Skip to content
Scale Technology and Consulting · Service Catalog · Version 2026.1LAW NUMBER 7545 IS IN FORCE · ANNUAL AUDIT IS MANDATORY
SERVICE CATALOGUE
COMPLIANCE · AUDIT · TECHNICAL ASSURANCE

Cyber Security Service Catalog
Obligation is not a choice. That's the preparation.

Cyber Security Law No. 7545, EMRA SGYM Regulation and KVKK No. 6698; It has subjected public institutions, critical infrastructure operators and corporate companies to an obligation regime with a schedule and sanctions, rather than a recommendation. This catalog includes the services that meet each article of that regime; It presents it in a single file with its scope, methodology and official outputs.

NUMBER OF SERVICES
13
CATEGORY
4
INSPECTION PERIOD
1 per year
PENALTY UPPER LIMIT
17.09 M₺

sanctions board

The amounts below are not recommendations, but administrative fine bands stipulated by the current legislation. The gap between the cost of compliance and the cost of enforcement is closed in most institutions by a single violation.

ADMINISTRATIVE FINE BANDS IN FORCE
SOURCEVERBAMOUNT
7545 p. Cyber Security LawNot taking cyber security measures / not reporting vulnerabilities and incidentsm. 16/10 (art. 7/1-b)1.000.000 – 10.000.000 ₺
7545 p. Cyber Security LawNon-compliance with audit obligationsm. 16/11 (art. 8/4); up to 5% of gross sales revenue in commercial companies100.000 – 1.000.000 ₺
6698 p. KVKKFailure to fulfill obligations regarding data securitym. 18/1-a; Amount applied to 2026 revaluation rate (25.49%)256.357 – 17.092.242 ₺
6698 p. KVKKFailure to comply with board decisionsm. 18/1-c; 2026 amount427.263 – 17.092.242 ₺
6698 p. KVKKFailure to fulfill the obligation to informm. 18/1-a; 2026 amount85.437 – 1.709.200 ₺
EMRA SGYM RegulationFailure to carry out independent sectoral audit on timeRG 06.06.2023/32213Risk in administrative sanction / licensing processes

KVKK amounts are current values ​​with the 2026 revaluation rate (25.49%) applied and are updated at the beginning of each calendar year. In case of obtaining benefit or causing damage within the scope of Law No. 7545, the penalty may be applied as up to three to five times the benefit or damage. The table is for informational purposes only; It does not replace legal opinion. For source texts, see the links in the SOURCE column. Last check: 23.09.2026.

CATEGORY 1 · ESTABLISH THE OBLIGATION

Compliance, Maintenance and Support Consultancy

End-to-end consultancy services that establish your legal and standards-based obligations from scratch, make them ready for certification and keep them alive against changing legislation.

UD-01

KVKK Compliance, Internal Audit, Maintenance and Support Consultancy6698 p. law

Designs the technical and administrative measures within the scope of KVKK No. 6698 by combining law, cyber security and governance disciplines; Integrated service that verifies in the field with independent auditing and keeps it constantly updated against changing legislation.

KVKK compliance consultancyKVKK internal auditLaw No. 6698personal data inventoryVERBISdata security guide
Service information, scope, deliveries and frequently asked questions
CATEGORY
Compliance, Maintenance and Support Consultancy
TYPICAL DURATION
Compliance: 3–5 months Independent audit: 3–6 weeks Maintenance and Support: 12 months (renewable)
FOR WHOM
All private sector organizations and public institutions acting as data controllers; especially healthcare, finance, retail, energy, telecom and human resource-intensive organizations that process large amounts of contact data.

DESCRIPTION OF THE SERVICE

This service is an integrated consultancy and audit model that brings together law, cyber security and governance disciplines to ensure that your organization fulfills its legal obligations under the Personal Data Protection Law No. 6698 and that the compliance process does not only remain on paper but provides real benefit to your business. The service consists of compliance consultancy, independent audit, maintenance and support modules; It includes designing the technical and administrative measures to be taken to prevent personal data from being processed and accessed unlawfully, verifying their effectiveness by independent auditors, and keeping the process constantly updated.

WHY IS IT NECESSARY?

Within the scope of Law No. 6698, it is a legal obligation for all data controllers to comply with the provisions of the Law and take all kinds of technical and administrative measures to ensure the necessary level of security (KVKK article 12). Being exempt from the obligation to register in the VERBIS registry does not mean that you are exempt from the Law. In order to prevent administrative fines, loss of reputation and possible data breaches, it is a critical requirement for institutions to periodically check their data processing activities and regularly carry out the audits prescribed by the Board from an external and independent perspective.

SANCTION AND RISK THRESHOLD

If data security obligations are not fulfilled, an administrative fine in the range of 256,357 ₺ - 17,092,242 ₺ may be imposed for 2026. If the Board's decisions are not fulfilled, the lower limit increases to 427,263 ₺.

LEGAL AND NORMATIVE BASIS

  • KVKK No. 6698
  • Personal Data Security Guide (KVKK Institution)
  • Regulation on Data Controllers Registry
  • TCK art. 135–140

ADDED VALUE PROVIDED

Synergy of law, cybersecurity and governance

The process is not seen as just legal documentation; Information security and cyber security dimensions are also included in the process and the administrative and technical measures expected by the Board (Data Security Guide) are fully integrated in the field.

Independent verification and objective analysis

Even if you have completed the integration process internally or with another provider, you will clearly see your compliance level and have valid and reliable evidence before the Authority, thanks to the objective report of our independent auditors.

Maintenance, support and proactive approach

Change management is applied on a semi-annual and annual basis in response to changing business processes and updated legislation. In case of a possible complaint, request or Board review, the institution is provided with immediate proactive legal and technical support.

Process isolation and confidentiality assurance

Your information security and trade secrets are secured in line with the confidentiality commitments signed from the beginning to the end of the process.

SERVICE SCOPE AND METHODOLOGY

MODULE 1KVKK Compliance ConsultancyMODULE 2KVKK Independent AuditMODULE 3Maintenance and Support (Continuousharmony)MODULE 4Training Program
MODULE 1
KVKK Compliance Consultancy

Organization and planning: identification of compliance teams, assignment of roles and responsibilities, preparation of personal data inventory, risk analysis and privacy impact assessment. Implementation: preparation of policies and procedures regulating data protection processes (Storage and Destruction Policy, etc.), implementation of risk processing actions, integration of administrative and technical measures. Control: checking the implemented measures and verifying them by internal audit.

MODULE 2
KVKK Independent Audit

Planning: understanding the organizational structure, examining the relevant processes in detail, creating the audit program by drawing the audit scope and boundaries. Field implementation: review of procedures and policies, evaluation of the effectiveness of data processing activities and technical/administrative controls in the field, detection and analysis of findings. Reporting: classifying findings in an actionable way, reporting people-process-technology requirements.

MODULE 3
Maintenance and Support (Continuous Adaptation)

Monthly support: information about new regulations, additional precautionary recommendations, bulletin sharing, legal/technical support in possible complaints and investigations. Six-month change management: updating business processes, processed data, contracts and changes in legislation in terms of compliance with KVKK. Annual evaluation: awareness training and repeating the comprehensive annual KVKK audit.

MODULE 4
Training Program

Organizing KVKK awareness, compliance process and technical measures trainings for institution personnel and special KVKK trainings for managers.

DELIVERIES AND OUTPUTS

  • Personal Data Processing Inventory and Privacy Risk Analysis Tables
  • Set of policies, procedures, clarification texts and contract annexes prepared within the scope of KVKK (administrative measures)
  • Technical Measures and Information Security Assessment Status Report
  • Independent KVKK Audit Report valid before the Board (detections, finding prioritization and solution road map)
  • Monthly KVKK information bulletins and six-month change management situation analyzes
  • Training participation certificates and measurement-evaluation results for staff and managers

TARGET OUTPUT / SUCCESS CRITERIA

  • During the processing of personal data, legal obligations are fully fulfilled not only with legal texts but also with the assurance of technological infrastructure compatible with the Data Security Guide.
  • The risk of administrative fines and loss of reputation is minimized by obtaining an "Independent Audit Report" that may be requested by the Board or that will protect the institution in case of a possible violation.
  • By moving away from a static compliance structure, a dynamic and sustainable data protection culture that can instantly react to changing corporate processes and new legal regulations is achieved.

FREQUENTLY ASKED QUESTIONS

We are exempt from VERBIS registration, do we need KVKK audit?
Yes. Being exempt from the VERBIS registration obligation is exempt from other obligations of Law No. 6698 - especially art. It does not provide exemption from the obligation to take technical and administrative measures within the scope of Article 12. Audit is the only objective tool that proves the existence and effectiveness of these measures.
We did the compliance work with another company; Can you also do the inspection?
Yes, this is the preferred fiction. Carrying out consultancy and auditing by different parties is a requirement of the principle of segregation of duties and increases the reliability of the report before the Board.
Does the audit report protect us during Board review?
The report is concrete evidence that shows that the institution pays due attention and checks the measures periodically. This is a decisive factor in determining the penalty in a possible investigation.

TAGS

KVKK compliance consultancyKVKK internal auditLaw No. 6698personal data inventoryVERBISdata security guideindependent KVKK auditstorage and destruction policyDPIA
UD-02

Information and Communication Security Guide (BİGR) Implementation Process Consultancy7545 p. law

A systematic consultancy model that manages the BIGR compliance process end-to-end, from planning to BIGDES reporting, and establishes documentation from scratch for public institutions and critical infrastructure operators.

BIGR compliance consultancyBIGDESCyber Security Law No. 7545entity groupingANNEX-C.1 criticality degreecompensatory control
Service information, scope, deliveries and frequently asked questions
CATEGORY
Compliance, Maintenance and Support Consultancy
TYPICAL DURATION
Typical compliance program 6–9 months Annual check and BIGDES cycle is continuous
FOR WHOM
Public institutions and organizations, critical infrastructure operators (energy, electronic communications, finance, transportation, water management, critical public services) and IT suppliers serving them.

DESCRIPTION OF THE SERVICE

This service is a systematic solution partnership and consultancy model that manages the BIGR compliance process of public institutions and critical infrastructure operators end-to-end, from planning to audit reporting, within the legal framework changed by the Cyber Security Law No. 7545. The process goes beyond being just a “guideline compliance” and includes identifying assets, minimizing risks, and making the institution fully ready for the auditing standards of the Cyber ​​Security Directorate.

WHY IS IT NECESSARY?

