Recently, Google Cloud and Information Services JSC, Bulgaria’s national system integrator, announced a strategic partnership to build an AI-powered national cybersecurity framework. With this initiative, Bulgaria has become one of the first in Europe to implement a centralised model for protecting public infrastructure against modern cyber threats.
To discuss the initiative and its broader implications, we spoke with Boris Georgiev, Director of Google Cloud for Central and Eastern Europe. In this exclusive interview for the Impulse GROWTH, part of IMPETUS Capital team, he explains the vision behind the project, how AI is reshaping modern cybersecurity, why cybersecurity has become a strategic priority for governments and businesses, and which trends are expected to shape the sector in the years ahead.
Could you briefly tell us more about the initiative, its objectives, and your role in the project?
Together with Information Services, Bulgaria’s national system integrator, we’ve built a strategic partnership to strengthen the country’s cyber defence. It’s one of the first Cybershield deployments in Europe. In practical terms, we’ve set up a federated Security Operations Centre. It gives the team a single, shared view of what’s happening across government ministries and agencies, and it runs on Google Cloud Security Operations and Google Threat Intelligence, which incorporates Mandiant’s frontline expertise – intelligence gathered by some of the world’s most experienced cybersecurity analysts, who respond to nation-state attacks and major security incidents every day.
The work started earlier this year and has already brought 54 government entities into scope. The whole point is to move from reacting to cyberattacks after they happen to anticipating and stopping threats before they cause damage, significantly reducing the time needed to detect and respond to incidents.
Bulgaria is among the first countries in Europe to implement such a centralised AI-powered cybersecurity model. In your view, what factors made this possible?
None of this happens overnight. It rests on an eight-year relationship between Information Services and Google Cloud, built on trust and technical excellence. Just as important was the clear decision by Bulgaria to centralise its defences. What we bring is the knowledge, the experience, and the systems to lift protection for nationally important infrastructure to a different level. That’s backed by EU funding and Bulgaria’s own national cyber defence strategy.
As a NATO and EU member, Bulgaria chose to lead rather than follow. This project is a good example of how a country in the region can take a sophisticated, centralized approach to national security.
In recent years, cybersecurity has evolved from a purely technological topic into a strategic priority for both governments and businesses. What are the main drivers behind this shift?
The threats now move at the speed of AI, and the old manual ways of defending against them just can't keep up.
We’re seeing more state-backed attacks, more ransomware, and more campaigns powered by AI. They’ve exposed real weak spots across finance, energy, and public services. As we discussed at the launch, conflict that used to be physical is increasingly playing out in the digital space, and that’s true right across the region. A growing share of attacks now use AI in some form. So if you haven’t put AI into your own defences, you can’t protect yourself timely and efficiently. That’s why this stopped being an IT topic a while ago and became a question of national and economic resilience, because there’s no real sovereignty without security.
We increasingly hear that AI is being used by organisations building defensive capabilities and by cybercriminals. How is artificial intelligence changing the nature of modern cyber threats?
AI genuinely cuts both ways. On the attacking side, criminals now use it to build very convincing phishing operations, along with automated voice and SMS systems designed to mimic people’s identities and get inside an organisation. The same technology can be turned on old, legacy software to dig out vulnerabilities that have gone unnoticed for years.
That’s exactly why both sides are now racing each other. The threats we see are the advanced, state-backed campaigns that go after diplomatic information, technological know-how, and strategic plans.
The only honest answer is to meet AI with AI, so you can respond as fast as the attacks arrive instead of always being a step behind.
When it comes to modern cyber threats, many organisations still rely on manual processes. To what extent can AI and automation help improve the speed of detecting, prioritising, and managing vulnerabilities and security incidents?
The difference AI makes here is fundamental. In an era when cyber threats evolve at AI speed, traditional manual defences are no longer sufficient. Most cyberattacks today involve AI in some form, and if organisations haven’t deployed it in their own defences, they simply cannot keep up. What we brought to Bulgaria was the ability to centralise threat detection and response across government institutions – moving from a model where each one tried to manage security on its own to a unified platform with real visibility across the entire infrastructure.
That shift alone dramatically reduces the time it takes to detect and respond to threats. The platform runs Google Cloud Security Operations and Google Threat Intelligence, which incorporates Mandiant’s frontline insight – the knowledge of experts who monitor what is happening globally, including in spaces like hacker forums and the dark web.
This gives the team a clear picture, by sector and by country, of who the adversaries are and what they are preparing. We are helping transform national security from a manual craft into an automated science – fighting AI-powered threats with superior AI-powered defences.
When it comes to modern cyber threats, many organisations still rely on manual processes. To what extent can AI and automation help improve the speed of detecting, prioritising, and managing vulnerabilities and security incidents?
One pattern we see often is organisations underestimating the scope of both their security exposure and their AI opportunity – treating each as something to be managed in isolation, rather than as priorities that touch the entire business. Another is treating AI as something relevant to just one part of the business when it can add value almost everywhere, and helping leaders see that is a big part of our conversations. There’s also a lingering caution across the wider region.
In Bulgaria specifically, only around 9% of businesses use AI today, well below Western Europe, even though 22.5% of Bulgarians already use it in their personal lives.
A lot of that hesitation comes from assuming you need a big in-house team of specialists, when modern cloud security is actually more affordable and accessible, with much of the heavy lifting handled by the provider. Once companies move past that caution, I expect we’ll see the same surge in adoption the West has already had.
Looking ahead over the next five years, what are the most important cybersecurity trends that businesses, public institutions and investors should not underestimate?
AI is going to be used by both attackers and defenders, so putting AI into your defences is no longer a choice, whether you run a business or a public institution.
We’ll also see more countries move toward the kind of centralised, national defence Bulgaria is building. Our own project is designed to expand in phases, with the ambition to extend this protection to many more state institutions over time, which is why it can serve as a model for other EU nations.
Alongside that, regulated industries like finance and telecommunications are moving fast into cloud and AI, and Central and Eastern Europe is steadily closing the gap with the West. For investors, I’d pay attention to the local AI ecosystem: institutions like INSAIT could turn into a real competitive edge for Bulgaria, benefiting both education and the wider economy.