InfoSec Group — Sofia, Bulgaria

Security built
by people who've
operated it.

End-to-end cybersecurity for organisations that cannot afford to get it wrong. Penetration testing, compliance, training, and advisory — under one roof.


About

Practitioners first,
consultants second.

InfoSec Group is a European cybersecurity practice based in Sofia, Bulgaria. Our team has spent years on the inside — building and operating real security programmes at scale, not just writing frameworks. That direct operational experience shapes every engagement we run.

We work with fintech companies, regulated enterprises, crypto and digital asset businesses, and public sector organisations navigating the demands of ISO 27001, SOC 2, NIS2, DORA, PCI-DSS, MiCA, VARA, and beyond. Our approach is straightforward: scope clearly, deliver accountably, produce outcomes that hold up under scrutiny — from investors, regulators, or a determined adversary.

From a scoped penetration test to a fully managed security function, we size our work to what clients genuinely need. No inflated retainers, no unnecessary complexity, no lock-in.

“To cybersecure the future of every organisation in need.”

30+
Clients served
12+
Compliance frameworks
EU
Based & regulated
0
Excuses for poor handover
What sets us apart
  • End-to-end delivery — test, train, certify, manage
  • Practitioner-led — we have built and operated real programmes
  • Physical penetration testing with ex-intelligence partners
  • EU cost efficiency, without quality compromise
  • Deep crypto & digital assets compliance experience
  • Clean handovers — documented everything, no lock-in

Services

What we do

We cover the full security lifecycle — from initial assessment through compliance, training, and ongoing programme management.

01
Penetration Testing

Controlled attack simulations across web, API, mobile, infrastructure, cloud, and physical premises — grey-box, black-box, and full red team. One of the very few European practices offering physical testing with ex-intelligence partners.

Web & API Mobile Cloud Red Team Physical
Explore service →
02
Security Compliance

Gap analysis through certification and beyond — ISO 27001, SOC 2, NIS2, DORA, PCI-DSS, and crypto frameworks, with one accountable partner. Particularly deep experience in financial services and crypto regulation.

ISO 27001 SOC 1 & 2 NIS2 DORA MiCA
Explore service →
03
Security Training

Programmes that build durable security skills across your engineering and product teams — developer AppSec, secure coding, cloud, and DevSecOps. Delivered in person or remotely, tailored to your stack.

AppSec Secure Coding DevSecOps CloudSec
Explore service →
04
Managed Security

We design, build, and operate your entire security function — playbooks, monitoring, incident support, and quarterly executive reporting. A dedicated security team without the hire.

Programme Build Managed Ops Incident Response SIEM
Explore service →
05
Security Awareness

Reduce human risk with engaging awareness programmes and managed phishing simulations tailored to your people and threat landscape — and measured so you can prove the improvement.

Awareness Phishing Sims Vishing Reporting
Explore service →
06
Security Operations

Detection and response that actually works — SOC design, SIEM and SOAR engineering, threat detection, continuous monitoring, and incident handling that turns alerts into action.

SOC SIEM / SOAR Detection Threat Hunting
Explore service →
07
vCISO

Senior security leadership on retainer — strategy, board and investor reporting, risk management, and compliance oversight without the cost of a full-time hire.

Strategy Board Reporting Risk Compliance
Explore service →
08
Advisory

On-demand expertise for the decisions that matter — virtual DPO and GDPR, incident response retainers with guaranteed SLAs, governance, and board-level cyber advisory.

vDPO IR Retainer Board Advisory Due Diligence
Explore service →
09
Security Program

Strategic assessments and a prioritised roadmap — maturity benchmarking, attack-surface mapping, and formal risk assessment your team can act on immediately, with an executive-ready presentation.

Maturity Attack Surface Risk Assessment Roadmap
Explore service →
Penetration Testing

Every attack surface.
Every methodology.

We perform controlled, authorised attack simulations using the same tools, techniques, and procedures as real-world adversaries. Every engagement is scoped precisely, executed methodically, and reported clearly — with findings your team can act on, not a PDF that lives in a folder.

We work across grey-box, white-box, and black-box approaches depending on your objectives. Physical penetration testing is available with our ex-intelligence partners — a capability almost no European firm offers.

