Line two
Advice with nothing to sell you.
Technology strategy and advice for the leadership. The large firms are tied to the vendors whose products they then put in front of you. This studio has no such tie, and the absence is the service: we say out loud which things are worth buying and which are not.
We take no commission from a vendor. Ever.
It is the one condition under which independent advice means anything. If we tell you not to buy, we lose possible work and gain nothing elsewhere, which is exactly why we are able to say it.
The services
Seven things, and the first of them is the way in.
| The service | What you receive | The shape |
|---|---|---|
| A review of where the estate standsTHE ENTRANCE | Where the technology stands today, what is holding it back, and which three things to do first, written so that you read it and decide for yourself. | Fixed price, fixed length |
| IT strategy and the investment plan | A strategy for the next few years and the budget it needs, written to survive a board meeting. | Fixed scope |
| Enterprise architecture and the exit from inherited systems | A target architecture and the order that reaches it, including what gets switched off, when, and against what risk. | Fixed scope |
| Cloud strategy and the bill that comes with it | What belongs in the cloud and what does not, plus a cost review that shows where the money is leaking. | Fixed scope or a monthly retainer |
| NIS2 readiness | A governance-level assessment, the gap against the law, and a roadmap that closes it. Penetration testing goes to partners. | Fixed scope |
| Fractional Chief Technology Officer, or Chief Information Officer | A senior person beside the leadership every month: the decisions, the people, the vendors, and the conversation nobody else is having. | Monthly retainer |
| Independent oversight of a large vendor programme | We sit on your side of the table while somebody else implements: plan, quality, risk, and whatever the status report leaves out. | Monthly retainer |
The law
Cybersecurity is a board duty now.
NIS2 entered Bulgarian law in February 2026 through the Cybersecurity Act. The scope grew from six sectors to eighteen and the organisations covered are split into essential and important. In August 2026 the secondary regulation is still being written, and the law gives it until October.
What that means for a board is plain enough: the responsibility is already yours and the detail arrives later. So the work starts at governance and at evidence rather than at a document nobody has finished.
The order
How a decision gets reached.
One method covers the whole studio and is not retold here: it lives on the consulting page. Below is the order inside this line, shorter than the first line’s, because it ends in a decision rather than in a system.
The questions
What leadership teams ask.
- How are you different from a large consultancy? Nobody pays us to recommend anything to you. And the person you spoke to is the person who then does the work.
- Do you work outside Bulgaria? Yes. The studio sits in Sofia and works across the European Union, on site when the work asks for it and remotely otherwise.
- Will you implement the system for us? Not with our own people. We help you choose who implements it, and then we watch the work for you rather than for them.
- Do you run penetration tests? No. That work goes to partners, so we are not the ones checking our own recommendation.
- What does it cost? The review carries one price and one length, both said up front. The rest is fixed scope or a monthly retainer, and the band comes in writing when you ask.
The beginning
Start with one honest review.
One paragraph about the decision ahead of you is enough. A person answers, and it is the person who would sit at that table with you.