BIGR compliance, which started with the Presidential Circular dated July 6, 2019, is a legal obligation for the security of digital assets. Today, this obligation has entered directly into the control and sanction area of the Cyber Security Directorate with the Cyber Security Law No. 7545. Incomplete, incorrect or delayed BIGR processes and BIGDES notifications; It causes institutions to face high administrative fines and causes serious cyber vulnerabilities.

SANCTION AND RISK THRESHOLD

Law No. 7545 art. In accordance with Article 16, failure to take cyber security measures and violation of the notification obligation may be sanctioned with an administrative fine of 1,000,000 ₺ - 10,000,000 ₺. In case of benefit or loss, the penalty may be imposed as up to three to five times the benefit/damage.

LEGAL AND NORMATIVE BASIS

  • Cyber Security Law No. 7545
  • Presidential Circular No. 2019/12
  • Information and Communication Security Guide
  • Cyber Security Presidency regulations

ADDED VALUE PROVIDED

Legal assurance and criminal protection

Risks of heavy administrative fines and sanctions that may be imposed by the competent authorities within the scope of Law No. 7545 are proactively eliminated.

Full integration with existing systems (ISO 27001)

Assets that require the same security level are isolated and grouped and combined with your existing ISMS inventory without creating duplicate effort.

Defense with global principles

Global approaches such as Security by Design, Privacy by Design, Defense in Depth and the Minimum Authority Principle are integrated into the corporate culture.

Dynamic and constant adaptation

Cybersecurity is not left static; Asset changes and new version updates of the Cyber ​​Security Directorate are instantly adapted to the corporate infrastructure through the Change Management process.

SERVICE SCOPE AND METHODOLOGY

STAGE 1Planning — Strategic PathmapSTAGE 2Application and DocumentationSTAGE 3Control and AuditManagementSTAGE 4Change Management —continuity
STAGE 1
Planning — Strategic Road Map

Identifying asset groups such as network, system, application, IoT, portable media, physical space and personnel. Determining the criticality levels (Degree 1, 2, 3) and performing the Current Situation (Gap) Analysis showing the deficiencies (Completely, Partially, None) using the ANNEX-C.1 Survey Form in line with the principles of Confidentiality, Integrity and Accessibility (CIA).

STAGE 2
Application and Documentation

Implementing the planned measures together with the institution's personnel, providing support for the choice of domestic and national products in technical specifications, and preparing all documents, policies and procedure sets in accordance with the Guide end-to-end / from scratch.

STAGE 3
Control and Audit Management

Managing the audit process, which must be carried out at least once a year within the scope of BIGR, and ensuring that the results obtained (including ANNEX-A, B, E, F, H forms) are uploaded to the official BIGDES system completely and without errors.

STAGE 4
Change Management — Continuity

Commissioning of new systems, changing asset criticality levels and constantly revising the compliance plan according to Guide updates.

DELIVERIES AND OUTPUTS

  • BİGR Asset Groups Inventory and ANNEX-C.1 Criticality Rating Analyzes
  • Current Situation / Gap Analysis Report and Implementation Roadmap
  • ANNEX-C.5 Compensatory Controls Framework for technically impracticable measures
  • Institution-specific BIGR administrative and technical measures documentation set (policy, procedure, form)
  • Official control forms ready to be uploaded to the BIGDES system (ANNEX-A, B, E, F, H)
  • BIGR training and workshop reports to increase personnel competence

TARGET OUTPUT / SUCCESS CRITERIA

  • Legal BIGR obligations required by Law No. 7545 and the Presidential Circular are fully completed at the legal and operational level without the risk of administrative fines.
  • Mandatory audit processes and BIGDES notifications are completed without any ambiguity, with error-free forms and in accordance with the Cyber Security Presidency standards.
  • An IT infrastructure that internalizes security and privacy-based design, is resistant to cyber threats and data leaks, and meets national security expectations is achieved.

FREQUENTLY ASKED QUESTIONS

We have ISO 27001 certification, is BIGR compliance still required?
Yes. ISO 27001 is a voluntary management system standard, while BIGR is a legal obligation for the institutions within the scope. However, the two studies can be combined on a largely common inventory and risk basis; This allows for significant reductions in effort and costs.
We cannot technically implement a measure, what happens?
The Guide foresees a compensatory control mechanism for this situation. Justification, alternative control and residual risk are recorded within the framework of ANNEX-C.5; Thus, a managed exception is created, not a non-compliance.
Will we do the BIGDES installation?
Installation is the official responsibility of the institution; We produce and verify the content of the forms ready for auditing and accompany the uploading process.

TAGS

BIGR compliance consultancyBIGDESCyber Security Law No. 7545entity groupingANNEX-C.1 criticality degreecompensatory controlCyber Security Directoratecritical infrastructure
UD-03

ISO/IEC 27001 Information Security Management System (ISMS) Compliance Consultancy and Internal AuditISO/IEC 27001

It's not a copy-paste template; A living ISMS architecture designed according to the business processes, organizational structure and risk appetite of the institution, aiming for zero major findings in the certification audit.

ISO 27001 consultancyISMS installationDeclaration of ApplicabilitySOAinformation assets inventoryISO 27001 internal audit
Service information, scope, deliveries and frequently asked questions
CATEGORY
Compliance, Maintenance and Support Consultancy
TYPICAL DURATION
Typical program 4–8 months (depending on scope size) Annual internal audit cycle
FOR WHOM
All organizations that enter into public tenders, serve corporate customers or operate in regulated sectors; software and cloud service providers, call centers, data centers and MSSPs.

DESCRIPTION OF THE SERVICE

This service is an end-to-end consultancy model designed to protect your organization's information assets, systematically manage cyber risks and comply with the internationally valid ISO/IEC 27001 standard. This process is not just a paper work; It involves establishing a governance system that integrates people, process and technology pillars into your corporate culture, increases your living and cyber resilience.

WHY IS IT NECESSARY?

In today's world where cyber attacks, data breaches and ransomware cases are rapidly increasing, protecting information assets is the primary responsibility of not only technical teams but also top management. In addition, participation in public tenders; In order to comply with regulatory authorities such as KVKK, BİGR, BRSA, EMRA and to make business partnerships with global brands, ISO 27001 certification is no longer an optional prestige, but a mandatory commercial and contractual criterion.

SANCTION AND RISK THRESHOLD

Although a direct administrative fine is not foreseen; Lack of certification leads to direct commercial losses such as elimination in public tenders, termination of corporate customer contracts and “unemployable” decisions in supplier audits.

LEGAL AND NORMATIVE BASIS

  • ISO/IEC 27001
  • ISO/IEC 27002
  • ISO/IEC 27005
  • Public tender technical specifications
  • Customer and supply chain contract terms

ADDED VALUE PROVIDED

Realistic and living system

Instead of copy-pasting templates from the internet; A dynamic ISMS architecture is designed that fully suits the business processes, organizational structure and risk appetite of the institution and does not make daily operations cumbersome.

Integrated GRC approach

By using the High Level Structure (High Level Structure) of ISO 27001, your system is combined with other standards such as KVKK, BİGR, ISO 27701 and ISO 9001 under the same roof; Audit fatigue and waste of effort are prevented.

Full audit readiness — zero non-conformance target

Thanks to independent internal audit simulations performed by our experts with ISO 27001 Chief Auditor competence, the risk of major findings in audits of external certification bodies is eliminated.

SERVICE SCOPE AND METHODOLOGY

STAGE 1Current Situation Analysisand ScopingSTAGE 2Asset and RiskManagementSTAGE 3Documentation andApplicationSTAGE 4Training and OperationSTAGE 5Internal Audit and YGG
STAGE 1
Current Situation Analysis and Scoping

Analyzing the organization of the institution, clearly drawing the boundaries of the ISMS and identifying the gaps between the requirements of the standard and the current situation (Gap Analysis).

STAGE 2
Asset and Risk Management

Inventorying information assets, analyzing cyber security risks in line with CIA principles and creating a Risk Treatment Plan.

STAGE 3
Documentation and Application

Based on the Declaration of Applicability (SoA); End-to-end / from scratch preparation of ISMS policies, procedures, instructions and form sets in accordance with the corporate culture and operational functioning.

STAGE 4
Training and Operation

Implementation of information security awareness trainings, incident/violation management, business continuity drills and technical security controls for all employees in the field.

STAGE 5
Internal Audit and YGG

Measuring the system performance through internal audit by our impartial and independent auditors, closing the deficiencies with CPA and accompanying the Management Review meeting.

DELIVERIES AND OUTPUTS

  • Current Situation (Gap) Analysis Report and Project Roadmap
  • Detailed Information Asset Inventory and ISMS Risk Assessment / Risk Processing Matrix
  • Statement of Applicability (SoA)
  • Institution-specific integrated ISMS documentation set (policy, procedure, instruction)
  • Personnel information security awareness training records and exam results
  • Independent internal audit report, DÖF registration forms and YGG meeting minutes

TARGET OUTPUT / SUCCESS CRITERIA

  • An official certificate is obtained by passing the ISO 27001 Stage 1 and Stage 2 audits of accredited certification bodies without any problems.
  • Information security becomes a sustainable governance culture that is spread across the entire organization, rather than a technical issue that is solely the responsibility of the IT department.
  • Instead of making reactive decisions against cyber incidents and business interruptions; A pre-planned, tested and provable security infrastructure is established against legal authorities.

FREQUENTLY ASKED QUESTIONS

Are you providing the document?
No. Certification is under the authority of an accredited certification body. We set up the system, independently conduct the internal audit and accompany Stage 1–2 audits. This distinction is a requirement of neutrality of the standard.
How many documents are produced?
The number of documents is not a measure of success. According to the scope and SoA decisions, the simplest operable set is targeted; The aim is to establish a structure that does not slow down the operation and is actually used.
Can it be combined with our current KVKK study?
Yes. Combination is done through a common asset inventory, common risk methodology and common policy framework; This reduces two separate project costs into a single program.

TAGS

ISO 27001 consultancyISMS installationDeclaration of ApplicabilitySOAinformation assets inventoryISO 27001 internal auditrisk treatment plancertification audit preparation
UD-04

ISO/IEC 27701 Personal Data Management System (KVYS/PIMS) Compliance Consultancy and Internal AuditISO/IEC 27701

Independent standards compliance consultancy that transforms KVKK and GDPR obligations into an internationally auditable and certifiable privacy management system (PIMS).

