Прогресивния данък – илюзия за справедливост

Автор: Светла Стайкова

Статията е изготвена с помощта на Google AI


Дебатът за премахването на 10%-ия плосък данък в България се завръща с маската на „социална справедливост“ и „европейски модел“. Прокарван от популистки политически лобита, този ляв завой обаче крие зловеща икономическа реалност. В държава с над 34% сива икономика, хронична корупция и дълбоки пазарни зависимости, прогресивният данък няма да накара богатите да плащат повече. Той ще се превърне в перфектното административно оръжие за разчистване на неудобната и независима конкуренция. Това е директен удар срещу зараждащата се българска средна класа и иновативните малки бизнеси, които нямат партиен „гръб“. Прогресивният данък у нас няма да преразпредели богатство – той ще предизвика вълна от фалити на честния бизнес и ще циментира позициите на монополите и олигархичните картели.

Връщането на прогресивния данък в България ще узакони монополите и ще нахрани сивата икономика. В среда с хронична корупция и пазарни зависимости, сложните данъчни скали няма да засегнат олигархичните структури – те ще ликвидират независимия малък бизнес и процъфтяващата средна класа. Опитът на Източна Европа и математиката зад ДДС приходите доказват, че 10%-ият плосък данък остава единствената работеща защита за българската икономика.

1. Парадоксът на сивата икономика

  • Фактите: Според международни доклади на консултантски компании като Kearney (2025/2026 г.), сивата икономика в България съставлява около 34,6% от БВП. Това е най-високият дял в целия Европейски съюз.
  • Аргументът: [Плоският данък от 10% (въведен през 2008 г.)]имаше една основна цел – да направи укриването на данъци икономически неизгодно. Рискът от глоби и счетоводни схеми стана по-скъп от плащането на ниската ставка.
  • Ефектът от промяната: Ако се въведе прогресивен данък (например 20% или 25% за по-високите доходи), хората няма да започнат да плащат повече. Вместо това те ще се върнат към масовите практики от преди 2008 г. – “пликове с пари” и осигуряване на минимална заплата. При сива икономика от над 34%, прогресивната система не събира повече пари от богатите, а просто ги прогонва в сенчестия сектор.

2. Корупционният натиск и административният произвол

  • Реалността: България традиционно заема незавидни позиции в ЕС по Индекса за възприятие на корупцията.
  • Аргументът: Настоящата плоска система е изключително проста: [всички плащат 10%](url_1.3.5, 1.3.6). Няма сложни данъчни облекчения, няма десетки скали и вратички. Това минимизира контакта между бизнеса и данъчната администрация.
  • Ефектът от промяната: Прогресивният данък изисква огромна и сложна администрация за контрол. В корумпирана среда това създава перфектни условия за “селективен натиск” от страна на проверяващите органи срещу неудобни бизнеси и корупционни споразумения под масата за пренасочване на фирми в по-ниски данъчни категории.

3. Бариери за навлизане на пазара и олигархични зависимости

  • Реалността: Българският пазар има сериозни скрити регулаторни бариери, висок монополизъм и зависимости на определени сектори от държавни поръчки или политическо покровителство.
  • Аргументът: За да стартира и пробие един нов, независим предприемач (без “гръб” и без държавни субсидии), той трябва да може да натрупа капитал бързо чрез чиста пазарна ефективност.
  • Ефектът от промяната: Прогресивният данък удря най-силно средната класа и бързо развиващите се нови бизнеси в момента, в който те започнат да стават успешни. Големите, исторически укрепени картели и олигархични структури имат ресурса да наемат скъпи чуждестранни счетоводители, да изнасят печалби през офшорни зони и да оптимизират данъците си. Така прогресивният данък се превръща в бариера, която защитава статуквото и пречи на новите малки играчи да застрашат големите субекти на пазара.

