Managed detection and NIS2/ZKS readiness for Bulgarian municipalities and companies — one team from the first gap review to the quarterly board report.
NIS2 and the Bulgarian Cybersecurity Act fix the reporting deadlines. Missing one is a finding in its own right, separate from the incident behind it.
Under the Bulgarian Cybersecurity Act and NIS2 the management body approves the security measures — and the signature that approves them carries the penalty.
Hundreds of municipalities, utilities and their suppliers fall inside NIS2 and the 2026 ZKS rules for the first time. Many find out when the inspector arrives.
Management bodies approve the measures, sign off the reports and answer for the fines. What protects them is documented evidence, not good intentions.
Architecture on one side, procurement files and inspection practice on the other. You are never left translating between two suppliers.
Readiness assessments against NIS2, ZKS and DORA, with the risk register, policy set and evidence file that go with them.
Readiness review · Risk register · Evidence file 02A Sofia SOC watching your estate around the clock, with endpoint response, log retention and incident handling included.
SOC · EDR · Log retention · Triage 03Firewall estates, identity and segmentation designed, deployed and documented by the engineers who then operate them.
NGFW · Identity · Segmentation · PAM 04Backups that cannot be altered, recovery plans with agreed targets, and restore tests that are actually carried out.
Immutable copies · Recovery plan · Restore drillsDeadlines arrive with an inspection date and a procurement procedure attached. We deliver the working system and the file that survives the review.
You are in scope directly, or because a customer wrote it into the contract. We build the controls and then run them, so you do not have to staff a night shift.
No stage closes on a verbal update. Each one ends in a document you can put in front of an inspector or your own board.
What you run, where the data goes, and which regime covers which part of it.
→ Scope & asset registerControls checked against the baseline, technical findings verified by hand, risk rated by what it would actually cost you.
→ Findings report · Risk registerFixes delivered in priority order by our own engineers — firewalls, identity, segmentation, backup and the policies behind them.
→ Implementation logContinuous monitoring, quarterly posture reviews and the paper trail a supervisory authority will ask to see.
→ Evidence pack · Board summaryOur architects come from systems engineering; our compliance leads come from the inspection and procurement side. That is why the technical result and the documentation arrive together, instead of one chasing the other.
A complete asset register, a segmented network, the appointed-officer framework in place and a reporting drill closed in 41 minutes.
Segmentation across the SCADA estate, brokered privileged access and continuous monitoring on 1,400 endpoints.
Provider mapping, exit strategies and a resilience testing scope the group risk committee approved without a second round.
“The inspectors wanted documents, not explanations. Every document they asked for was already written and already signed.”
“The argument about products ended and the findings started closing. What took days to spot now takes minutes, and the quarterly report is short enough that the board reads it.”
We run the reporting clock with you — early warning, notification, final report — so a technical incident does not become an administrative one.