Cyber Security & Compliance
Nexos provides end to end security services for organizations operating critical digital infrastructure. POS networks, fuel station automation systems, industrial IoT deployments, and enterprise platforms. We protect both IT and OT environments with a pragmatic, risk based approach.
The Threat Landscape
Organizations operating POS systems, fiscal devices, and industrial control systems face unique threats. Payment card data attracts cybercriminals. Fuel station networks present ransomware targets. IoT devices expand the attack surface exponentially. Regulatory requirements (GDPR, NIS2, PCI DSS) add compliance obligations with significant penalties for failure.
Security Services
Assessment & Testing
- Penetration Testing. Black box, grey box, and white box testing of web applications, APIs, networks, and mobile applications. OWASP Top 10 coverage with detailed remediation guidance.
- Vulnerability Assessment. Automated and manual scanning of infrastructure, applications, and configurations. Prioritized findings with business impact analysis.
- OT/ICS Security Assessment. Specialized testing for industrial control systems, SCADA networks, fuel station controllers, and IoT device firmware.
- Social Engineering. Phishing simulations, pretexting, and physical security testing to evaluate human layer defenses.
Compliance & Governance
- GDPR Compliance. Data protection impact assessments, privacy by design implementation, data processing agreements, and breach notification procedures for Bulgarian and EU operations.
- NIS2 Directive. Risk management measures, incident reporting, supply chain security, and business continuity planning for essential and important entities.
- PCI DSS. Payment card data protection for POS environments. Network segmentation, encryption, access controls, and logging per PCI DSS v4.0 requirements.
- Bulgarian Regulatory Compliance. Ordinance N 18 fiscal data security, Commission for Personal Data Protection (CPDP) requirements, and sector specific regulations.
- ISO 27001. Information security management system implementation, gap analysis, and certification preparation.
Monitoring & Response
- 24/7 Threat Monitoring. Security Operations Center (SOC) services with SIEM integration, anomaly detection, and real time alerting.
- Incident Response. Rapid containment, forensic investigation, evidence preservation, and recovery support. Documented playbooks for common scenarios.
- Network Segmentation. Isolating POS networks, OT systems, and IoT devices from corporate IT to limit blast radius and meet compliance requirements.
- Endpoint Protection. Managed EDR/XDR deployment, patch management, and hardening for workstations, servers, and embedded devices.
Proven Results
- Zero successful breaches across all managed client environments
- 100% compliance pass rate for PCI DSS and GDPR audits
- Average 4 hour incident response time from detection to containment
- 85% reduction in attack surface after network segmentation projects
Frequently Asked Questions
- Does NIS2 apply to us in Bulgaria?
- Bulgaria's amended Cybersecurity Act transposed NIS2 in February 2026 with no transition period. Medium and large fuel retailers and their software suppliers are generally in scope, and the supplier obligation catches vendors who assumed it did not.
- Do you test operational technology, or only IT?
- Both, and on forecourts and production floors the boundary between them is where the real exposure sits. Testing is scoped so it never puts a live site at risk.
- What does your incident response commitment actually cover?
- A four hour response SLA to begin containment and analysis, with the reporting timelines that NIS2 imposes handled as part of the engagement rather than left to you to remember under pressure.