SoCyber
SoCyber is a Sofia-based cybersecurity firm providing penetration testing, vulnerability assessment, and SECaaS to enterprise customers in banking, fintech, healthcare, and critical infrastructure, supplemented by the Kikimora machine-learning vulnerability management platform.
- Company typePrivate
- Founded2018
- HeadquartersSofia, Bulgaria
- Headcount1–10
- GTM typeB2B
- OfferingServices
What SoCyber does
SoCyber is a Bulgarian cybersecurity firm founded in 2018 in Sofia by Krasimir Kotsev, delivering penetration testing, vulnerability assessment, social engineering testing, security-as-a-service (SECaaS) and recurring vulnerability management to enterprises across three continents. The company employs a small team (1-10) of certified ethical hackers (CEH, OSCP, CCSA) operating under OWASP and NIST 800-115 standards with an 80% manual / 20% automated testing methodology, and reports 200+ closed projects, 70+ customers and 211 vulnerabilities identified at an average CVSS of 7.6 since inception.
SoCyber's core technology stack combines commercial and open-source scanners (Nmap, Nessus, Nexpose, OWASP ZAP, Nikto) with proprietary machine-learning software called Kikimora (housed under a separate Kikimora.io entity since 2023) that automates vulnerability data analysis and prioritization. Kikimora is positioned in the vulnerability intelligence/analysis layer and is offered as a SaaS subscription targeting organizations with 500+ employees.
SoCyber operates a hybrid go-to-market: professional security testing engagements sold through consultative enterprise field sales with a pre-scoping questionnaire funnel, project-based pentesting priced per scope with 5-30 day delivery, SECaaS engagements for mid-market clients lacking internal security staff, and recurring Kikimora subscriptions priced €199-€1,960 per month. Customers are concentrated in regulated industries — banking and fintech (Bulgarian-American Credit Bank, Société Générale Expressbank, BenchMark Finance), insurance (POC Doverie), technology (MobiSystems, BulPros), with active verticals in eCommerce, telecom, healthcare, critical infrastructure and online gaming. FY2022 revenue was €640K and cumulative venture funding reached approximately €1.99M by end-2023 across rounds led by Vitosha Venture Partners and IMPETUS Capital, alongside angels and a strategic investment from BGO Software.
SoCyber firmographics
Firmographics- Name
- SoCyber
- Legal name
- SoCyber
- Website
- https://so-cyber.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- SoCyber is a Sofia-based cybersecurity firm providing penetration testing, vulnerability assessment, and SECaaS to enterprise customers in banking, fintech, healthcare, and critical infrastructure, supplemented by the Kikimora machine-learning vulnerability management platform.
- Ownership category
- akta.pro rank
SoCyber industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Computer Systems Design and Related Services (5415), Other Computer Related Services (541519)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Prepackaged Software (7372)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industry
- Managed Detection & Response (MDR) & SOC Services (HDADAGAG)
Keywords
Where SoCyber is headquartered
LocationHeadquarters
- HQ city
- Sofia
- HQ country
- Bulgaria
- HQ region
- Europe
Offices4 records
Markets served
SoCyber business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Kikimora Subscription Plans: Monthly subscription plans ranging from $199 to $1,960 for the Kikimora vulnerability management platform, targeting businesses with over 500 employees. Enterprises can save up to $10,000 per month in labor costs and millions from prevented breaches.
- Professional Security Testing Services: Project-based penetration testing and security assessment services. Pricing is determined after reviewing the pre-scoping questionnaire. Projects typically take 5-30 days depending on scope and complexity. Services include Vulnerability Assessment, API/Web/Mobile/Network Penetration Testing, Social Engineering Testing, and SECaaS.
- SECaaS (Security as a Service): Ongoing security officer services providing an information security officer dedicated to the company combined with full SoCyber team expertise. Cost-efficient model for companies without internal security teams, with consultants up-to-date with latest technology, trends, and best practices.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Kikimora Platform - Basic to Enterprise tiers |
| Other | Multi-year contract | Custom Penetration Testing Projects |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels5 records
SoCyber product offering
Product offeringCore offering
SoCyber provides professional cybersecurity testing and management services to enterprise customers across regulated industries, including vulnerability assessment, API/network/web/mobile penetration testing, social engineering testing, security-as-a-service (SECaaS), and ongoing vulnerability management. The company also developed and operates Kikimora, a machine learning-powered vulnerability management platform (marketed under subsidiary Kikimora.io) that automates the analysis and prioritization of vulnerability data for businesses with over 500 employees.