4. Наказание за единствения истински успешен сектор (IT и аутсорсинг)

  • Фактите: Максималният осигурителен доход в България за 2026 г. бе повишен на 3850 лв. Сектори като IT, иновации и високотехнологични услуги са основните двигатели на средната класа и плащат реални, “бели” заплати с високи осигуровки.
  • Аргументът: Прогресивният данък ще таргетира точно тези високоплатени специалисти. Тъй като техният труд е изключително мобилен, повишаването на данъците ще доведе до два ясни резултата:
    1. Изтичане на мозъци: Специалистите ще се преместят в държави с по-добро качество на публичните услуги за същите данъци.
    2. Преминаване към сивия сектор: Масово преминаване към замаскирани граждански договори или фирми в чужбина с цел избягване на българските налози.

Обобщена таблица за вашата статия:

Проблем на българската средаКак влияе Плоският данък (Сега)Как ще повлияе Прогресивният данък
Сива икономика (34.6% от БВП)Мотивира излизането на светло, защото 10% е по-евтино от укриването.Стимулира масово укриване на доходи и връщане към “заплати в плик”.
Корупционни практикиЛипсата на сложни правила ограничава възможностите за корупция на инспекторите.Сложните скали създават корупционни вратички и селективен административен натиск.
Пазарни бариериПомага на новите и честни бизнеси да растат бързо и да се конкурират с картелите.Защитава статуквото. Големите компании ще оптимизират данъка, малките ще фалират.
Бюджетни приходиОсигурява стабилност чрез широка данъчна основа и висок икономически растеж.Дългосрочно свива приходите поради масово укриване на данъци и отлив на капитал.

5. Урокът от Източна Европа: Държавите, които съжалиха за прогресивния данък

Много политици в България сочат Западна Европа като модел за прогресивно облагане, но умишлено пропускат опита на страните от нашия регион (Централна и Източна Европа). Тези държави имат същата посткомунистическа структура, сходни проблеми с корупцията и сивата икономика. Техният опит е прекият прецедент за България:

  • Словакия (Горчивият опит): Словакия беше икономическият “тигър” на Европа след въвеждането на плоския данък от 19% през 2004 г., което привлече огромни автомобилни заводи и инвестиции. [През 2013 г. обаче страната се поддаде на левия популизъм и върна прогресивната скала (достигаща до 25%, а за 2026 г. бяха въведени още по-високи ставки до 35%)](url_1.3.2, 1.3.5). Резултатът? Според анализи на OECD (Организация за икономическо сътрудничество и развитие) реформата се оказа “приходно неутрална” в дългосрочен план. Държавата не събра очакваните планини от пари от богатите, защото капиталът се оптимизира юридически, но икономическият растеж на Словакия се забави рязко, а преките чуждестранни инвестиции се сринаха спрямо съседите.
  • Румъния (Устойчивият отпор): Нашата северна съседка поддържа плосък данък от 10%, точно както България. В Румъния редовно се водят ожесточени дебати за въвеждане на прогресивен данък под натиск на Световната банка. Правителствата им обаче съзнателно отказват да го направят (включително в бюджетните планове), тъй като румънските икономисти ясно изчисляват, че при техните нива на сива икономика, прогресивният данък незабавно ще прогони процъфтяващия им IT сектор и ще върне масовото укриване на доходи. Плоският данък остава основното им оръжие за икономическия възход на Румъния.
  • Чехия (Голямото завръщане): Чехия премахна плоския си данък за няколко години, но бързо осъзна негативните ефекти върху конкурентоспособността на местния бизнес и средната класа. Впоследствие страната коригира политиката си, за да върне ниски и предвидими преки ставки, уверявайки се, че усложняването на системата облагодетелства само сивия сектор и големите корпорации, които могат да си позволят счетоводни трикове.

6. Истинският двигател на бюджета: Косвените данъци

Най-големият мит на популистите в България е, че държавата се издържа от данъците върху заплатите (Данък върху доходите на физическите лица – ДДФЛ), който лесно може да бъде оборен с официалните цифри от Консолидираната фискална програма на Министерството на финансите.

