Skip to content
normSight — Cyber Security

Security testing and consultancy

Solutions

We test your entire attack surface — from the network to mobile applications — with real attack scenarios, verifying every finding manually.

KVKK Compliance Consultancy

KVKK consultancy analyses an organisation's personal data processing activities under Turkish data protection law no. 6698 and determines the technical and administrative measures required for compliance.

View details

Mobile Application Penetration Testing

Mobile application penetration testing identifies security flaws in what an iOS or Android application stores on the device, how it communicates with the server, and in its back-end APIs.

View details

DoS/DDoS Testing

DoS/DDoS testing measures, under controlled conditions, at what point and in what way an organisation's web and network systems fail under denial-of-service attack.

View details

Network Penetration Testing

Network penetration testing is the authorised exploitation of vulnerabilities found on an organisation's servers, clients and network devices, verifying them the way a real attacker would.

View details

Social Engineering Assessment

A social engineering assessment measures how well an organisation's employees withstand phishing and persuasion-based attacks, using controlled scenarios.

View details

Web Application Penetration Testing

Web application penetration testing is the identification of security flaws in an application's source code, session management, authorisation and data layer through authorised exploitation by a specialist.

View details

Wireless Network Security Testing

Wireless network security testing identifies encryption, authentication and network segregation weaknesses in an organisation's Wi-Fi infrastructure through an authorised intrusion attempt.

View details

Frequently Asked Questions

How do I know which type of penetration test I need?

Start from your attack surface: a public web application calls for a web application penetration test, internal servers and clients for a network penetration test, and a mobile app for a mobile application penetration test. During scoping we map your assets together and recommend the right engagement.

Will the tests disrupt running systems?

No. Testing runs within an agreed scope and time window, designed not to cause service interruption. Work that generates load by nature, such as DoS/DDoS testing, is carried out only with written approval and usually outside business hours.

Is the retest charged separately?

No. Verification testing after you remediate the reported findings is included in the engagement.

See the real risks in your systems.

Talk to our team about a penetration test or training plan that fits your scope.