# CENTIO > We take responsibility for your #Cybersecurity. CENTIO is a Bulgarian cybersecurity company, founded 2001, serving Bulgaria and the wider EU. We run security rather than advise on it: SOC as a Service, penetration testing, ISO 27001 and NIS2 compliance, and 24/7 monitoring. ## Reading this site as a machine Every page has a clean Markdown twin. Ask for it either way: - append `?output_format=md` to any URL, or - send `Accept: text/markdown` and follow the redirect. The twin is generated from the same data the page renders, so it carries the page's content and none of its navigation, styling or layout. ## Terms CENTIO grants permission to read, index, quote and cite the content of this site, including in AI-generated answers, provided the material is attributed to CENTIO with a link to the source page. Content must not be presented as another party's own work, and technical claims must not be altered when quoted. ## Pages ### Services - [SOC as a Service](https://centio.bg/uslugi/soc-security-monitoring): A named analyst team watching and acting on your estate around the clock, with 14-minute detection and a one-hour containment SLA. - [Penetration testing](https://centio.bg/uslugi/penetration-testing): Manual penetration testing across web, network, cloud, mobile and red team, with reproducible findings and a prioritised remediation report. - [Baseline security audit](https://centio.bg/uslugi/baseline-security-audit): Two weeks reviewing endpoints, email, cloud, identity and policy. Findings ranked by real exposure, and a plan anyone can execute. - [Security awareness training](https://centio.bg/uslugi/security-awareness-training): Short practical sessions built on what a live test showed, covering the tells, everyday habits, passwords and second factors, and how to report without fear of blame. - [ISO 27001 certification](https://centio.bg/uslugi/iso-27001): Gap analysis, scoping, documentation and internal audit through to Stage 1 and Stage 2. Certified in four to six months. - [NIS2 compliance](https://centio.bg/uslugi/nis2-compliance): Start with a free ten-minute self-assessment against Article 21(2). Then applicability, gap closure, drills and an audit-ready evidence pack in four to five months. - [Threat hunting and digital forensics](https://centio.bg/uslugi/threat-hunting-forensics): Hypothesis-led hunting for attackers already inside your network, and full forensic investigation with an evidenced timeline when something has happened. - [Security programme management](https://centio.bg/uslugi/security-programme-management): A named owner for your security programme: one roadmap ordered by exposure, cross-team remediation chased to completion, and progress reported as risk closed. - [Phishing simulation programme](https://centio.bg/uslugi/phishing-simulation): Unannounced phishing campaigns across email, phone and text, written from your own suppliers, reported by department and process rather than by name — so management can see where the business gives and what to change. - [Managed vulnerability management](https://centio.bg/uslugi/vulnerability-management): Continuous scanning across network, web, cloud and containers, with every finding validated by an analyst, ranked by real exploitability and tracked to a confirmed fix. - [Cloud security posture and hardening](https://centio.bg/uslugi/cloud-security): Misconfiguration, identity, encryption and container security across AWS, Azure and Google Cloud, assessed against the CIS benchmark and held in place with infrastructure-as-code guardrails. - [AI Skill Check: agent skills checked before they run](https://centio.bg/uslugi/ai-skill-check): Agent skills from public repositories inspected before your people install them — permissions, referenced URLs, the full download-and-execute chain, and behaviour in a sandboxed agent. - [Mobile device security and management](https://centio.bg/uslugi/mobile-device-security): Company phones and tablets enrolled, encrypted and policy-managed, with remote wipe and the same monitoring as the rest of your estate. - [Email and cloud file protection](https://centio.bg/uslugi/email-and-cloud-files): Phishing filtered before the mailbox, cloud file exposure watched, and mail and file events correlated with the rest of your estate. - [Major incident coordination](https://centio.bg/uslugi/major-incident-coordination): Incident command from the first hour: containment through recovery, one decision log, and the regulatory and customer notifications drafted to their deadlines. - [Standby incident response capacity](https://centio.bg/uslugi/standby-response-capacity): Named engineer capacity held in reserve with contractually agreed response timings, sized to your environment. - [Executive and board security reporting](https://centio.bg/uslugi/executive-reporting): Security risk reported in business language on your board's cycle: what changed, what remains open, and what closing it would cost. - [AI security: discovery, governance and runtime protection](https://centio.bg/uslugi/ai-security): Find the AI already in use across your business, define what it may do with which data, and enforce it at runtime against prompt injection, data leakage and unauthorised agent actions. - [vCISO and security consultancy](https://centio.bg/uslugi/security-consultancy): A named security consultant owning strategy, governance, risk and board reporting for a fixed number of days a month, with readiness for ISO 27001, NIS2, SOC 2 and GDPR. - [Managed security products](https://centio.bg/uslugi/managed-security-products): We operate the security tools you already own — SIEM, SOAR, EDR, XDR, firewalls, WAF, mail and cloud — audited, tuned and monitored, with a monthly report. ### Solutions - [ESET](https://centio.bg/reshenia/eset): Official ESET distributor in Bulgaria, five-time Customer Loyalty Award winner. Endpoint, mail, cloud, encryption and MFA, deployed and managed by our team. - [Safetica data loss prevention](https://centio.bg/reshenia/safetica-dlp): Stop the client list leaving with the person who resigns, the contract going to the wrong Ivan, the folder copied to a USB stick. Safetica, deployed and run by our team. - [Check Point](https://centio.bg/reshenia/check-point): Network, cloud and user protection as one estate, with a policy written once and enforced everywhere. Deployed and run by CENTIO engineers. - [Qualys](https://centio.bg/reshenia/qualys): Continuous asset discovery and vulnerability detection across network, web, cloud and containers, delivered by CENTIO as a managed service. ### Other - [Console notes](https://centio.bg/news): security notes and incident write-ups. Full text of every page: https://centio.bg/llms-full.txt