ISO 27701 consultancyPIMSKVYSGDPR complianceDPIAdata controller data processor
Service information, scope, deliveries and frequently asked questions
CATEGORY
Compliance, Maintenance and Support Consultancy
TYPICAL DURATION
Typical program 4–7 months Shortened to 3–4 months if ISO 27001 available
FOR WHOM
Organizations that transfer data abroad or process the data of data subjects resident in the EU; technology and BPO companies serving as data processors; Health and insurance organizations that process large-scale sensitive data.

DESCRIPTION OF THE SERVICE

This service is a strategic consultancy model that covers KVKK, GDPR and other international data protection regulations in order to ensure the security and privacy of personal data (PII) processed by your institution. ISO 27701, which is an independent and fully comprehensive management standard on its own with its updated structure; It transforms your personal data management processes into an internationally auditable, certifiable and provable management system in accordance with your “Data Controller” and “Data Processor” roles.

WHY IS IT NECESSARY?

Today, compliance with legal regulations such as KVKK or GDPR cannot be achieved only with clarification texts or contracts prepared by lawyers. Institutions are expected to prove at international standards how they apply technical and administrative security measures in the entire process from collection to destruction of personal data. In this period when data breaches lead to administrative fines of millions of liras and irreversible reputational losses, ISO 27701 closes the gap between law and information technologies.

SANCTION AND RISK THRESHOLD

Violation of data security obligations on the KVKK side: 256,357 ₺ – 17,092,242 ₺ for 2026; On the GDPR side, it may be subject to administrative fines of up to 4% of global annual turnover.

LEGAL AND NORMATIVE BASIS

  • ISO/IEC 27701
  • KVKK No. 6698
  • EU General Data Protection Regulation (GDPR)
  • Regulations regarding data transfer abroad

ADDED VALUE PROVIDED

Global trust and GDPR compliance

It allows you to prove to your international customers, business partners and regulators with an official certificate that you protect personal data not only according to local laws but also according to global ISO standards.

Independent and comprehensive governance

ISO 27701 has gone beyond being an add-on and has been designed as an independent standard that can manage privacy and data protection processes on its own, end-to-end.

Legal and IT integration

It transforms the abstract legal requirements of the law into concrete and measurable technical controls that IT and information security teams can implement.

Full audit readiness — zero non-conformance target

External certification risk is eliminated with independent internal audit simulations performed by our ISO 27701 competent experts.

SERVICE SCOPE AND METHODOLOGY

STAGE 1Current Situation Analysisand ScopingSTAGE 2PII RiskEvaluationSTAGE 3Documentation andGovernance DesignSTAGE 4Training and OperationSTAGE 5Internal Audit and YGG
STAGE 1
Current Situation Analysis and Scoping

Analyzing the institution's Data Controller and/or Data Processor. Identifying gaps between existing KVKK/GDPR processes and the independent requirements of the ISO 27701 standard.

STAGE 2
PII Risk Assessment

Analyzing risks and creating risk treatment plans by performing Privacy Impact Assessment (PIA/DPIA) through Personal Data Inventory.

STAGE 3
Documentation and Governance Design

End-to-end / from scratch preparation of the entire set of documents in accordance with the corporate culture, including privacy policies, data breach communication procedures, data subject application processes, clarification texts and forms.

STAGE 4
Training and Operation

Data privacy and security awareness training; Implementation of data storage, masking, anonymization and destruction processes in the field.

STAGE 5
Internal Audit and YGG

Measuring the KVYS performance by our independent auditors, closing the findings with the CPA and technical support during the certification processes.

DELIVERIES AND OUTPUTS

  • ISO 27701 Current Situation (Gap) Analysis Report and Project Roadmap
  • Comprehensive Personal Data (PII) Inventory and Privacy Risk Assessment Matrix
  • KVMS Declaration of Applicability (SoA)
  • Institution-specific KVMS documentation set (policy, procedure, business processes)
  • Personnel data privacy awareness training records
  • Independent internal audit report, CPA records and YGG executive summary presentation

TARGET OUTPUT / SUCCESS CRITERIA

  • Personal data protection standards are certified by passing the ISO 27701 Stage 1 and Stage 2 audits of accredited certification bodies without any problems.
  • KVKK and GDPR compliance ceases to be a legal obligation and turns into a corporate reflex and an element of international trust.
  • A sustainable privacy management infrastructure is established that minimizes the risk of administrative fines and loss of reputation that may arise from data breach, leakage or employee error.

FREQUENTLY ASKED QUESTIONS

Can ISO 27701 be obtained without ISO 27001?
The current structure of the standard has made ISO 27701 independently certifiable. On the other hand, an existing ISMS significantly reduces time and cost.
Does ISO 27701 certificate mean KVKK compliance?
Documentation alone is not a substitute for legal compliance; but KVKK m. It is the most powerful tool that proves the existence and operation of technical and administrative measures within the scope of 12 at the international level.
Our overseas customers request an audit. Will this document be sufficient?
In most cases yes. ISO 27701 certification is a widely accepted assurance tool that shortens the repetitive question set processes in customer audits.

TAGS

ISO 27701 consultancyPIMSKVYSGDPR complianceDPIAdata controller data processorpersonal data inventoryprivacy impact assessment
UD-05

ISO/IEC 42001 Artificial Intelligence Management System (AIMS) Compliance and Consultancy ServiceISO/IEC 42001

Systematically manages the operational, legal and ethical risks of machine learning and generative artificial intelligence projects; The world's first AI governance standard compliance program that provides proactive preparation for the EU AI Act.

ISO 42001 consultancyartificial intelligence management systemAIMSEU AI Act compliancealgorithmic biasresponsible artificial intelligence
Service information, scope, deliveries and frequently asked questions
CATEGORY
Compliance, Maintenance and Support Consultancy
TYPICAL DURATION
Typical program 4–6 months Shortened to 3 months if ISO 27001/27701 available
FOR WHOM
Technology companies developing their own AI models; Institutions that use Generative Artificial Intelligence in customer service, credit, recruitment or decision support processes; Exporters offering products/services to the EU market.

DESCRIPTION OF THE SERVICE

This service is a strategic consultancy model that covers the compliance process with ISO/IEC 42001, the world's first artificial intelligence management standard, in order to ensure that your organization develops or uses artificial intelligence systems in a safe, transparent, ethical and traceable manner in its operations. Our service aims to enable you to benefit from the power of artificial intelligence in a controlled, responsible and reliable way by minimizing the operational, legal and ethical risks inherent in machine learning (ML) and generative artificial intelligence (Generative Artificial Intelligence) projects.

WHY IS IT NECESSARY?

Rapid integration of artificial intelligence technologies into business processes; It brings with it huge corporate risks such as data privacy violations, algorithmic bias, hallucination, copyright issues and lack of transparency. In addition, binding global regulations such as the European Union Artificial Intelligence Law (EU AI Act) impose heavy penalties on institutions based on their global turnover in case of violations.

SANCTION AND RISK THRESHOLD

Within the scope of the EU AI Act, administrative fines of up to 7% of the global annual turnover are foreseen for prohibited applications and 3% for high-risk system liabilities. Türkiye-based organizations that offer products/services to the EU market are also included.

LEGAL AND NORMATIVE BASIS

  • ISO/IEC 42001
  • EU Artificial Intelligence Law (EU AI Act)
  • ISO/IEC 23894 (AI risk management)
  • NIST AI Risk Management Framework
  • KVKK No. 6698 (automatic decision making)

ADDED VALUE PROVIDED

Safe and responsible use of AI

It protects your brand reputation from crises by ensuring that your AI systems operate in an impartial, explainable and ethical manner.

Proactive compliance with global regulations

It allows you to be ready today for not only today's but also tomorrow's international artificial intelligence laws and legal requirements.

Integrated governance (Top Level Structure)

ISO 42001; It prevents waste of effort and budget by working fully integrated with the existing ISO 27001 and ISO 27701 systems in your institution through a common language and structure.

Accelerating innovation with confidence

Prevents AI projects from getting bogged down by legal departments or security concerns; It supports your technology teams to produce quickly by setting safe boundaries (guardrails).

SERVICE SCOPE AND METHODOLOGY

STAGE 1Current Situation (Gap)AnalysisSTAGE 2AI Asset Inventoryand RiskEvaluationSTAGE 3Governance, Politicsand Process DesignSTAGE 4Education andawarenessSTAGE 5Internal Audit andCertificationSupport
STAGE 1
Current Situation (Gap) Analysis

Review of the organization's current AI policies, supplier contracts and business processes according to ISO 42001 requirements.

STAGE 2
AI Asset Inventory and Risk Assessment

Inventorying all internally developed or outsourced (SaaS/API-based) AI systems; Identifying risks with AI System Impact Assessment.

STAGE 3
Governance, Policy and Process Design

End-to-end / from scratch preparation of the entire set of documents in compliance with the standard, including the AI Code of Ethics, AI Acceptable Use Policy, Transparency Guidelines and Data Quality Standards.

STAGE 4
Education and Awareness

Providing Responsible Use of Artificial Intelligence and AI Security awareness training to technical teams (developers / data scientists) and all employees.

STAGE 5
Internal Audit and Certification Support

Independent internal audit before certification, CPA follow-up for findings and technical support during the external audit (Stages 1–2).

DELIVERIES AND OUTPUTS

  • ISO 42001 Current Situation (Gap) Analysis Report and Project Roadmap
  • Comprehensive Artificial Intelligence Systems Inventory and Risk/Impact Assessment Matrix
  • Integrated set of AIMS policies, procedures and forms with Statement of Applicability (SoA)
  • Staff awareness measurement and Responsible AI training completion reports
  • Internal audit report, CPA records and YGG executive summary presentation

TARGET OUTPUT / SUCCESS CRITERIA

  • The internationally valid ISO/IEC 42001 certificate is obtained from accredited certification bodies with the target of zero major findings.
  • Information security, data privacy, bias and transparency risks that may arise when integrating artificial intelligence into business processes are minimized.
  • An international certificate officially proves to customers, business partners and regulatory authorities that artificial intelligence is used in a safe, law-abiding and human-oriented manner.

FREQUENTLY ASKED QUESTIONS

We don't develop our own model, we just use ready-made AI tools. Are we covered?
Yes. The standard covers AI systems that are procured and used as well as developed. In most organizations, the real risk arises from SaaS/API-based tools that are not inventoried.
Why do we care about the EU AI Act?
The law is market based, not place based. If you offer products or services to the EU market, being resident in Turkey does not exclude you from the scope.
Does ISO 42001 slow down innovation?
On the contrary. Predefined safe boundaries eliminate the need for legal and security approval for each AI project.

