Assessment Services

We measure your security level, assets and IT infrastructure, and map out your next steps.

Security Maturity & Cyber Risk Assessment

Our Information Security Maturity and Cyber Risk Assessment Service

Our Information Security Maturity and Cyber Risk Assessment service follows a methodology based on internationally recognized management frameworks such as ISO 27001, COBIT, NIST CSF and TISAX. It has three layers: a maturity audit of information security against these frameworks, an assessment of how adequate personal data processes and practices are, and a vulnerability analysis of the external attack surface, where internet-facing digital assets reside. Together they show the organization’s information security level and cyber risks from every angle.

The service helps you see and test your organization’s ability to defend against potential threats, determine the maturity of your information security against international standards, strengthen your ability to identify and manage cyber risks, and ultimately build a roadmap of the work needed to improve your information security.

Completing compliance work (for example KVKK) and obtaining certifications (for example ISO 27001) is not enough on its own: being compliant does not mean being secure. That is why the relevant international standards should be used so that they complement one another, and the assessment backed with data from security scans run on the actual environments.

Why Is This Service Needed?

Cyber threats are growing more complex and information security risks are rising. As information grows more valuable and competition intensifies, “information theft” has also become a serious risk for organizations. Organizations therefore need to assess their information security and risks regularly and take the necessary measures.

Phases of the Service

Our service essentially consists of the following phases:

1. KVKK Compliance Assessment

The organization’s processes and day-to-day practices concerning personal data are audited for compliance with the Personal Data Protection Law (KVKK) and the related compliance guide.

2. Information Security Maturity/Adequacy Assessment

Audits are carried out to assess information security policies, procedures, processes and infrastructure.

3. Identifying and Assessing Cyber Risks

The organization’s digital footprint on the internet is mapped to define its attack surface. Scans identify all internet-facing digital assets and every cybersecurity vulnerability related to them, and the organization’s cybersecurity risk score is calculated.

4. Reporting the Results

All findings from the work are presented in comprehensive assessment reports.

Assessing and Auditing Stakeholders / Suppliers

It is not enough for organizations to protect only themselves. In recent years, many cyber attacks on large companies have come not through classic methods but by compromising third parties (stakeholders). Protecting the whole digital ecosystem, including the third parties an organization works with, has therefore become necessary. Examples of third parties include OEMs, dealers, liaison and sales offices, law offices, insurance firms, advertising agencies, marketing companies, IT service providers, and computer and mobile software developers.

Third parties that do not invest enough in security, or do not give it the attention it needs, can introduce information security threats and vulnerabilities that harm the organizations they serve.

Organizations should therefore have this assessment done not only for themselves but also for the third parties they work with.

Methodology

We apply our methodology in two main stages: the Audit Process and the Scanning Process.

1. Audit Process

Our service applies a multi-dimensional assessment model covering technical, administrative, social and legal aspects.

For the information security maturity and cyber risk assessment, we use a methodology we developed on the basis of the most widely used international standards and management frameworks in this field (KVKK, ISO 27001, COBIT, NIST CSF, TISAX). With it, we determine the information security maturity level and cyber risks of the organizations we assess, based on evidence.

The methodology used to determine information security maturity is built on the following standards:

Personal Data Protection: An evidence-based audit and assessment is carried out using a question set built in line with the law in force and the compliance guide published by the Personal Data Protection Authority (KVKK).

Determining Information Security Maturity/Adequacy: An evidence-based audit and assessment is carried out using question sets built with reference to the following standards and management systems:

ISO 27001

The ISMS (Information Security Management System) is an international standard that gives organizations a framework for protecting their information assets and managing information security effectively. Designed to protect the confidentiality, integrity and availability of information assets, ISO 27001 applies to organizations of every sector and size.

COBIT

Control Objectives for Information and Related Technologies is an enterprise governance and management framework that provides structure and guidance for information security and the management of information systems. COBIT is designed to help organizations manage, audit and control their information technology effectively, efficiently and securely.

NIST CSF

The National Institute of Standards and Technology Cybersecurity Framework is a guide and framework created under the US Department of Commerce for assessing information security risks, developing security measures and improving cybersecurity.

TISAX

A framework developed to assess and verify the cybersecurity practices of companies in the automotive supply chain. Short for “Trusted Information Security Assessment Exchange”, TISAX builds on the ISO 27001 standard but adds requirements to meet the automotive industry’s specific needs in areas such as data confidentiality and integrity, access control, physical security, communication security and continuity planning.

KVKK Compliance Assessment

Carried out in person by our auditors and based on evidence, using assessment questions in 5 categories (Criminal, Legal, Technical, Physical and Administrative).

Information Security Maturity Assessment

Carried out in person by our auditors and based on evidence, using assessment questions in 14 categories (Policies, Organization, Human Resources, Assets, Access Control, Physical Environments, Suppliers, etc.).

The audits establish the organization’s status and maturity level in personal data protection and information security, and the changes and work needed for improvement are identified and presented.

2. Scanning Process

Cybersecurity vulnerabilities and risks are identified with SURFACEMON, the next-generation external attack surface analysis platform developed by our company.

Designed as a cloud service that needs no software installation, SURFACEMON only needs the organization’s internet domain name to get started. It then discovers all of the organization’s digital assets and gathers detailed information under the following headings:

  • Internet domain names
  • Websites
  • Web technologies in use
  • Open services and ports
  • IP addresses
  • Servers, databases, network devices and applications
  • Cloud-based systems and storage
  • SSL certificates
  • Threat intelligence
  • Brand intelligence
  • Vulnerabilities and threats
  • Password leaks

Evaluating the scan results reveals the cyber risks arising from the vulnerabilities and threats identified for the digital assets on the organization’s external attack surface.

