Protectiva — Managed security & NIS2/ZKS compliance in Bulgaria
Managed security & integration · Sofia

Hardened infrastructure. Compliance you can evidence.

Managed detection and NIS2/ZKS readiness for Bulgarian municipalities and companies — one team from the first gap review to the quarterly board report.

ISO 27001 certified practice · Sofia SOC, round the clock · Documentation built for ZOP
Compliance posture MUNICIPALITY OF · Q3 2026
AUDIT-READY
NIS2 · risk management measures92%
ISO/IEC 27001 · Annex A controls78%
ZKS · 24-hour early warning drill PASSED · 00:41
Immutable backup verification 14 MIN AGO
NEXT EXTERNAL AUDIT · 12 NOV 2026
24/7 Monitored estate
6,412Assets monitored 14Open findings 11 minMean containment
NIS2 Art. 21 · control coverage 78%
Implemented In progress Gap
93 CONTROLS ASSESSED · LAST REVIEW 12.09.2026
14:22 elapsed since detection 24 H WINDOW
Early warning · national CERTFILED Incident notificationIN PREPARATION Final reportSCHEDULED
Technology we deploy and operate
PALO ALTO NETWORKS MICROSOFT SENTINELONE NETWRIX TENABLE FORTINET VEEAM
Regulatory clock

The deadlines start at detection

NIS2 and the Bulgarian Cybersecurity Act fix the reporting deadlines. Missing one is a finding in its own right, separate from the incident behind it.

Early warning 24 h To the national CERT An initial signal is due within a day of becoming aware — long before the full scope is known.
Notification 72 h Assessment and indicators Severity, impact and indicators of compromise, updating whatever the early warning said.
Final report 1 month Cause and measures taken A full account of the incident, its root cause and the mitigation you put in place.
Exposure €10M Or 2% of global turnover The ceiling on administrative fines for essential entities — whichever figure is higher.
Why Protectiva

Signed for by name, not delegated to IT.

Under the Bulgarian Cybersecurity Act and NIS2 the management body approves the security measures — and the signature that approves them carries the penalty.

The scope widened

Hundreds of municipalities, utilities and their suppliers fall inside NIS2 and the 2026 ZKS rules for the first time. Many find out when the inspector arrives.

The signature carries weight

Management bodies approve the measures, sign off the reports and answer for the fines. What protects them is documented evidence, not good intentions.

Engineering and procedure, one team

Architecture on one side, procurement files and inspection practice on the other. You are never left translating between two suppliers.

Core services

Assess, build, run, restore

All services & packages →
01

Compliance & risk governance

Readiness assessments against NIS2, ZKS and DORA, with the risk register, policy set and evidence file that go with them.

Readiness review · Risk register · Evidence file
02

Managed detection & response

A Sofia SOC watching your estate around the clock, with endpoint response, log retention and incident handling included.

SOC · EDR · Log retention · Triage
03

Infrastructure & integration

Firewall estates, identity and segmentation designed, deployed and documented by the engineers who then operate them.

NGFW · Identity · Segmentation · PAM
04

Continuity & recovery

Backups that cannot be altered, recovery plans with agreed targets, and restore tests that are actually carried out.

Immutable copies · Recovery plan · Restore drills
Who we work with

Two kinds of pressure. The same delivery team.

For public administration

Municipalities, agencies and public operators

Deadlines arrive with an inspection date and a procurement procedure attached. We deliver the working system and the file that survives the review.

  • ZKS programmes and support for the officer you appoint
  • Technical specifications that stand up in a ZOP procedure
  • Continuity for the e-services and registers citizens use
  • A reporting workflow to the national CERT, rehearsed before it is needed
  • Awareness training written for administrative staff
Ask for the public sector outline
For private enterprise

Mid-sized companies and their suppliers

You are in scope directly, or because a customer wrote it into the contract. We build the controls and then run them, so you do not have to staff a night shift.

  • Scoping: essential entity, important entity, or out of scope
  • Security questionnaires answered with evidence that already exists
  • Round-the-clock detection without hiring a team
  • Documentation for cyber insurance and bank due diligence
  • Quarterly reporting the board can actually read
Arrange an intro call
How we work

Four stages, each ending in something you can hand over

No stage closes on a verbal update. Each one ends in a document you can put in front of an inspector or your own board.

01

Map the estate

What you run, where the data goes, and which regime covers which part of it.

→ Scope & asset register
02

Test the controls

Controls checked against the baseline, technical findings verified by hand, risk rated by what it would actually cost you.

→ Findings report · Risk register
03

Close the gaps

Fixes delivered in priority order by our own engineers — firewalls, identity, segmentation, backup and the policies behind them.

→ Implementation log
04

Run and evidence

Continuous monitoring, quarterly posture reviews and the paper trail a supervisory authority will ask to see.

→ Evidence pack · Board summary
NIS2, ZKS, DORA and ISO/IEC 27001 overlap, but they are not interchangeable — each carries its own controls and its own reporting duties. Compare the frameworks →
The advantage

Engineering depth, procurement fluency.

Our architects come from systems engineering; our compliance leads come from the inspection and procurement side. That is why the technical result and the documentation arrive together, instead of one chasing the other.

140+ Audits and integrations delivered
<15 min To first response on a critical alert
24 h The reporting window we work to
About the team →
Image placeholder · engineers at the SOC console, wide crop
Selected engagements

Engagements that survived the review

All case studies →
Image · municipal data centre
Regional municipality · 24 sites

No documentation to inspection-ready in eleven weeks

A complete asset register, a segmented network, the appointed-officer framework in place and a reporting drill closed in 41 minutes.

Image · water utility SCADA room
Water utility · important entity

Splitting OT from IT without stopping the plant

Segmentation across the SCADA estate, brokered privileged access and continuous monitoring on 1,400 endpoints.

Image · trading floor / finance
Financial services · DORA

A third-party ICT register, accepted first time

Provider mapping, exit strategies and a resilience testing scope the group risk committee approved without a second round.

“The inspectors wanted documents, not explanations. Every document they asked for was already written and already signed.”
Secretary, district municipality · Southern Bulgaria
“The argument about products ended and the findings started closing. What took days to spot now takes minutes, and the quarterly report is short enough that the board reads it.”
IT Director, manufacturing group · 600 employees
Threat bulletins

What our analysts raised this month

All bulletins →
CRITICAL04.09.2026 WordPress core RCE chain, no login required — municipal sites exposed HIGH27.08.2026 Credential replay at scale against internet-facing firewall VPN portals REGULATORY19.08.2026 ZKS secondary rules: the incident classification changes landing this quarter
Incident response

Could you file an early warning inside 24 hours?

We run the reporting clock with you — early warning, notification, final report — so a technical incident does not become an administrative one.

PDF · 14 pages · Early warning → notification → final report