Come and find out more about iCard on our blogCome and find out more about iCard on our blogCome and find out more about iCard on our blogCome and find out more about iCard on our blog
  • Go to iCard.com
  • English
    • English
    • Български
    • Italiano
    • Română

Meet the team: Obreten Obretenov

Ivelina Nedeva Ivelina Nedeva 20 December, 2024

In the latest instalment of “Meet the team,” we’ll introduce you to Obreten, to whom cybersecurity is not just a profession but a true passion. Playfully called by his friends “Horatio of computers,” in his spare time, Otto conducts computer-related criminal forensics for the prosecutor’s office and trains Jiu-Jitsu. Learn more about him and peek into the exciting world of information security.

How did you discover Jiu-Jitsu?

I like sports, so I trained a few different ones as a kid. I am happy that I work for a company that regularly invests in equipment and sports programs to motivate the employees. I met Flavio, a Jiu-Jitsu coach, in the Business Park where iCard’s headquarters is located. Together with Radoslav Panchev, we decided to offer a new type of group training, and for a little more than 2 years now, I have been training in Jiu-Jitsu after work.

Besides good physical conditioning, this fight sport has taught me many life lessons. I know now that when you’re in a difficult situation, and you’re “suffocating,” you need to stay calm, look at what’s happening from a different angle, look for a better solution, and know that it’s always there.

Recently, Flavio had to relocate to Slovakia, and I missed our training sessions a lot. I talked to him, and he trusted me to lead the group. I record everything on video. Then he watches it and tells us what we can improve upon. Now, we’re not so relaxed when we fight, while before, I would often chafe from the kimono. I even defended my thesis with a covered-up blue eye.

Currently, we’re focusing on the general dynamics, the body’s balance during a fight, and how not to get tired quickly during prolonged periods of exertion. We avoid the full execution of the arm-locking techniques because one can easily make a mistake and hurt a joint, but we practice the choking techniques since the control there is easier.

Who’s the girl that makes you truly happy?

Her name is Betina, and we’ve been together for almost 10 years now. We met in our village when we were both 13 years old. I liked her, but I wasn’t brave enough to admit it. Once, we were playing together, along with my brother, and I don’t remember what I said exactly, but he decided that it was a good time to add: “I think someone wants to say that he likes someone else.” Then, she must have realized that the sentiment was mutual because she asked to see me outside the village. On the way there, though, I had an accident. I was badly injured, and I couldn’t make our date. She had to confess her feelings to me over a text. We grew up together and formed each other’s characters. Besides being a couple, we’re also best friends.

Recently, we got engaged, but we have one failed marriage proposal. I wanted to propose to her in France. While we were travelling to the airport, it was very sunny, and my eyes started tearing up, but I knew that my sunglasses were in my backpack, along with the ring. Betty offered to get them for me a few times, but I stubbornly kept refusing. Ultimately, she decided to hand them to me after all, and as could be expected, the box with the ring fell right off. When she asked me what this was, the situation developed like a scene from “Fast and Furious” – I was holding the wheel, I looked at her, I looked at the road, and finally, I asked her if she would marry me. After that, however, we decided that the surprise was ruined, so I returned the ring.

The second time around, I was much better prepared, and it turned out very romantic and surprising. On her birthday, we were in Budapest, and I made a secret reservation in the most beautiful café in the world – “New York Café.” It’s style is Rococo, and the atmosphere is very refined. While we were talking, two violinists approached our table and began singing “Happy birthday.” After that, the waiter put a tray in front of Betty, and she thought he was serving her a piece of cake. When she opened it, the box with the ring appeared, and the violinists started playing a romantic song. I fell to my knees and asked her if she would marry me. She accepted, and we started dancing in front of everyone at the café, but the excitement was great, and we quickly returned to the privacy of our table.

What did you want to be when you grew up? Did your dream come true?

I had many different interests, and my desires often changed. At one point, I was playing a lot of League of Legends. I had even reached 13th place in the Server for Northern and Eastern Europe. I was winning money from tournaments and teaching people how to play better. However, my parents didn’t believe I could support myself with this hobby, despite the fact that a friend of mine recently bought an apartment from streaming and advertisements while playing.

While studying in the mathematics high school in Ruse, I loved making 3D models of houses and wanted to become an architect. I applied my knowledge to 3D models, and I was calculating dependencies and proportions and looking out for the golden ratio. Unfortunately, I had no desire to go to drawing classes, so I let go of this dream. My passion for 3D modelling continued at the university, where we collaborated with NASA, during which I created a few models for space stations, bases and rockets for them.

After I missed all the preliminary exams, Betty had already signed up to study at the University of Economics – Varna, so I decided I should also come to Varna. I made it thanks to my mother, who discovered some clauses that allow for a student from a mathematics high school with an excellent diploma to be accepted to the Naval Academy without exams. All other majors required extended absences from home and one’s family, so I chose “Cybersecurity.”

What type of cybersecurity student were you?

