EN

03 — BASE LAYER

Cyber Security

We initiate security not by selling products, but by measuring the current situation. First, we answer the question of where the open is and then what control is required.

When will we be called?

If these sound familiar

If you have one of the following situations, it means there is something concrete to talk about in this area.

  • Security status has never been measured
  • Shared passwords and missing MFA
  • Ensuring the existence of backups and not attempting a rollback
  • Technical side not being ready for KVKK and ISO 27001

Scope

21 service items

The scope narrows or expands depending on the project; You don't have to buy them all at once.

  • Cyber Security Analysis
  • Security Risk Analysis
  • Network Security
  • Server Security
  • Cloud Security
  • Web Application Security
  • Endpoint Security
  • Email Security
  • firewall
  • VPN Security
  • M.F.A.
  • Vulnerability Assessment
  • Penetration Testing
  • Backup Security
  • Microsoft 365 Security
  • Identity & Access Management
  • Log Management
  • SIEM
  • KVKK Technical Security
  • ISO 27001 Technical Preparation
  • Security Monitoring

What changes?

measured status

Not an assumption, but a reported risk chart.

prioritization

Findings are ranked by impact; Not everything is done at the same time.

Tried replacement

A spare without a return test is not considered a spare.

Technologies

  • Microsoft Defender
  • Entra ID
  • Fortinet
  • sophos
  • Wazuh
  • Nessus
  • cloudflare

Working model

How are we moving forward?

Each step has a written output; We do not leave progress to verbal agreement.

Discovery

We examine existing systems, processes and team on site. Output: written status report.

Scope

We write down what to do, what not to do and the acceptance criteria.

Setup

We develop in two-week cycles and show a working version at the end of each cycle.

Put in to use

We go live with training, documentation and a transition plan.

Business

We monitor and continue to improve with the service level agreement.

frequently asked questions

Will penetration testing disrupt our business?

Test scope and time interval are determined in writing in advance. In production systems, risky tests are taken out of hours or performed in a duplicate environment.

Do you provide KVKK consultancy?

We do not provide legal advice. We establish and document the technical requirements of KVKK — access control, logging, encryption, backup, deletion.

Let's talk about what can be done on the Cyber Security side.

We listen to your existing systems and return with a scope and approach recommendation within two business days. The first meeting is free.