Beyond the entry products

Specialist services

The full capability map. These services are scoped individually — every engagement begins with a conversation and ends with a fixed written quote within 48 hours.

Regulatory & compliance advisory

DORA, NIS2, EU AI Act, Cyber Resilience Act, GDPR, MiCA. Gap assessments, remediation roadmaps, supplier-contract reviews, Register of Information preparation, third-party risk programmes, DPO-as-a-Service.

Certification & attestation readiness

ISO/IEC 27001, ISO/IEC 42001 and SOC 2 (Type I and Type II): control design, policy sets, evidence discipline and the gap work that happens before an auditor is engaged. The certification body or CPA firm stays independent — as it must.

Email & domain trust engineering

Why your mail and domain are distrusted — and the fix: authentication (SPF, DKIM, DMARC, MTA-STS, BIMI), deliverability recovery, blacklist removal, continuous monitoring, brand-impersonation and look-alike-domain defence.

Vendor due diligence & security questionnaires

The recurring tax on every SaaS company selling to regulated buyers. We answer the questionnaires, build the reusable evidence set, and turn a two-week scramble into a same-day response.

Cloud & product security

Secure-architecture and cloud-configuration review, secure development practices, and product-security readiness for software makers — down to the operational hygiene larger firms skip.

AI security & governance

Shadow-AI discovery, AI inventories and governance, ISO/IEC 42001 gap analysis, and risk reviews of AI agents and the systems that connect them.

Brand & trust engineering

Making legitimate businesses stop looking suspicious to the algorithms and people that judge them — anti-scam design review, executive digital-footprint hardening, dark-web exposure checks, recurring trust monitoring.

Fractional security leadership

Named, accountable security leadership in clear monthly tiers from €3,500/month — including the independent second-line oversight regulators expect, cleanly separated from those who build and run the systems.

Human risk & behavioural resilience

Psychology-informed programmes, security-culture assessments, board crisis exercises and executive resilience under regulatory pressure — framed as operational risk, never wellbeing.

Strategic incident management

Coordination, decision support and the 24-hour regulatory report when it matters most. Technical forensics and containment run through vetted, pre-agreed partners — we never promise a 24/7 capability we don't have.

Public sector — Bulgaria

NIS2 / ЗКС readiness for administrations and municipalities

Since February 2026, Bulgarian administrative bodies — including every municipality — are essential entities under the Cybersecurity Act, regardless of size. Since 1 June 2026, fines for management are personal.

  • Fixed-price readiness assessment mapped to the ЗКС, delivered in Bulgarian, priced for public budgets (from €3,900 / BGN equivalent).
  • Management-body training — the obligation the law places on leadership directly.
  • Incident-reporting readiness — the 24-hour and 72-hour workflows, rehearsed before they are needed.
  • Shared security leadership for clusters of neighbouring municipalities on a split retainer.
Where accreditation is required, we hand off — openly. ISO 27001 certification, SOC 2 attestation, threat-led testing under TIBER-EU, legal interpretation and statutory audits run through accredited partners we have vetted. You are never left stranded between advisers.
Book a scoping call