
UAB Osama is a distribution company in the Baltic states’ FMCG (fast-moving consumer goods) sector that has been operating for nearly 30 years, with branches in Lithuania, Latvia, and Estonia. The company serves manufacturers, retailers, and the HoReCa sector, and also provides coffee and vending machine solutions. It represents brands such as Tymbark, Nestea, Kubuš, and Calvo. In 2025, its revenue reached approximately 60 million euros; the company employs about 120 people, and its products are supplied to more than 3,000 customers and 8,000 points of sale.
The organisation views cybersecurity as a vital component of long-term growth and competitiveness, which is why it focuses on the security aspects of AI integration, the management of third-party access and associated risks, and future technological challenges. Osama strives to constantly move forward and be at least 1% better, and views investments in cybersecurity as an investment in business continuity, reliability, and preparedness for the future.

Responsibility is in the company’s DNA, which is why it views obligations such as the renewed Republic of Lithuania’s Cyber Security Law not only as a requirement but also as an opportunity to strengthen our organization’s resilience and reputation.
We spoke with Edita Virvičienė, the organisation’s Executive Director, about why cyber resilience and its strengthening are important to Osama, why they chose to use CISO services from external providers, and why they specifically chose to partner with NRD Cyber Security.
For a long time, we had IT maintenance service providers who also handled cybersecurity. Both the measures and the needs were fairly simple, so everything worked well. As the business grew, management began to wonder whether we had all the answers, whether our current focus was sufficient, and whether we understood and managed the risks. We reviewed many areas, including IT. Since the scale and nature of cybersecurity attacks have changed as they’ve become more precise and coordinated, the answers and results we received were not encouraging and prompted us to take action. Undoubtedly, the update to the Lithuania’s Cybersecurity Law was also a significant catalyst. Since accountability is one of the core principles guiding Osama’s work, we view laws not merely as a matter of “ticking boxes”, but as an opportunity to understand how these obligations can help develop the organisation and its reputation. The law prompted us to think of ourselves as a reliable supplier, to review the associated risks, to ask questions, and to consider our reputation from a slightly different perspective.
The need for a CISO in the organisation arose from a legal requirement to designate a person responsible for cybersecurity and to help the organisation implement and oversee the described controls. That was the initial expectation – to help us “comply” with the law. However, once we understood how to manage risks, we began to view the CISO as a strategic partner who helps assess risks and consider solutions. A common format for these discussions is a three-way conversation: the IT administrator, the CISO, and me. This helps me, as a manager, not only to hear the facts, problems, and potential solutions, but also to understand the associated risks. And this is very important because, at the end of the day, the decision, and the responsibility for it, is mine.
I also see a consistent shift in education – we regularly conduct cybersecurity hygiene training and are building people’s competence in the area of cyber resilience.
No, we didn’t consider the in-house option – it seemed difficult and expensive to find a truly qualified specialist, and we have neither the resources nor the capacity to train and develop one. That’s why we decided to look for external services fairly quickly. We wanted quality and expertise, and we needed someone who truly understood the field and would “take ownership” of the responsibility.
We did not want the same organisation that provides our IT maintenance services to also fulfil the CISO role, since one of the CISO’s responsibilities is to assess IT-related risks. It can be very difficult to do this objectively when it relates to one’s own job. We wanted independent expertise and an analysis of our situation – where we stand and what solutions are needed. When selecting vendors, we paid close attention to reliability as we didn’t want a company that had just been established and whose operating principles were unclear. We also looked at their experience and current client base – what works for the public sector may not necessarily work for us, so we sought out an organisation with business clients. And, of course, an important aspect was the scope of the proposal since we wanted not only the “paperwork” to be in order, but also the technological issues to be resolved.
We had already heard of NRD Cyber Security and had discussed cybersecurity training with them. We knew that the company could offer not only a wide range of cybersecurity services, but also a multifaceted approach and expertise. When discussing CISO services with the organisation’s specialists, we were convinced of both their expertise in the field of cybersecurity and their in-depth understanding of the updated cybersecurity law. I was particularly impressed by the fact that the NRD Cyber Security team approached our cybersecurity needs from the perspective of the risks we face. Although we received many proposals from other potential vendors, the solutions they offered were unfounded; they were simply trying to sell us everything just to comply with the law.
The CISO should be a key partner who understands business risks and advises us on the nuances of cybersecurity that are relevant to us. We expect this role, especially when “filling” it by purchasing services from an external provider, to bring experience and expertise. Since we deliberately chose a company that has been in business for a long time, we expect that a larger team will be indirectly involved in providing the services – a team with whom we can consult, whether with other CISOs or with other departments. So, although the CISO we’re actively working with – and whom I can call for advice—is currently a single person, our partnership is with the company as a whole. We really feel this through the additional advice and insights we receive. For example, we recently had questions regarding power plant audits, which fall outside the typical scope of a CISO’s responsibilities, but the broader NRD Cyber Security team helped us resolve them.
As for our future expectations, they revolve around growth: both our own and that of the digital environment in which we operate. Technological systems will continue to advance, so questions arise regarding AI integration from a security perspective – what and how we should assess, what third-party access should look like, what the associated risks are, and what matters most. We work with large enterprises subject to various regulations, so all these aspects have (or will have) a significant impact on reputation. We also set a goal for ourselves to be 1% better, to keep moving forward, and to be forward-thinking. It’s important for us to understand what the market will look like in the future and how we’ll meet those needs, remain competitive, and what impact investments in cybersecurity will have on that.