For many firms the subject arrives by email. A bank, an energy company or a large manufacturer sends every supplier a lengthy security questionnaire: what happens when you are attacked, which people and companies can log in to your servers, how long logs are kept, and whether the board has formally approved the rules? At other times the question starts internally, because someone read in the press about Turkey's Cybersecurity Law and the new Cybersecurity Directorate. Exactly what the relevant legislation demands of your company is for your legal adviser to judge. Whatever the verdict, though, the same foundations are expected everywhere: a documented risk assessment, an incident response plan that works, suppliers kept under control, logs that are captured and retained, and leadership that owns all of it. Apply builds the technical half of those foundations and prepares the paperwork to go with it, entirely remotely.
used as the framework, with no claim of certification
1
written incident plan naming who spots, who decides and who reports
100%
delivered through remote sessions and video meetings
What we build with you
Readiness is mostly about how a company is organised and only partly about technology, and the two must match. Auditors and customers see through a rulebook staff ignore just as quickly as through security equipment with no paperwork behind it.
Your lawyer can only judge applicability with facts in hand, so we collect them: activities, services offered, any deliveries to critical infrastructure operators, group ownership. At the same time we catalogue systems, user accounts, integrations and external providers. You end up with a shortfall register benchmarked on the national Information and Communication Security Guide and ISO 27001 controls, ranked so the cheap, high-value fixes come first.
A risk assessment people read
Assets, threats, likelihood and impact, applied to real things: the ERP server, the online store, PCs on the production line, administrator accounts. Each risk gets an owner, the control chosen and the residual risk the company accepts. We keep it brief enough to be read and specific enough to be audited, using the Presidency's Digital Transformation Office guide and ISO 27001 as yardsticks rather than handing you a 300-page manual.
Incident response plan
Who notices an incident, who assesses it, who may order systems offline, and who speaks to the outside world? Each role gets a named holder and a stand-in, and fill-in forms cover the first hour, progress updates and the final write-up. The plan further notes whether USOM or your sector's response team expects to hear from you, and how that runs in step with the 72-hour KVKK notice to the Board if customer or staff data is affected.
Supplier security
Your accounting software vendor, the CNC machine maker's remote maintenance link, the host behind your web shop, the payroll bureau: any of them could open the door to an attacker. You get a register of the vendors that matter, a two-page set of security questions to send them and wording for contracts on remote access and incident notice. When the roles are reversed and a customer is quizzing you, we help fill in their forms.
Logging and monitoring
Sign-ins, administrator actions, firewall and VPN events are gathered in one place, clocks are synchronised and retention follows whatever your policy states. After an incident, the answers to “what happened and when did it start” live in these records. Where Microsoft 365 is in use we rely on Defender and Entra ID logs; elsewhere we use tools you already license.
Leadership buy-in and training
Nearly every framework expects the board to approve security decisions, follow up on them and leave a record of doing so. Owners and directors get one focused online briefing covering only the choices that sit with them. Everyone else receives bite-sized lessons on spotting fake emails, handling passwords and reporting anything suspicious straight away.
Order of work
You do not have to tackle everything at once. Sorting out two-step sign-in and knowing who phones whom during an incident protects you more than a flawless folder of policies sitting next to unguarded administrator logins.
01
Where you stand today
A few conversations with key people online, exported settings from your tenant and servers, and a read of any existing policies. From this comes the list of shortfalls plus a rough idea of the hours involved.
02
Decide the route
Directors choose what matters most and how much to spend. The result is a dated plan: immediate actions, items deferred a few months, and risks the company chooses to live with, each signed off.
03
Do the work
A second login factor everywhere, dedicated admin identities, update reports you can show an auditor, EDR across PCs and servers, and backup copies out of ransomware's reach. Production changes happen only in windows you approve, while the written rules take shape in parallel.
04
Practise, then prove it
We walk your team through a simulated incident around a table, bring a system back from backup and send a fake phishing email. What we learn goes into a yearly check-up, keeping the paperwork fresh and giving you dated records for the next customer who asks.
Businesses outside the direct scope feel the pressure too. Consider a 60-person automotive parts plant in Bursa. The plant itself may fall into no special regulatory category, but its customer is a major carmaker held responsible for how secure its suppliers are. One morning a form arrives asking about two-step sign-in, backup testing, the number of hours before the customer hears about an incident and whether shop-floor machines share a network with the office. A supplier able to attach a short security policy, a backup with a test log and a written incident plan stands a far better chance of keeping the business.
Frequently asked questions
Only your legal adviser can say for certain. The law and the rules issued under it focus on particular organisations and service providers, above all critical infrastructure operators, and much of the detail is being settled through secondary regulation. We do not interpret law. We prepare the concrete facts your adviser needs: the services you provide, whom you supply, and whose operations would suffer if your systems went down.
For most smaller firms, customers are the real driver. As infrastructure operators, banks and big manufacturers are pushed to secure their supply chains, they ask their suppliers for proof. Cyber insurance applications ask much the same things. Having a risk assessment, an incident plan and a backup you have actually restored lets you reply confidently, regardless of whether the legislation names you.
Broadly, the rules look for security that is actually managed, not for a specific badge on the wall. That said, a management system built on ISO 27001 answers a large share of what regulators and customers ask, so it is a practical skeleton to hang the work on. We follow the standard's principles and can help you get ready if you decide to pursue the certificate; the certifying audit is always done by an accredited body, not Apply.
USOM is Turkey's national centre for responding to and coordinating cyber incidents; it publishes alerts and lists of malicious addresses. Some sectors also have their own response teams. Apply follows USOM announcements and can feed the published blocklists into your firewall and email filtering. Whether you must report an incident to one of these bodies depends on your position and is written into the incident plan on your legal adviser's advice.
Yes. Banking and capital markets regulators set their own detailed expectations, and interpreting them is the job of your compliance function and lawyers. In that setting Apply acts as the technical delivery partner: we configure systems and logging, close gaps and assemble the technical evidence auditors ask to see. Compliance decisions remain yours.
Not at all. Apply can handle the whole programme, or just the assessment, documentation and drills while your existing partner carries on with routine support. In that arrangement they count as one of your critical suppliers, so we sit down with them to check how they connect, what they log and how fast they react. Physical tasks at your premises stay with your employees or that partner, because Apply never sends people on site.
How ready is your company for cybersecurity scrutiny?
Give us a brief picture of your sector, size and IT set-up, and mention any security questionnaires customers have sent. Within one working day we will come back with a proposal for the baseline review.
Availability Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls By video, over Microsoft Teams or Google Meet
We have your enquiry
A reply will reach you by the next working day at the latest. If your message says work has come to a halt, it goes to the top of the pile.
Filling the gaps. If we need more information to judge the job, we send questions by email or propose a quick Teams or Google Meet call.
A written quote. It lists the scope, a euro price excluding VAT and a realistic start date. No hidden clauses, no items that appear later.
Your decision. The quote arrives by email. Take whatever time you need, raise questions on any line, and decide when you are ready.
Where are you based?
No such city in our list. Try another spelling, or just pick the closest big city: we work entirely over remote connections, so nothing about the service changes from one province to the next.
The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.