Skip to main content

Welcome to Kaizen Mentality LLC

About

I am an independent consultant with 20+ years in information security, helping organizations strengthen their security, manage ICT risks and navigate an increasingly complex regulatory environment.

My work focuses on the intersection of cybersecurity, ICT risk, governance and regulatory compliance, with particular expertise in DORA, NIS2, ISO/IEC 27001, ICT risk management and operational resilience.

I work primarily with financial institutions, regulated organizations and technology companies that need experienced, independent expertise to assess their current security posture, address regulatory requirements and build sustainable security practices.


What I do

Provide practical consulting services across the information security and ICT risk lifecycle, including:

  • DORA & Digital Operational Resilience – readiness assessments, gap analysis, ICT risk management, governance, incident management and resilience
  • Cybersecurity & ICT Risk Management – risk assessments, control frameworks, risk treatment and management reporting
  • ISO/IEC 27001 & ISMS – implementation, improvement, gap assessments, internal audit and certification readiness
  • NIS2 & Cybersecurity Compliance – regulatory assessments, governance and remediation planning
  • Third-Party & ICT Supplier Risk – security assessments, outsourcing and ICT service provider risk management
  • Business Continuity & Operational Resilience – BIA, continuity strategies, recovery planning and testing
  • Cybersecurity Governance & GRC – policies, procedures, roles, responsibilities, KPIs, KRIs and management reporting
  • Security Advisory & Fractional CISO Services – experienced security leadership and advisory support without the cost of a full-time executive function


Approach

I believe cybersecurity consulting should go beyond producing documentation for compliance purposes.

The approach is practical, risk-based and business-oriented, to translate regulatory and technical requirements into clear actions, appropriate controls and measurable improvements that organizations can actually implement and maintain.

Working closely with management, risk functions, IT teams, business owners and other stakeholders to ensure that security is integrated into the way an organization operates — rather than treated as a separate compliance exercise.


Independent expertise

As an independent consultant, the goal is to provide objective advice based on the organization's business objectives, risk profile and regulatory obligations.

I do not sell security products or promote a particular technology vendor. The role is to help the clients understand their risks, make informed decisions and establish security capabilities that are appropriate for their organization.

I combine extensive professional experience with internationally recognized certifications, including but not limited to CISSP, CISM, CISA and ISO/IEC 27001 Lead Auditor.


European perspective

Based in Croatia, I work with clients across the European Union and wider European market, providing remote and hybrid consulting services.

The experience in regulated environments, combined with a strong understanding of European cybersecurity and ICT regulations, enables to support organizations operating across different jurisdictions while maintaining a practical and business-focused approach.


The mission

The mission is simple:


To help organizations understand their cybersecurity risks, meet their regulatory obligations and build resilience they can rely on.


I believe effective cybersecurity is not about achieving perfect security. It is about understanding what matters, managing risk intelligently and continuously improving the organization's ability to prevent, withstand and recover from disruption.


Vladimir Josipovic, CISSP, CISM, CISA

Founder of Kaizen Mentality LLC



About Kaizen


Kaizen is a Japanese philosophy of continuous, incremental improvement meaning "good change."


• Small Daily Steps: 
Focus on getting just 1% better each day rather than seeking instant perfection.

• Process over Outcome: 

Build sustainable daily habits and systems instead of relying solely on massive, stressful life overhauls.

• Eliminate Waste: 

Remove non-value-adding habits, distractions, and inefficiencies from your work and daily routines.

• Embrace Mistakes: 

Treat errors and obstacles as normal learning opportunities rather than reasons to quit.

• Use Creativity First: 

Rely on imagination, resourcefulness, and existing resources before throwing money or complex tools at a problem.


The lowercase sigma (σ) in company's logo primarily symbolizes precision, quality control, data dispersion, and adherence to performance standards.


Contact 


Location: Zagreb, Croatia

E-mail: kaizen.mentality.doo@gmail.com

LinkedIn: https://www.linkedin.com/company/kaizen-mentality-llc