Product overview
SoCyber provides a portfolio of cybersecurity services and an automated vulnerability management product. The service portfolio covers Vulnerability Assessment (automated scanning without exploitation), five types of Penetration Testing services (API, Network, Web Applications, Mobile Applications, and Social Engineering), SECaaS (Security as a Service with a dedicated information security officer), and Vulnerability Management (ongoing vulnerability identification and remediation). SoCyber also developed Kikimora, a machine learning-powered vulnerability management platform that automates analysis and prioritization of vulnerability data, providing a centralized monitoring and decision-support system for enterprise security teams. The company has operated since 2018, serving clients across finance, fintech, eCommerce, government, and other sectors that process sensitive data.
Differentiator
Problem solved
Functional benefit
Brands
- Kikimora: A groundbreaking vulnerability management software powered by machine learning that automates vulnerability data analysis, enabling companies to identify and address security gaps promptly. Kikimora is aimed at businesses with over 500 employees and provides a centralized space for monitoring and managing security gaps.
Products and services
- Vulnerability Assessment Identification and classification of security vulnerabilities in computer, network, or communications infrastructure using mainly automated tools (Nmap, Nessus, Nexpose, OWASP Zap, Nikto). Unlike penetration testing, it does not attempt to exploit identified vulnerabilities.
- API Penetration Testing Security testing of an API's functions and methods, assessing how they could be abused, how authorization and authentication could be bypassed, and whether command injection or XSS can be triggered. Tests include fuzz testing, parameter tampering, and unauthorized endpoint testing.
- Network Penetration Testing Security testing aimed at identifying and exploiting vulnerabilities in network devices, hosts, and other systems. SoCyber tests routers, switches, firewalls, IPS/IDS devices, VPNs, servers, and anti-virus systems, covering Layer 2 and Layer 3 attacks, session hijacking, cryptographic weaknesses, and zero-day vulnerabilities.
- Web Applications Penetration Testing Security testing using a combination of automated and manual methods to exploit vulnerabilities in web applications. Testing covers front-end and back-end systems, databases, programming code, authentication mechanisms, and all communication channels and APIs. Follows OWASP methodology.
- Mobile Applications Penetration Testing Security testing of mobile applications focusing on client-side, hardware, file system, and network security. Testing covers architecture and threat modelling, data storage and privacy, cryptography verification, authentication and session management, network communication, environmental interaction, code quality, and resiliency against reverse engineering.
- Social Engineering Testing Security testing that exploits human factors by attempting scams on company employees to test adherence to security policies and practices. Activities include vishing, phishing via email and web, in-person testing, dumpster diving, insider accomplice scenarios, identity theft, and satellite imagery reconnaissance.
- SECaaS (Security as a Service) Provides a dedicated information security officer for organizations combined with full access to SoCyber's team expertise. Includes policies and procedures, risk management, vulnerability management and scanning, asset management, identity and access management, data security, system security, staff awareness training, BCP and DRP, and security monitoring.
- Vulnerability Management Recurring process of identifying, classifying, prioritizing, remediating, and mitigating security vulnerabilities. SoCyber designs and implements a vulnerability management process within an organization to provide a continuous overview of vulnerabilities in the IT environment and associated risks.
- Kikimora Machine learning-powered vulnerability management platform that automates the analysis and prioritization of vulnerability data. Provides a centralized space for monitoring and managing security gaps, enabling companies to proactively prevent security incidents and safeguard sensitive data. Designed for businesses with over 500 employees, available via monthly subscription plans ranging from $199 to $1,960.
Quantifiable outcome
- Average CVSS score of 7.6 across discovered vulnerabilities, indicating high-severity vulnerability identification capability
- +3 more outcomes
Companies that use SoCyber
Customer profileNamed customers7 records
Segments7 records
Ideal customer profiles5 records
SoCyber technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability4 records
Feature2 records
SoCyber partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core and minor.
- BGO Software Ltd.coreStrategic partner contributing €260K in December 2023 funding round. Company specialized in software development for healthcare and cybersecurity industry, providing complementary expertise and potential integration opportunities.
