Testing Services
From penetration testing to Red Team simulation, from DDoS/DoS resilience tests to social engineering audits: we uncover your vulnerabilities and show you how to close them.
Explore services →We measure your security level, assets and IT infrastructure, and map out your next steps.
Our Information Security Maturity and Cyber Risk Assessment service follows a methodology based on internationally recognized management frameworks such as ISO 27001, COBIT, NIST CSF and TISAX. It has three layers: a maturity audit of information security against these frameworks, an assessment of how adequate personal data processes and practices are, and a vulnerability analysis of the external attack surface, where internet-facing digital assets reside. Together they show the organization’s information security level and cyber risks from every angle.
The service helps you see and test your organization’s ability to defend against potential threats, determine the maturity of your information security against international standards, strengthen your ability to identify and manage cyber risks, and ultimately build a roadmap of the work needed to improve your information security.
Completing compliance work (for example KVKK) and obtaining certifications (for example ISO 27001) is not enough on its own: being compliant does not mean being secure. That is why the relevant international standards should be used so that they complement one another, and the assessment backed with data from security scans run on the actual environments.
Cyber threats are growing more complex and information security risks are rising. As information grows more valuable and competition intensifies, “information theft” has also become a serious risk for organizations. Organizations therefore need to assess their information security and risks regularly and take the necessary measures.
Our service essentially consists of the following phases:
The organization’s processes and day-to-day practices concerning personal data are audited for compliance with the Personal Data Protection Law (KVKK) and the related compliance guide.
Audits are carried out to assess information security policies, procedures, processes and infrastructure.
The organization’s digital footprint on the internet is mapped to define its attack surface. Scans identify all internet-facing digital assets and every cybersecurity vulnerability related to them, and the organization’s cybersecurity risk score is calculated.
All findings from the work are presented in comprehensive assessment reports.
It is not enough for organizations to protect only themselves. In recent years, many cyber attacks on large companies have come not through classic methods but by compromising third parties (stakeholders). Protecting the whole digital ecosystem, including the third parties an organization works with, has therefore become necessary. Examples of third parties include OEMs, dealers, liaison and sales offices, law offices, insurance firms, advertising agencies, marketing companies, IT service providers, and computer and mobile software developers.
Third parties that do not invest enough in security, or do not give it the attention it needs, can introduce information security threats and vulnerabilities that harm the organizations they serve.
Organizations should therefore have this assessment done not only for themselves but also for the third parties they work with.
We apply our methodology in two main stages: the Audit Process and the Scanning Process.
Our service applies a multi-dimensional assessment model covering technical, administrative, social and legal aspects.
For the information security maturity and cyber risk assessment, we use a methodology we developed on the basis of the most widely used international standards and management frameworks in this field (KVKK, ISO 27001, COBIT, NIST CSF, TISAX). With it, we determine the information security maturity level and cyber risks of the organizations we assess, based on evidence.
The methodology used to determine information security maturity is built on the following standards:
Personal Data Protection: An evidence-based audit and assessment is carried out using a question set built in line with the law in force and the compliance guide published by the Personal Data Protection Authority (KVKK).
Determining Information Security Maturity/Adequacy: An evidence-based audit and assessment is carried out using question sets built with reference to the following standards and management systems:
The ISMS (Information Security Management System) is an international standard that gives organizations a framework for protecting their information assets and managing information security effectively. Designed to protect the confidentiality, integrity and availability of information assets, ISO 27001 applies to organizations of every sector and size.
Control Objectives for Information and Related Technologies is an enterprise governance and management framework that provides structure and guidance for information security and the management of information systems. COBIT is designed to help organizations manage, audit and control their information technology effectively, efficiently and securely.
The National Institute of Standards and Technology Cybersecurity Framework is a guide and framework created under the US Department of Commerce for assessing information security risks, developing security measures and improving cybersecurity.
A framework developed to assess and verify the cybersecurity practices of companies in the automotive supply chain. Short for “Trusted Information Security Assessment Exchange”, TISAX builds on the ISO 27001 standard but adds requirements to meet the automotive industry’s specific needs in areas such as data confidentiality and integrity, access control, physical security, communication security and continuity planning.
Carried out in person by our auditors and based on evidence, using assessment questions in 5 categories (Criminal, Legal, Technical, Physical and Administrative).
Carried out in person by our auditors and based on evidence, using assessment questions in 14 categories (Policies, Organization, Human Resources, Assets, Access Control, Physical Environments, Suppliers, etc.).
The audits establish the organization’s status and maturity level in personal data protection and information security, and the changes and work needed for improvement are identified and presented.