Methodologies: OWASP Testing Guide OWASP API Top 10 OWASP MASVS PTES OSSTMM NIST SP 800-115 MITRE ATT&CK CWE Top 25 CVSS v3.1
01
Web Application Testing

Comprehensive security testing of web applications covering authentication, authorisation, session management, input validation, business logic flaws, and data exposure. We go beyond automated scanning — every finding is manually verified and contextualised to your application's logic.

OWASP Top 10 OWASP Testing Guide v4.2 CVSS v3.1 risk scoring Manual verification of all findings
Grey-box · Black-box · White-box
02
API Security Testing

Security assessment of REST, GraphQL, and SOAP APIs. We test for broken object-level authorisation, authentication weaknesses, mass assignment, rate limiting bypass, excessive data exposure, and injection flaws that automated tools routinely miss.

OWASP API Security Top 10 REST & GraphQL attack patterns Auth token and session analysis Business logic abuse testing
REST · GraphQL · SOAP · gRPC
03
Mobile Application Testing

Security testing of iOS and Android applications covering local data storage, network communication, binary protections, authentication mechanisms, and reverse engineering resilience. We test both the client-side app and its associated backend APIs together.

OWASP MASVS & MSTG Static & dynamic analysis Certificate pinning bypass Reverse engineering & hooking
iOS · Android · React Native · Flutter
04
Infrastructure & Network Testing

Assessment of internal and external network infrastructure including servers, firewalls, routers, VPN gateways, and Active Directory environments. We map your real attack paths — from initial foothold through lateral movement to domain compromise.

PTES · OSSTMM Active Directory attack chains Lateral movement & privilege escalation Internal & external network segments
External · Internal · Active Directory · VPN
05
Cloud Security Review

Configuration and security assessment of cloud environments covering IAM policies, network segmentation, storage permissions, logging and monitoring, encryption posture, and serverless function security. We map misconfigurations to real exploitation paths, not just checklist gaps.

CIS Benchmarks (AWS / GCP / Azure) IAM privilege escalation analysis CSA Cloud Controls Matrix Container & serverless security
AWS · Google Cloud · Microsoft Azure
06
Source Code Review

Manual and tooling-assisted review of application source code to identify security vulnerabilities at the code level — before they reach production. We combine automated static analysis with expert manual review to eliminate false positives and uncover logic flaws no scanner finds.

OWASP Code Review Guide CWE Top 25 Most Dangerous Weaknesses SAST tooling + manual verification Secure SDLC integration guidance
All major languages & frameworks
07
Social Engineering

Simulated phishing campaigns, vishing (voice phishing), pretexting, and other social engineering attacks to assess your human layer. We design realistic scenarios tailored to your organisation, execute the campaign, and produce a detailed report with awareness recommendations.

NIST SP 800-115 Spear phishing & pretexting Vishing & SMS-based attacks Post-campaign awareness debrief
Phishing · Vishing · Pretexting · USB drops
08
Physical Penetration Testing

On-site security testing of physical premises, access controls, surveillance systems, and employee security awareness. We partner with ex-intelligence professionals for advanced engagements covering headquarters, data centres, and executive protection — a capability almost no European firm offers.

PTES Physical Security Access control bypass techniques Tailgating & impersonation scenarios Ex-intelligence delivery partners
Offices · Branches · HQ · Data Centres
09
Red Team Exercises

Full-scope adversary simulation combining digital, social, and physical attack vectors to test your organisation's real-world detection and response capability. We emulate a specific threat actor profile over weeks — testing not just your controls, but your people's ability to detect and respond under realistic pressure.

MITRE ATT&CK Framework Threat actor profile emulation Multi-vector campaign planning Detection & response evaluation
Multi-vector · 15–30 day engagements

Compliance & Regulation

Every framework.
One partner.

We have hands-on implementation experience across the full landscape of international security standards and emerging regulation — including financial services mandates, EU digital regulation, and virtual asset frameworks that most firms have never touched.

Whether you need to achieve first-time certification, prepare for a regulatory inspection, or maintain ongoing compliance, we act as your dedicated compliance partner from gap analysis through post-certification maintenance.

ISO 27001
Information Security Management

ISMS design, risk assessment, policy development, Stage 1 & 2 audit preparation, and ongoing surveillance support.

International
ISO 27005
Information Security Risk Management

Structured risk identification, analysis, evaluation, and treatment aligned with ISO methodology. Risk register and treatment plan included.

International
SOC 1
Service Organisation Controls — Financial

Controls relevant to user entities' internal control over financial reporting. Readiness assessment, control design, and auditor coordination.