I wouldn’t say I was among the most dedicated students because I’ve only filled half a notebook for all these years. However, cybersecurity quickly turned into my passion, and this didn’t go unnoticed. I’ll never forget the exam on network security taught by a very strict professor who constantly tried to show us how many things we didn’t know. I got stubborn, and I made it a point to pass the exam not only with an excellent grade but also with the maximum number of points. This was the only exam of my whole undergraduate course, for which I prepared beforehand. It so happened that I was one hour late on the day of the exam, but regardless, I managed to pass it as I intended. The colonel had no reason to nag at me after that.

Even before that, though, the Student Council had contacted me and shared that iCard was looking to fill some vacant positions. The company works closely with the universities in the city and gives students a chance to gain practical experience in some areas. My interview with Bozhidar was my first job interview since I previously did a different type of freelance.

Why do you like working for iCard?

Initially, I wanted to find out what working in a corporate environment feels like. Even though I’ve studied a lot, I had no practical experience in cybersecurity. The good thing is that in iCard, you can learn a lot and better yourself. In some other companies, cybersecurity specialists have different divisions and work in narrow fields of cybersecurity like “pen testing,” audits, removal of vulnerabilities, analysis of malicious code, and others. Our tasks are multifaceted, and we often need to look for new ways to deal with fraud. This means we work in a dynamic and challenging work environment, which allows us to upgrade our knowledge continuously. I really like the team I work with. Dido, Krasi, and I are like a well-oiled machine. We haven’t fought or raised our voices, not even once.

What are the main tasks of the cybersecurity team at iCard?

Our job has no tangible end product or service that we can show for it. We are responsible for the entire PCI DSS audit, and every year, we strive to get the certificate. However, the certificate itself doesn’t show how much is required to get it. As a financial institution, we fall under the strictest PCI DSS regulations. The goal of all regulations we must follow is to prevent banking fraud. If we don’t comply with the requirements of the certificate, the trust of the card schemes in our company will diminish. Then, we would have to pay serious compensation fees since we could potentially expose the cards we issue with their logos to risk.

Besides the PCI DSS requirements, we adhere to other good practices that keep the company safe. We integrated a new solution that significantly diminished the spam and phishing communication from external parties via email. We’re responsible for remote access when our colleagues work from home. We create a secure connection that they can use to access the information on the devices and servers at the office. We constantly look out for new types of fraud in the specialized security blogs. When we learn about such threats, we check to see if we’re vulnerable, and if we are, we find out what we need to improve so that we can prevent potential threats. We also take care of the HSMs (Hardware Security Module), which is an expensive and not widely available tech. Its purpose is to ensure the secure storage and management of cryptographic keys and conduct cryptographic operations in an isolated and safe environment.

What are your additional cybersecurity activities?

I love what I do so much that I find additional projects to occupy my time outside iCard’s office. I’ve been preparing criminal expertise reports for the Prosecution’s cases. My work on those cases has to be completely impartial. I follow the data – I find out by whom it was created, when and where it was created or manipulated and then the lawyers, policemen, and the Prosecution decide what can be introduced as evidence in particular cases. Some friends joke that I’m the Horatio of computers. I also do consulting work by giving cybersecurity training and analyzing companies’ vulnerabilities. I try to teach small and medium business owners that cybersecurity is critical, and that luck and scale are the only reasons they haven’t been hacked by now.

What good practices can users follow to protect themselves from threats?

It’s imperative not to share your bank card details with strangers. To send a transfer to a debit card, the sender needs only the cardholder’s name, the city where the recipient lives, and the 16-digit PAN, but not the CVS code or the card’s expiration date. Anyone who has those last details can take advantage.

However basic it may be, phishing that threatens us by claiming to have access to our emails, passwords or video recordings of us watching erotic websites during working hours still works well. To prevent this information from becoming public, the receiver of the email “has to” send a particular amount of money to a Bitcoin account. It’s important to be vigilant and pay attention to the emails we get and not to open emails with suspicious attachments or links. When we’re on a desktop device, with a hover of the mouse over the link, you can quickly check where the link leads without opening it.

I advise shopping online from apps that have many downloads and high ratings, which proves they are legitimate. Fraud is easier to fall for when shopping from the phone because it’s more difficult to see the irregularities on the small screen. Fraudsters create websites that look similar to the original ones, but the URL is slightly changed – for example, it says “corn” instead of “com.” Some websites try to distract consumers with attractive offers that will expire soon, such as “only now” or “expiring in 15 minutes.” Under pressure, people provide their card details. Then, their card balance is depleted, and the order is never delivered.

If we often shop online, card details are saved on the device and filled with a single tap in the corresponding field. This means they can be stolen just as quickly if the device is compromised. It’s important to make sure the connection is encrypted and no one else can connect to copy the details while we’re filling them in. On secure websites, there is a lock before the domain, which indicates the presence of a Secure Socket Layer (SSL), and the address is https://. This “s” in the end means “secure.” Just to clarify, this guarantees that no one can connect in the process of filing in the details and steal them, not that the website itself is legitimate.

Rely on the iCard digital wallet, where your money is stored according to the highest security standards:

 

1

Copyright © iCard AD 2025 | All Rights Reserved | Privacy Policy
  • Facebook
  • X
  • Instagram
  • LinkedIn
  • YouTube
  • Go to iCard.com
  • English
    • English
    • Български
    • Italiano
    • Română
Come and find out more about iCard on our blog