TAGS

ISO 42001 consultancyartificial intelligence management systemAIMSEU AI Act compliancealgorithmic biasresponsible artificial intelligenceartificial intelligence impact assessmentGenerative AI governance
UD-06

ISO 27019 & SGYM Compliance, Maintenance and Support ConsultancyOT / ICS

Centering on the OT and ICS dynamics of the energy sector; Consultancy that builds industrial cyber resilience architecture by integrating ISO 27019, IEC 62443 and EMRA SGYM requirements into the ISO 27001 framework.

ISO 27019 consultancyEMRA SGYM complianceIEC 62443OT securitySCADA securityPurdue model
Service information, scope, deliveries and frequently asked questions
CATEGORY
Compliance, Maintenance and Support Consultancy
TYPICAL DURATION
Typical program 8–12 months Scales according to number of sites and facilities
FOR WHOM
Electricity distribution and production companies, natural gas distribution companies, refineries, transmission operators, OIZ electricity distribution license holders and industrial facilities operating critical infrastructure.

DESCRIPTION OF THE SERVICE

This service is a comprehensive consultancy and governance model that goes beyond classical IT security requirements and centers on the dynamics of Operational Technology (OT) and Industrial Control Systems (ICS), which are the heart of the energy sector. It is created by integrating industrial standards (ISO 27019, IEC 62443) and EMRA Cyber ​​Security Competency Model (SGYM) administrative and technical requirements on top of the basic ISO 27001 ISMS.

WHY IS IT NECESSARY?

Energy infrastructures; It is a primary target of state-sponsored cyber threat actors, ransomware groups and supply chain attacks. Classical IT security approaches do not coincide with the "process integrity" and "operational uninterruptibility" principles of industrial systems such as SCADA, PLC, RTU. It is vital to protect energy production, transmission and distribution processes against destructive effects in the physical world (production stoppage, environmental disaster, life safety risk). In addition, to comply with EMRA regulations and Law No. 7545; A sector-specific standardized model is essential to prevent heavy sanctions such as administrative fines and license cancellation.

SANCTION AND RISK THRESHOLD

Administrative fines and sanctions in licensing processes within the scope of EMRA legislation; Within the scope of Law No. 7545, there is a risk of administrative fines in the range of 1,000,000 ₺ - 10,000,000 ₺.

LEGAL AND NORMATIVE BASIS

  • EMRA Cyber Security Competency Model (SGYM) Regulation — June 6, 2023
  • Cyber Security Law No. 7545
  • ISO/IEC 27019
  • IEC 62443 series
  • EKS Security Procedures and Principles
  • NIST SP 800-82

ADDED VALUE PROVIDED

Operational continuity and physical security

By prioritizing “zero interruption” (availability) and “safety” in OT environments, a mathematical risk modeling and solution architecture that does not put production lines at risk is presented.

Hybrid and integrated security architecture

The managerial framework of ISO 27001 is combined with the technical depth of the IEC 62443 series. The boundaries between IT and OT networks are clarified according to the international Purdue Model, preventing lateral cyber attacks (lateral movement).

Full and sustainable compliance with regulations

EPDK SGYM, BİGR and KVKK compliance is ensured. Processes are given a structure that is independent of individuals, based on corporate memory, and measurable.

Proactive crisis and incident management capability

Both the technical intervention reflexes of field engineers (Red/Purple Teaming, threat hunting) and the strategic crisis management of the management level (desktop exercises) are tested and developed in practice.

SERVICE SCOPE AND METHODOLOGY

PURDUE REFERENCE ARCHITECTURE — REGION AND CHANNEL DIFFERENCELEVEL 4-5Corporate IT / ERPBusiness applications, office networkDMZIndustrial DMZData diode, bounce server, unidirectional transferLEVEL 3Operations ManagementHistorian, OT-SOC, patching and backupLEVEL 2Supervisory ControlSCADA/HMI, engineering stationLEVEL 1Basic ControlPLC, RTU, IEDLEVEL 0Field DevicesSensor, actuator, smart meter
STAGE 1
Project Start and Current Situation Analysis

Drawing IT and OT network boundaries, preparing scope documentation (SoA). Analysis of the current maturity level and deficiencies of the institution with reference to ISO 27019, EMRA SGYM and BİGR.

STAGE 2
EKS/OT Asset and Risk Management

Creating a detailed OT asset inventory including SCADA, PLC, RTU and smart meters. ISO 27005 and IEC 62443-3-2 (Zone & Conducting production continuity-oriented threat, vulnerability and risk analyzes with the Conduit) methodology.

STAGE 3
Governance, Policy and Process Design

Writing secure remote access, patch management, supplier security and USB usage policies specific to OT environments. Creation of Incident Response (IRP) and Business Continuity / Disaster Recovery (BCP/DRP) plans based on industrial scenarios.

STAGE 4
Technical Architecture Design and Solution Consultancy

OT network segmentation (DMZ, data diodes) in accordance with Purdue reference architecture, OT-SOC/SIEM monitoring architecture consultancy with understanding of Zero Trust IAM/PAM processes for third parties and industrial protocols (Modbus, IEC 104). Excludes product supply or configuration; architectural orientation is made.

STAGE 5
Testing, Simulations and Exercises

MITRE ATT without risking production&Technical cyber attack simulations (lateral movement, industrial protocol manipulation) within the framework of CK for ICS. Strategic cyber crisis tabletop exercises and transition to manual operation (BIA/DRP) tests for decision makers.

STAGE 6
Advanced Awareness and Training

EKS awareness training for field personnel in accordance with ISO 27019 standards. Advanced technical ICS defense training for engineers, including secure PLC coding, deep packet analysis and industrial threat hunting.

STAGE 7
Audit, YGG and Certification Support

Internal audit in accordance with ISO 27019 and EMRA norms before certification, CPA follow-up for findings, YGG reporting and accompanying the official certification body in Stage 1–2 audits.

DELIVERIES AND OUTPUTS

  • ISO 27019 & SGYM Compliance Gap Analysis Report
  • ICS/OT Asset Inventory Records and Mathematical Risk Processing Matrix
  • Declaration of Applicability (SoA) and integrated ISMS policy/procedure set
  • Industrial Incident Response (IRP) and Business Continuity (BCP/DRP/BIA) plans
  • Purdue Model network segmentation and security technologies architecture design document
  • Technical simulation (Red/Purple Team) results and tabletop exercise report
  • Internal audit report, CPA records and YGG executive summary presentation
  • Staff awareness measurement and training completion reports

TARGET OUTPUT / SUCCESS CRITERIA

  • The internationally valid ISO 27001 certificate is obtained to include ISO 27019 additional controls specific to the energy sector.
  • EMRA SGYM obligations are met with technical and administrative controls that actually operate in the field, not on paper, thus making it fully ready for official inspections.
  • A resilient industrial infrastructure with tested crisis reflexes that can maintain operational safety against the most advanced industrial attacks, including APT groups and sabotage, is achieved.

FREQUENTLY ASKED QUESTIONS

Does testing on our OT network stop production?
No. All technical activities are conducted with OT-specific methodologies that prioritize production continuity, through passive listening and testbed where possible; Active testing is carried out only during planned stops and with written agreement.
Who determines our SGYM level?
The level is determined by the regulation depending on the criticality class of the organization and is reported to EMRA via EBİS. Consulting establishes the set of controls needed to achieve the target level.
Does IEC 62443 conflict with ISO 27019?
No, they are complementary. ISO 27019 provides the administrative framework and energy sector-specific controls, and IEC 62443 provides technical depth such as zone/channel architecture and security levels.

TAGS

ISO 27019 consultancyEMRA SGYM complianceIEC 62443OT securitySCADA securityPurdue modelZone and ConduitEKS asset inventoryMITRE ATT&CK for ICSdata diode
UD-07

Cyber Hygiene Compliance ConsultancySSB / TRTEST

Preparing defense industry suppliers and critical sector SMEs for independent audits carried out by TRTEST within the scope of the SSB Cyber Hygiene Certification Program; End-to-end consultancy that measures the current situation in 13 key audit areas, establishes the path to the target maturity level and undertakes post-certificate operation.

Cyber Hygiene certificateSSB Cyber HygieneTRTEST auditdefense industry supplierClass A findingEYDEP
Service information, scope, deliveries and frequently asked questions
CATEGORY
Compliance, Maintenance and Support Consultancy
TYPICAL DURATION
Gap analysis 2–4 weeks Preparation program 2–5 months Annual operating and re-inspection cycle
FOR WHOM
Sub-suppliers and SMEs that provide products, software or services to defense industry prime contractors; Companies preparing for SSB tenders; Organizations that want to take part in the qualified supplier pool within the scope of EYDEP or maintain their position.

DESCRIPTION OF THE SERVICE

TRTEST Test and Evaluation Inc., established under the coordination of SSB and with the support of the Turkish Cyber ​​Security Cluster. Cyber ​​Hygiene Certification Program carried out by; It aims to ensure that main contractors and sub-suppliers in the defense industry ecosystem reach the minimum security level against cyber attacks. This service includes inspection based on the "Cyber ​​Hygiene Emergency Measures Criteria Set", officially known as the institution; It prepares you end-to-end, from selection of the target level to gap analysis, from pre-audit to post-document operation.

WHY IS IT NECESSARY?

Cyber Hygiene certificate is not a choice in the defense industry, but a requirement for market entry. Unlike documentation-focused management systems such as ISO 27001, the standard focuses directly on the technical configurations in the field and the operational resilience of the organization: the auditor wants to see the setting of your device, not your policy. RDP/Telnet ports left open, missing SPF-DKIM-DMARC records, admin panels exposed to the internet, untested penetration testing and default passwords are immediately considered a Class A (major) finding; Documentation cannot be obtained without closing these findings.

SANCTION AND RISK THRESHOLD

Exclusion from the market instead of monetary penalties: the company with a major finding in the audit cannot receive orders from main contractors; Poor cyber hygiene directly affects EYDEP classification and position in the pool of qualified suppliers. TSE approved penetration testing is mandatory for certification — due to the principle of independence, the testing is planned separately from the consulting team.

