About SoCyber

Cybersecurity built for real-world resilience

Senior-led penetration testing, incident response and compliance work for organizations that cannot afford to guess.

SoCyber was founded in Bulgaria and works across offensive security, cloud and infrastructure hardening, AI security and governance. Kikimora.io, our own platform, keeps remediation visible after the engagement ends rather than filing it away in a PDF.

400+ completed engagements, 150+ organizations, 5.0/5 across independent Clutch reviews.

Who We Are

Security expertise with practical outcomes

SoCyber was founded in Bulgaria by security practitioners with a shared background: testing and defending live production systems, not lab environments.

Finding a vulnerability is the easy part. What we get judged on is whether your team actually understands the risk and closes it. That is why every engagement ends with prioritized, developer-ready remediation, not just a findings list.

Every engagement is led by a senior consultant. We do not put junior staff on client work.

Mission & Vision

Why we do this

Mission

Give security teams evidence they can act on, not a PDF that gets read once and archived.

Vision

Become the security partner regulated European businesses call before an auditor or an attacker forces the conversation.

Key Stats

A proven track record

400+
Projects completed
150+
Organizations supported
50+
Security certifications
100%
Senior consultants
Trusted By

Partners and organizations we work with

  • BACB
  • Raiffeisen Bank
  • Texim Bank
  • Doverie
  • Cashwave
  • MaldoPay
  • Liptrade
  • BenchMark
  • Enery
  • Pentagon
  • Iris
  • Beluga
  • Jodayn
  • Komm
  • Kyte
  • MobiSystems
  • Digital
  • Inforce Cyber
What We Do

From security assessments to continuous resilience

SoCyber combines hands-on security engagements, penetration testing, red teaming, code review, cloud and network assessments, with Kikimora.io. Findings do not disappear into a report nobody reopens.

Here is what we test and build controls around most often for European SMEs.

Core capabilities
  • Penetration testing
  • Red teaming
  • Secure code review
  • Web and middleware security testing
  • Cloud and network security
  • Vulnerability management
  • Threat modeling
  • AI and LLM red teaming
  • Governance, risk, and compliance support
  • Remediation validation
Our Approach

Evidence-based security, not passive reporting

A finding with no proof of exploitability is a guess. We validate what we report, so your team can trust the severity rating instead of re-testing it themselves.

That distinction matters most in the gap between a scanner output and a real attack path, which is where manual testing earns its cost.

How we work
  • Define scope around your real assets and business context
  • Test using proven offensive and defensive methodologies
  • Validate findings with technical evidence
  • Prioritize vulnerabilities by severity and impact
  • Support remediation with clear, developer-ready guidance
  • Track progress through structured reporting and platform workflows
Kikimora.io

Visibility, tracking, and compliance in one workflow

Most penetration test findings live in a PDF that gets read once. Kikimora.io is our answer to that: findings stay open, assigned, and tracked until someone actually closes them.

It grew out of our own engagements. We needed a way to see whether last quarter's remediation actually held, not just trust that it did.

Platform outcomes
  • Centralized vulnerability visibility
  • Remediation tracking and ownership
  • Asset discovery and inventory support
  • Compliance-oriented reporting
  • Security workflow transparency
  • Better continuity between assessments, fixes, and validation
Explore the platform kikimora.io
Why SoCyber

Technical depth with long-term accountability

Our Clutch reviews average 5.0 out of 5 across 13 engagements, most of them for banks, fintechs and public-sector clients.

Every consultant holds hands-on offensive certifications such as OSCP, OSWE and CREST CRT. Not a training-course badge from a vendor whose product we are also reselling.

What sets us apart
  • Senior consultants only, no junior staff on client engagements
  • 5.0/5 across independent Clutch reviews, including banking and fintech clients
  • Hands-on offensive certifications (OSCP, OSWE, CREST CRT) across the team
  • Kikimora.io tracks remediation after the report ships, not just at delivery
  • Reporting built for the engineer implementing the fix and the auditor reviewing it
Sector Experience

Built for demanding security environments

A meaningful share of our engagement history sits in banking, fintech, government and critical infrastructure. In those sectors, a missed finding carries direct regulatory exposure, not just reputational risk.

That mix shapes how we scope and report: assuming a regulator or auditor will read the findings, not just an engineering team.

Banking and financial servicesFintech and digital paymentsRetail and e-commerceGovernment and public sectorCritical infrastructureTechnology and SaaS companiesRegulated digital businesses
From the CEO

A message from our CEO

Krasimir Kotsev, Founder & CEO of SoCyber

I started SoCyber after years spent testing and hardening live production systems, not advising from the outside.

The lesson that never changed: a client does not remember the vulnerability count in a report. They remember whether the fix actually held six months later.

That gap between a report and a fix that sticks is what Kikimora.io exists to close. It is why every SoCyber engagement is built around continuous evidence your team can act on, not a document that gets filed away.

Krasimir Kotsev Founder & CEO, SoCyber
Our Direction

Toward continuous, AI-powered security

NIS2 and DORA both push in the same direction: regulators now expect continuous evidence of control effectiveness, not an annual assessment filed once and forgotten.

That is less a trend we are reacting to and more the reason Kikimora.io exists in the first place. It gives you continuous, compliance-ready evidence between assessments, instead of a report that goes stale the day it is signed off.

Focus areas
  • Continuous vulnerability visibility
  • AI-assisted risk prioritization
  • Embedded security validation
  • Automated compliance support
  • Cloud and development workflow integration
  • Stronger remediation accountability
Our Values

What guides our work

Technical credibility

If we cannot reproduce an exploit ourselves, it does not go in the report as confirmed. Every finding we hand you is something we have actually proven, not flagged by a scanner and left for your team to verify.

Practical remediation

A report that just lists severity scores is half the job. Ours comes with the actual fix, written for the developer who has to implement it that week.

Client trust

We work under NDA as standard and report findings only to the people you name, not a default distribution list. Most of our client base is in banking and fintech, where that discretion is not optional.

Continuous resilience

A security posture decays the moment an assessment ends unless something is tracking whether the fixes stick. That is an ongoing job, not a once-a-year checkbox, which is exactly what Kikimora.io is built to support.

Our credentials

Verified expertise you can trust

Backed by a wide array of globally recognized cybersecurity certifications.

Offensive Security

  • Offensive Security Certified Professional (OSCP)
  • Offensive Security Certified Expert (OSCE / OSCE3)
  • Offensive Security Web Expert (OSWE)
  • Offensive Security Wireless Professional (OSWP)
  • Offensive Security Experienced Penetration Tester (OSEP)
  • Offensive Security Exploit Developer (OSED)
  • Certified AI/ML Pentester (C-AI/ML Pen)

Technical & Specialized

  • EC-Council Certified Ethical Hacker (CEH)
  • CREST Registered Penetration Tester (CRT)
  • eWPTXv2, eCPPTv2, eWPT, eJPT
  • Certified Red Team Operator (CRTO)
  • Certified Mobile Penetration Tester (CMPen)
  • AWS Certified Security - Specialty
  • (ISC)² Certified in Cybersecurity (CC)
  • CCNP Security, CPSA, CAP, ICCA

Management & Audit

  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Systems Auditor (CISA)
  • ISO 9001:2015 (Quality Management)
  • ISO 27001:2013 (Information Security Management)

Ready to strengthen your security posture?

Work with SoCyber to identify risk, validate defenses, track remediation, and build long-term cyber resilience.

Copy / Ask AI