Advisory

I provide independent advisory services in information security governance and digital operational resilience, with a focus on ISO/IEC 27001:2022 implementation, DORA, and NIS2 compliance. My client base spans Bulgaria’s financial sector and small-to-medium organizations across other industries.


Services

Gap analysis and readiness assessment
An evidence-based assessment of your organization’s current position against ISO/IEC 27001:2022, DORA, or NIS2.

ISO/IEC 27001:2022 implementation
Full development of a certifiable information security management system, including scope and context definition, risk assessment methodology, the Statement of Applicability, mandatory documentation and operational procedures, awareness planning, and preparation for internal audit.

DORA compliance and readiness
Applicability assessment, ICT risk management framework alignment, third-party risk documentation, and incident reporting procedures for financial entities and their ICT service providers. Engagements are structured against the regulatory technical standards.

NIS2 compliance and readiness
Applicability evaluation, risk management measures aligned to the directive’s requirements, incident reporting procedures, and supply chain security obligations for essential and important entities under the national transposition of NIS2. Includes assessment of governance and management-body accountability requirements.

Training and awareness
Structured training programs for boards, IT departments, and general staff, covering AI and cybersecurity, ISMS, DORA and NIS2 fundamentals, and ISO 27001 awareness. Delivered in half-day or full-day formats.

Industry-specific threat landscape analysis and strategy adoption


Engagement process

Every engagement begins with a scoping call, followed by a written proposal defining scope, timeline, and cost.


Contact

contact@vladimirbabanov.com