  • Косвените данъци пълнят хазната: Над 70% от всички данъчни приходи в българския бюджет идват от косвени данъци – ДДС и Акцизи. Истинският спонсор на държавата е потреблението.
  • Как работи моделът в България: Благодарение на плоския данък от 10%, работещите хора и бизнесът разполагат с повече чисти пари (разполагаем доход). Тези пари не стоят под дюшека – те веднага влизат в икономиката. Хората купуват стоки, услуги, горива и имоти. При всяка покупка държавата прибира 20% ДДС и съответните акцизи.
  • Математическият абсурд на прогресивния данък: Ако държавата вземе повече пари от средната класа чрез прогресивен данък върху доходите (например 25%), тя ще постигне следния автогол:
    1. Хората ще свият рязко потреблението си.
    2. Приходите от ДДС (които са основният стълб на бюджета) ще спаднат драстично.
    3. Загубата от намаленото потребление и спада на ДДС ще бъде в пъти по-голяма от жалките допълнителни приходи, които държавата се надява да събере чрез по-високия данък върху доходите.

Истинската социална политика не се прави чрез наказване на успеха. България има уникално предимство – проста и ефективна данъчна система, която остава сигурно убежище за средната класа в несигурни времена. Опитът на нашите съседи в Източна Европа показва, че прогресивният данък в корумпирана среда носи само едно: растеж на сивата икономика и глад за държавния бюджет. Ако искаме повече пари в хазната, трябва да оставим парите в джобовете на гражданите, за да въртят те колелото на потреблението и икономическия растеж.

Имате нужда от стратегическо планиране или икономически анализ за вашия бизнес?

Или попълнете формата за контакт:

Contact Form

admin
SOL-SAND NEXUS (STARA ZAGORA)

PROJECT SUMMARY


Sol-Sand Nexus is a next-generation 10 MW AI data center located in the energy heart of Bulgaria – Stara Zagora. The project solves the biggest problem of the AI ​​industry in 2026: the huge heat generation and high energy costs. Through innovative integration, we turn waste heat from servers into a revenue-generating asset for city heating.


KEY BENEFITS


Energy efficiency (PUE 1.06): We use liquid cooling, which is 40% more efficient than standard air cooling. (p. 2)
Circular economy: We capture 90% of waste heat and store it in low-cost sand batteries (600°C) for the needs of the city grid. (p. 3)
Own energy: A building-integrated photovoltaic (BIPV) facade provides autonomous power supply for critical infrastructure. (p. 2)
Strategic location: Direct access to the transmission network (ESO) and existing heat supply infrastructure. (p. 11)
FINANCIAL HIGHLIGHTS (Phase 1)
Total investment (CAPEX): €27.2 million (excluding customer IT hardware). (p. 10)
Annual revenue: €13.5 million (AI Colocation + Heat Sales + Carbon credits). (p. 2)
Net profit margin: 35% – 45%. (p. 10)
Payback period: 3.2 years. (p. 10)
Government incentives: Eligible for financing under the Just Transition Fund (up to 50% grant) and a Class A Investor certificate. (p. 2)


INVESTMENT CALL


We are looking for a strategic partner to finalize Phase 1. The project offers a unique combination of exposure to the high-tech AI sector and stable profitability from utilities (Heat-as-a-Service).


TO RECEIVE A FULL INVESTMENT MEMORANDUM AND TECHNICAL PLAN, PLEASE SIGN THE NDA.

Confidentiality agreement

admin
The Most Dangerous Myths About Cloud Data

Backup for businesses, Software-as-a-Service (SaaS) solutions offer unparalleled opportunities to enhance efficiency, scalability and overall operations. However, growing SaaS backup-related misconceptions also have the potential to hurt your business growth.

In this blog, we’ll shed light on some SaaS-related truths you simply cannot afford to ignore. Let’s dive in.

Don’t let these myths put your business at risk
As businesses move to the cloud, here are some common misconceptions that need to be dispelled:

Myth 1: My SaaS solution is completely secure.
While leading SaaS solutions like Office 365, G Suite and Salesforce do offer top-of-the-line security along with robust recovery features, the truth is that they aren’t completely foolproof against all threats. They can’t protect your business data from malicious insiders, accidental deletions or hackers.

Solution: By regularly backing up your cloud data, you can protect it against a wide range of threats and unforeseen disasters.

