Services
Every engagement is scoped in a free call and quoted in writing within 48 hours. Entry products carry a published fixed price; specialist work is quoted after scoping.
Corporate Digital Trust Audit
How your company looks to email systems, blacklists, fraud filters, search and AI engines — and to impersonators.
DORA / NIS2 Evidence Sprint
A defensible evidence pack for your regulatory obligations — proof, not just a plan. Includes an executive fraud briefing.
AI Governance & Shadow-AI Sprint
The AI tools already in use across your business — found, inventoried and governed before they become an incident.
DORA
For financial entities supervised by БНБ, КФН, CySEC or an equivalent authority, and for the ICT providers they depend on. A published fixed price for the readiness assessment.
Obliged, exposed, and under-resourced.
Our clients have a regulatory obligation they did not ask for, a reputation that a single incident would damage, and no in-house security leadership to deal with either.
- Financial firms — payment institutions, e-money issuers, asset managers, brokers, insurers and crypto-asset service providers.
- Software and SaaS vendors that must clear the due diligence of regulated buyers, where SOC 2 and ISO 27001 are the currency.
- Public bodies and critical suppliers in scope of NIS2.
Specialist capabilities
Regulatory and compliance advisory
DORA, NIS2, the EU AI Act, the Cyber Resilience Act, GDPR and MiCA: gap assessments, roadmaps, supplier-contract review, Register of Information preparation, third-party risk programmes.
Certification and attestation readiness
ISO/IEC 27001, ISO/IEC 42001 and SOC 2 — control design, policy sets and evidence discipline before an auditor is engaged. The certification body stays independent, as it must.
Email and domain trust engineering
Why your mail and your domain are distrusted, and how to fix it: authentication (SPF, DKIM, DMARC), deliverability recovery, blacklist removal, impersonation defence.
Security questionnaires and vendor due diligence
The recurring tax on every vendor selling to regulated buyers. We answer the questionnaires and build the reusable evidence set.
Cloud and product security
Secure architecture and cloud configuration review, secure development practices, and product-security readiness for software makers.
AI security and governance
Shadow-AI discovery, AI inventories and governance, ISO/IEC 42001 gap analysis, and risk review of AI agents and their connectors.
Fractional security leadership
Named, accountable security leadership in clear monthly tiers — including the independent oversight supervisory authorities expect.
Strategic incident management
Coordination, decision support and regulatory reporting when it matters. Technical forensics runs through vetted partners — we never promise 24/7 capability we do not have.