What You Gain

  • Optimizes information security investments.
  • Meets information security compliance requirements.
  • Helps manage and reduce cybersecurity risks.
  • Prevents losses of corporate reputation and trust.
  • Helps preserve competitive advantage.
  • Helps prevent financial losses.
  • Helps ensure business continuity.
  • Improves the organization’s ability to deal with threats.
  • Makes the organization more resilient against cyber attacks.
  • Helps achieve compliance with the data protection and cybersecurity regulations the organization is subject to.
  • As an organization that takes information security seriously, helps you prove to customers and business partners that you are a more trustworthy partner.
  • Highlighting your information security maturity and risk management can help keep your organization ahead of competitors.
  • Strengthens your ability to protect and secure your organization’s most valuable information assets.
  • The results of the maturity and cyber risk assessment let you base strategic decisions on more accurate information.

Why Work With Us?

Comprehensive Assessment

Our service consists of multi-layered information gathering, audit and assessment processes to determine the organization’s personal data protection compliance, its information security maturity and its cyber risks.

Our Expert Team

Our senior consultants, who hold international certifications, run the engagement with their information security experience.

Our Own Platform

SURFACEMON, the platform we built ourselves, discovers all of your assets on the external attack surface and identifies their security vulnerabilities.

Scope That Fits

Every organization is different, so we set the scope of the service to fit your environments and needs.

Our Own Methodology

The service is built on a methodology we created by combining international information security standards, together with the scanning platform we developed ourselves; it addresses information security in all its dimensions.

Write to us for a scope and a quote: contact us.

Information Asset Inventory Management

Building an Information Asset Inventory and Classifying It by Confidentiality Level

Information assets are all the data an organization stores, produces and/or processes: customers’ personal and commercial information, the organization’s confidential financial information, information on products and services, special categories of personal data about employees, and other important data.

Confidentiality classifications are made according to TSE K 523, the Turkish Standards Institution’s criterion for classifying information assets by confidentiality level.

Information assets are classified by confidentiality level, taking into account their content, their purpose of use and other factors. The classification is done to determine the measures needed to keep the data secure and confidential. For example, customers’ personal information or the organization’s financial information may have a higher confidentiality level, because it falling into unauthorized hands could have serious consequences. The classification also ensures that the measures needed to store, process and back up data accurately and up to date are in place.

Data leakage is one of the most significant cybersecurity risks organizations face. To prevent it, the following basic steps can be taken, based on the classified information assets:

Access Control

Access controls can be put in place to protect classified data. They make the data accessible only to authorized personnel and aim to prevent unauthorized access.

Encryption

Data can be encrypted to make it more secure. If data leaks, encryption can stop it from being usable by unauthorized people and keep it protected.

Data Monitoring and Detection

Leaks must first be noticed and then resolved quickly, so data monitoring and detection systems should be set up. These systems can detect data leaks and other potential security threats immediately and make it possible to respond.

Policies and Procedures

Organizations should create policies and procedures to prevent data leakage. They set out how to act with regard to data security and confidentiality, and must be followed by all staff.

Training

All staff should be trained in data security and confidentiality to raise awareness. Training plays an important part in preventing potential security threats by making sure the necessary care and attention is given to keeping data secure and confidential.

IT Health Check

Our IT Health Check Service

An IT Health Check is a comprehensive assessment of your organization’s technology systems and infrastructure. Its purpose is to identify potential problems and weaknesses in your IT systems and to recommend improvements. During an IT health check, an IT specialist reviews your systems and runs a series of tests to establish the overall state of your IT environment.

IT Health Check: Why Regular System Maintenance Matters

Businesses rely heavily on technology to run their operations. Computers, networks and software keep work running smoothly and efficiently. But like any machine, these systems wear out, fall out of date, or get hit by malware and other threats. That is why regular IT health checks matter for keeping your systems in good shape.

Why is an IT health check important?

Preventive Maintenance

IT health checks are a preventive approach to maintaining your systems. They let you spot potential issues before they become big problems, so you can fix them early and avoid costly downtime and data loss.

Higher Efficiency

Regular IT health checks improve your systems’ efficiency. By finding and fixing issues and keeping your systems running at their best, you reduce the risk of slowdowns and disruption.

Better Security

Cybersecurity threats are a constant risk for businesses. An IT health check helps you find the vulnerabilities in your systems and get recommendations on how to fix them. Keeping your systems secure helps prevent data breaches and protects your business and your customers.

Cost Savings

Regular IT health checks can save you money in the long run. By catching and fixing problems early, you can avoid costly outages and the need for major repairs down the line.

What should an IT health check cover?

Network and Server Health

An assessment of your network infrastructure, servers and storage systems to make sure they are performing at their best.

Software Updates

Our specialists check that all software, including operating systems and applications, is up to date and has no known vulnerabilities left open.

Backup and Disaster Recovery

Checking that your backup systems are in place and working properly, and making sure your disaster recovery plan is up to date.

Security

Our specialists examine your systems for security vulnerabilities and recommend how to improve your security level.

Performance

Checking how your systems perform and recommending ways to improve their speed and efficiency.

When should you do an IT health check?

An IT health check is recommended at least once a year. It is also important to run one after any major update, change or outage. Regular checks let you be sure your systems are running at their best and your business is prepared for potential problems.

Write to us to schedule an IT health check.

Our Other Services

Our Accreditations