# SoCyber > SoCyber is a European cybersecurity and compliance company helping organizations identify, remediate and manage security risk through specialist services, evidence-led guidance and the Kikimora.io vulnerability management platform. SoCyber focuses on European SMEs and security-sensitive organizations, mapping technical security work to regulatory outcomes (GDPR, NIS2, DORA and more). Capabilities span offensive security and penetration testing, detection and response, cloud and infrastructure security, secure AI adoption, and governance and compliance, delivered with methodology, evidence and measurable results. ## Core Information - [About SoCyber](https://so-cyber.com/about): Company experience, capabilities and approach. - [Cybersecurity Services](https://so-cyber.com/services): Overview of all SoCyber security and compliance services. - [Team](https://so-cyber.com/team): The specialists behind SoCyber. - [Contact SoCyber](https://so-cyber.com/contact): Discuss a security requirement or request an assessment. ## Offensive Security and Penetration Testing - [Web Application Penetration Testing](https://so-cyber.com/web-app-penetration-testing): Controlled, adversary-simulated testing of web applications, APIs, authentication flows and business logic. - [API Penetration Testing](https://so-cyber.com/api-penetration-testing): Assessment of API authentication, authorization, business logic and data exposure. - [Mobile App Penetration Testing](https://so-cyber.com/mobile-app-penetration-testing): Security testing of iOS and Android applications and their backends. - [Network Penetration Testing](https://so-cyber.com/network-penetration-testing): External and internal network testing, segmentation and infrastructure security. - [Wireless Penetration Testing](https://so-cyber.com/wireless-penetration-testing): Assessment of wireless networks, access controls and rogue-device exposure. - [Automated Penetration Testing](https://so-cyber.com/automated-penetration-testing): Continuous, scalable testing to complement manual engagements. - [Web and Middleware Security](https://so-cyber.com/web-middleware-security): SAST, DAST, secure code review and middleware security testing. - [Secure Code Review](https://so-cyber.com/secure-code-review): Manual and tool-assisted review of source code for security defects. - [Threat Modeling](https://so-cyber.com/threat-modeling): Structured analysis of attack surface, trust boundaries and design-level risk. - [Social Engineering](https://so-cyber.com/social-engineering): Phishing and human-targeted attack simulation to manage impersonation and manipulation risk. ## Detection and Response - [Incident Response](https://so-cyber.com/incident-response): Incident containment, investigation, recovery and forensic support. - [Digital Forensics](https://so-cyber.com/digital-forensics): Evidence acquisition and analysis for investigations and disputes. - [Cyber Threat Intelligence (CTI)](https://so-cyber.com/cyber-threat-intelligence-cti): Evidence-led intelligence for threats, exposure and decision support. - [Vulnerability Management](https://so-cyber.com/vulnerability-management): Continuous identification, prioritization and remediation tracking. ## Cloud and Infrastructure Security - [Cloud Security](https://so-cyber.com/cloud-security): Assessment and hardening of cloud configurations, identity and workloads. - [IT Systems Security](https://so-cyber.com/it-systems-security): Hardening, secure configuration and monitoring of endpoints and infrastructure. ## AI Security - [AI Best Practices](https://so-cyber.com/ai-best-practices): Principles and controls for adopting AI and LLMs securely at work. - [AI and LLM Red Teaming](https://so-cyber.com/ai-red-teaming): Testing AI systems for prompt injection, data leakage, unsafe agency and control failure. ## Governance and Compliance - [Compliance Overview](https://so-cyber.com/compliance): How SoCyber maps controls to regulatory frameworks with evidence. - [Governance, Risk and Compliance](https://so-cyber.com/governance-risk-compliance): Building and operating an effective security governance program. - [Virtual CISO (vCISO)](https://so-cyber.com/vciso): On-demand security leadership, strategy and program ownership. - [NIS2](https://so-cyber.com/nis2): Preparing governance, risk and incident-response capabilities for the NIS2 Directive. - [DORA](https://so-cyber.com/dora): ICT risk, resilience testing and third-party controls for financial entities. - [ISO 27001](https://so-cyber.com/iso-27001): Building and maintaining an effective information security management system. - [GDPR](https://so-cyber.com/gdpr): Technical and organizational measures for protecting personal data. - [SWIFT CSP](https://so-cyber.com/swift-csp): Preparing for the SWIFT Customer Security Controls Framework. - [PCI DSS](https://so-cyber.com/pci-dss): Protecting payment environments and preparing for PCI DSS assessments. ## Guides Live guides also have a plain-markdown version at the same path with a .md extension, for clean ingestion without page chrome. - [Security Guides](https://so-cyber.com/guides): Practical, evidence-led guides on the threats and controls that matter, with step-by-step plans. - [Phishing in 2026 and Beyond](https://so-cyber.com/guides/phishing-threats-2026): Modern phishing as identity and workflow compromise - AI impersonation, session hijacking, OAuth abuse, QR and synthetic-voice attacks, with practical controls. Markdown: https://so-cyber.com/guides/phishing-threats-2026.md ## Full content - Service, compliance, guide and core pages have a clean Markdown version at the same path with a .md extension (for example https://so-cyber.com/web-middleware-security.md), for ingestion without page chrome. - [Everything in one file](https://so-cyber.com/llms-full.txt): This index plus the full text of every guide, for single-fetch ingestion. ## Platform - [Kikimora.io](https://kikimora.io/): Vulnerability visibility, asset discovery, remediation tracking and compliance reporting. ## Optional - [EU Funding Opportunities](https://so-cyber.com/funding): Curated EU cybersecurity funding (Digital Europe, Horizon Europe, EIC Accelerator and more), with the key parameters for each call and how SoCyber helps SMEs apply and deliver. - [News and Media](https://so-cyber.com/news): Technical analysis, regulatory updates and practical security guidance. - [Podcast](https://so-cyber.com/podcast): Conversations on cybersecurity, compliance and the threat landscape. - [Events](https://so-cyber.com/events): Live events, webinars and practical advice videos for security and compliance teams.