Skip to content
GlabIT
GlabIT

Managed security · offensive testing · SOC monitoring

Security operations for European companies that cannot afford downtime.

GlabIT provides managed security, penetration testing and SOC monitoring — with round-the-clock coverage available under a contracted coverage model — for mid-market and enterprise organisations in Italy, Romania and the wider EU, delivered in English, Italian and Romanian by the engineers who do the work.

SERVICES: CAAS · SOC · IT AUDIT · PENTEST · RED TEAM · AI SECURITY · ENGINEERING · WEB APPS · AI PRODUCTS. DETECTION: MAPPED TO MITRE ATT&CK. TESTING: OWASP WSTG · PTES. COVERAGE: ROUND-THE-CLOCK MODEL AVAILABLE BY CONTRACT. READINESS: NIS2 · DORA · EU AI ACT. LANGUAGES: EN · IT · RO. SCOPE: AGREED IN WRITING BEFORE ANY WORK

Methodology

  • OWASP WSTG
  • PTES
  • MITRE ATT&CK
  • OWASP GenAI LLM Top 10
  • ISO/IEC 27001-aligned
  • NIS2 · DORA

We reference frameworks we actually work to. Certifications appear here only when held.

Services

Nine ways we work with you

Subscription security, evidence-based audits, point-in-time testing and continuous monitoring — plus the engineering to fix what we find and build what you need next. Delivered from Oradea for organisations across Romania and the EU, in Romanian and English.

01

Cybersecurity-as-a-Service

A fractional security team on subscription: vulnerability management, hardening, awareness training, vendor risk and an incident response retainer.

Read more
02

SOC & managed detection

Monitoring, detection, triage and response for your endpoints, cloud and identity, mapped to MITRE ATT&CK — round-the-clock coverage available under a contracted model.

Read more
03

IT audit

An evidence-based review of your IT environment, operations and controls — what is actually in place, whether it works, and a prioritised roadmap to fix what is not.

Read more
04

Penetration testing

Web, external and internal network and cloud testing to OWASP WSTG and PTES. Executive and technical reports, retest included.

Read more
05

Red team operations

Objective-based adversary simulation under strict rules of engagement. Tests whether your people and detections work, not just whether a vulnerability exists.

Read more
06

AI security

LLM application testing against the OWASP GenAI LLM Top 10, model and data-pipeline review, AI usage policy and EU AI Act readiness.

Read more
07

Secure engineering

Web and application development with security built in — secure development practices, code review and hardened hosting where in scope. Building software since 2008, online as glabit.com since 2016.

Read more
08

Web applications

Business-critical portals, internal platforms, e-commerce systems and APIs, built around your workflows — a written specification and acceptance criteria first, then reviewed iterations with the security checks agreed in scope.

Read more
09

AI product engineering

AI use cases validated before a big build: an evaluated prototype on your data first, then a production system with documented data flows, human oversight, cost monitoring and security controls.

Read more

NIS2 · DORA readiness

More companies may fall within NIS2's scope than expect to — and in Italy the clock is already running.

Whether NIS2 applies is a legal question that depends on your sector, your size (including linked enterprises), national implementation and a set of exceptions and special categories — not on a single headcount figure. Where it applies: Article 21 security measures, reporting of significant incidents, management accountability. In Italy, entities notified by ACN in April 2025 generally have to have the baseline measures in place around October 2026. We run a technical gap assessment against your regulator's framework (ACN in Italy, DNSC in Romania), hand you a remediation roadmap, and can support the ongoing technical measures through CaaS. Legal scope and compliance conclusions stay with you and your counsel.

Readiness work delivered in your language and your regulator's framework.

NIS2 timeline Four milestones from the directive entering into force in January 2023 to Italy's October 2026 deadline. JAN 2023 NIS2 (EU 2022/2555) enters into force OCT 2024 Member-state transposition deadline NOW Registration, gap assessment, Article 21 measures ~OCT 2026 Italy — baseline measures due for entities notified April 2025

How an engagement works

Assess, remediate, operate

Three stages, in this order. Engagements usually start with an assessment; some stop there, many continue.

  1. Assess

    Scope agreed in writing. We test, review and interview — pentest, configuration review, policy and process — and deliver findings ranked by business impact, with evidence.

  2. Remediate

    We fix or help fix: hardening, code changes, architecture, policies, training. Eligible remediated findings can be retested within the agreed scope and window — you see verification, not just a report.

  3. Operate

    Monitoring, vulnerability management and an incident retainer under CaaS or SOC, per the contracted coverage — with periodic reviews so the security posture keeps up with the business.

Why GlabIT

Three things that are actually different

Delivered in your language

Engineers who work in English, Italian and Romanian — reports, workshops and incident calls in the language your board and your regulator use, as agreed in the engagement. Not a translation layer.

Senior-led engagements

By default the engineers who scope your work are the engineers who do it — no handoff to a separate delivery team after the call, and you deal directly with the person holding the findings.

Engineering DNA

We have built and shipped software since 2008 and we break it for a living. Where the scope includes it, findings come with a fix — in code where needed — not only a PDF.

Next step

Book an assessment

A call with an engineer, not a salesperson. Tell us what you run and what keeps you up at night; we come back with a written scope and a proposal — fixed-price wherever the scope can be defined — with no obligation.

Headquarters

Glab IT Solutions SRL Tudor Vladimirescu 64, 410203 Oradea, Bihor, Romania