Skip to content
normSight — Cyber Security

Against Cyber Threats

Full-time proactive protection

Since 2018 we deliver penetration testing, security consultancy and specialist training to public institutions and the private sector. We have reported critical vulnerabilities in software by Apple, Sony, Opera and WordPress.

Founded
2018 Founded
Offices: Diyarbakır, Istanbul, Ankara
3 Offices: Diyarbakır, Istanbul, Ankara
Security testing services
7 Security testing services
Specialist training courses
14 Specialist training courses

Solutions

See what an attacker would see — first.

We test your network, web, mobile and wireless layers with real attack scenarios, verifying every finding manually.

All solutions

KVKK Compliance Consultancy

KVKK consultancy analyses an organisation's personal data processing activities under Turkish data protection law no. 6698 and determines the technical and administrative measures required for compliance.

View details

Mobile Application Penetration Testing

Mobile application penetration testing identifies security flaws in what an iOS or Android application stores on the device, how it communicates with the server, and in its back-end APIs.

View details

DoS/DDoS Testing

DoS/DDoS testing measures, under controlled conditions, at what point and in what way an organisation's web and network systems fail under denial-of-service attack.

View details

Network Penetration Testing

Network penetration testing is the authorised exploitation of vulnerabilities found on an organisation's servers, clients and network devices, verifying them the way a real attacker would.

View details

Social Engineering Assessment

A social engineering assessment measures how well an organisation's employees withstand phishing and persuasion-based attacks, using controlled scenarios.

View details

Web Application Penetration Testing

Web application penetration testing is the identification of security flaws in an application's source code, session management, authorisation and data layer through authorised exploitation by a specialist.

View details

Wireless Network Security Testing

Wireless network security testing identifies encryption, authentication and network segregation weaknesses in an organisation's Wi-Fi infrastructure through an authorised intrusion attempt.

View details

Technology Partners

  • Cisco
  • Sophos
  • ESET
  • Berqnet
  • Recorded Future
  • ELS

Frequently Asked Questions

What is the difference between a penetration test and a vulnerability scan?

A vulnerability scan lists known issues using automated tools. In a penetration test an expert exploits the findings like a real attacker, proving impact and uncovering chained attack paths. Every normSight finding is verified manually.

How long does a penetration test take?

It depends on scope. A single web application typically takes 5-10 business days; a full corporate network 3-4 weeks. A precise schedule is shared after the scoping call.

What is delivered at the end of a test?

A report containing an executive summary, technical findings, evidence screenshots, risk ratings and remediation guidance. A post-remediation retest is part of the engagement.

Are trainings delivered remotely or on-site?

Both. Courses can be scheduled on-site at your organisation or as live online classes; hands-on lab access is provided either way.

What does compliance consultancy cover?

Gap analysis, data inventory and processing records, assessment of technical and administrative measures, review of privacy notices and consent texts, and a prioritised compliance roadmap.

Let's talk about your scope.

We serve clients across Türkiye from our Diyarbakır, Istanbul and Ankara offices.