US / International
SOC 2
Trust Service Criteria

Readiness, control design and implementation, evidence collection across Security, Availability, Confidentiality, Processing Integrity, and Privacy criteria.

US / International
NIS2
Network & Information Security Directive

EU directive for essential and important entities. Risk management measures, incident reporting, supply chain security, and governance requirements.

European Union
DORA
Digital Operational Resilience Act

ICT risk management framework, TLPT programme, third-party risk management, and incident classification and reporting for financial entities.

European Union
PCI-DSS
Payment Card Industry Standard

Gap analysis, network segmentation guidance, SAQ preparation, remediation support, and QSA coordination for organisations handling cardholder data.

International
CSA STAR
Cloud Security Alliance

Cloud security assurance and transparency programme. Self-assessment, third-party audit preparation, and continuous monitoring support for cloud service providers.

International
MiCA
Markets in Crypto-Assets Regulation

EU regulation for crypto-asset service providers and issuers. Cybersecurity obligations, operational resilience, governance requirements, and regulatory submission support.

European Union
VARA
Virtual Assets Regulatory Authority

Dubai's virtual asset regulatory framework. Cybersecurity controls, IT risk management, compliance programme design, and regulatory liaison support for VASPs.

UAE / Dubai
vCISO
Virtual Chief Information Security Officer

Part-time senior security leadership on retainer. Strategy, risk management, board reporting, compliance oversight, vendor evaluation, and incident coordination.

Ongoing Advisory
Cyber Essentials
UK Government Baseline Certification

Rapid-turn preparation and assessment support for the UK government's baseline cybersecurity standard. Both standard and Plus (CE+) levels.

United Kingdom

How we work

Our engagement process

Every engagement follows the same five phases — regardless of scope or service line. No surprises in delivery.

Phase 01
Scoping

Define objectives, scope, methodology, rules of engagement, and timeline. Everything agreed in writing before work begins.

Phase 02
Evaluation

Assess current security posture through testing, documentation review, or structured analysis. Evidence-based, not opinion-based.

Phase 03
Implementation

Execute the core work with regular status communication and full milestone visibility throughout the engagement.

Phase 04
Reporting

Clear, actionable reports for technical teams and executive stakeholders. CVSS-scored findings with reproduction steps and remediation guidance.

Phase 05
Finalising

Debrief session, remediation support, optional re-testing to verify fixes, and a clean documented handover.


Clients

Trusted by

Fintech companies, banks, crypto businesses, municipalities, and enterprise technology firms across Europe and beyond.

D Bank
Weavr
Sprinque
Datamaran
InvestPro
Shkolo
Skillo
eDIH Trakia
Municipality of Radomir
Municipality of Pernik
Karavani
VMware
Payhawk
Evrotrust
Soul &
Silicon
WiseBee
Centillion
90K
BeduinX
Bitval
Xchange
Stanga
ChangeX
Fintech & Payments Banking & Insurance Crypto & Digital Assets EdTech Government & Public Sector EU Innovation Hubs Enterprise Technology
Pricing

How much does
it cost?

We believe pricing should be transparent. Use our interactive estimator to build a budget based on your organisation size, the services you need, and scope parameters like number of endpoints, lines of code, or regulatory frameworks.

Estimates reflect our 2026 pricing, benchmarked against the EU market. All figures are indicative — confirmed after a 30-minute scoping call at no charge.

Open the estimator → Talk to us instead
Indicative ranges — 2026

Starting points

Every engagement is scoped individually. These are common entry points — the estimator gives you a full breakdown by service and size.

Pentest (web app)
€4K – 7K
ISO 27001 (monthly)
€2.5K – 4K
NIS2 / DORA
€2K – 5K/mo
vCISO (monthly)
€3K – 6K
MiCA / VARA
€3K – 5K/mo
Red Team
€15K – 35K
10–13% bundle discount for 3+ services
Scope-adjusted — endpoints, LOC, cloud accounts
Organisation size multipliers applied automatically

Ready to talk?

A 30-minute scoping call costs nothing. A breach costs considerably more.

Book a meeting Send an email
Contact

Get in touch

Whether you need a penetration test, compliance guidance, or simply want to understand your current exposure — we are happy to have an initial conversation at no charge.

Location Sofia, Bulgaria
All services

Explore every service