End-to-end cybersecurity for organisations that cannot afford to get it wrong. Penetration testing, compliance, training, and advisory — under one roof.
InfoSec Group is a European cybersecurity practice based in Sofia, Bulgaria. Our team has spent years on the inside — building and operating real security programmes at scale, not just writing frameworks. That direct operational experience shapes every engagement we run.
We work with fintech companies, regulated enterprises, crypto and digital asset businesses, and public sector organisations navigating the demands of ISO 27001, SOC 2, NIS2, DORA, PCI-DSS, MiCA, VARA, and beyond. Our approach is straightforward: scope clearly, deliver accountably, produce outcomes that hold up under scrutiny — from investors, regulators, or a determined adversary.
From a scoped penetration test to a fully managed security function, we size our work to what clients genuinely need. No inflated retainers, no unnecessary complexity, no lock-in.
“To cybersecure the future of every organisation in need.”
We cover the full security lifecycle — from initial assessment through compliance, training, and ongoing programme management.
Controlled attack simulations across web, API, mobile, infrastructure, cloud, and physical premises — grey-box, black-box, and full red team. One of the very few European practices offering physical testing with ex-intelligence partners.
Explore service →Gap analysis through certification and beyond — ISO 27001, SOC 2, NIS2, DORA, PCI-DSS, and crypto frameworks, with one accountable partner. Particularly deep experience in financial services and crypto regulation.
Explore service →Programmes that build durable security skills across your engineering and product teams — developer AppSec, secure coding, cloud, and DevSecOps. Delivered in person or remotely, tailored to your stack.
Explore service →We design, build, and operate your entire security function — playbooks, monitoring, incident support, and quarterly executive reporting. A dedicated security team without the hire.
Explore service →Reduce human risk with engaging awareness programmes and managed phishing simulations tailored to your people and threat landscape — and measured so you can prove the improvement.
Explore service →Detection and response that actually works — SOC design, SIEM and SOAR engineering, threat detection, continuous monitoring, and incident handling that turns alerts into action.
Explore service →Senior security leadership on retainer — strategy, board and investor reporting, risk management, and compliance oversight without the cost of a full-time hire.
Explore service →On-demand expertise for the decisions that matter — virtual DPO and GDPR, incident response retainers with guaranteed SLAs, governance, and board-level cyber advisory.
Explore service →Strategic assessments and a prioritised roadmap — maturity benchmarking, attack-surface mapping, and formal risk assessment your team can act on immediately, with an executive-ready presentation.
Explore service →We perform controlled, authorised attack simulations using the same tools, techniques, and procedures as real-world adversaries. Every engagement is scoped precisely, executed methodically, and reported clearly — with findings your team can act on, not a PDF that lives in a folder.
We work across grey-box, white-box, and black-box approaches depending on your objectives. Physical penetration testing is available with our ex-intelligence partners — a capability almost no European firm offers.
Comprehensive security testing of web applications covering authentication, authorisation, session management, input validation, business logic flaws, and data exposure. We go beyond automated scanning — every finding is manually verified and contextualised to your application's logic.
Security assessment of REST, GraphQL, and SOAP APIs. We test for broken object-level authorisation, authentication weaknesses, mass assignment, rate limiting bypass, excessive data exposure, and injection flaws that automated tools routinely miss.
Security testing of iOS and Android applications covering local data storage, network communication, binary protections, authentication mechanisms, and reverse engineering resilience. We test both the client-side app and its associated backend APIs together.
Assessment of internal and external network infrastructure including servers, firewalls, routers, VPN gateways, and Active Directory environments. We map your real attack paths — from initial foothold through lateral movement to domain compromise.
Configuration and security assessment of cloud environments covering IAM policies, network segmentation, storage permissions, logging and monitoring, encryption posture, and serverless function security. We map misconfigurations to real exploitation paths, not just checklist gaps.
Manual and tooling-assisted review of application source code to identify security vulnerabilities at the code level — before they reach production. We combine automated static analysis with expert manual review to eliminate false positives and uncover logic flaws no scanner finds.
