# InfoSec Group > Cybersecurity consulting in Sofia, Bulgaria, serving businesses and public organisations across Europe. Cybersecurity, made manageable. InfoSec Group helps clients find security weaknesses, prepare for audits and manage day-to-day security. Priority audiences include fintech companies, SaaS businesses and startups. Work is scoped individually; calculator figures are indicative estimates, not binding quotes. Contact: info@infosecgroup.io | +359 876 830 388 | Sofia, Bulgaria. ## Key pages - [Cybersecurity & Penetration Testing in Sofia | InfoSec Group](https://www.infosecgroup.io/): Cybersecurity services from Sofia, Bulgaria: penetration testing, ISO 27001 and SOC 2 readiness, managed security and vCISO support for organisations across Europe. - [Penetration Testing Services in Bulgaria | InfoSec Group](https://www.infosecgroup.io/penetration-testing.html): Find out where your systems are vulnerable and what to fix first. We test your apps, infrastructure, and cloud, then explain the results to your team. - [Web Application Penetration Testing — InfoSec Group](https://www.infosecgroup.io/web-application-penetration-testing.html): Find security gaps in your web app, including login, permissions, and business logic. Get verified findings and clear steps to fix them. - [API Penetration Testing — InfoSec Group](https://www.infosecgroup.io/api-penetration-testing.html): Check who can access your API and what they can do with it. We test permissions, authentication, and the business logic behind each endpoint. - [Cloud Security Assessment — InfoSec Group](https://www.infosecgroup.io/cloud-security-assessment.html): Check your AWS, Azure, or Google Cloud configuration. Find risky permissions and exposed resources, then decide what to fix first. - [Cybersecurity Compliance & Audit Readiness | InfoSec Group](https://www.infosecgroup.io/security-compliance.html): An audit coming up? We help you understand the requirements, close the gaps, and gather the evidence you need. - [ISO 27001 Certification — InfoSec Group](https://www.infosecgroup.io/iso-27001.html): Build a security management system that fits your organisation. We help with risk assessments, policies, evidence, and audit preparation. - [SOC 2 Compliance — InfoSec Group](https://www.infosecgroup.io/soc-2.html): Prepare for your SOC 2 audit with a clear plan. We help you put controls in place and gather the evidence your auditor needs. - [NIS2 Compliance — InfoSec Group](https://www.infosecgroup.io/nis2.html): Understand your NIS2 requirements and plan the work. We help with risk management, supplier security, governance, and incident reporting. - [DORA Compliance — InfoSec Group](https://www.infosecgroup.io/dora.html): Work through your DORA requirements with a clear plan. Get help with ICT risk, supplier reviews, resilience testing, and incident procedures. - [Managed Cybersecurity Services | InfoSec Group](https://www.infosecgroup.io/managed-security.html): Need more hands on security? We help run the day-to-day work, from checking vulnerabilities to preparing for incidents. - [Cybersecurity & Secure Coding Training | InfoSec Group](https://www.infosecgroup.io/security-training.html): Help your engineers build more secure software. Practical sessions, real examples, and time to work through questions from your team. - [Security Awareness — InfoSec Group](https://www.infosecgroup.io/security-awareness.html): Give your colleagues the confidence to spot suspicious messages and handle information safely. Training that connects to their everyday work. - [Security Operations — InfoSec Group](https://www.infosecgroup.io/security-operations.html): Get clearer signals from your security tools and a plan for responding. We help with monitoring, investigation, and incident handling. - [vCISO & Fractional Security Leadership | InfoSec Group](https://www.infosecgroup.io/vciso.html): Bring an experienced security leader into your team. Get help setting priorities, managing risk, and answering questions from your board or customers. - [Advisory — InfoSec Group](https://www.infosecgroup.io/advisory.html): Some security decisions need a second pair of eyes. Talk to us about privacy, governance, incident planning, or a difficult customer requirement. - [Security Program — InfoSec Group](https://www.infosecgroup.io/security-program.html): Not sure where to start? We assess what you have, identify the gaps, and build a realistic plan with your team. - [Fintech Cybersecurity & Penetration Testing | InfoSec Group](https://www.infosecgroup.io/fintech-security.html): Keep payments and customer data secure. We help fintech teams test their systems and prepare for audits and banking-partner reviews. - [SaaS Security & Penetration Testing | InfoSec Group](https://www.infosecgroup.io/saas-security.html): Answer customer security questions with confidence. We help SaaS teams test their product, secure their cloud, and prepare for audits. - [Cybersecurity Services for Startups | InfoSec Group](https://www.infosecgroup.io/startup-security.html): Get the security basics right while you build. We help you tackle customer requirements and prepare for your first audit. - [Security Budget Estimator — InfoSec Group](https://www.infosecgroup.io/cybersecurity-services-calculator-pricing.html): Free interactive cybersecurity pricing estimator — build a budget for penetration testing, ISO 27001, SOC 2, NIS2, DORA, vCISO and more, benchmarked against the EU market. - [Partnerships — InfoSec Group](https://www.infosecgroup.io/partners.html): Your clients need security help. We can deliver it alongside your team, under your brand, or through a referral. ## Further reading - [Full public-page text](https://www.infosecgroup.io/llms-full.txt): Generated from the same HTML that visitors read. - [All public pages](https://www.infosecgroup.io/sitemap.xml): Canonical URL sitemap. - [Company profile](https://www.infosecgroup.io/assets/documents/infosec-group-company-profile-services-email.pdf): Printable overview. - [Contact](https://www.infosecgroup.io/#contact): Phone, email, WhatsApp, Viber and booking.