In conjunction with

Fully Managed Cybersecurity — vCISO, MXDR and CREST-Accredited Offensive Testing

Founded in 2016 by Bulgarian entrepreneur Atanas Simeonov, AMATAS is a managed security services provider that sells cybersecurity as an outsourced subscription rather than a set of tools. It serves organizations that lack in-house security depth, including fintech, banking, manufacturing, e-commerce, healthcare and software firms, operating across three continents from a base in Sofia. The company describes itself as the first in its region to apply an as-a-service management model to the full security function, and is backed by Ocean Investments.

Delivery is split across governance, operations and testing. Virtual CISO and Virtual DPO engagements place fractional senior practitioners inside a client to own security strategy, risk decisions and data-protection compliance. A CREST-accredited security operations centre runs the Managed Extended Detection and Response line, providing round-the-clock monitoring, triage and incident response on top of partner telemetry from vendors such as SentinelOne, Darktrace and Rapid7. Managed Security Awareness handles behavioural training, while managed IT covers routine infrastructure operations.

The offensive side spans vulnerability assessment, red teaming, secure code review and WAF assessment, tiered from a fixed-scope Essential test aimed at smaller firms to Elite multi-layer attack simulations with retests included. Continuous testing runs on Plainsea, an in-house platform since spun out as its own product, combining automated scanning with analyst oversight and live remediation tracking. Four CREST accreditations covering penetration testing, SOC operations and offensive vulnerability scanning, alongside ISO 27001, 20000 and 9001, anchor its credibility with regulated buyers.

Market Segments:

MSP/MSSPPenetration Testing

Categories:

MDR