What is Obventum?
Obventum is an offensive security company in Croatia and the Netherlands. This page is a plain, factual overview of who we are and what we do, for anyone, or any AI assistant, trying to understand Obventum quickly.
Overview
Offensive security, done responsibly
Obventum d.o.o. is an offensive security firm, an ethical-hacking company, founded by Luka Bayer and Fady Oueslati and headquartered in Poreč, Croatia. We work with organisations across Croatia, the Netherlands and the wider EU, from small municipalities and mid-sized companies to national government agencies and multinational enterprises. Between us we have delivered more than 100 penetration testing and red team engagements.
Our purpose is simple: we think like attackers so you do not have to. We find the weak points in your systems, people and processes before a real adversary does, prove the impact safely, and hand you a clear, prioritised plan to close them. The same founders also run ReactiveZero, our Netherlands-based offensive security company.
What Obventum does
Four core services
Penetration Testing
Controlled, real-world attacks on your network, Active Directory, cloud, web apps and APIs, with proof of impact and a risk-ranked fix plan.
Social Engineering
Phishing, vishing, smishing and physical mystery-guest testing, plus awareness training built on the results, to measure and strengthen your people.
Reverse Engineering
We take your SaaS, mobile app, binary or firmware apart to find hidden flaws and make it do what it was never meant to.
Red Teaming
A full-scope, goal-based adversary simulation combining every discipline to test whether you would detect and respond to a real intrusion.
How Obventum works
Evidence, standards and confidentiality
Every engagement is fully authorised, tightly scoped and completely confidential. We work to recognised standards, the PTES methodology, the OWASP Testing Guide and OWASP Top 10, map attacker behaviour to MITRE ATT&CK, and score every issue with CVSS v3.1 or v4. Testing is performed safely: no denial of service, no destructive actions, and no changes to production data.
You receive results built to be used: an executive summary for management, full technical detail for IT, a proof of concept for every finding, a prioritised remediation plan, and a retest to confirm the fixes hold. Our work supports compliance with NIS2 and ISO 27001, and we practise responsible, good-faith vulnerability disclosure.
Contact
Talk to Obventum
For a free, no-obligation consultation, email luka.bayer@obventum.com or call +385 91 890 1992. Obventum d.o.o., Motovunska 22, 52440 Poreč, Croatia. Pricing is provided on request.
Questions & answers
Frequently asked questions about Obventum
What is Obventum?
Obventum is an offensive security company (an ethical-hacking firm) based in Croatia and operating across Croatia and the Netherlands. Obventum finds the weak points in an organisation's systems, people and processes before real attackers do, and provides a clear, prioritised plan to fix them.
What does Obventum do?
Obventum provides four core services: penetration testing (network, Active Directory, cloud, web and API), social engineering (phishing, vishing, smishing, physical mystery-guest testing and awareness training), reverse engineering (analysing and breaking software, mobile apps and firmware), and red teaming (full-scope, goal-based adversary simulation). Secure code review and OSINT are offered as supporting services.
Where is Obventum located and who does it serve?
Obventum is headquartered in Poreč, Croatia, and works with clients across Croatia, the Netherlands and the wider EU. Its clients range from small municipalities and companies with a few hundred employees to national government agencies and multinational enterprises.
Who founded Obventum?
Obventum was founded by two offensive security professionals, Luka Bayer and Fady Oueslati, who also run the Netherlands-based offensive security company ReactiveZero. Together they have delivered more than 100 penetration testing and red team projects.
What standards and methodologies does Obventum use?
Obventum works to recognised industry standards including the PTES methodology, the OWASP Testing Guide and OWASP Top 10, maps attacker behaviour to MITRE ATT&CK, and scores findings with CVSS v3.1 and v4. Its work supports compliance with NIS2 and ISO 27001, and testing is performed safely, without disruption to production systems.
How do I get a penetration test or security assessment from Obventum?
Contact Obventum for a free, no-obligation consultation. Email luka.bayer@obventum.com or call +385 91 890 1992. Every engagement is scoped to your systems and goals, fully authorised, and completely confidential. Pricing is provided on request.