- Partnering Companies for Vulnerability RemediationminorSoCyber refers clients to partnering companies for vulnerability remediation when clients lack internal capacity to fix discovered vulnerabilities. SoCyber avoids fixing vulnerabilities itself to prevent conflict of interest.
Scale indicators10 records
Recent moves7 records
Expansion highlights7 records
SoCyber competitors and assessment
Company assessmentDirect peers
- HackerOne: HackerOne operates a pentesting and bug bounty platform connecting organizations with ethical hackers. Direct competitor in the penetration testing services space, with a similar crowdsourced-plus-platform model that overlaps with SoCyber's Kikimora and pen testing offerings.
- NetSPI: NetSPI is a penetration testing and vulnerability management services firm serving enterprise clients across financial services, healthcare, and technology. Direct competitor in enterprise-focused pentesting with similar methodology emphasizing manual plus automated testing.
- Bugcrowd: Bugcrowd provides crowdsourced security testing, pen testing as a service, and vulnerability disclosure programs. Direct competitor combining a SaaS platform with curated security researcher talent, parallel to SoCyber's platform-plus-services model.
- Cobalt: Cobalt offers Pentest as a Service (PtaaS) connecting enterprises to a vetted community of testers through a platform. Direct competitor in the PtaaS model with similar focus on combining human expertise with software-driven workflow automation.
- Bishop Fox: Bishop Fox is an offensive security firm providing penetration testing, red teaming, and vulnerability research to enterprise clients. Direct competitor with similar consulting-led, expert-driven methodology (80% manual testing per SoCyber's approach).
- BreachLock: BreachLock delivers penetration testing and vulnerability management via a SaaS platform that combines AI/automation with human expertise. Direct competitor to Kikimora and SoCyber's pen testing business with a similar tech-enabled services model.
- Secarma: Secarma (now Bridewell) is a UK-based cybersecurity consultancy offering penetration testing and managed security services. Regional direct competitor serving similar enterprise and regulated-industry clients in the UK and European markets.
Emerging players
- Astra Security: Astra Security provides automated vulnerability scanning and penetration testing through a SaaS platform targeting SMB and mid-market. Emerging player with adjacent product offering in vulnerability management SaaS, paralleling Kikimora's positioning.
Broad incumbents
- NCC Group: NCC Group is a UK-listed cybersecurity consultancy providing penetration testing, threat intelligence, and managed security services globally. Broad incumbent operating in the same pen testing and vulnerability management space with much larger scale and brand recognition.
- Rapid7: Rapid7 offers a broad security platform including vulnerability management (InsightVM), pen testing services (Metasploit-based), and managed detection. Broad incumbent competing with Kikimora in vulnerability management and with SoCyber in pen testing services.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights7 records
Customer concentration
SoCyber social profiles
Digital presenceSoCyber financial estimates
Financial estimateRevenue estimate
Valuation estimate
SoCyber leadership team
Management profileNumber of profiles
Profiles7 records
SoCyber funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SoCyber M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SoCyber
What does SoCyber do?
SoCyber provides professional cybersecurity testing and management services to enterprise customers across regulated industries, including vulnerability assessment, API/network/web/mobile penetration testing, social engineering testing, security-as-a-service (SECaaS), and ongoing vulnerability management. The company also developed and operates Kikimora, a machine learning-powered vulnerability management platform (marketed under subsidiary Kikimora.io) that automates the analysis and prioritization of vulnerability data for businesses with over 500 employees.
Is SoCyber a public or private company?
SoCyber is a private company. It is classified as venture growth investor backed and is currently operating.
When was SoCyber founded?
SoCyber was founded in 2018. It employs 1 to 10 people.
Where is SoCyber based?
SoCyber is headquartered in Sofia, Bulgaria, in the Europe region.
How does SoCyber make money?
Three revenue lines are on record. Kikimora Subscription Plans are the primary driver. The others are professional Security Testing Services and SECaaS (Security as a Service).
Who are SoCyber's main competitors?
Direct peers on record are HackerOne, NetSPI, Bugcrowd, Cobalt, Bishop Fox, BreachLock and Secarma. Astra Security is listed as an emerging player. Broad incumbents are NCC Group and Rapid7.
Does SoCyber have an API?
No public API is recorded for SoCyber.
What industry is SoCyber in?
SoCyber's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of HDADAGAG, Managed Detection & Response (MDR) & SOC Services. Its NAICS code is 5415 and its SIC code is 7370.