Why us

Not just a platform. Also the team that puts things in order.

The software shows where something is missing. But the gap does not close by itself. That is why the work does not stop at the assessment and the GAP analysis - we go all the way to implementation, technical and documented.

The requirement has two sides. Usually only one is in order.

An organisation may have a good firewall and no documentation at all. Or the opposite: excellent policies that no one applies. The requirement is met only when both sides match and can be proven.

Documentary side

The process and the evidence

  • Policies, procedures and responsibilities suited to the real organisation
  • Judgement on scope and applicability, with review by an owner
  • Assessment of the status against the requirements, with no unconfirmed answers
  • GAP analysis, findings and a remediation plan
  • Evidence linked to the specific requirement and version
  • A history of decisions and readiness for review by a supervisory authority
Technical side

The environment and the measures

  • Access control and multi-factor protection
  • Firewalls, segmentation and secure remote access
  • Backups and tested recovery
  • Proactive monitoring and a centralised event log
  • Servers, virtualisation and private cloud
  • Incident response within agreed deadlines

From requirement to implemented measure

The table shows how the platform and the team's technical work complement each other. The same requirement gets both a trace and a real measure.

Correspondence between requirement, platform and technical implementation
RequirementThe platformTechnical implementation
Risk management and policies Assessment of the status against the requirements, linked evidence and recorded decisions. Audit and risk assessment, an optimisation and migration plan, implementation and documentation.
Access control and multi-factor protection Roles, permissions and traceability of who changed what and when. Identity management, multi-factor authentication, access segmentation and 802.1X for wireless networks.
Network and perimeter security Asset register and the measures linked to it. Firewalls and traffic filtering, secure remote access and VPN, building network infrastructure.
Continuity and recovery Tasks with an owner and a deadline, test protocols as evidence. Backups and a recovery plan, recovery testing and documenting the result.
Monitoring and incident response Status of the open work and a history of actions. Proactive monitoring, a centralised event log and response within agreed deadlines.
Servers, virtualisation and cloud The context of the requirement and the evidence attached to it. Virtualisation and server solutions, private cloud, data centre colocation and hosting services.

The expertise

Certified specialists, not intermediaries.

The technical part is carried out by the team of BGO Cloud, an IT company from Sofia that manages and maintains the infrastructure of organisations across the country. The team maintains ongoing technical qualification in the technologies it works with daily.

This means that when the assessment shows a gap in access, backups or monitoring, there is someone to fix it - not just describe it.

Certified technologies and partnerships

  • ProxmoxCertified Specialist
  • VMwareCertified Professional
  • MicrosoftCertified Professional
  • MikroTikCertified Network Associate
  • ESETCertified Partner
  • cPanelCertified Partner

The certificates belong to the technology vendors and attest to qualification in the respective products and platforms. They are not a certificate of NIS2 compliance.

What the work looks like

Five steps that lead from the first conversation to a working process - not to a report that stays in a folder.

  1. 01

    We clarify the scope

    Which activities and services fall within scope and what that means for the organisation.

  2. 02

    We assess the current status

    A minimum against the requirements, a maximum against the real environment - documentation, access, network, backups.

  3. 03

    We put things in order

    Policies, procedures and responsibilities on one side, technical measures on the other.

  4. 04

    We document and track

    Every requirement gets evidence, an owner and a deadline in the platform.

  5. 05

    We maintain it

    Monitoring, maintenance and periodic review, so the status does not go stale.

When it makes sense

We work best with organisations that have decided to put their work in order.

  • You have an assessment, but it does not lead to action.The gaps are described, but no one fixes them or checks them.
  • You have technical measures, but no evidence.The protection works, but at review time you cannot show what was decided and when it was checked.
  • You work with a consultant, but implementation stalls.The analysis is ready, but the technical part is left to you and there is no capacity.
  • You need to show the status to management or a supervisory authority.What is needed is traceability, not a retelling.

Next step

Tell us what the status is today.

We will review the scope, show what the evidence looks like at review time and discuss what is needed technically.

Request a demo