Obventum, offensive security from Poreč, Croatia

We find the way in before a real attacker does.

An ethical hacking company working across Croatia, the Netherlands and the EU. Under written authorisation we attack your systems as a real intruder would. We prove what we reached and hand you a ranked plan to fix it.

Free intro call. No obligation. Pricing on request.

Diagram: an attack path from the internet to the domain controller is found, proven, closed and retested.

Illustration: a typical attack path we find, prove, close and retest.

How we work

Written rules, known standards, six phases

Six phases on every engagement, following public standards, under safety rules we put in writing.

  1. 01

    Kick-off

    Scope, rules of engagement, testing windows and written authorisation.

  2. 02

    Discovery and scanning

    Systems, services and versions mapped: your real attack surface.

  3. 03

    Testing and exploitation

    We prove what an attacker could reach and how far they could spread, without causing damage.

  4. 04

    Reporting

    Findings ranked by risk, each with evidence and a remediation step.

  5. 05

    Debrief workshop

    A walkthrough of the findings with your team.

  6. 06

    Retest

    We confirm the key findings are actually closed.

PTESOWASP Testing Guide and Top 10MITRE ATT&CKCVSS v3.1 / v4Supports NIS2 and ISO 27001

In writing

What we promise, and what you receive

Safety rules

  • No denial of service, no destructive actions, no changes to production data
  • Agreed scope and testing windows
  • A direct channel to the tester
  • Critical findings reported the moment they are confirmed

Deliverables

  • Executive summary for management
  • Technical findings ranked by risk with CVSS
  • Evidence and proof of concept for every finding
  • Prioritised remediation plan
  • Debrief workshop
  • Retest of key findings

Who we are

Two founders who scope the work, do the testing and write the report

Luka Bayer and Fady Oueslati have been taking systems apart since they were kids, from hacking to infrastructure, and both turned it into a profession. Through Obventum and its sister company ReactiveZero, their clients range from small municipalities and companies with a few hundred employees to national government agencies and multinational enterprises, across Croatia and the Netherlands.

No sales layer, no handover: the founder on your intro call is the one inside your network.

Luka Bayer, Founder and Ethical Hacker at Obventum

Luka Bayer

Founder and Ethical Hacker

Leads client projects, from external network tests to full-scale intrusions. Writes reports engineers and executives can both act on.

LinkedIn
Fady Oueslati, Co-founder and Ethical Hacker at Obventum

Fady Oueslati

Co-founder and Ethical Hacker

OSCP (hands-on exploitation) and CHFI (digital forensics) certified. Web application, API and infrastructure testing. Finds the business logic flaws automated tools miss and hands developers the fix.

LinkedIn

From the blog

Guides on AI testing, NIS2 and ransomware

Practical reading for EU companies on the threats we test against.

Sister company

Obventum, ReactiveZero and an AI pentesting platform in beta

ReactiveZero is our sister company in the Netherlands, run by the same two founders. Same people, same method.

Together we run four NVIDIA DGX systems in our own environment, training a local offensive security model for an AI-assisted penetration testing platform, now in beta. A human tester validates every result, and data never leaves hardware we control.

Free intro call, no obligation

Tell us what you run. We will tell you how we would test it.

A short call with one of the founders to agree scope, then a quote for that scope. You talk to the tester, not a sales team.

Book a free intro call

luka.bayer@obventum.com / +385 91 890 1992