Information security has become a strategic question for every organisation. We turn information risk into an advantage through policies, contracts and procedures that work in practice.
Contact usBanks, insurers and payment institutions rely on us for ICT risk management, supplier and cloud contracts, incident reporting and audit readiness.



Four reasons companies bring their security compliance work to us.
We prepare you for the obligations under the new Serbian information security framework, aligned with NIS2 logic: redefined obliged entities, shorter deadlines and expanded supervisory powers.
We explain how European rules (NIS2) spill over into local obligations, what the difference between essential and important entities means, and how it affects supervision, reporting and penalties.
For finance we connect cyber obligations with the DORA regime, in force since 17 January 2025, including ICT risk management, incident reporting and third-party risk.
From gap analysis and policy to training, incident response playbooks and supplier contracts with cloud, SOC, MSSP and forensics providers.
Four sets of rules decide your status, your deadlines and what your documentation has to prove.
Priority and important operators, wider sectors, 24-hour incident reporting and higher fines under the Serbian framework.
The EU cyber security framework across 18 critical sectors: risk management, incident reporting, supervision and enforcement.
For finance: ICT risk management, incident reporting, resilience testing and oversight of critical ICT third parties.
Where an incident involves personal data, the 72-hour breach notification runs in parallel with the cyber filing.
From governance design and risk assessment to incident reporting, supplier contracts and training.
Four stages, from mapping your status to standing beside you in an incident.
We establish whether you are a priority or important operator, and which regimes reach you.
Risk assessment, policies, supplier contracts and records measured against the obligations.
Policies, playbooks, contracts and training put in place, with owners and deadlines.
Filings to the CERT and the Commissioner, and representation through inspections.
Our team works inside Whisperly, an AI-powered compliance platform built for banks. Legal advice and the software that carries it out sit in one place, so every vendor assessment is documented and audit-ready from day one.

Each vendor completes its questionnaire in a dedicated workspace, and the bank tracks progress live.
Vendor answers flow straight into the operational risk assessment and the supporting reports.
Prepare the notification and track approval status, including the 30-day tacit approval, with reminders on the 30 and 15-day deadlines.
Every questionnaire, response, revision and approval is time-stamped, ready for supervisory review, with board and audit materials generated in one click.
We set up your workspace, map your existing documentation and show you where the gaps are.
What companies ask us most often about information security.
It depends on the sector and the role. The draft law introduces priority and important operators of ICT systems of special importance, and the list of sectors is wider than before: water, postal services, information society services, qualified trust services, DNS and the domain registry among them. A formal mapping of status is needed, and that is where every project starts.
Shorter deadlines (24 hours for significant incidents), mandatory updates to the filing, and a more precise set of information. The draft also introduces reporting of serious threats, not only events. We recommend a single process that covers the GDPR and Serbian data protection obligations (72 hours) at the same time.
Yes. The National CERT is the operational point for reporting and coordination, with public forms and guidance. Its role includes early warning, advice and keeping records of incidents.
The new Serbian framework is designed to follow NIS2 logic, so you will see similar mechanisms: wider scope, risk management, incident reporting, supervision and penalties. That simplifies cooperation with EU partners and raises compatibility with cross-border delivery.
Yes. DORA has applied since 17 January 2025 and requires harmonised ICT risk processes, reporting, testing and strong contracts with ICT third parties, particularly cloud. If you are part of an EU group, the DORA standard becomes the mandatory baseline for contracts and policies.
Alongside the cyber filing, the GDPR and Serbian data protection regime applies with a 72-hour notification to the competent authority, and notice to individuals where the risk is high. That is why the incident response team and the DPO have to work together, and we set up a single decision and documentation flow.
Tell us what you run and who you serve, and we will map the status, the deadlines and the documents you need.
Contact usLegal developments in Serbia and the EU, each with the step it asks of your business.
Two emails a month. Unsubscribe any time.