LEGAL AND NORMATIVE BASIS

  • SSB Cyber Hygiene Certification Program
  • Cyber Hygiene Emergency Measures Criteria Set (TRTEST)
  • TS 13638 Penetration Test Company Certificate (TSE)
  • EYDEP — Industrial Competence Assessment and Support Program

ADDED VALUE PROVIDED

Protecting market access

Class A finding candidates are made visible before the TRTEST inspection; The risk of delays in certification and loss of orders and tenders is reduced.

Correct target level

The correct one from Awareness, Basic, Medium or Advanced level is selected based on the main contractor contract terms, the confidentiality level of the processed data and the target tenders; Unnecessary costs and calendar burden are prevented.

Field-oriented preparation

Each of the thirteen areas of control is evaluated not by policy on paper but by actual configuration and evidence on the ground; There are no surprises left on the audit day.

Post-document continuity

The document is protected in re-audit cycles by running the periodic penetration test, awareness training and phishing simulation schedule required by the level.

SERVICE SCOPE AND METHODOLOGY

STAGE 1Target Level andScopingSTAGE 2Gap Analysis(13 Control Areas)STAGE 3Preparation andPreliminary AuditSTAGE 4Post Documentoperating
STAGE 1
Determining Target Level and Scope

Determining the maturity level (Awareness · Basic · Medium · Advanced) to be targeted through main contractor requirements, the degree of confidentiality of the processed data and target tenders; Clarifying the assets, locations and services open to the outside in scope.

STAGE 2
Gap Analysis (13 Control Areas)

Measuring the current situation in control areas S1–S13 based on configuration and evidence in the field; Prioritizing class A (major) finding candidates and creating a certification preparation road map.

STAGE 3
Preparation and Pre-Inspection

Follow-up of road map items with institutional teams, structuring the audit evidence file and verifying critical items with a preliminary audit before the TRTEST audit. The TS 13638 penetration test required by the level is planned separately from the consultancy team in accordance with the principle of independence.

STAGE 4
Post-Document Operation

Periodic control schedule for document preservation; Planning at least one or two penetration tests, staff awareness training and phishing simulations per year depending on the level; Preparation for the re-audit cycle.

13 CONTROL AREAS INSPECTED

  • S1 · Asset Management
  • S2 · System Update and Patch Management
  • S3 · Authorization and Access Control
  • S4 · Endpoint (Client) Security
  • S5 · Backup Management
  • S6 · Vulnerability Management and Security Tests
  • S7 · Risk Management
  • S8 · Awareness Trainings
  • S9 · System and Network Secure Configuration
  • S10 · App and Web Secure Configuration
  • S11 · Security Monitoring and Records Management
  • S12 · Data Security and Email Security
  • S13 · Incident and Violation Management

DELIVERIES AND OUTPUTS

  • Target Level and Scope Determination Note
  • Cyber Hygiene Gap Analysis Report (S1–S13)
  • Class A findings preliminary checklist and prioritized findings log
  • Certification Preparation Roadmap
  • Audit evidence file structure and preliminary audit report
  • Annual operating calendar (penetration testing, training, phishing simulation)

TARGET OUTPUT / SUCCESS CRITERIA

  • Cyber ​​Hygiene certificate at the targeted level is obtained without Class A (major) findings.
  • The ability to receive orders from main contractors and participate in SSB tenders is maintained; In EYDEP classification, loss due to cyber hygiene is prevented.
  • The document is maintained sustainably across re-audit cycles; cyber hygiene becomes a working routine, not a one-time project.

FREQUENTLY ASKED QUESTIONS

Does the Cyber Hygiene certificate replace ISO 27001?
No. The focus of the two frameworks is different: ISO 27001 measures the management system, while the Cyber ​​Hygiene audit measures the technical configuration on site. Evidence of an existing ISMS accelerates preparation but does not replace the document.
Do you also perform mandatory penetration testing?
TSE approved (TS 13638) penetration test is mandatory for certification. Due to the principle of independence, testing is planned separately from the consulting team; The test report is taken as input to the preparation road map.
What level should we aim for?
The contract terms of the main contractor, the degree of confidentiality of the processed data and the tenders planned to be entered are decisive. The target level is determined together through these three inputs in the first stage of the project.

TAGS

Cyber Hygiene certificateSSB Cyber HygieneTRTEST auditdefense industry supplierClass A findingEYDEPCyber Hygiene Emergency Measures Criteria SetTS 13638 penetration testSPF DKIM DMARCphishing simulation
CATEGORY 2 · COLLECT UNDER ONE ROOF

Holistic Packages

Multi-annual programs that combine technical assurance and GRC, consolidating all regulations that create waste of effort and budget when carried out separately from each other, under a single governance umbrella.

BP-01

Corporate Maturity, GRC and Cyber Resilience Program12 Months

Combining KVKK, ISO 27001/27701/42001 and Law No. 7545 obligations under a single governance umbrella; 12-month integrated model that brings GRC and technical assurance (penetration testing, threat hunting, SOME support) together in the same program.

GRC consultancycorporate maturity programcyber resilienceintegrated management systemKPI KRIthreat hunting
Service information, scope, deliveries and frequently asked questions
CATEGORY
Holistic Packages
TYPICAL DURATION
12 months · Monthly progress reporting · Renewable
FOR WHOM
Medium and large-sized organizations, holdings, group companies and fast-growing technology companies that are subject to multiple regulations at the same time.

DESCRIPTION OF THE SERVICE

This service; KVKK is a 12-month integrated strategic consultancy and governance model designed to ensure compliance with ISO 27001, ISO 27701, ISO 42001, Cyber ​​Security Law No. 7545 and Cyber ​​Security Presidency legislation, establish the information security infrastructure in accordance with international standards and increase technical resilience against cyber incidents. It is a proactive solution partnership that anticipates risks instead of reactive processes, ensures operational continuity and creates a sustainable ecosystem with in-house resources at the end of 12 months.

WHY IS IT NECESSARY?

In today's threat environment, treating GRC and technical cyber security as independent structures leads to operational security vulnerabilities and traceability deficiencies in institutions. Different requirements such as KVKK, ISO standards, Law No. 7545 and Cyber ​​Security Directorate regulations cause process confusion, budget waste and duplication of effort. It is inevitable to consolidate this structure with a holistic approach, create a strategic committee culture and have expert guidance in crises.

SANCTION AND RISK THRESHOLD

The program establishes a comprehensive line of defense at once against all administrative fine bands of Law No. 7545, ranging from 1,000,000 ₺ to 10,000,000 ₺, and KVKK, which reaches 17,092,242 ₺.

LEGAL AND NORMATIVE BASIS

  • Cyber Security Law No. 7545
  • KVKK No. 6698
  • ISO/IEC 27001
  • ISO/IEC 27701
  • ISO/IEC 42001
  • Cyber Security Presidency regulations

ADDED VALUE PROVIDED

Cost and effort optimization

KVKK, ISO standards and legal regulations are combined in a central management structure; By creating single asset inventories and consolidated risk registers, duplicate efforts of different units and allocation of multiple budgets for the same processes are prevented.

Synergistic value creation

Technical findings obtained through penetration tests and vulnerability scans are directly integrated with business processes and corporate risk analyzes to verify the effectiveness of theoretical policies in the field.

Alignment with business goals and managerial vision

Cybersecurity processes are positioned as a strategic component through the formation of GRC steering committees; Security investments become traceable through transparent KPI/KRI metrics.

Transition to a proactive security approach

Beyond traditional environmental security; The infrastructure is kept ready at all times with Zero Trust architecture, threat hunting, SOME support and cyber drills.

SERVICE SCOPE AND METHODOLOGY

SINGLE ROOFCorporate GRC and Cyber Resilience ProgramKVKKISO 27001ISO 27701ISO 420017545 p. lawTechnical AssuranceCONCLUSIONSingle asset inventory · consolidated risk register · common policy set · single KPI dashboard
BLOCK 1
Corporate Maturity and GRC Package

National Cyber Security Legislation (Law No. 7545) compliance level assessment and impact analysis. Design of an integrated policy/procedure set that meets ISO 27001, ISO 42001 and KVKK requirements. Methodological guidance and operational KPI/KRI definition for the GRC/BG/KVKK committee establishment. Operation of an integrated risk analysis methodology covering basic asset/process inventory and embedded/cloud systems. ISO 42001 AI Management System consultancy. Internal/external audit preparation and supplier chain security audits. Design of Business Continuity (BCP/DRP) framework, corrective action architecture support and GRC software selection consultancy. Cybersecurity awareness program and root cause analyzes for breach incidents.

BLOCK 2
Cyber Resilience and Technical Assurance Package

Extended Black/Grey-Box penetration testing (web, mobile application, API services, external/internal network). Active intervention support to SOME teams in possible crisis moments (crime scene investigation, isolation, digital forensics within SLA). New generation security architecture (Zero Trust, IAM, SOC use-case scenarios) and logging consultancy. “Secure Location IT Security Standard” design for distributed structures. Testing and integration (health-check/reference value) review of security technologies. Social engineering testing, evidence/trace analysis on 50 critical endpoints, and threat hunting (Breach Assessment). Tabletop cyber exercise crisis management moderation.

DELIVERIES AND OUTPUTS

  • Corporate Current Status Report, Risk Analysis and prioritized improvement plan
  • GRC Committee Structure Document (including RACI matrix) and integrated information security policy/procedure set
  • Business Continuity (BCP) and Disaster Recovery (DRP) framework document
  • Internal audit reports and supplier security audit report
  • Extended penetration testing and security technology assessment reports
  • Social engineering, awareness and cyber drill reports
  • Monthly progress reports and closing review in executive summary format

TARGET OUTPUT / SUCCESS CRITERIA

  • Corporate operations; KVKK is placed under a governance umbrella that is fully compatible with regulatory obligations such as ISO standards and Law No. 7545 and provides operational flexibility.
  • A resilient structure is established that goes beyond traditional IT deficiencies, proactively monitors cyber threats and can close gaps by integrating them into operational processes.
  • Investments are saved from duplicate regulation efforts and conflicting security technologies; It is transformed into a holistic ecosystem that is monitored with transparent KPIs and maintained with in-house resources.

FREQUENTLY ASKED QUESTIONS

Why 12 months?
This is the minimum time required to establish the governance structure, process risks, close the findings of technical tests and complete one full audit cycle. Shorter programs produce documentation, not culture.
Are you replacing our existing team?
No. The program is based on the transfer of knowledge; The obvious goal is to maintain the system with in-house resources at the end of 12 months.
Can we buy the blocks separately?
Receivable; but the real value of the package comes from the fact that technical findings flow directly into the risk register and management reporting. Segregation weakens this synergy.