Cybersecurity vulnerabilities and risks are identified with SURFACEMON, the next-generation external attack surface analysis platform developed by our company.
Designed as a cloud service that needs no software installation, SURFACEMON only needs the organization’s internet domain name to get started. It then discovers all of the organization’s digital assets and gathers detailed information under the following headings:
Evaluating the scan results reveals the cyber risks arising from the vulnerabilities and threats identified for the digital assets on the organization’s external attack surface.
Our service consists of multi-layered information gathering, audit and assessment processes to determine the organization’s personal data protection compliance, its information security maturity and its cyber risks.
Our senior consultants, who hold international certifications, run the engagement with their information security experience.
SURFACEMON, the platform we built ourselves, discovers all of your assets on the external attack surface and identifies their security vulnerabilities.
Every organization is different, so we set the scope of the service to fit your environments and needs.
The service is built on a methodology we created by combining international information security standards, together with the scanning platform we developed ourselves; it addresses information security in all its dimensions.
Write to us for a scope and a quote: contact us.
Information assets are all the data an organization stores, produces and/or processes: customers’ personal and commercial information, the organization’s confidential financial information, information on products and services, special categories of personal data about employees, and other important data.
Confidentiality classifications are made according to TSE K 523, the Turkish Standards Institution’s criterion for classifying information assets by confidentiality level.
Information assets are classified by confidentiality level, taking into account their content, their purpose of use and other factors. The classification is done to determine the measures needed to keep the data secure and confidential. For example, customers’ personal information or the organization’s financial information may have a higher confidentiality level, because it falling into unauthorized hands could have serious consequences. The classification also ensures that the measures needed to store, process and back up data accurately and up to date are in place.
Data leakage is one of the most significant cybersecurity risks organizations face. To prevent it, the following basic steps can be taken, based on the classified information assets:
Access controls can be put in place to protect classified data. They make the data accessible only to authorized personnel and aim to prevent unauthorized access.
Data can be encrypted to make it more secure. If data leaks, encryption can stop it from being usable by unauthorized people and keep it protected.
Leaks must first be noticed and then resolved quickly, so data monitoring and detection systems should be set up. These systems can detect data leaks and other potential security threats immediately and make it possible to respond.
Organizations should create policies and procedures to prevent data leakage. They set out how to act with regard to data security and confidentiality, and must be followed by all staff.
All staff should be trained in data security and confidentiality to raise awareness. Training plays an important part in preventing potential security threats by making sure the necessary care and attention is given to keeping data secure and confidential.
An IT Health Check is a comprehensive assessment of your organization’s technology systems and infrastructure. Its purpose is to identify potential problems and weaknesses in your IT systems and to recommend improvements. During an IT health check, an IT specialist reviews your systems and runs a series of tests to establish the overall state of your IT environment.
Businesses rely heavily on technology to run their operations. Computers, networks and software keep work running smoothly and efficiently. But like any machine, these systems wear out, fall out of date, or get hit by malware and other threats. That is why regular IT health checks matter for keeping your systems in good shape.
IT health checks are a preventive approach to maintaining your systems. They let you spot potential issues before they become big problems, so you can fix them early and avoid costly downtime and data loss.
Regular IT health checks improve your systems’ efficiency. By finding and fixing issues and keeping your systems running at their best, you reduce the risk of slowdowns and disruption.
Cybersecurity threats are a constant risk for businesses. An IT health check helps you find the vulnerabilities in your systems and get recommendations on how to fix them. Keeping your systems secure helps prevent data breaches and protects your business and your customers.
Regular IT health checks can save you money in the long run. By catching and fixing problems early, you can avoid costly outages and the need for major repairs down the line.
An assessment of your network infrastructure, servers and storage systems to make sure they are performing at their best.
Our specialists check that all software, including operating systems and applications, is up to date and has no known vulnerabilities left open.
Checking that your backup systems are in place and working properly, and making sure your disaster recovery plan is up to date.
Our specialists examine your systems for security vulnerabilities and recommend how to improve your security level.
Checking how your systems perform and recommending ways to improve their speed and efficiency.
An IT health check is recommended at least once a year. It is also important to run one after any major update, change or outage. Regular checks let you be sure your systems are running at their best and your business is prepared for potential problems.
Write to us to schedule an IT health check.
From penetration testing to Red Team simulation, from DDoS/DoS resilience tests to social engineering audits: we uncover your vulnerabilities and show you how to close them.
Explore services →Legal and technical consulting for setting up an ISO 27001 Information Security Management System, KVKK (Turkish data protection law) process management, and compliance with the Information and Communication Security Guide.
Explore services →









