IT Advisory and Risk

IT Advisory

We support our clients by providing services that help them navigate through the digital complexity to make better, faster and more confident decisions.

IT Advisory can enable you to fulfill established business strategy goals                          

The future is Now, concept by Crowe!

Your business is constantly facing challenges in managing new and persistent risks, while balancing revenue growth and expense saving business priorities. In order to make your day easier and let you focus on doing your business and achieving growth, Crowe IT Advisory team will evaluate all IT aspects of your business processes and assist you in implementing necessary changes making you comply with legislative requirements, standards and best practices.

Increase process optimization

Most common risk to one company’s increase of profitability is lack of process performance optimization. Resources, are scattered and time is lost but doing things inefficiently. Crowe IT Advisory will assist you in process optimization, enabling you to achieve maximum from your available resources by performing evaluation of your business processes and suggesting necessary improvements.



Learn more about IT Advisory in Serbia:

  • IT Risk management
  • Cyber Security
  • IT Project management
  • Business continuity management

View Brochure

Application development
Advisory services in development of SDLC methodology and process. Assessment of a design and implementation of in-house software development life cycle, coding and application security standards, a level of documentation support and source code maintenance. 
Administration of secondary IT systems

Advisory services ensuring that the design and configuration of supporting IT systems (antivirus, email, proxy, web servers) provides the agreed-to performance and security and responsible administrators have required competences. Assistance in implementation of endpoint security solutions. 

Business continuity management
Business Continuity and Disaster Recovery process implementation and review. Business impact assessments and advisory in evaluation of key business processes. Assessment of the governance process aimed on identification of potential threats to a company, minimizing an impact on the business operations and a framework for building organizational resilience with the capability for an effective recovery of operations. Appraisal of adequacy of backup approach and disaster recovery activities and tests is performed as well.
Cyber security
Advisory services in performing of Cybersecurity assessments including FFIEC approach for financial institutions, audits and penetration testing. 
Database administration
Assessment and advisory services in process improvement of a database (DB) management processes, DBs security configuration, protective measures, systems performance and availability. Assessment of staff competences, adequacy of the DMBS systems configuration and an appropriate change management process, especially for emergency changes and design and maintenance of access permissions, especially for privileged accounts in production DBs.
Governance and organization of it functions

Overall assessment of the organization's IT department and its divisions. Analysis of the quality of design and implementation of key IT processes and their monitoring by IT managers. Assessment to include key governance areas:

  •  Planning and budgeting of department’s activities.
  •  Procurement of IT resources and assets.
  •  Staff management.
  •  Quality of reporting to the Management of institution.

 Advisory services in establishing all lacking processes.

Incident and problem management
Implementataion and evaluation of incident management process, including recovery of services / functionality after downtimes, minimization of their impact on the main business and design of preventive measures. Advisory services covering discovery and treatment of problems based on the assessment of incidents.
Information security
Implementation of ISMS 27001 based methodology and development of policies. Examination of adequacy, scaled to particular company’s needs, and quality of an Information Security Management System in each and every of its form (physical, technical, organizational security). Advisory and verification of the process approach for information security. Information security Risk Assessment process implementation and review.
IT audit services and regulatory compliance

Performing of IT audit services along with review of regulatory compliance related to Information security law reporting, GDPR gap assessments and related reporting. 

The IT Audit Department works on identifying and eliminating deficiencies in the organization, functioning and management of information systems, as well as resource optimization.

Our approach in conducting the implementation review is designed to improve security, functionality and efficiency.

We help companies in achieving their goals by focusing on IT processes, people, technology, reporting, organization, data and documentation.

Our services include, but are not limited to:

  • Internal and external audit of information systems
  • IT Due Diligence
  • IT risk management
  • Vulnerability assessment of the information system,
  • Assistance with compliance with IT regulations.
  • Software Asset Management (SAM) and License review
  • Reduction of IT costs because they represent a significant part of the total costs of the organization
  • Testing disaster recovery procedures

The services we provide in the field of audit of IT projects and information technology systems help clients to achieve the full value of their strategic technology initiatives and increase satisfaction with established IT solutions, through effective risk management. 

More information about service 



IT project management
Appraisal of how IT related projects are initiated, planned, executed, monitored and closed. Assessment of portfolio management quality and a detailed review of the implementation of IT projects. Providing of IT project management services and process implementation.
IT risk management
Advisory services in IT risk management are covering IT risk assessments and self assessment process. Insight in how IT related risks are identified, estimated, evaluated and treated both periodically, operationally and during execution of IT projects. Advice on how Risk Event Database maintenance and filling is performed.
Maintenance of core business applications

Appraisal of key aspects, related to maintenance and support of core business applications that directly process financial transactions. Development and appraisal of key aspects, elated to maintenance and support of business applications that do not directly process financial transactions. Specific attention is paid to:

  •  Configuration and performance of applications.
  •  Capacity planning and physical infrastructure.
  •  Existing security controls, including user access and roles management, logging and monitoring, “4 eyes principle”, etc.
  •  Application backups, redundancy solutions and recovery procedures.
  •  Integrity of batch processing: appraisal of various interfaces between systems, batch file processing, direct changes via DB interface.
Microsoft SSPA

Annual SSPA control services 

View Brochure 

Network administration
Advisory services aimed at review and improvement of how a company manages its network and identifies, corrects and prevents vulnerabilities in its design. Assessment of staff competences, adequacy of configuration of network systems and a change management process. Advisory services in network security area covering firewalls, IPS/ IDS and other network devices configurations and vulnerability assessments.
Processing card management and ATMs
Applicable for card issuers and banks. Appraisal of existing protection of cardholder data, security of the network in which data circulates, available access control and monitoring measures and controls. Assessment and assistance in implementation of processes of physical handling of cards, key management and equipment maintenance. Physical and logical protection of ATM and POS terminals. Implementation and review of ATM security methodology.
User support and service desk
Assessment and advisory in process of how IT handles and manages requests from users, how the problems are tracked, communicated and resolved at both primary and secondary levels of support. Quality of the support as well as reporting of key problems to the Management.

Annual SWIFT CSP control services 

View Brochure 

Contact us

We provide the expertise you need to grow, control, defend, and, if necessary, restructure your assets. Contact Crowe today.
Djordje Dimic
Partner / Audit and Advisory
Crowe RS Advisory d.o.o.
Milan Stevovic
Director / IT Advisory and Audit
Crowe RS Advisory d.o.o.