Services — Protectiva
Services

One team builds it, runs it and proves it

Four practice areas, taken on as a project or as a subscription. Scope follows the framework that binds you, not a standard list of deliverables.

01 · GRC

Compliance & risk governance

We measure your estate against the controls that bind you, rank findings by real risk, and leave behind the register, the policies and the evidence an inspection expects to see.

Typical engagement · 4–12 weeks
NIS2 readiness assessmentEvery Art. 21 measure, rated and ranked.
ZKS programmeYour obligations, the officer to appoint, the route for reporting.
DORA readinessThe ICT risk framework and the register of providers.
ISO 27001 supportFrom defining the ISMS boundary to the review that precedes certification.
Risk register & treatment planKept current, with a named owner and a format the board can read.
Supply-chain reviewWhat you must ask of suppliers, and what customers will ask of you.
02 · SOC

Managed detection & response

Analysts in Sofia on your estate around the clock, with containment authority agreed up front so nobody waits for a meeting to act.

Subscription · onboarding in 2–3 weeks
Round-the-clock monitoringCritical alerts triaged inside fifteen minutes.
EDR / XDR managementRolled out, tuned and acted on — not left generating alerts.
Log collection & retentionHeld for the periods the regulator expects.
Vulnerability managementScanned continuously, ordered by what is actually reachable.
Incident response retainerNamed responders, an agreed SLA, and a rehearsal behind it.
Phishing simulationCredible campaigns, followed by short training where it is needed.
03 · Integration

Infrastructure & integration

The engineers who reviewed the estate design and install the replacement, migration plan included, so services stay up while it happens.

Project · certified vendor partners
Firewall estate deploymentPalo Alto Networks and Fortinet platforms.
Identity-first access designAccess decided per user and per application, not per network.
OT / IT segmentationSCADA and utility networks, without taking them offline.
Privileged access managementBuilt on the Netwrix and Microsoft identity stack.
Endpoint hardeningSentinelOne rollout with baseline policy sets.
Cloud configuration reviewMicrosoft 365 and Azure, checked against a hardened baseline.
04 · Continuity

Continuity & recovery

An untested backup is a theory. We design copies that cannot be altered, then demonstrate recovery against the targets you agreed.

Project + quarterly restore tests
Immutable copy designVeeam architecture, with a copy kept offline.
Recovery planningA written runbook for every critical service.
Restore drillsScheduled, documented and reported upward.
Crisis playbooksWho decides, who speaks publicly, who files what and when.
Tabletop exercisesManagement rehearses the reporting clock before it matters.
Recovery targetsAgreed with the people who own the service, not with IT alone.
Packages

Three ways to work with us

Each package is sized to your estate and your framework. We quote per engagement, and structure it to fit procurement rules when that applies.

Baseline

Reach compliance

A single audit and a plan to fix what it finds, for organisations starting with nothing.

  • Framework scoping and readiness assessment
  • Risk register and policy set
  • A roadmap ordered by priority
  • A briefing for management
Ask for a quote
ManagedMost common

Remain compliant

Everything in Baseline, after which we operate the controls and keep the evidence current.

  • Round-the-clock monitoring and EDR management
  • Vulnerability management, continuously
  • Response retainer and help with regulatory filings
  • Quarterly review and a summary for the board
Arrange an intro call
Sovereign

Critical estates

For essential entities, utilities and multi-site administrations that have OT in scope.

  • A dedicated lead architect and named analysts
  • OT and ICS monitoring with segmentation
  • An annual tabletop and adversary exercise
  • On-site engineering days each quarter
Speak to an architect
Not sure which framework applies? The first call costs nothing and ends with a written answer: essential entity, important entity, or out of scope. Compare frameworks →