Myth 2: My SaaS provider is solely responsible for my data security.
There is a widely held misconception that your SaaS provider is solely responsible for protecting your cloud data. The truth, however, is more nuanced. While a provider is expected to implement robust security to protect your data, businesses also are expected to play an active role.

Solution: Proactive steps like training your employees on data security best practices and implementing access control steps can ensure your data remains secure in the cloud.

Myth 3: My SaaS provider’s backup is all I need.
While some of the top SaaS providers offer features such as Recycle Bins and Vaults that can store accidentally deleted files, these solutions have limitations and don’t offer comprehensive backup and recovery.

Solution: Consider taking the help of an experienced IT service provider who can not only securely back up your data but also help you enhance your cloud security.

Elevate your data security with a strategic partnership
Ready to empower your business with an advanced backup and recovery strategy? Partner with an IT service provider like us to build a comprehensive SaaS backup and recovery strategy that suits your business needs.

Let data recovery be the last of your worries! Contact us today for a free consultation and learn how our IT team can be your strategic partner.

Loading...
admin
Why Your Business Needs to Prepare for Cyber Incidents

As the world becomes more digital, so do the risks of conducting business online. Cyber incidents can happen to any business, regardless of size or industry, and can have serious consequences.

The following are some examples of common types of incidents to look out for:

Phishing
Phishing is an online scam in which criminals send emails or instant messages falsely claiming to be from a legitimate organization. These messages typically contain links to bogus websites designed to steal your personal information such as your login credentials or credit card number. Phishing attacks can be challenging to detect because scammers use familiar logos and language to dupe their victims.

Denial-of-service
A denial-of-service attack makes a computer or other service inaccessible to users. These attacks are carried out by flooding the victim’s computers or network with requests, rendering it unable to respond to legitimate traffic or causing it to crash. Such attacks can be excessively disruptive and can result in significant financial losses.

Ransomware
A ransomware attack is a cyberattack through which hackers encrypt a victim’s data and demand a ransom to decrypt it. Encryption is the process of transforming readable data into an unreadable format. This is done using a key, which is a piece of information that controls the transformation. Only the same key can convert the unreadable format to readable data or decrypt it.

These attacks can be incredibly detrimental to individuals and organizations since they frequently lead to loss of data or money.

SQL injections
An SQL injection is a form of attack cybercriminals use to execute malicious SQL code in a database. Simply speaking, SQL code is a language to communicate to computers. You can use it to tell the computer what you want it to do, like find some information or create a table, for example. Cybercriminals use this code to change, steal or delete data.

SQL injection attacks pose a serious risk to any website that relies on a database because they can cause irreversible damage.

Malware
Malware is software that is intended to harm computer systems. It can take the form of viruses, Trojans or spyware. Malware can be used to steal personal information, corrupt files and even disable systems.

Nothing could be further from the truth if you believe cybercriminals only target large corporations. According to a recent report, 43% of all cyberattacks target small businesses.1

Real cyber incidents experienced by small businesses

Although the media usually underreports attacks on small businesses and focuses on data breaches that affect large corporations, here are two instances of incidents that severely impacted small businesses:2

1. When the bookkeeper of a boutique hotel began receiving insufficient fund notifications for regularly recurring bills, the chief executive officer (CEO) realized their company had been the victim of wire fraud.

A thorough examination of the accounting records revealed a severe issue. A few weeks prior, the CEO had clicked on a link in an email that they mistook for one from the Internal Revenue Service (IRS). It wasn’t the case. Cybercriminals obtained the CEO’s login information, giving them access to sensitive business and personal information.

This attack had a significant impact. The company lost $1 million to a Chinese account and the money was never recovered.

2. The CEO of a government contracting firm realized that access to their business data, including their military client database, was being sold in a dark web auction. The CEO soon noticed that the data was outdated and had no connection to their government agency clients.

How did this data leak happen? The company discovered that a senior employee had downloaded a malicious email attachment thinking it was from a trusted source.

The breach had a significant operational and financial impact, costing more than $1 million. The company’s operations were disrupted for several days since new security software licenses and a new server had to be installed.

