Cybersecurity
Take a forty-person automotive parts supplier in Bursa. Within a single month the carmaker it supplies adds an information security questionnaire to the annual vendor review, the insurer wants proof of multi-factor sign-in on every account before renewing the cyber policy, and accounts receives an email from a familiar supplier's address announcing new bank details. It looks like three separate headaches. Really it is one question: can the company show what it does, and does what it does actually hold up? In this area we write the paperwork that KVKK and Turkish cybersecurity rules call for and put in place the controls that stop it being fiction. Everything happens remotely and over video calls.
Rules and evidence
KVKK, cybersecurity legislation, supplier questionnaires from big customers and insurers' forms use different wording, but underneath they circle the same few issues. Who can reach what? How is risk assessed? What happens on the day something goes wrong? Get the foundation right and one set of answers serves every audience. We follow ISO 27001 principles and use the Information and Communication Security Guide of the Presidency's Digital Transformation Office as a reference point. For financial sector firms, BDDK and SPK requirements come into the picture as well.
KVKK and personal data protection
Privacy from the IT side: where each record in your personal data inventory is physically stored, who can see them, how access and erasure requests get handled in practice, and the first-hours playbook if data leaks.
Security policies and documentation
Policies, risk assessment and incident procedures built by talking to the people who do the work, not lifted from a downloaded template. The result describes how the company really operates, which is exactly why it survives an audit.
Technical protection
Nine services, one for each layer an attacker might use: user identities, laptops and phones, the network, business software, databases, public websites and the way files travel. Nobody buys the lot on day one; the risk review decides what is urgent and what can sit on next year's list.
Security tooling roll-out
When you pay for Microsoft 365 Business Premium but use little of it, or the EDR you bought has sat in audit-only mode for months: a pilot group, a staged expansion, then a switch to blocking without halting anyone's work.
Infrastructure security
The remote desktop port exposed to the internet gets closed, security cameras and the visitor wireless network are fenced off in separate VLANs, and your software vendor's technician logs in with a personal account and a second factor instead of a shared password.
Application security
Which Logo users may change bank details on a vendor record, which account your store uses to sync with the marketplaces, and where the iyzico or PayTR API key is kept.
Data leak prevention (DLP)
Documents carrying T.C. identity numbers, bank account details or doctor's reports get detected. Sending one to a private Gmail address brings up a prompt first; hard blocks are reserved for the clear-cut cases. Staff receive a KVKK privacy notice about the monitoring beforehand.
Database security
The shared “sa” superuser that half the office knows is disabled, data at rest in SQL Server and MySQL gets encrypted, reads of patient or customer tables are logged, and forgotten export files are cleared away.
Web application firewall (WAF)
Rules in Cloudflare, or in the firewall your host provides, set up weeks before Black Friday and 11.11, so card-testing bots and password spraying are stopped while genuine buyers pass straight through.
Access control and endpoint security
A leaked password by itself opens nothing: multi-factor sign-in with no exceptions, company data reachable only from Intune-enrolled devices, no local admin rights for everyday work.
VPN and encryption
Encrypted tunnels (WireGuard or IPsec) between head office, warehouse and branches, disk encryption on all laptops with the recovery keys stored centrally, and one fixed, encrypted route for payroll files heading to your mali müşavir.
Vulnerability scanning
A monthly scan from inside the network and from the internet, with USOM advisories and flaws under active exploitation pushed to the top. Shorter reports, and more patches that actually get installed.
Monitoring and ongoing care
Whatever was configured at the start of the year has drifted by autumn: people join, software changes, attackers find new tricks. The following four carry on well after the initial project has been signed off.
Where to begin
With a limited budget, the order of work matters more than the vendor logo. For SMEs with 10 to 250 employees we suggest this sequence, which shuts the most common entry points first.
List the demands
On a video call we gather everything already on the table: security clauses in customer contracts, the insurer's form, KVKK duties and, if your sector counts as critical infrastructure, the relevant legislation. That tells us which evidence is needed and where the most sensitive data sits.
Accounts and email
Multi-factor sign-in, removal of orphaned accounts left behind by former staff, and defences against fake invoices and bank detail change requests. It is where most small-business breaches begin, and fixing it costs the least.
Devices, network and backup
EDR in blocking mode, baseline hardening, no remote access straight from the internet, and backups proven by at least one real restore. Ransomware is halted, or at worst boxed in, at this stage.
Documents and monitoring
Once the basics work, the written policies can describe reality instead of intentions. After that you add whatever the risk justifies: WAF, DLP, finer network segmentation or a SOC.
Start by pricing a week without IT. An online seller with daily sales of €4,000 through Trendyol and its own site, or a warehouse that cannot dispatch a single lorry because it is unable to issue e-İrsaliye documents, can easily forfeit more during a short outage than a year of reasonable security would cost. That figure, not fear of an administrative fine, should steer how much you spend and in what order.
Frequently asked questions
The law and the regulations under it place duties chiefly on critical infrastructure operators and certain sectors, with the details filled in by secondary legislation and by the Cybersecurity Presidency. Whether your company falls directly within scope is a question for a legal adviser. In practice the pressure tends to arrive second-hand: smaller companies that are not covered themselves receive questionnaires and contract clauses from customers who are inside it. We work out the technical answers and the supporting evidence with you.
Before paying, confirm with the supplier through a channel you already had on file, never the details in that email. In this kind of fraud a mailbox, either theirs or yours, has usually been compromised, and the attacker has been reading the correspondence for weeks, waiting for the right invoice. We examine inbox rules, sign-in logs and message headers, lock down any hijacked account and fix SPF, DKIM and DMARC. The lasting fix is a rule in accounts that any IBAN change needs a second person to approve it.
We go through it together and sort the questions into three piles: things you can truthfully tick today, things that need a little effort, and things that would be a project of their own. Multi-factor sign-in, documented access rights, a written incident procedure and a recent vulnerability scan usually cover a large share. A yes on paper that is a no in reality can turn the contract and the insurance against you after an incident. If the customer asks for ISO 27001, we help you prepare for certification.
Do not power machines off; unplug the network cable or disconnect Wi-Fi so the traces survive. Using a machine you trust, reset every administrator password and write to support@apply.tr, or helpme@apply.tr if you are under contract with us. Where personal data may have been exposed, the 72-hour deadline for notifying the KVKK Board starts running. You can also report the incident to USOM and, where one exists, to your sector's SOME.
It is. Workshops take place on Teams or Meet, and changes are made through an encrypted remote connection with every session logged. Anything that needs hands on a device is done by a colleague of yours or your local IT contractor, with us talking them through it on screen. The schedule is fixed once the first assessment is done and written into our proposal.
Related areas
Tell us what is being asked of you and what you have today
A customer questionnaire, a cyber insurance renewal, KVKK preparation or a specific suspicion. After a remote review you will know what is missing, the order to tackle it in and what it will cost.
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
By video, over Microsoft Teams or Google Meet
We have your enquiry
A reply will reach you by the next working day at the latest. If your message says work has come to a halt, it goes to the top of the pile.
- Filling the gaps. If we need more information to judge the job, we send questions by email or propose a quick Teams or Google Meet call.
- A written quote. It lists the scope, a euro price excluding VAT and a realistic start date. No hidden clauses, no items that appear later.
- Your decision. The quote arrives by email. Take whatever time you need, raise questions on any line, and decide when you are ready.