Policy statement
Signed by leadership and kept brief: what the company is protecting, which parts of the business are covered, who answers for it and when it will be revisited. It becomes the yardstick for everything else, not a wall of slogans.
Security paperwork is almost always written because somebody outside asked for it. A Bursa component maker gets a hundred-item questionnaire from the carmaker it supplies and has a fortnight to reply. A contractor to an energy or telecoms operator finds new clauses in its renewal, because its client now carries duties under the Cybersecurity Law and sector regulation and expects its suppliers to share them. An insurer will not quote a cyber policy until it sees an incident plan. The usual reflex is a downloaded template, and seasoned auditors recognise one almost immediately: software that the company has never run, job titles nobody holds, procedures no employee has heard of. Our method starts from observation instead. We talk to the people doing the work, record the practices that are sound, write those down as the rules, and note every weakness we trip over along the way together with a plan to fix it. The result is a document set an assessor can test and your staff will recognise as describing their own workplace.
The reason behind the request sets the depth. A single customer questionnaire rarely needs more than a compact set. Firms that serve critical infrastructure operators, or might be regulated themselves, need fuller coverage and clear sign-off from the top.
Signed by leadership and kept brief: what the company is protecting, which parts of the business are covered, who answers for it and when it will be revisited. It becomes the yardstick for everything else, not a wall of slogans.
We sit down with you and rate the assets that keep the company running against the threats that could stop them. Real scenarios anchor the scoring, whether that is an ERP outage halting production planning at a supplier or a law firm losing its client files.
Short, readable guidance on sign-in and second factors, company phones, home working, sharing files, email hygiene and AI chatbots. Each rule names a contact for questions.
How an incident is handled, including reporting to USOM or a sector SOME where required, how data is restored, how access is granted and withdrawn, how suppliers are vetted. Written as flows with named roles and time limits.
Customer assessments get answered with references to real documents. Anything you cannot truthfully confirm yet turns into an action item with a deadline, which assessors tend to respect far more than an unconvincing tick.
Your documents set side by side with ISO 27001, the Information and Communication Security Guide or a customer's own framework, showing coverage and the holes still to fill.
Most of the time goes into listening, not typing.
A few video calls with the director, whoever looks after IT and the heads of key departments. Questions are about habits: who sets up a newcomer's login, what happens after a phone is stolen, who calls the shots if systems go down.
Assets and threats rated jointly in a plain spreadsheet that stays yours to update.
Policy, rules and procedures go back to the people they affect. Anything unworkable is rewritten to match reality.
Leadership signs, employees receive a briefing and a review date is booked for next year. Ongoing upkeep can stay with us if you like.
An assessor will test your documents against your systems. Suppose the policy demands twelve-character passwords while the directory still allows eight: that paper now evidences the weakness. We check every written requirement against the live settings before anything goes for signature.
The detailed duties sit mainly with critical infrastructure operators and particular sectors, and implementing rules are still being issued. Many firms outside that circle feel the effect anyway, because regulated customers pass requirements along through audits and contract terms. We can give you an initial view based on your sector and size, while a definitive answer should come from your legal adviser.
Roughly a three-to-four-page policy, five to eight short rule sheets, one risk register and three to five procedures such as incident response and data restore. More pages would not add protection.
It lays the groundwork. We follow ISO 27001 principles and shape the documents so they can become the core of a management system. Only an accredited certification body can issue the certificate, and Apply is not one.
The Information and Communication Security Guide from the Presidency's Digital Transformation Office was written for the public sector, arranging controls by asset type. For a private firm it is a handy Turkish-language checklist; whether it is obligatory depends on your sector. We draw on it as a source.
Each document carries a named owner and a review date. Either we run the annual review or you follow the checklist we leave behind. Any extra hours are charged at €55 per hour plus VAT, with an estimate up front.
Say what prompted this and which documents you have today. We will propose a scope that fits.
We have your enquiry
A reply will reach you by the next working day at the latest. If your message says work has come to a halt, it goes to the top of the pile.
No such city in our list. Try another spelling, or just pick the closest big city: we work entirely over remote connections, so nothing about the service changes from one province to the next.
The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.