About — Protectiva
About us

Engineering depth, procurement fluency, one team.

Our architects build systems at the level the threat requires, and we know how Bulgarian public procurement actually works from the inside. What we deliver is not a software licence — it is operational resilience that survives a legal inspection.

Why we exist

Two trades that rarely share a vocabulary

Engineers produce findings no administration can turn into a tender. Consultants produce documents no engineer can build from. The obligation falls into the space between them, and the budget goes to tooling that nobody ends up running.

Protectiva exists to occupy that space. Architects and analysts certified on both the offensive and defensive side sit alongside people who have drafted technical specifications for public tenders and been in the room for the inspections afterwards.

2018Operating since
140+Engagements delivered
18Engineers & analysts
31Professional certifications
Image placeholder · office / team, environmental portrait
The team

No junior handover

Whoever scopes your engagement is whoever delivers it. Nothing changes hands to a cheaper team once the contract is signed.

Portrait placeholder
Managing partner Delivery, procurement and contracts in the public sector. Fifteen years split between integrators and administrations. CISM · ISO 27001 LA
Portrait placeholder
Head of GRC Maps NIS2, ZKS and DORA against each other; lead auditor on ISO 27001 and 20000-1 programmes. CISA · CIPP/E · ISO 27001 LA
Portrait placeholder
Head of SOC Detection engineering and incident command. Owns the 24/7 rota and the escalation model. GCIH · GCFE · CySA+
Portrait placeholder
Lead security architect Zero trust design, OT/IT separation and identity architecture across multi-site estates. CISSP · OSCP · PCNSE
Certifications across the team
OSCP CISSP CISA CISM CRISC ISO 27001 LEAD AUDITOR GCIH GCFE PCNSE NSE 7 AZ-500 CIPP/E
Case studies

Three engagements, three unrelated problems

Names are withheld under NDA. Scope, approach and outcome are recorded as delivered.

Regional municipality · 24 sites

Eleven weeks from no documentation to ZKS-ready

GRC · Integration · Continuity
Problem. An inspection notice landed with nothing to answer it: no asset register, no approved policy, no appointed officer. Twenty-four locations, three still running unsupported systems. Result. A complete inventory, a segmented network, an approved policy set, an appointed-officer framework, and a reporting drill run end to end in 41 minutes. The inspection closed with no prescriptions issued.
Water utility · important entity

OT/IT separation with no maintenance window available

Integration · Managed SOC
Problem. One flat network, with SCADA engineering workstations sharing broadcast domains with office IT — and not a minute of acceptable interruption to supply. Result. Segmentation delivered in phases behind a privileged access broker, 1,400 endpoints brought under continuous monitoring, and no unplanned downtime at any cutover.
Financial services · DORA

ICT third-party register accepted on the first pass

GRC · Resilience testing
Problem. Provider arrangements sat in four separate departments, with nothing assessed for criticality and no exit strategy anywhere, six weeks out from a group deadline. Result. A complete register, a criticality model, exit strategies and a resilience testing scope — approved by the group risk committee with nothing sent back.
Accreditations & partners

Certified as a company, not just as individuals

We hold and annually audit our own management systems against the same standards we implement for clients.

ISO 9001 ISO/IEC 27001 ISO/IEC 20000-1
Vendor partnerships
PALO ALTO NETWORKS MICROSOFT SENTINELONE NETWRIX TENABLE FORTINET VEEAM BECOME A PARTNER →