatory compliance. We assess the technical issue and its business impact together, so remediation priorities reflect the risk.

01

Cybersecurity & resilience

We test applications and infrastructure for exploitable weaknesses. Incident exercises and response playbooks help your team prepare for disruptions.

  • Penetration testing & application security
  • Vulnerability & cyber risk assessments
  • Incident exercises & response playbooks
Typical deliverables

Risk-ranked findings with remediation recommendations.

Discuss the scope
02

IT audit & assurance

We assess whether IT controls are properly designed and operating effectively. The scope can cover internal systems, technology projects and critical suppliers.

  • Internal IT audit & audit outsourcing
  • SWIFT CSP assessments
  • Third-party assurance & project audits
Typical deliverables

An assessment report with documented findings and a summary for management or the audit committee.

Discuss the scope
03

Governance, risk & compliance

We define how regulatory requirements apply to your organization and help implement the policies, controls and reporting they require.

  • ISO 27001 & information security governance
  • DORA, NIS2 & operational resilience advisory
  • IT risk management, data protection & business continuity
Typical deliverables

A gap assessment and implementation plan with assigned responsibilities.

Discuss the scope
04

Outsourced functions & ongoing support

We support internal teams through recurring IT audits and ongoing information security or data protection work. Responsibilities and reporting are agreed at the outset.

  • Outsourced information security function
  • Data protection officer support
  • Recurring IT audit & GRC support
Typical deliverables

An agreed work programme with scheduled reviews and reporting.

Discuss the scope

From risk to assurance.

Each engagement follows an agreed scope, with findings linked to evidence and remediation priorities. Reports distinguish what has been addressed from what remains unresolved.

Scope and deliverables are agreed for each engagement.

  1. Define the scope

    Identify critical systems, relevant obligations and dependencies on suppliers. Agree the assessment objectives and reporting requirements.

    A defined scope & risk context
  2. Assess

    Review documentation and test selected controls. Evaluate findings against the agreed criteria and their potential business impact.

    Evidence & risk-ranked findings
  3. Strengthen

    Agree remediation priorities, action owners and target dates. Define how corrective work will be reviewed.

    An actionable remediation plan
  4. Conclude

    Report conclusions and unresolved issues to the agreed audience, with evidence to support each finding.

    Documented conclusions & supporting evidence

Standards and regulation in practice.

We agree which requirements apply before defining the scope. The assessment considers your systems, supplier relationships and existing controls.

SWIFT CSP

Independent assessment against the applicable controls in the SWIFT Customer Security Controls Framework (CSCF).

Discuss the scope
DORA

Assess information and communication technology (ICT) risk and resilience against applicable requirements of the Digital Operational Resilience Act (DORA).

Discuss the scope
ISO 27001

Support implementation and review of an information security management system (ISMS) against ISO 27001.

Discuss the scope
NIS2

Identify gaps in cybersecurity governance and incident reporting against applicable NIS2 requirements and national legislation.

Discuss the scope
NIST CSF

Assess current cybersecurity practices using the NIST Cybersecurity Framework (CSF) and set improvement priorities.

Discuss the scope
COBIT

Review IT governance and management practices using COBIT objectives and guidance.

Discuss the scope
Southeast Europe
Map of Southeast Europe highlighting Bosnia and Herzegovina, Croatia, Serbia, Slovenia, Montenegro, Albania, North Macedonia and Kosovo as markets with project experience. A blue dot marks the head office in Banja Luka.
Head office in Banja Luka Countries where the team has worked

Experience in the region's financial institutions.

Based in Banja Luka, Euridica specializes in cybersecurity, IT audit and governance, risk management and compliance (GRC).

Our team's experience includes work with banks, payment institutions and central banks. We understand the evidence and reporting these institutions need for oversight and regulatory review.

Markets with project experience

Bosnia and Herzegovina · Croatia · Serbia · Slovenia · Montenegro · Albania · North Macedonia · Kosovo

Discuss your requirements

An assessment, an audit or a second opinion?

Tell us what you need to assess and any deadlines you are working towards. We can discuss the scope and the expertise required.

Banja Luka office Jevrejska 69a, 78000 Banja Luka
Bosnia and Herzegovina
LinkedIn