Against Cyber Threats
Full-time proactive protection
Since 2018 we deliver penetration testing, security consultancy and specialist training to public institutions and the private sector. We have reported critical vulnerabilities in software by Apple, Sony, Opera and WordPress.
- Founded
- 2018 Founded
- Offices: Diyarbakır, Istanbul, Ankara
- 3 Offices: Diyarbakır, Istanbul, Ankara
- Security testing services
- 7 Security testing services
- Specialist training courses
- 14 Specialist training courses
Solutions
See what an attacker would see — first.
We test your network, web, mobile and wireless layers with real attack scenarios, verifying every finding manually.
KVKK Compliance Consultancy
KVKK consultancy analyses an organisation's personal data processing activities under Turkish data protection law no. 6698 and determines the technical and administrative measures required for compliance.
View detailsMobile Application Penetration Testing
Mobile application penetration testing identifies security flaws in what an iOS or Android application stores on the device, how it communicates with the server, and in its back-end APIs.
View detailsDoS/DDoS Testing
DoS/DDoS testing measures, under controlled conditions, at what point and in what way an organisation's web and network systems fail under denial-of-service attack.
View detailsNetwork Penetration Testing
Network penetration testing is the authorised exploitation of vulnerabilities found on an organisation's servers, clients and network devices, verifying them the way a real attacker would.
View detailsSocial Engineering Assessment
A social engineering assessment measures how well an organisation's employees withstand phishing and persuasion-based attacks, using controlled scenarios.
View detailsWeb Application Penetration Testing
Web application penetration testing is the identification of security flaws in an application's source code, session management, authorisation and data layer through authorised exploitation by a specialist.
View detailsWireless Network Security Testing
Wireless network security testing identifies encryption, authentication and network segregation weaknesses in an organisation's Wi-Fi infrastructure through an authorised intrusion attempt.
View detailsTrainings
Bring your team up to the attacker's level.
Defensive Trainings
Detection, analysis and response: forensics, malware analysis, threat hunting, CSIRT.
- 01 CSIRT / Incident Response Training
- 02 Cyber Threat Hunting
- 03 Digital Forensics
- 04 Malware Analysis
- 05 Network Security
- 06 Reverse Engineering
- 07 Web Application Security
Offensive Trainings
The offensive side: penetration testing, web and mobile application security, exploit development.
- 01 Exploit Development
- 02 Mobile Application Security and Penetration Testing
- 03 Penetration Testing eXtreme
- 04 Penetration Testing Student
- 05 Professional Penetration Testing
- 06 Web Application Penetration Testing Course
- 07 Web Application Penetration Testing eXtreme
Technology Partners
Frequently Asked Questions
What is the difference between a penetration test and a vulnerability scan?
A vulnerability scan lists known issues using automated tools. In a penetration test an expert exploits the findings like a real attacker, proving impact and uncovering chained attack paths. Every normSight finding is verified manually.
How long does a penetration test take?
It depends on scope. A single web application typically takes 5-10 business days; a full corporate network 3-4 weeks. A precise schedule is shared after the scoping call.
What is delivered at the end of a test?
A report containing an executive summary, technical findings, evidence screenshots, risk ratings and remediation guidance. A post-remediation retest is part of the engagement.
Are trainings delivered remotely or on-site?
Both. Courses can be scheduled on-site at your organisation or as live online classes; hands-on lab access is provided either way.
What does compliance consultancy cover?
Gap analysis, data inventory and processing records, assessment of technical and administrative measures, review of privacy notices and consent texts, and a prioritised compliance roadmap.
Let's talk about your scope.
We serve clients across Türkiye from our Diyarbakır, Istanbul and Ankara offices.