Collaborate for success

Your business is not immune to cyberthreats. To address incidents as they occur, adequate security measures and an incident response plan are required. Consider consulting with an IT service provider like us if you need help identifying the right technologies to prevent a cyber incident or help with developing an incident response plan.

Feel free to reach out now.

To get you better acquainted with incident response best practices, we have created a checklist titled “Cyber Incident Prevention Best Practices for Your Small Business,” which you can download by clicking here.

 

Loading...
admin
Cyber Incident Response 101 for Small Businesses

Imagine it’s the end of a long workday and you’re ready to head home for the evening. However, just as you’re about to leave, you find out your email credentials have been hacked and critical data has been stolen from your business. As a small business, you may have to deal with similar scenarios caused by phishing attacks, ransomware, malware or any other security threat.

The question is, do you have a plan in place to respond quickly and effectively to minimize the impact on your business?

Remember, the longer it takes to address a cyber incident, the more harm cybercriminals can do to your business, such as severe data loss and damage to your bottom line and reputation.

That’s why, in addition to having strong cybersecurity measures in place, you need to have an incident response plan to fall back on.

An incident response plan is a set of steps that can be implemented following a breach to minimize its impact and get the company back up and running as soon as possible.

Cyber incident response 101

According to the National Institute of Standards and Technology (NIST), incident response has five phases:

Identify
There are numerous security risks to be aware of in order to develop an effective incident response plan. This includes threats to your technology systems, data and operations, among other things. Understanding these risks allows you to be better prepared to respond to incidents and reduce their impact.

To identify risks, you can start by looking at system logs, examining vulnerable files or tracking suspicious employee activity.

Protect
It’s critical to create and implement appropriate safeguards to protect your business. Safeguards include security measures to guard against threats and steps to ensure the continuity of essential services in the event of an incident.

To protect your business against cyberthreats, you can use backups, implement security controls such as firewalls, and train employees on security best practices.

Detect
Quickly detecting irregularities, such as unusual network activity or someone attempting to access sensitive data, is essential to limit the damage and get your systems back up and running faster.

Deploying techniques such as intrusion detection systems (ISDs) is an effective way to tackle irregularities.

Respond
You need to have a plan in place to respond to detected cyber incidents. This plan should include strategies for breach containment, investigation and resolution.

A few things you can do to respond to an incident are isolating affected systems and cutting off access to every impacted system.

Recover
Following an incident, you must have a plan in place to resume normal business operations as soon as possible to minimize disruption.

These steps can be part of your recovery plan:

• Restoring systems that have been affected by the attack
• Implementing security controls to prevent the incident from happening again
• Investigating the root cause of the event
• Taking legal action against perpetrators

Keep in mind that a well-crafted incident response plan will help you resolve a breach, minimize the damage caused and restore normal operations quickly and effectively. It’s critical to ensure that all staff are aware of the incident response plan and know their roles and responsibilities in the event of a breach.

An incident response plan should be reviewed and updated regularly to ensure that it remains relevant and effective. Cyber incidents can occur at any time, so it’s crucial to be prepared.

Collaborate with an IT service provider to ramp up your defenses

A specialist IT service provider like us may be exactly what your business needs to develop an incident response plan. By employing our expertise and experience, we can help you:

• Protect your business against cyber incidents
• Create a comprehensive incident response plan
• Abide by NIST’s five phases of incident response

These are just a few of the ways we can help you with your incident response journey. If you’re looking for help protecting your business against cyber incidents, be sure to contact us to schedule a no-obligation consultation.

To provide you with an understanding of the threats small businesses face, we created an infographic titled “Small Business Incidents: What You Can Learn From Their Experiences,”

Loading...
admin
Cyber Incident Prevention Best Practices for Small Businesses

As a small business owner, you may think you are “too small” to be the target of cybercrime because you aren’t a large, multimillion-dollar company. However, this couldn’t be further from the truth. Although the media mainly focuses on attacks on big businesses, small businesses are low-hanging fruit for cybercriminals.

