Information Security



ISMS Consulting (ISO27001:2013)

ISO/IEC 27001 is the only globally auditable and certifiable standard that defines the requirements for an Information Security Management System (ISMS). It is suitable for organizations of all sizes, regardless of country or sector. Establishing, implementing, monitoring, operating, maintaining, and improving an Information Security Management System, based on a business risk approach, is one of our areas of expertise.

ISO27001 Internal & External Audit Services

For companies that already have ISO27001 certification or believe they are ready to obtain it, our audit service provides a report on their current status and offers suggestions on potential improvements.

PCI-DSS Compliance Consulting

The PCI Data Security Standard (Payment Card Industry Data Security Standard – PCI DSS) is a standard established by a council of credit card companies such as VISA, Mastercard, Discover, American Express, and JCB, and is expected to be followed by all merchants and financial institutions processing credit card transactions. This standard defines numerous requirements for merchants to protect cardholder information. Since 2010, banks in Türkiye have also been requiring and expecting merchants to conduct transactions in accordance with this standard. Our PCI-certified technology consultants provide support in completing your organization's preparations and conducting self-assessments based on the SAQ (Safety Quality Question) statement.

Vulnerability Analysis & Penetration Testing / APT Tests

Vulnerability analysis, or vulnerability assessment, is the in-depth examination and analysis of vulnerabilities in organizational structures, prioritizing them according to their importance. The goal is to identify and correct vulnerabilities that could disrupt process flow before attacks occur, or to minimize them.
Penetration testing (or penetration testing) is:
* Determining which data and/or systems the structure can access.
* Determining which data and/or internal systems the structure can access.
These situations are detected by deliberately attacking systems using pre-determined vulnerabilities.

Information Security Awareness Services

A major risk threatening information security is a lack of employee awareness regarding security issues. Regular training is a fundamental element of this service and a key factor in increasing employee awareness levels. As an additional option, we can conduct tests to assess and report on your organization's awareness levels.

SOC/SOME Services

The primary objective of this service is to guide and organize institutions that will establish their own Cyber Incident Response Teams (CIRT) and take the necessary measures to ensure national cybersecurity under the control and guidelines of the National Cyber Incident Response Center (USOM).

pepsi-logo_5ef1c15f0cbd8.jpg
petrol-ofisi_5ef1c172a92f7.jpg
philips-morris_5ef1c2fb27957.jpg
wittur_5ef1c18fb2764.jpg
egis_5ef1c342829b7.jpg
sita_5ef1c362b8fca.jpg