TAGS

GRC consultancycorporate maturity programcyber resilienceintegrated management systemKPI KRIthreat huntingcompromise assessmenttabletop exerciseZero Trust
BP-02

Cyber Security, Corporate Maturity, Maintenance and Support Package Special for the Energy SectorEnergy / EMRA

Melting the holding and group companies' obligations of Law No. 7545, EMRA legislation, BİGR, SGYM, ISO 27001, IEC 62443 and ISO 42001 in a single pot; Integrated GRC program that manages IT and OT together.

energy cyber security consultancyEMRA complianceSGYMBIGRIEC 62443OT SCADA security
Service information, scope, deliveries and frequently asked questions
CATEGORY
Holistic Packages
TYPICAL DURATION
12 months and above · Scalable according to multi-company structure
FOR WHOM
Energy holdings and group companies; electricity/natural gas distribution and production license holders; refinery and transmission operators; structures that manage multiple facilities and legal entities.

DESCRIPTION OF THE SERVICE

This service is an integrated consultancy and governance model that consolidates the complex regulatory (Law No. 7545, EMRA regulations) and standard (BİGR, SGYM, ISO 27001, IEC 62443, ISO 42001, etc.) obligations faced by holdings and group companies operating in the energy sector. It is a proactive solution partnership that acts with agile project management principles, foresees risks, provides methodological direction to teams and transfers knowledge.

WHY IS IT NECESSARY?

Energy companies that are critical infrastructure operators; The national vision of the Cyber ​​Security Presidency is in a tighter control grip than ever with the legally binding nature of Law No. 7545 and EMRA's secondary legislation containing heavy sanctions. Different regulations such as BIGR for IT, SGYM and IEC 62443 for OT, and KVKK for data privacy cause process confusion and duplication of effort. Combining this multi-headed structure with an umbrella GRC model is an inevitable requirement for operational and reputational continuity.

SANCTION AND RISK THRESHOLD

EMRA sanctions can directly affect licensing processes; Administrative fines within the scope of Law No. 7545 can be applied up to 10,000,000 ₺. In case of benefit or loss, the penalty may increase by up to three to five times.

LEGAL AND NORMATIVE BASIS

  • Cyber Security Law No. 7545
  • EMRA SGYM Regulation
  • EKS Security Procedures and Principles
  • Information and Communication Security Guide
  • ISO/IEC 27019
  • IEC 62443
  • KVKK No. 6698

ADDED VALUE PROVIDED

Operational efficiency (consolidation)

By harmonizing BİGR, SGYM, IEC 62443, ISO 27001 and KVKK requirements with each other, single asset inventory and consolidated risk registers are created; Duplicate work by corporate teams is prevented and cost optimization is achieved.

Managerial and strategic vision (GRC)

By guiding the establishment of holding-wide regulation and artificial intelligence (ISO 42001) governance committees, the processes are ensured to be monitored transparently by the senior management through board of directors reporting and KPIs.

Legal and regulatory assurance

Changes in Law No. 7545 and EMRA legislation are followed proactively; Administrative sanction risks are minimized by providing legal and technical support in possible EMRA or Board investigations.

Technical proactiveness and resilience

With operational security services such as penetration tests, cyber drills, SOME active field support, threat hunting and technical surveillance countermeasures, vulnerabilities are detected before they are exploited and the institution's cyber crisis response muscles are strengthened.

SERVICE SCOPE AND METHODOLOGY

SINGLE ROOFEnergy Sector Integrated GRC ProgramBIGREMRA SGYMIEC 62443ISO 27001/27019ISO 42001KVKKCONCLUSIONSingle asset inventory · consolidated risk register · common policy set · single KPI dashboard
MODULE 1
Regulatory Compliance and Strategic Governance (GRC)

Legal/technical process support in energy legislation follow-up (Law No. 7545, EMRA, etc.), impact analyzes and possible investigations. Methodological guidance for the establishment of a holding-wide umbrella committee (GRC, maintenance and support, artificial intelligence governance). Defining holistic policies and KPIs covering different standards. Integration consultancy with creating a strategic road map and selecting GRC software suitable for multi-company structure.

MODULE 2
Risk Management and Audit

ISO 42001 AI Management System consultancy (model risk assessment). IT and OT/EKS (Zone & Creating a consolidated single asset inventory and risk log for Conduit architecture) in BIGR, ISO and SGYM standards, and management of risk analysis workshops. EMRA, SGYM and BIGR internal/external audit preparation support, preliminary audits and internal audits. Inspection of critical system suppliers according to official standards on behalf of the institution and support for corrective action plans.

MODULE 3
Cyber Security Operations and Business Continuity

Guidance on Business Continuity (BCP/DRP) and incident/violation root cause analysis processes for IT and OT (SGYM/IEC 62443) environments. Detailed unauthorized access/penetration tests and vulnerability analysis for IT (BIGR) and OT/SCADA environments. Architectural consultancy on the compliance of security technologies with the IEC 62443 Depth of Defense architecture. Active field support (coordination and forensic analysis) to SOME teams in times of crisis and threat hunting on critical servers and OT endpoints. Management of cyber drills and technical surveillance countermeasures service in control rooms.

MODULE 4
Sustainment, Support, Communication and Culture

Guiding corporate communications teams in their (PR) strategies for managing public and regulatory expectations. Phishing/social engineering drills twice a year. BİGR/SGYM consolidated maturity reporting specific to the board of directors and senior management. Trainings specific to the needs of the institution: BG/KVKK for all employees; GRC/AI Governance to senior management; BIGR compatible SOME and SGYM/IEC 62443 based OT/SCADA security for technical teams.

DELIVERIES AND OUTPUTS

  • Integrated asset inventory, consolidated risk register and holistic security policy documents
  • Supplier audit reports, GAP (difference) analysis and internal audit reports
  • Detailed ICS/OT and IT penetration test report and threat hunting (Breach Assessment) findings
  • Board of directors information presentations and cyber drill result/development report
  • GRC committee setup / working principles framework with Executive (Senior Level) reports
  • Training participation/achievement certificates and social engineering test reports

TARGET OUTPUT / SUCCESS CRITERIA

  • Different regulatory vertical obligations such as IT, OT (EKS) and KVKK are gathered under a complex, integrated and sustainable governance umbrella.
  • It is not reflexive in times of possible audit (Cyber ​​Security Presidency, EMRA) and cyber crisis; It operates a proactive defense mechanism that is planned in advance and has a solid legal and technical infrastructure.
  • Technology and human resources investments are channeled to common goals that maximize cost and time efficiency, rather than being made in parts for repetitive regulations.

FREQUENTLY ASKED QUESTIONS

Are each of our group companies handled separately?
No. The model establishes a single policy and risk framework at the holding level; At the company level, an additional layer is applied only for local differences (license type, facility structure). This is where the cost advantage of consolidation arises.
What happens if there is an EMRA inspection?
The service includes legal and technical assistance during review processes; Compilation of the requested records, preparation of the technical infrastructure of the defense texts and meeting accompaniment are included in the scope.
Why is the pest screening service included in this package?
Control rooms and boardroom meeting areas are high-value targets that pose the risk of physical eavesdropping. This risk is the overlooked physical leg of cyber defense.

TAGS

energy cyber security consultancyEMRA complianceSGYMBIGRIEC 62443OT SCADA securityholding GRCinsect crawlingcritical infrastructurecomputer forensics
CATEGORY 3 · PROVE INDEPENDENTLY

Audit Services

Providing reasonable assurance to official authorities through authorized, impartial and evidence-based audits; Independent audit services in full compliance with the principle of separation of consultancy and audit.

DN-01

Information and Communication Security Guide (BİGR) Compliance Audit ServiceTSE Authorized

An independent audit that is fully compliant with the Cyber ​​Security Presidency's Audit Guide methodology, carried out by a TSE authorized company and BİGR D1/D2 chief auditors, and produces an official audit file ready to be uploaded to BİGDES.

BIGR auditTSE authorized audit firmBIGR chief auditorBIGDES reportingAnnex-A Annex-H formsdesign and operating effectiveness
Service information, scope, deliveries and frequently asked questions
CATEGORY
Audit Services
TYPICAL DURATION
3–8 weeks depending on scope size · Repeated at least once a year
FOR WHOM
All public institutions and organizations and critical infrastructure operators within the scope of BIGR; Any institution that has an annual audit obligation.

DESCRIPTION OF THE SERVICE

This service is in full compliance with the "Information and Communication Security Audit Guide" methodology published by the Cyber ​​Security Presidency; It is an independent, impartial and evidence-based examination of the BIGR compliance processes of public institutions and critical infrastructure operators. Authorized by TSE as "Company Providing Information and Communication Security Guide Compliance Audit Service"; The audit, carried out by our expert staff with BİGR D1/D2 Lead Auditor and ISO 27001 Lead Auditor certificates, aims to provide reasonable assurance to official authorities by testing the design and operational effectiveness of your institution's security measures.

WHY IS IT NECESSARY?

In accordance with the Presidential Circular and the Cyber ​​Security Presidency regulations, it is a legal obligation for institutions and organizations within the scope of BIGR to audit their compliance practices at least once a year and submit the results to the Presidency in an official format (forms from Annex-A to Annex-H). These inspections; Protecting data that may threaten national security is critical for measuring the cyber resilience of the institution and proving with an independent eye whether existing controls are really working.

SANCTION AND RISK THRESHOLD

Failure to fulfill the annual audit obligation and incomplete/delayed BIGDES notifications are subject to administrative fines within the scope of Law No. 7545; For non-compliance with audit obligations, a penalty of 100,000 ₺ - 1,000,000 ₺ may be imposed, and up to 5% of the gross sales revenue in commercial companies.

LEGAL AND NORMATIVE BASIS

  • Information and Communication Security Audit Guide
  • Cyber Security Law No. 7545
  • Presidential Circular No. 2019/12
  • TSE authorization criteria

ADDED VALUE PROVIDED

Full compliance with official methodology

The 3 main processes (Planning, Implementation, Reporting) in the Audit Guide required by the Cyber ​​Security Directorate are strictly followed. The risk of the report being rejected or found incomplete is reduced to zero.

Evidence-based and objective evaluation

Security checks are not just on paper; It is verified in the field by methods such as interview, review, security audit, penetration test and source code analysis and in accordance with statistical sampling rules.

