Service · Cybersecurity

VPN and encryption

When something goes wrong, encryption decides whether you have a bad day or a crisis. Imagine a wholesaler with its head office in İstanbul, a warehouse in Gebze and a sales office in Ankara. The link between sites was built years ago on an outdated protocol, field sales staff reach the ERP from hotel Wi-Fi using one shared VPN login, and none of the laptops has disk encryption. When a bag is stolen from a car, the customer list, price sheets and saved passwords leave with the laptop. Had the disk been encrypted, the loss would have been a piece of hardware and nothing more. This service makes data unreadable both in transit and at rest: tunnels between locations, authenticated access for remote staff, full-disk encryption on laptops and secure ways to send sensitive documents. We pay particular attention to the part most often neglected, namely where the keys are kept and who can get to them. All configuration is carried out remotely on the equipment you already have.

BitLocker
and FileVault on every laptop
Recovery keys
stored centrally, never on paper
WireGuard or IPsec
in place of outdated protocols
Second factor
on every VPN login

What the work covers in practice

The method follows the purpose. Not every remote user needs a full VPN, and not every document needs encrypting on its own.

Agree the scope with the engineer who will do the work

Site links

Firewall-to-firewall tunnels between head office, branches, warehouses and plants. Weak legacy ciphers are replaced with current ones, and a dropped tunnel raises an alert.

Remote working

Personal VPN accounts with a second factor for home and field staff. Where possible, a narrower design that exposes only the needed applications, such as the ERP or file server, instead of the whole network.

Disk encryption

BitLocker on Windows and FileVault on macOS, enforced through Intune. Recovery keys are escrowed in Entra ID, with access to them logged.

Email encryption

TLS enforced between mail servers by default, plus Microsoft Purview message encryption or a similar service for sensitive messages, without the recipient needing extra software.

File exchange

Expiring, password-protected links instead of attachments, and dedicated, logged spaces for regular exchanges with your accountant, lawyer or external designer.

Certificates and keys

An overview of TLS certificates on the website, mail server and VPN, with expiry dates and automatic renewal. A certificate that silently expires causes some of the most irritating outages.

How we approach the job, from first call to handover

Encryption rarely fails for technical reasons; it fails because a key has gone missing. Key management therefore comes first.

01

Current state

Which devices are encrypted, where the keys are, which tunnels run with which settings, who holds a VPN account and how many of those are still in use.

02

Approach

Methods, key storage, who may access keys and who is responsible are agreed, including what happens if a key is lost.

03

Implementation

Devices are encrypted while in use; tunnels and VPN settings change in a maintenance window, and users receive a short guide.

04

Evidence

A report showing encryption status for every device, ready for insurance forms, supplier questionnaires and your KVKK safeguard records.

A lost encrypted laptop is a hardware problem; a lost unencrypted one is a data breach. The gap between the two is often one setting and a recovery key kept in the right place. Yet when we ask, that setting is frequently only partly done, or not done at all.

Frequently asked questions

Not noticeably on current hardware, which encrypts at processor level. The initial encryption runs in the background while the machine is in use. Very old devices may take a little longer for that first pass.

No. KEP is registered electronic mail with evidential value in Turkish law and is used for formal notifications. Encrypted email simply ensures only the recipient can read the content. They serve different purposes; a KEP address comes from an authorised KEP service provider.

If they only use Microsoft 365 or cloud apps, a VPN is often unnecessary; conditional access and managed devices protect better. Access to an on-premises ERP or file server calls for a VPN or application-level access. We decide after looking at the applications you actually use.

Without it, data on an encrypted disk is practically unrecoverable, which is the point of encryption. That is why keys are stored centrally in Entra ID or another documented location, access is logged and we test that a key can really be retrieved.

Protect data on the move and in the bag

Tell us how many sites and remote staff you have and which devices they use. We will suggest an encryption plan.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.