← Scale Technology Group SSB Cyber Hygiene: major finding = inability to receive orders

Sectoral · Defense Industry · SSB · MSB · TRTEST

Cyber Security for Defense Industry Suppliers

In the defense industry, cyber hygiene is not an IT expense, but a requirement for doing business

Rather than directly targeting prime contractors with high protection, attackers — especially state-backed APT groups — look for the weakest link in the chain: subcontractors and SMEs. That's why SSB and MSB operate strict supply chain security standards, from the prime contractor to the bottom supplier. A company that does not meet these standards cannot take part in national defense projects, no matter how high its production or R&D capacity is.

13
Control Area
4
Maturity Level
1+ per year
Mandatory Penetration Test
A · B · C
EYDEP Classes

Three Layers of Liability

You go through three separate gates in the supply chain

A company that wants to work in the defense ecosystem; must manage all three: cyber hygiene certification, facility security and industrial competency assessment.

SSB · TRTEST

Cyber Hygiene Certification Program

TRTEST Test and Evaluation Inc., which was established under the coordination of SSB and with the support of the Turkish Cyber ​​Security Cluster. Certification carried out by. With its official name Cyber Hygiene Emergency Measures Criteria SetIt is based on; Unlike documentation-oriented systems such as ISO 27001, it looks directly at the technical configuration in the field. Companies awareness · Basic · medium · Advanced at levels, in 13 key control areas is inspected. The company with a major (Class A) finding cannot receive documents and therefore cannot receive orders from main contractors.
Full details of the program →

MSB · 5202 p. law

Facility Security Certificate (TGB) and Personal Security Certificate (KGB)

Prerequisite for entering a tender for "National Secret" or "NATO Secret" projects. Not just physical security; It also covers cyber-physical requirements such as network isolation (air-gap), controlled rooms and TEMPEST compliance. KGB based on security investigation is a must for every personnel who will access the projects.

SSB · EYDEP

Industrial Competence Assessment (A / B / C)

The mechanism by which SSB classifies suppliers based on organizational maturity. Inspections as well as production competence information security (ISO 27001) and secure software development (DevSecOps) criteria are also measured. Companies with poor cyber hygiene cannot receive a high class in the Qualified Supplier Pool.

TRTEST Audit Scope

You are audited in 13 key areas

Below are the highlights of the audit areas. The controls by which each area is measured and the current situation in your institution are discussed together in a free pre-evaluation session.

S1 Asset Management S2 Patch Management S3 Authorization and Access Control S4 Endpoint Security S5 Backup Management S6 Vulnerability Management and Penetration Testing S7 Risk Management S8 Awareness Trainings S9 System and Network Secure Configuration S10 App and Web Secure Configuration S11 Security Monitoring and Records Management S12 Data and Email Security S13 Incident and Violation Management
Why it matters: The most common way organizations are hacked is through fake emails (phishing); TRTEST directly scores staff awareness and phishing drills. Penetration tests are a process taken to pass the audit. «paper» It is not a mandatory item of evidence repeated at every level. — and can only be done by TSE approved companies.
Details of the four maturity levels, what the thirteen control areas individually measure, and what instantly stops the document Class A (major) findings for: Cyber Hygiene Certification page →

Critical Infrastructure Connectivity

Defense industry is also one of the 15 critical sectors

Within the scope of Law No. 7545, the defense industry is included in the list of critical infrastructure monitored by the SGB (Category B). SOME establishment and breach notification obligations are valid as of today; BIGR audit schedule will be announced by SGB. This means that industry firms are also subject to the national cybersecurity regime in addition to SSB/MSB requirements — the two layers are not interchangeable.

Critical Infrastructures Page Sanctions Board Cyber Hygiene Certification

Roadmap with Scale

We set up the path to the document in a single program

01

Cyber Hygiene Compliance Consultancy

Gap analysis across all 13 audit areas, pre-screening of Class A findings, closure roadmap by target level and post-document operational support. Service detail →

02

TS 13638 Penetration Test

Penetration testing, which is a mandatory condition for certification, is carried out by our TSE approved and TS 13638 certified staff. Service detail →

03

ISO 27001 (EYDEP Criteria)

It establishes the information security management system measured in the EYDEP evaluation ready for certification. Service detail →

Note: TRTEST/SSB issues the Cyber Hygiene Certificate, and MSB issues the TGB; Scale prepares for these audits and produces technical assurance. In accordance with the principle of independence, penetration testing is planned separately from the consultancy team.

Free Pre-Assessment

Let us secure your place in the supply chain

It maps which document you need, at which level, with which calendar, in a single session; We deliver the written road map to you.

Create My Liability Map Request Expert Session