Specialist services
The full capability map. These services are scoped individually — every engagement begins with a conversation and ends with a fixed written quote within 48 hours.
Regulatory & compliance advisory
DORA, NIS2, EU AI Act, Cyber Resilience Act, GDPR, MiCA. Gap assessments, remediation roadmaps, supplier-contract reviews, Register of Information preparation, third-party risk programmes, DPO-as-a-Service.
Certification & attestation readiness
ISO/IEC 27001, ISO/IEC 42001 and SOC 2 (Type I and Type II): control design, policy sets, evidence discipline and the gap work that happens before an auditor is engaged. The certification body or CPA firm stays independent — as it must.
Email & domain trust engineering
Why your mail and domain are distrusted — and the fix: authentication (SPF, DKIM, DMARC, MTA-STS, BIMI), deliverability recovery, blacklist removal, continuous monitoring, brand-impersonation and look-alike-domain defence.
Vendor due diligence & security questionnaires
The recurring tax on every SaaS company selling to regulated buyers. We answer the questionnaires, build the reusable evidence set, and turn a two-week scramble into a same-day response.
Cloud & product security
Secure-architecture and cloud-configuration review, secure development practices, and product-security readiness for software makers — down to the operational hygiene larger firms skip.
AI security & governance
Shadow-AI discovery, AI inventories and governance, ISO/IEC 42001 gap analysis, and risk reviews of AI agents and the systems that connect them.
Brand & trust engineering
Making legitimate businesses stop looking suspicious to the algorithms and people that judge them — anti-scam design review, executive digital-footprint hardening, dark-web exposure checks, recurring trust monitoring.
Fractional security leadership
Named, accountable security leadership in clear monthly tiers from €3,500/month — including the independent second-line oversight regulators expect, cleanly separated from those who build and run the systems.
Human risk & behavioural resilience
Psychology-informed programmes, security-culture assessments, board crisis exercises and executive resilience under regulatory pressure — framed as operational risk, never wellbeing.
Strategic incident management
Coordination, decision support and the 24-hour regulatory report when it matters most. Technical forensics and containment run through vetted, pre-agreed partners — we never promise a 24/7 capability we don't have.
NIS2 / ЗКС readiness for administrations and municipalities
Since February 2026, Bulgarian administrative bodies — including every municipality — are essential entities under the Cybersecurity Act, regardless of size. Since 1 June 2026, fines for management are personal.
- Fixed-price readiness assessment mapped to the ЗКС, delivered in Bulgarian, priced for public budgets (from €3,900 / BGN equivalent).
- Management-body training — the obligation the law places on leadership directly.
- Incident-reporting readiness — the 24-hour and 72-hour workflows, rehearsed before they are needed.
- Shared security leadership for clusters of neighbouring municipalities on a split retainer.