Measuring design and operational effectiveness

A realistic security picture is presented to the institution by testing not only whether a security rule is written (design effectiveness) but also whether it is actually implemented in the field (operational effectiveness).

International independence and ethical principles

The audit has not previously provided consultancy to the institution; It is carried out on the principle of segregation of duties, with authorized auditors involved in the process with commitments of impartiality and confidentiality.

SERVICE SCOPE AND METHODOLOGY

STAGE 1Audit Planning andDetermining the ScopeSTAGE 2Guide Application ProcessChecking the EffectivenessSTAGE 3Effectiveness of MeasuresEvaluation (Fieldstudy)STAGE 4Detection of Findings andRating
STAGE 1
Planning the Audit and Determining the Scope

Understanding the organization's business processes; Examining asset groups such as network, system, application, IoT and personnel according to materiality and risk criteria (Delfi method, etc.). Appointment of the audit team (Annex-A) and audit scope (Annex-B) in accordance with the official templates.

STAGE 2
Auditing the Effectiveness of the Guide Implementation Process

Methodological examination of the institution's preparations for BIGR compliance (accuracy of asset groupings, suitability of criticality surveys, documentation of compensatory controls and progress of the road map) and recording them in the Annex-E form.

STAGE 3
Evaluation of the Effectiveness of Measures (Field Study)

Testing technical and administrative controls on selected samples. Evaluating controls from firewall rules to physical server rooms and penetration test results as "Active, Partially Active, Inactive" and recording them on the Annex-F form.

STAGE 4
Detection and Grading of Findings

Classifying the identified administrative or technical deficiencies according to their risk impact on the institution (Very High, High, Medium, Low) with official labeling standards (e.g. U01, T04) and determining their root causes.

DELIVERIES AND OUTPUTS

  • BIGR Official Audit Report — signed main report including executive summary, scope, methodology and reasonable assurance statement
  • Audit Team Information (Annex-A) and Asset Groups / Scope File (Annex-B)
  • Guide Implementation Process (Annex-E) and Measure Effectiveness (Annex-F) status reports
  • Official Table of Findings (Annex-G) — list of nonconformities coded in legal labeling format
  • Signed Audit Opinion (Annex-H) — closing report signed by the audit team and the corporate executive
  • Official audit file, whose integrity is protected by hash value, ready to be uploaded to BIGDES

TARGET OUTPUT / SUCCESS CRITERIA

  • The annual independent BIGR audit obligation required by the Cyber ​​Security Presidency is fully fulfilled through an authorized institution and by meeting all legal format (Annex-A/H) expectations.
  • How effective the compliance efforts on paper are at the operational level is verified with concrete evidence (penetration test, configuration analysis, interview).
  • Weak links and “Very High/High” risk findings are recorded in an official report, and a clear CPA road map is presented to the senior management for the next year's investments.

FREQUENTLY ASKED QUESTIONS

You also provided our consultancy, can you also perform the audit?
No. The Audit Guide and international audit ethics prohibit providing both consultancy and audit to the same institution. Maintaining this distinction is a prerequisite for the validity of the report.
How many days does the audit take?
Duration; It is determined according to the number of asset groups, their degree of criticality and the number of locations. The sample size is calculated according to statistical rules and cannot be arbitrarily narrowed.
If the findings come out, will we be out of control?
Audit is not an exam, but a detection process. The presence of findings is expected; The important thing is to grade them and connect them to the CPA plan.

TAGS

BIGR auditTSE authorized audit firmBIGR chief auditorBIGDES reportingAnnex-A Annex-H formsdesign and operating effectivenesssampling samplingreasonable assurance
DN-02

Cyber Security Competence Model (SGYM) Independent Audit Service in the Energy SectorEMRA / EBIS

Within the scope of EMRA SGYM Regulation, carried out by authorized independent auditors; OT/EKS audit that produces an official sectoral audit report ready to be submitted to EMRA via EBİS.

SGYM auditEMRA independent sectoral auditEBIS notificationSGYM level 1 2 3ICS auditOT security audit
Service information, scope, deliveries and frequently asked questions
CATEGORY
Audit Services
TYPICAL DURATION
Minimum 2–3 days field inspection + remote inspection depending on criticality level · Total 3–6 weeks
FOR WHOM
Carrying out electricity distribution, natural gas distribution, electricity production, refinery and transmission activities; EPDK licensed organizations in criticality class A, B or C.

DESCRIPTION OF THE SERVICE

This service is within the scope of the "Cyber ​​Security Competence Model Regulation in the Energy Sector" published by EMRA on June 6, 2023; It is the process of examining the industrial control systems (ICS) and operational technology (OT) infrastructures of energy sector organizations by authorized independent auditors. The service includes re-analyzing more than 10 main control headings prescribed by SGYM on the basis of current risks and requirements, with an "evaluation from scratch" approach, and auditing and reporting the compliance of the organization with the mandatory competency levels (Level 1, 2, 3) in EMRA standards.

WHY IS IT NECESSARY?

In accordance with the EMRA Regulation and the Cyber Security Law No. 7545, it is a legal obligation for energy companies, which are critical infrastructure operators, to certify their SGYM compliance through authorized independent audit firms. In addition, following the level notifications that must be submitted to EMRA via EBİS, depending on the criticality class (A, B, C) of the organization, Independent Sectoral Audit Reports must be submitted to the institution within 12 months at the latest according to the official calendar. Inspections that are not carried out on time and in accordance with the procedure can lead to heavy sanctions and administrative fines.

SANCTION AND RISK THRESHOLD

Failure to submit the inspection report within the 12-month legal period following the level notification creates risks in administrative sanctions and licensing processes; Violations of audit obligations within the scope of Law No. 7545 are also punished.

LEGAL AND NORMATIVE BASIS

  • EMRA SGYM Regulation — June 6, 2023
  • Cyber Security Law No. 7545
  • SGYM Audit Guide
  • ISO/IEC 27019
  • IEC 62443
  • NIST SP 800-82

ADDED VALUE PROVIDED

legal contribution

In accordance with Law No. 7545 and EMRA SGYM Regulation dated June 6, 2023, the independent sectoral audit obligation is fully fulfilled and the risks of heavy administrative sanctions and license suspension are eliminated.

Operational contribution

An independent evaluation identifies blind spots in ICS and OT networks and transparently reveals your compliance with international standards such as ISO 27019, IEC 62443 and NIST SP 800-82.

Managerial contribution

An objective picture of the organization's cybersecurity maturity level is presented to senior management. By clarifying the “Partly Compatible” and “Incompatible” items, an objective decision support mechanism is provided for technology, process and human resource investments.

SERVICE SCOPE AND METHODOLOGY

LEVEL 1Core CompetenceMinimum control set Class CLEVEL 2Managed CompetenceMeasured and monitored processes Class BLEVEL 3Advanced CompetenceOptimized, proven Class A
STAGE 1
Opening Meeting and Scope Determination

Drawing the scope of holistic evaluation of OT network boundaries, remote connections, supplier processes, auxiliary facilities and all communicating systems according to regulatory expectations (Full Compliance, Partial Compliance, Incompatible, Out of Scope).

STAGE 2
Remote Audit Activities

Remote analysis of policies, procedures, directives and process documentation via secure sharing platforms (hash verified) and verification of their compliance with SGYM controls.

STAGE 3
On-Site (Field) Controls and Technical Inspections

SGYM Regulation art. Physical and technical security checks are carried out on live systems by our 11 Critical Infrastructures National Test Bed Center certified experts. Minimum 2 or 3 days field inspection depending on criticality level.

STAGE 4
White Paper and Safe Sampling

Examining network device, server/client and security systems logs on live screens without direct access by authorized personnel of the organization. Methodological sampling in distributed structures in accordance with the rule of the square root of the number of assets (maximum 5).

STAGE 5
Reconciliation and Closing Meeting

Preparing and signing the official memorandum of understanding by presenting the detected "Full Compliance", "Partial Compliance", "Incompatible" and "Out of Scope" findings to the organization.

DELIVERIES AND OUTPUTS

  • EMRA SGYM Independent Sectoral Audit Report - in official EMRA format, ready to be submitted to EMRA via EBİS
  • Formal Audit Memorandum — minutes containing audit dates, numbers of substances evaluated, sampling justifications, and legal compliance statements (consultancy/audit separation, no-data retention rule).
  • Executive Summary Presentation — due diligence summary prepared for senior management

TARGET OUTPUT / SUCCESS CRITERIA

  • The independent sectoral audit process, which is mandatory in accordance with the EMRA SGYM Regulation (Part Three, Article 10), is completed completely through an officially authorized and certified institution.
  • By fulfilling EMRA's official notification obligations accurately and on time, criminal sanctions are avoided.
  • Cybersecurity maturity (Level 1, 2 or 3) is recorded in a transparent, measurable and provable manner; Internal processes are verified against national and global standards.

FREQUENTLY ASKED QUESTIONS

We have made our level notification, how long do we have for the inspection?
According to the official calendar, the independent sectoral audit report must be submitted to the institution within 12 months at the latest following the level notification. Initiating planning early leaves room to maneuver for finding closure.
Will auditors have direct access to our systems?
No. Log and configuration reviews are carried out on live screens by authorized personnel of the organization; The audit team does not request direct access and does not retain data.
Will all our sites be inspected?
In distributed structures, methodological sampling is applied in accordance with the rule of the square root of the number of assets (maximum 5); Sampling justifications are recorded in the memorandum of understanding.

TAGS

SGYM auditEMRA independent sectoral auditEBIS notificationSGYM level 1 2 3ICS auditOT security auditcriticality class A B Cenergy sector audit
DN-03

Independent Supplier Cyber Security Audit ServiceSupply Chain

Inspects the information security maturity of suppliers and subcontractors with risk-oriented classification; Independent audit with a quantitative score that forms the basis for the “operability decision”.

supplier auditsupply chain securitythird party risk managementNIST CSF 2.0data processor auditsupplier risk scoring
Service information, scope, deliveries and frequently asked questions
CATEGORY
Audit Services
TYPICAL DURATION
Per supplier Type A: 2–5 days Type B: 3–7 days Type C: 1–3 days
FOR WHOM
Institutions that have outsourced their critical services; All organizations working with cloud, software development, call center, maintenance-repair and field service suppliers; Managements that will make purchasing and contract renewal decisions.

