Area 08 · Security

Cybersecurity

Take a forty-person automotive parts supplier in Bursa. Within a single month the carmaker it supplies adds an information security questionnaire to the annual vendor review, the insurer wants proof of multi-factor sign-in on every account before renewing the cyber policy, and accounts receives an email from a familiar supplier's address announcing new bank details. It looks like three separate headaches. Really it is one question: can the company show what it does, and does what it does actually hold up? In this area we write the paperwork that KVKK and Turkish cybersecurity rules call for and put in place the controls that stop it being fiction. Everything happens remotely and over video calls.

15
services within this area
KVKK
plus the new expectations that came with the Cybersecurity Law
72 h
to notify the KVKK Board of a personal data breach
0
site visits, the work is entirely remote

Rules and evidence

KVKK, cybersecurity legislation, supplier questionnaires from big customers and insurers' forms use different wording, but underneath they circle the same few issues. Who can reach what? How is risk assessed? What happens on the day something goes wrong? Get the foundation right and one set of answers serves every audience. We follow ISO 27001 principles and use the Information and Communication Security Guide of the Presidency's Digital Transformation Office as a reference point. For financial sector firms, BDDK and SPK requirements come into the picture as well.

Talk through your situation

Technical protection

Nine services, one for each layer an attacker might use: user identities, laptops and phones, the network, business software, databases, public websites and the way files travel. Nobody buys the lot on day one; the risk review decides what is urgent and what can sit on next year's list.

Security tooling roll-out

When you pay for Microsoft 365 Business Premium but use little of it, or the EDR you bought has sat in audit-only mode for months: a pilot group, a staged expansion, then a switch to blocking without halting anyone's work.

Infrastructure security

The remote desktop port exposed to the internet gets closed, security cameras and the visitor wireless network are fenced off in separate VLANs, and your software vendor's technician logs in with a personal account and a second factor instead of a shared password.

Application security

Which Logo users may change bank details on a vendor record, which account your store uses to sync with the marketplaces, and where the iyzico or PayTR API key is kept.

Data leak prevention (DLP)

Documents carrying T.C. identity numbers, bank account details or doctor's reports get detected. Sending one to a private Gmail address brings up a prompt first; hard blocks are reserved for the clear-cut cases. Staff receive a KVKK privacy notice about the monitoring beforehand.

Database security

The shared “sa” superuser that half the office knows is disabled, data at rest in SQL Server and MySQL gets encrypted, reads of patient or customer tables are logged, and forgotten export files are cleared away.

Web application firewall (WAF)

Rules in Cloudflare, or in the firewall your host provides, set up weeks before Black Friday and 11.11, so card-testing bots and password spraying are stopped while genuine buyers pass straight through.

Access control and endpoint security

A leaked password by itself opens nothing: multi-factor sign-in with no exceptions, company data reachable only from Intune-enrolled devices, no local admin rights for everyday work.

VPN and encryption

Encrypted tunnels (WireGuard or IPsec) between head office, warehouse and branches, disk encryption on all laptops with the recovery keys stored centrally, and one fixed, encrypted route for payroll files heading to your mali müşavir.

Vulnerability scanning

A monthly scan from inside the network and from the internet, with USOM advisories and flaws under active exploitation pushed to the top. Shorter reports, and more patches that actually get installed.

Monitoring and ongoing care

Whatever was configured at the start of the year has drifted by autumn: people join, software changes, attackers find new tricks. The following four carry on well after the initial project has been signed off.

Where to begin

With a limited budget, the order of work matters more than the vendor logo. For SMEs with 10 to 250 employees we suggest this sequence, which shuts the most common entry points first.

01

List the demands

On a video call we gather everything already on the table: security clauses in customer contracts, the insurer's form, KVKK duties and, if your sector counts as critical infrastructure, the relevant legislation. That tells us which evidence is needed and where the most sensitive data sits.

02

Accounts and email

Multi-factor sign-in, removal of orphaned accounts left behind by former staff, and defences against fake invoices and bank detail change requests. It is where most small-business breaches begin, and fixing it costs the least.

03

Devices, network and backup

EDR in blocking mode, baseline hardening, no remote access straight from the internet, and backups proven by at least one real restore. Ransomware is halted, or at worst boxed in, at this stage.

04

Documents and monitoring

Once the basics work, the written policies can describe reality instead of intentions. After that you add whatever the risk justifies: WAF, DLP, finer network segmentation or a SOC.

Start by pricing a week without IT. An online seller with daily sales of €4,000 through Trendyol and its own site, or a warehouse that cannot dispatch a single lorry because it is unable to issue e-İrsaliye documents, can easily forfeit more during a short outage than a year of reasonable security would cost. That figure, not fear of an administrative fine, should steer how much you spend and in what order.

Frequently asked questions

The law and the regulations under it place duties chiefly on critical infrastructure operators and certain sectors, with the details filled in by secondary legislation and by the Cybersecurity Presidency. Whether your company falls directly within scope is a question for a legal adviser. In practice the pressure tends to arrive second-hand: smaller companies that are not covered themselves receive questionnaires and contract clauses from customers who are inside it. We work out the technical answers and the supporting evidence with you.

Before paying, confirm with the supplier through a channel you already had on file, never the details in that email. In this kind of fraud a mailbox, either theirs or yours, has usually been compromised, and the attacker has been reading the correspondence for weeks, waiting for the right invoice. We examine inbox rules, sign-in logs and message headers, lock down any hijacked account and fix SPF, DKIM and DMARC. The lasting fix is a rule in accounts that any IBAN change needs a second person to approve it.

We go through it together and sort the questions into three piles: things you can truthfully tick today, things that need a little effort, and things that would be a project of their own. Multi-factor sign-in, documented access rights, a written incident procedure and a recent vulnerability scan usually cover a large share. A yes on paper that is a no in reality can turn the contract and the insurance against you after an incident. If the customer asks for ISO 27001, we help you prepare for certification.

Do not power machines off; unplug the network cable or disconnect Wi-Fi so the traces survive. Using a machine you trust, reset every administrator password and write to support@apply.tr, or helpme@apply.tr if you are under contract with us. Where personal data may have been exposed, the 72-hour deadline for notifying the KVKK Board starts running. You can also report the incident to USOM and, where one exists, to your sector's SOME.

It is. Workshops take place on Teams or Meet, and changes are made through an encrypted remote connection with every session logged. Anything that needs hands on a device is done by a colleague of yours or your local IT contractor, with us talking them through it on screen. The schedule is fixed once the first assessment is done and written into our proposal.

Tell us what is being asked of you and what you have today

A customer questionnaire, a cyber insurance renewal, KVKK preparation or a specific suspicion. After a remote review you will know what is missing, the order to tackle it in and what it will cost.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.