CISO services for a distribution company Osama

Icon

UAB Osama is a distribution company in the Baltic states’ FMCG (fast-moving consumer goods) sector that has been operating for nearly 30 years, with branches in Lithuania, Latvia, and Estonia. The company serves manufacturers, retailers, and the HoReCa sector, and also provides coffee and vending machine solutions. It represents brands such as Tymbark, Nestea, Kubuš, and Calvo. In 2025, its revenue reached approximately 60 million euros; the company employs about 120 people, and its products are supplied to more than 3,000 customers and 8,000 points of sale.

The organisation views cybersecurity as a vital component of long-term growth and competitiveness, which is why it focuses on the security aspects of AI integration, the management of third-party access and associated risks, and future technological challenges. Osama strives to constantly move forward and be at least 1% better, and views investments in cybersecurity as an investment in business continuity, reliability, and preparedness for the future.

Responsibility is in the company’s DNA, which is why it views obligations such as the renewed Republic of Lithuania’s Cyber Security Law not only as a requirement but also as an opportunity to strengthen our organization’s resilience and reputation.

We spoke with Edita Virvičienė, the organisation’s Executive Director, about why cyber resilience and its strengthening are important to Osama, why they chose to use CISO services from external providers, and why they specifically chose to partner with NRD Cyber Security.

CISO as a strategic partner

1. Osama will soon celebrate its 30th anniversary; the organisation has grown and evolved a lot over this period. Can you tell us how your focus on cybersecurity has changed as the business has expanded?

For a long time, we had IT maintenance service providers who also handled cybersecurity. Both the measures and the needs were fairly simple, so everything worked well. As the business grew, management began to wonder whether we had all the answers, whether our current focus was sufficient, and whether we understood and managed the risks. We reviewed many areas, including IT. Since the scale and nature of cybersecurity attacks have changed as they’ve become more precise and coordinated, the answers and results we received were not encouraging and prompted us to take action. Undoubtedly, the update to the Lithuania’s Cybersecurity Law was also a significant catalyst. Since accountability is one of the core principles guiding Osama’s work, we view laws not merely as a matter of “ticking boxes”, but as an opportunity to understand how these obligations can help develop the organisation and its reputation. The law prompted us to think of ourselves as a reliable supplier, to review the associated risks, to ask questions, and to consider our reputation from a slightly different perspective.

2. What value do you see in the CISO role in general? What role does this position play in your organisation?

The need for a CISO in the organisation arose from a legal requirement to designate a person responsible for cybersecurity and to help the organisation implement and oversee the described controls. That was the initial expectation – to help us “comply” with the law. However, once we understood how to manage risks, we began to view the CISO as a strategic partner who helps assess risks and consider solutions. A common format for these discussions is a three-way conversation: the IT administrator, the CISO, and me. This helps me, as a manager, not only to hear the facts, problems, and potential solutions, but also to understand the associated risks. And this is very important because, at the end of the day, the decision, and the responsibility for it, is mine.

I also see a consistent shift in education – we regularly conduct cybersecurity hygiene training and are building people’s competence in the area of cyber resilience.

3. What led you to choose external CISO services? Didn’t you consider filling this role internally?

No, we didn’t consider the in-house option – it seemed difficult and expensive to find a truly qualified specialist, and we have neither the resources nor the capacity to train and develop one. That’s why we decided to look for external services fairly quickly. We wanted quality and expertise, and we needed someone who truly understood the field and would “take ownership” of the responsibility.

4. Following the updates to the Republic of Lithuania’s Cyber Security Law, a truly abundant supply of CISO services has emerged on the market. What was your selection process like? What criteria were particularly important in your decision?

We did not want the same organisation that provides our IT maintenance services to also fulfil the CISO role, since one of the CISO’s responsibilities is to assess IT-related risks. It can be very difficult to do this objectively when it relates to one’s own job. We wanted independent expertise and an analysis of our situation – where we stand and what solutions are needed. When selecting vendors, we paid close attention to reliability as we didn’t want a company that had just been established and whose operating principles were unclear. We also looked at their experience and current client base – what works for the public sector may not necessarily work for us, so we sought out an organisation with business clients. And, of course, an important aspect was the scope of the proposal since we wanted not only the “paperwork” to be in order, but also the technological issues to be resolved.

We had already heard of NRD Cyber Security and had discussed cybersecurity training with them. We knew that the company could offer not only a wide range of cybersecurity services, but also a multifaceted approach and expertise. When discussing CISO services with the organisation’s specialists, we were convinced of both their expertise in the field of cybersecurity and their in-depth understanding of the updated cybersecurity law. I was particularly impressed by the fact that the NRD Cyber Security team approached our cybersecurity needs from the perspective of the risks we face. Although we received many proposals from other potential vendors, the solutions they offered were unfounded; they were simply trying to sell us everything just to comply with the law.

5. What are your expectations, and what requirements do you set for an external CISO?

The CISO should be a key partner who understands business risks and advises us on the nuances of cybersecurity that are relevant to us. We expect this role, especially when “filling” it by purchasing services from an external provider, to bring experience and expertise. Since we deliberately chose a company that has been in business for a long time, we expect that a larger team will be indirectly involved in providing the services – a team with whom we can consult, whether with other CISOs or with other departments. So, although the CISO we’re actively working with – and whom I can call for advice—is currently a single person, our partnership is with the company as a whole. We really feel this through the additional advice and insights we receive. For example, we recently had questions regarding power plant audits, which fall outside the typical scope of a CISO’s responsibilities, but the broader NRD Cyber Security team helped us resolve them.

As for our future expectations, they revolve around growth: both our own and that of the digital environment in which we operate. Technological systems will continue to advance, so questions arise regarding AI integration from a security perspective – what and how we should assess, what third-party access should look like, what the associated risks are, and what matters most. We work with large enterprises subject to various regulations, so all these aspects have (or will have) a significant impact on reputation. We also set a goal for ourselves to be 1% better, to keep moving forward, and to be forward-thinking. It’s important for us to understand what the market will look like in the future and how we’ll meet those needs, remain competitive, and what impact investments in cybersecurity will have on that.

Other stories

A growing business and increasing regulatory demands: Softera chooses NRD Cyber Security's SOC services
A growing business and increasing regulatory demands: Softera chooses NRD Cyber Security's SOC services
CISO services to confectionery manufacturer "Vilniaus pergalė"
CISO services to confectionery manufacturer "Vilniaus pergalė"
Lemona Electronics strengthens the cyber resilience of its e-commerce electronics business through a partnership with NRD Cyber Security
Lemona Electronics strengthens the cyber resilience of its e-commerce electronics business through a partnership with NRD Cyber Security
National Health Insurance Fund (VLK) is working with NRD Cyber Security to strengthen its cyber resilience
National Health Insurance Fund (VLK) is working with NRD Cyber Security to strengthen its cyber resilience
Artea Bank enlisted the help of NRD Cyber Security to monitor cyber threats 24/7
Artea Bank enlisted the help of NRD Cyber Security to monitor cyber threats 24/7
Staticus enlisted the services of NRD Cyber Security for its Security Operations Centre (SOC)
Staticus enlisted the services of NRD Cyber Security for its Security Operations Centre (SOC)
The Acme Group sets high standards for cyber resilience and begins cooperation with NRD Cyber Security
The Acme Group sets high standards for cyber resilience and begins cooperation with NRD Cyber Security
Teltonika strengthens its competitive edge with a firm focus on cybersecurity through partnership with NRD Cyber Security
Teltonika strengthens its competitive edge with a firm focus on cybersecurity through partnership with NRD Cyber Security