Service · IT infrastructure

Infrastructure health check

Imagine a Gaziantep exporter of home textiles with 35 staff. One morning its largest buyer, based in Germany, emails over fifty questions about information security: is MFA mandatory, when were backups last tested, is anything running past its vendor support date, what is the incident notification procedure? Within days the cyber insurer sends a renewal questionnaire along the same lines. Operations run fine. Still, most answers would be guesses. Nobody is sure of the age of the machine in the comms cupboard, whose personal details sit on the domain registration, or whether last night's backup could ever be brought back. That is the situation this service was built for. It suits the moment a customer or underwriter wants proof, when you are replacing an IT contractor, when the colleague who quietly kept everything going resigns, or when the board wants to know which investment would reduce risk most. Our access is strictly read-only; nothing is reconfigured and nobody has to travel to you. You end up with a brief, plain-language summary for leadership and a thorough appendix for the technicians who will act on it.

Seven questions
not a 300-line checklist
Read-only access
your settings stay as they are
Actual restore
backups proven, not assumed
Ranked findings
by risk and estimated effort

What the work covers in practice

Checklists with hundreds of lines tend to bury what matters. We organise the review around seven plain questions that any company owner should be able to answer, and rate each one red, amber or green with the reasoning written out.

Agree the scope with the engineer who will do the work

What is actually out there?

A full register of devices, including the ones that dropped off everybody's radar: an old storage box in a meeting room, the time clock by the entrance, a copier that sends scans using a saved email password, an unsupported PC next to the production line.

How do you look to an attacker?

Internet-facing services, the software version on the VPN gateway, certificates about to lapse, and whether your domain publishes proper sender authentication records. All of it is visible to outsiders without any login.

Who holds which rights?

Leavers whose logins still work, administrator privileges on day-to-day accounts, users not covered by MFA, and generic shared usernames in the directory, in Microsoft's cloud identity service or inside packages like Logo and Mikro.

How far behind are updates?

Patch state for servers, desktops, firewall and switching, plus a schedule of when each product loses support. Replacements can then be planned into a budget instead of ordered in a panic.

Would a restore really work?

We bring back a sample file and, if you agree, an entire virtual machine, stopwatch running. We also establish whether a copy exists somewhere ransomware could never touch.

In whose name is everything registered?

Domain, Microsoft 365 or Google Workspace tenant, internet contract, hosting, the account with your e-invoice integrator and business software licences: registered holder, renewal date and who is able to act on it in a crisis.

What are regulators and buyers looking for?

The main technical safeguards expected under KVKK, a first reading against Turkey's cybersecurity legislation in general terms, ISO 27001 principles and the themes customers and insurers keep raising. Preparation is our part; certification is not.

How we approach the job, from first call to handover

Plan on two to three weeks from first meeting to delivery for an organisation with 20-40 desks. Staff time on your side adds up to only a handful of hours.

01

Opening meeting

Forty-five minutes online covering what triggered the review, your locations, the systems you cannot live without and any concerns already on the table. The priorities are clear by the end.

02

Data gathering

Temporary read-only logins and a discovery agent collect information across several working days, while your public IP addresses are probed from the internet.

03

Hands-on sampling

A trial restore, a walk through the administration portals and a short chat with two or three people who use the systems every day. Informal workarounds and unofficial apps only show up that way.

04

Report in two layers

A four-page management summary and a technical annex listing each issue with an hour-based remediation plan, presented to you in an online session.

A green backup report does not mean you can recover. Backup software proudly reports success every night, but frequently it is only confirming that a job ran. Common finds include jobs saving an empty directory ever since a server migration, database copies taken while files were in use and therefore unreadable, and encrypted archives whose key disappeared with a former employee. So our health check always includes a real restore rather than reading log files. Anything critical is reported to you the same day instead of waiting for the final document.

Frequently asked questions

Scanners are good at spotting exposed services and absent updates. They are blind to a domain held in the founder's own name or a backup quietly saving nothing since a migration. We let software handle the repetitive part and keep the assessment human.

Confidentiality and data processing terms are agreed in writing before we log in anywhere. Each engineer uses a personal, audited account, and raw material is destroyed within the agreed time after delivery. The report and annex stay with you.

It does. At each site the agent just needs one computer we can reach, and a local colleague snaps photos of the comms rack on their phone. Branches get separate chapters, since they rarely mirror head office.

The answer turns on your sector, scale, whether you count as a critical infrastructure operator and how the rules are implemented as they develop. We give you a reasoned preliminary view and list the paperwork you would lack. For a binding answer, consult a lawyer.

Time is billed at €55 per hour plus VAT within a range we quote up front. You are free to walk away afterwards: the remediation plan is written so that your existing IT company, or anyone else, can execute it.

Request a health check

Share the number of workstations and sites and what has prompted the check. Within one working day we will suggest a kick-off date and an expected range of hours.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.