DESCRIPTION OF THE SERVICE

This service is the process of examining the information security maturity levels of suppliers, subcontractors and business partners serving your organization by independent auditors authorized within the framework of ISO 27001, NIST CSF v2.0 and KVKK standards. The service, with the "Risk Based Classification (Tiering)" approach; It includes analyzing 5 basic main control headings (GRC, technical security, operational security, etc.) according to the sensitivity and access rights of the data processed by the supplier and auditing and reporting the security level.

WHY IS IT NECESSARY?

In today's complex cyber threat environment, the security of institutions depends not only on the measures they take; It is also directly linked to the security level of the supplier network they work with. A data breach or service outage on the supplier side has the potential to directly impact your organization. Independent supplier audits are a critical necessity to verify whether contractual and legal security obligations are actually met by the supplier.

SANCTION AND RISK THRESHOLD

Responsibility for violations occurring through the data processor lies with the data controller; Violation of KVKK data security obligation is subject to an administrative fine of 256,357 ₺ - 17,092,242 ₺ for 2026.

LEGAL AND NORMATIVE BASIS

  • KVKK No. 6698 - obligation to audit data processors
  • ISO/IEC 27001 A.5.19–A.5.23
  • NIST CSF v2.0
  • Information and Communication Security Guide — supplier security

ADDED VALUE PROVIDED

legal contribution

Within the framework of legal regulations, especially KVKK, the institution's obligation to "supervise data processors" is fulfilled independently, and possible risks of legal and administrative sanctions are minimized.

Operational contribution

An independent evaluation identifies blind spots in your suppliers' information security infrastructure, transparently reveals their compliance with international standards and increases service quality.

Managerial contribution

With structured reports (operability decision, etc.), senior management is presented with an unbiased picture of the risk status of the supplier relationship; An objective decision support mechanism is provided for strategic purchasing and contract renewal processes.

SERVICE SCOPE AND METHODOLOGY

RISK-FOCUSED CLASSIFICATIONTYPE AOn-Site InspectionCritical supplier · field interview and physical checkTYPE BRemote ControlKey supplier documentation and evidence reviewTYPE CDeclaration BasedStandard supplier · question set and self-assessment
STAGE 1
Supplier Classification and Scoping

Classification of suppliers according to data sensitivity, access authority and business impact (Critical, Important, Standard) and determination of the audit method to be applied (Type A on-site, Type B remote, Type C declaration).

STAGE 2
Question Set and Documentation Review (Type B and C)

Analyzing policies, procedures and information security process documentation remotely or via question set and verifying their compliance with standards.

STAGE 3
On-Site (Field) Checks and Technical Inspections (Type A)

Interviews, physical security (data center, office) and technical security checks conducted by our experts in the field for critical suppliers.

STAGE 4
White Paper and Safe Sampling

Examination of log management, network security (VLAN, firewall), identity management (MFA) and backup systems (BCP/DR) within the framework of technical standards.

STAGE 5
Reconciliation, Scoring and Closing

The identified deficiencies are graded with quantitative scores at the levels of "Urgent", "High", "Medium" and "Low" and presented to the organization.

DELIVERIES AND OUTPUTS

  • Technical Detail Report and Solution Plan — detailed roadmap with each finding rated with a quantitative score, business impacts explained, and applicable technical solution steps
  • Executive Summary — summary report that includes the vendor's overall risk score and most critical vulnerabilities to support the operability decision
  • Structured set of reports including audit criteria, methodology, findings and recommendations

TARGET OUTPUT / SUCCESS CRITERIA

  • Cyber security and data breach risks that may arise from the supplier chain are determined objectively through an independent and expert audit process.
  • Strategic decisions can be made based on clear evidence about whether to continue working with suppliers or revise contract terms.
  • Security gaps in supplier infrastructures are recorded in a transparent and measurable manner, and a clear improvement plan is presented to the supplier to close them.

FREQUENTLY ASKED QUESTIONS

What happens if our supplier does not accept the audit?
The right to audit is a fundamental right that should be written into the data processing clauses of contracts. Rejection is itself an indicator of risk and should be taken into account in the workability decision.
Do we have to audit all suppliers?
No. With risk-based classification, on-site inspection is applied to critical suppliers, and remote or declaration-based inspection is applied to others. The goal is to cover risk, not coverage.
Is the report shared with the supplier?
The technical detail report is designed to be shared with the supplier's IT and security teams so that findings can be closed; The executive summary is for your institution's decision-making mechanism.

TAGS

supplier auditsupply chain securitythird party risk managementNIST CSF 2.0data processor auditsupplier risk scoringworkability decisionsupplier classification
CATEGORY 4 · VERIFY IN THE FIELD

Penetration Tests

Technical assurance services carried out by TS 13638 certified staff, verifying the controls on paper by exploiting them at the operational level.

ST-01

Comprehensive Penetration Test (Penetration Test) Service in TS 13638 StandardsTS 13638 Certificated

Conducted by CEH/OSCP/CISSP certified staff with TSE TS 13638 Penetration Testing Company Certificate; Independent technical assurance covering web, mobile, API, network, wireless and SCADA layers with a formal 8-step methodology.

penetration testpenetration testTS 13638OWASPweb application security testingAPI security testing
Service information, scope, deliveries and frequently asked questions
CATEGORY
Penetration Tests
TYPICAL DURATION
1–6 weeks depending on scope · Free verification (validation test) included
FOR WHOM
All institutions operating applications and services open to the Internet; Public and critical infrastructure organizations preparing for BİGR/SGYM audit; Companies that have periodic testing obligations pursuant to PCI-DSS, ISO 27001 or customer contracts.

DESCRIPTION OF THE SERVICE

This service; It is an independent security audit activity carried out to ensure the security of your institution's information systems, network infrastructure, applications and data, to detect vulnerabilities through technical analysis and to verify that these vulnerabilities have been resolved. This audit is carried out by our expert staff who have the TS 13638 Penetration Testing Company Certificate issued by TSE and are internationally valid (CEH, OSCP, CISSP, etc.); Provides reasonable assurance on your corporate governance, risk and compliance processes. Designed with a vision to work fully integrated with MSSP operations, the process aims to prove the effectiveness of your security controls not only at the design but also at the operational level.

WHY IS IT NECESSARY?

It is mandatory for operational continuity to independently examine the potential damage that current cyber threats may cause to corporate networks and critical infrastructures, adhering to the defense in depth principle. These tests are of critical importance in order to detect high-risk exploitation routes resulting from the combination of low-risk vulnerabilities used in a certain order, to measure the ability of network protection devices to respond to events, and to report security investments to senior management.

SANCTION AND RISK THRESHOLD

Failure to detect and report vulnerabilities and incidents is subject to an administrative fine of 1,000,000 ₺ - 10,000,000 ₺ within the scope of Law No. 7545. In addition, penetration test findings are sought as mandatory evidence items in BİGR and SGYM audits.

LEGAL AND NORMATIVE BASIS

  • TS 13638 Penetration Test standard
  • Cyber Security Law No. 7545
  • Information and Communication Security Guide
  • EPDK EKS Security Procedures and Principles
  • ISO/IEC 27001 A.8.8
  • KVKK no. 6698. 12
  • OWASP methodologies

ADDED VALUE PROVIDED

Full compliance with official methodology

The 8-stage process required by the TS 13638 standard (Pre-Contact, Information Collection, Vulnerability Analysis, Threat Modeling, Infiltration, Post-Infiltration, Reporting and Verification) is strictly implemented.

Multi-layered attacker simulation

Risks are evaluated in every aspect by simulating all user profiles, from an anonymous attacker outside the firewall (Black Box), to an unauthorized user who has infiltrated the internal network (Grey Box) and a system administrator with full knowledge (White Box).

Evidence-based technical reporting

You can't just rely on automatic scanning tools; Business logic errors in the security architecture are verified in the field through manual in-depth analysis by auditors with international expertise.

SERVICE SCOPE AND METHODOLOGY

01Preliminary Contact02Informationcollection03vulnerabilityAnalysis04threatmodeling05infiltration06infiltrationafter07Reporting08verification
LAYER 1
Network and System Infrastructure Penetration Tests

Lateral movement, privilege escalation and weak configuration tests on external network (Internet/DMZ) and local network (Intranet).

LAYER 2
Application Security Tests

Audit of web, mobile, API / web service and optionally desktop applications in accordance with OWASP methodology.

LAYER 3
SCADA / Industrial Control Systems Tests

Examination of critical infrastructure devices with special methodologies that are fully compatible with EMRA procedures and principles and will not risk operational continuity.

LAYER 4
Wireless Network and Communication Tests

Corporate authentication, isolation vulnerabilities and fake access point (Fake Access Point) analysis.

LAYER 5
DDoS and Social Engineering Tests

Measuring the behavior of systems under overload and phishing simulations targeting staff awareness.

DELIVERIES AND OUTPUTS

  • Penetration Test Result Report - In accordance with TS 13638 format; Detailed technical section including executive summary, scope/IP information, risk rating table (5 levels from Urgent to Minor) and evidence of exploitation
  • Verification Test Report — free check test result report following resolution of findings
  • Operational Management Documents — Mandatory scoping form, confidentiality commitments, mandate letters and customer waivers as required by TSE standards
  • All outputs are delivered in encrypted form in accordance with data security standards

TARGET OUTPUT / SUCCESS CRITERIA

  • Cyber security investment strategies are based not only on risk theories; It can be shaped based on concrete data exploited in the technological field itself.
  • A clear Corrective and Preventive Action (CAPA) action plan is available in which the identified vulnerabilities are prioritized according to their risk weight.
  • Independent security audit requirements expected by regulatory institutions (TSE, EMRA, etc.) are met through an accredited service.

FREQUENTLY ASKED QUESTIONS

Will our systems be damaged during testing?
Fragility thresholds, testing windows and stopping criteria are agreed in writing on the scoping form. Tests that may have a production impact (DDoS, ICS) are carried out only within planned windows and with written approval.
Is the verification test paid?
No. The verification test performed following the elimination of the detected findings by the institution is within the scope of the service and an updated status report is delivered.
What is the difference between automated scanning and penetration testing?
Automatic scanning lists known signatures; Penetration testing chains these findings and reveals real exploitation paths and business logic errors with evidence. It is the second one that is accepted in regulatory audits.

TAGS

penetration testpenetration testTS 13638OWASPweb application security testingAPI security testingSCADA penetration testingwireless network testphishing simulationblack box gray box

Get the entire catalog in one file

General brochure; It is an expanded document that includes all four categories, sanctions dashboard, service comparison matrix, methodology diagrams and selection guide. Each service also has its own brochure.