Imagine a Gaziantep exporter of home textiles with 35 staff. One morning its largest buyer, based in Germany, emails over fifty questions about information security: is MFA mandatory, when were backups last tested, is anything running past its vendor support date, what is the incident notification procedure? Within days the cyber insurer sends a renewal questionnaire along the same lines. Operations run fine. Still, most answers would be guesses. Nobody is sure of the age of the machine in the comms cupboard, whose personal details sit on the domain registration, or whether last night's backup could ever be brought back. That is the situation this service was built for. It suits the moment a customer or underwriter wants proof, when you are replacing an IT contractor, when the colleague who quietly kept everything going resigns, or when the board wants to know which investment would reduce risk most. Our access is strictly read-only; nothing is reconfigured and nobody has to travel to you. You end up with a brief, plain-language summary for leadership and a thorough appendix for the technicians who will act on it.
Checklists with hundreds of lines tend to bury what matters. We organise the review around seven plain questions that any company owner should be able to answer, and rate each one red, amber or green with the reasoning written out.
A full register of devices, including the ones that dropped off everybody's radar: an old storage box in a meeting room, the time clock by the entrance, a copier that sends scans using a saved email password, an unsupported PC next to the production line.
How do you look to an attacker?
Internet-facing services, the software version on the VPN gateway, certificates about to lapse, and whether your domain publishes proper sender authentication records. All of it is visible to outsiders without any login.
Who holds which rights?
Leavers whose logins still work, administrator privileges on day-to-day accounts, users not covered by MFA, and generic shared usernames in the directory, in Microsoft's cloud identity service or inside packages like Logo and Mikro.
How far behind are updates?
Patch state for servers, desktops, firewall and switching, plus a schedule of when each product loses support. Replacements can then be planned into a budget instead of ordered in a panic.
Would a restore really work?
We bring back a sample file and, if you agree, an entire virtual machine, stopwatch running. We also establish whether a copy exists somewhere ransomware could never touch.
In whose name is everything registered?
Domain, Microsoft 365 or Google Workspace tenant, internet contract, hosting, the account with your e-invoice integrator and business software licences: registered holder, renewal date and who is able to act on it in a crisis.
What are regulators and buyers looking for?
The main technical safeguards expected under KVKK, a first reading against Turkey's cybersecurity legislation in general terms, ISO 27001 principles and the themes customers and insurers keep raising. Preparation is our part; certification is not.
How we approach the job, from first call to handover
Plan on two to three weeks from first meeting to delivery for an organisation with 20-40 desks. Staff time on your side adds up to only a handful of hours.
01
Opening meeting
Forty-five minutes online covering what triggered the review, your locations, the systems you cannot live without and any concerns already on the table. The priorities are clear by the end.
02
Data gathering
Temporary read-only logins and a discovery agent collect information across several working days, while your public IP addresses are probed from the internet.
03
Hands-on sampling
A trial restore, a walk through the administration portals and a short chat with two or three people who use the systems every day. Informal workarounds and unofficial apps only show up that way.
04
Report in two layers
A four-page management summary and a technical annex listing each issue with an hour-based remediation plan, presented to you in an online session.
A green backup report does not mean you can recover. Backup software proudly reports success every night, but frequently it is only confirming that a job ran. Common finds include jobs saving an empty directory ever since a server migration, database copies taken while files were in use and therefore unreadable, and encrypted archives whose key disappeared with a former employee. So our health check always includes a real restore rather than reading log files. Anything critical is reported to you the same day instead of waiting for the final document.
Frequently asked questions
Scanners are good at spotting exposed services and absent updates. They are blind to a domain held in the founder's own name or a backup quietly saving nothing since a migration. We let software handle the repetitive part and keep the assessment human.
Confidentiality and data processing terms are agreed in writing before we log in anywhere. Each engineer uses a personal, audited account, and raw material is destroyed within the agreed time after delivery. The report and annex stay with you.
It does. At each site the agent just needs one computer we can reach, and a local colleague snaps photos of the comms rack on their phone. Branches get separate chapters, since they rarely mirror head office.
The answer turns on your sector, scale, whether you count as a critical infrastructure operator and how the rules are implemented as they develop. We give you a reasoned preliminary view and list the paperwork you would lack. For a binding answer, consult a lawyer.
Time is billed at €55 per hour plus VAT within a range we quote up front. You are free to walk away afterwards: the remediation plan is written so that your existing IT company, or anyone else, can execute it.
Share the number of workstations and sites and what has prompted the check. Within one working day we will suggest a kick-off date and an expected range of hours.
Availability Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls By video, over Microsoft Teams or Google Meet
We have your enquiry
A reply will reach you by the next working day at the latest. If your message says work has come to a halt, it goes to the top of the pile.
Filling the gaps. If we need more information to judge the job, we send questions by email or propose a quick Teams or Google Meet call.
A written quote. It lists the scope, a euro price excluding VAT and a realistic start date. No hidden clauses, no items that appear later.
Your decision. The quote arrives by email. Take whatever time you need, raise questions on any line, and decide when you are ready.
Where are you based?
No such city in our list. Try another spelling, or just pick the closest big city: we work entirely over remote connections, so nothing about the service changes from one province to the next.
The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.