Simulated phishing campaigns, vishing (voice phishing), pretexting, and other social engineering attacks to assess your human layer. We design realistic scenarios tailored to your organisation, execute the campaign, and produce a detailed report with awareness recommendations.
On-site security testing of physical premises, access controls, surveillance systems, and employee security awareness. We partner with ex-intelligence professionals for advanced engagements covering headquarters, data centres, and executive protection — a capability almost no European firm offers.
Full-scope adversary simulation combining digital, social, and physical attack vectors to test your organisation's real-world detection and response capability. We emulate a specific threat actor profile over weeks — testing not just your controls, but your people's ability to detect and respond under realistic pressure.
We have hands-on implementation experience across the full landscape of international security standards and emerging regulation — including financial services mandates, EU digital regulation, and virtual asset frameworks that most firms have never touched.
Whether you need to achieve first-time certification, prepare for a regulatory inspection, or maintain ongoing compliance, we act as your dedicated compliance partner from gap analysis through post-certification maintenance.
ISMS design, risk assessment, policy development, Stage 1 & 2 audit preparation, and ongoing surveillance support.
InternationalStructured risk identification, analysis, evaluation, and treatment aligned with ISO methodology. Risk register and treatment plan included.
InternationalControls relevant to user entities' internal control over financial reporting. Readiness assessment, control design, and auditor coordination.
US / InternationalReadiness, control design and implementation, evidence collection across Security, Availability, Confidentiality, Processing Integrity, and Privacy criteria.
US / InternationalEU directive for essential and important entities. Risk management measures, incident reporting, supply chain security, and governance requirements.
European UnionICT risk management framework, TLPT programme, third-party risk management, and incident classification and reporting for financial entities.
European UnionGap analysis, network segmentation guidance, SAQ preparation, remediation support, and QSA coordination for organisations handling cardholder data.
InternationalCloud security assurance and transparency programme. Self-assessment, third-party audit preparation, and continuous monitoring support for cloud service providers.
InternationalEU regulation for crypto-asset service providers and issuers. Cybersecurity obligations, operational resilience, governance requirements, and regulatory submission support.
European UnionDubai's virtual asset regulatory framework. Cybersecurity controls, IT risk management, compliance programme design, and regulatory liaison support for VASPs.
UAE / DubaiPart-time senior security leadership on retainer. Strategy, risk management, board reporting, compliance oversight, vendor evaluation, and incident coordination.
Ongoing AdvisoryRapid-turn preparation and assessment support for the UK government's baseline cybersecurity standard. Both standard and Plus (CE+) levels.
United KingdomEvery engagement follows the same five phases — regardless of scope or service line. No surprises in delivery.
Define objectives, scope, methodology, rules of engagement, and timeline. Everything agreed in writing before work begins.
Assess current security posture through testing, documentation review, or structured analysis. Evidence-based, not opinion-based.
Execute the core work with regular status communication and full milestone visibility throughout the engagement.
Clear, actionable reports for technical teams and executive stakeholders. CVSS-scored findings with reproduction steps and remediation guidance.
Debrief session, remediation support, optional re-testing to verify fixes, and a clean documented handover.
Fintech companies, banks, crypto businesses, municipalities, and enterprise technology firms across Europe and beyond.











We believe pricing should be transparent. Use our interactive estimator to build a budget based on your organisation size, the services you need, and scope parameters like number of endpoints, lines of code, or regulatory frameworks.
Estimates reflect our 2026 pricing, benchmarked against the EU market. All figures are indicative — confirmed after a 30-minute scoping call at no charge.
Every engagement is scoped individually. These are common entry points — the estimator gives you a full breakdown by service and size.
A 30-minute scoping call costs nothing. A breach costs considerably more.
Book a meeting Send an emailWhether you need a penetration test, compliance guidance, or simply want to understand your current exposure — we are happy to have an initial conversation at no charge.