Cybercriminals know that small businesses are less likely to have strong security measures in place, making it easier for them to breach their data. In this blog post, you’ll learn the steps you can take to protect your business from the claws of cybercriminals.

Follow these cyber incident prevention best practices

While there is no single silver bullet for preventing all incidents, there are some best practices that can help you reduce the risk of falling victim to a cyberattack.

  1. Ensure your cybersecurity policy supports remote work

When implementing a cybersecurity policy supporting remote work, consider the following:

  • How will employees access company resources off-site?

  • What security measures should be put in place to protect company data?

  • How will remote employees collaborate and share data?

Additionally, you should identify any support mechanisms to help employees struggling to adjust to remote work. By taking these factors into account, you can create a cybersecurity policy that is productive, seamless and secure.

 

  1. Provide cybersecurity awareness training for employees

Implementing a security awareness training program for employees is critical in today’s digital age. As a responsible business executive, you must strive to ensure that the program is comprehensive, engaging and adaptable to new threats.

  1. Deploy software patches

Threats to your network security are becoming more prevalent as technology advances. That’s why it’s critical to keep your software up to date with the latest security patches.

There are two different ways to keep your software up to date. One way is to set your software to update automatically while the other is to manually check for updates on a regular basis.

  1. Have active antivirus and antimalware protection

There are numerous antivirus and antimalware solutions in the market, so select one that is appropriate for your company. When doing so, you’ll have to consider the size of your company, the type of data you need to safeguard and your budget.

Once you’ve decided on a solution, make sure you follow through with it. This includes installing it on all your company’s computers and keeping it updated.

  1. Implement multifactor authentication (MFA)

Multifactor authentication is a security measure that requires users to provide more than one form of identification when accessing data, thus reducing the chances of unauthorized data access. This can include something that the user knows (like a password), something that the user has (like a security token) or something that the user is (like a fingerprint).

  1. Use a virtual private network (VPN)

A virtual private network encrypts your company’s data and allows you to control who has access to it. This can help prevent data breaches and keep your company’s information safe. However, make sure to choose a reputable provider that offers robust security features.

  1. Deploy single-sign-on (SSO) and password management

A single sign-on solution can make your users’ login process easier by allowing them to log in once to a central system and then access all the other applications and systems they require. This can make the login process more efficient for them.

In addition to SSO, a password management solution simplifies the user login process by allowing them to manage their passwords more securely and efficiently.

  1. Encrypt your data

Data encryption is the process of converting information into a code that can only be deciphered by someone who has the key to decrypt it. It is done to prevent unauthorized individuals from accessing the information. Data encryption is a critical tool in cybersecurity since it can help reduce the exposure of your data to risks and ensure compliance with data privacy regulations.

  1. Have backup and disaster recovery solutions

It is critical to have backup and disaster recovery solutions in place in case of system failure or data loss. Make sure to research the different options and find the best solution for your company. To ensure that your backup and disaster recovery solutions are working correctly, test them on a regular basis.

 

Collaborate for success

If you’re a small business owner, you may not have the time or expertise to implement effective cyber incident prevention best practices. However, by partnering with us, you can leverage our experience to build a digital fortress around your business. Contact us today to find out how we can help you protect your business against potential cyberthreats.

In addition, click here to download our infographic titled “Is Your Business Prepared for a Cyber Incident?” for a deeper dive into the concept.

Loading...
admin
Ръководството на бизнес лидера за управление на киберрискове

Ръководството на бизнес лидера за управление на киберрискове

20.12.2023 - 18h

Навигирайте в сложния свят на киберсигурността, като посетите нашия уебинар.
Киберзаплахите представляват постоянна грижа за фирми от всякакъв размер и индустрии в днешния непрекъснато развиващ се бизнес пейзаж. Истинското предизвикателство е да останете напред и ефективно да защитите бизнеса си срещу тези рискове.
По време на уебинара ще придобиете ценни знания за:
• Разбиране на най-големите киберрискове днес
• Оценка на потенциалните въздействия на кибер инциденти
• Прилагане на практическа стратегия за управление на кибернетичния риск
• И още много

Loading...
admin