Data Protection Compliance and Cyber Security Package

We turn the data protection policies on paper into technical measures that are actually enforced on your servers and in your applications.

Technical Measures Audit Penetration Testing Log and Security Monitoring Breach Response Plan
AddressAtaşehir, Istanbul
Phone+90 850 335 10 87
E-mailinfo@360-soft.com
Data Protection Compliance and Cyber Security Package

Measures in practice, not policy on paper

At many companies, data protection compliance is considered “done” once a law firm has drafted the privacy notices, a cookie banner has been added to the website and the company has registered with the authority (VERBİS in Turkey). Yet most breaches come from systems, not documents: a backup file left publicly accessible, an admin account whose password was never changed, a plugin that has not been updated for years, database access that is never logged. After such a breach, the regulator will not ask “did you have a policy?” but “which technical measures did you take, and when did you notice the breach?”

The Data Protection Compliance and Cyber Security Package takes the technical and organisational measures guide published by Turkey’s Personal Data Protection Authority as its starting point, which maps closely to GDPR expectations, and combines three pieces of work: a technical compliance audit that traces the journey of personal data through your systems, penetration testing that checks whether those measures actually work, and security monitoring that helps you spot a breach early.

Who is it designed for?

  • E-commerce sites: shops that process large volumes of personal data through customer addresses and contact details, order history and marketplace integrations.
  • Healthcare providers and health tech companies: clinics, outpatient centres, laboratories and companies that use or develop appointment and patient management software.
  • Finance and fintech companies: brokerages and companies offering payment and lending solutions that process customer identity, income and transaction data.
  • B2B software suppliers: SaaS and software companies whose enterprise customers ask for security questionnaires and audit reports.

If you are only looking for a vulnerability test of a specific application, our Penetration Testing (Pentest) Service page covers the scope and reporting details; for your website’s regular update and backup needs, we offer Website Maintenance and Security. This package brings those pieces of work together in a single framework from a data protection perspective.

Package modules

Modules can be taken together or separately; we define the scope with you based on your sector and system architecture.

Personal data flow map

A technical data flow diagram from the forms where data is collected, to the databases where it is stored, to the third-party services it is shared with (shipping, SMS, e-mail, analytics, payments).

Technical measures audit

Review of encryption (in transit and at rest), access rights, password and multi-factor authentication policies, backups, log retention and data destruction practices.

Web, mobile and API penetration testing

Controlled attacks on applications holding personal data to test for privilege escalation, data leakage, injection and session management vulnerabilities.

Server and cloud configuration review

Open ports, publicly accessible storage, unpatched services, access restrictions on admin panels and security group rules.

Third-party and supplier access

Identifying agency, software supplier and former employee accounts; removing shared passwords and permanent remote access.

Log collection and security monitoring

Collecting application, server and database logs in one central place, with alert rules for suspicious logins, bulk data exports and permission changes.

Breach response plan

Who does what when a breach is suspected, which logs must be preserved, how the affected people and data are identified and how technical input for the notification process is prepared.

Remediation and retesting

Findings are fixed together with your team or by us, then the fixes are retested and closed.

From audit to ongoing monitoring - Data Protection Compliance and Cyber Security Package

From audit to ongoing monitoring

01

Scope and authorisation

The systems to be audited, the environments to be tested and the time windows are agreed. Written authorisation and a non-disclosure agreement are signed for the penetration test.

02

Inventory and data flow mapping

Through interviews with your IT team and process owners, system reviews and, if needed, network traffic analysis, we establish where personal data resides.

03

Audit and testing

Technical measures are reviewed against a checklist and the penetration test is carried out. If a critical finding emerges, it is reported immediately without waiting for the report.

04

Reporting and prioritisation

Findings are ranked by risk level, affected data category and remediation effort; an executive summary and a detailed report for the technical team are prepared.

05

Remediation and monitoring setup

Priority findings are closed, log collection and alert rules are put in place and the breach response plan is tested with a drill.

06

Ongoing monitoring and periodic retesting

Alerts are monitored and a monthly security summary is shared; tests are repeated after major releases and at planned intervals.

Audit priorities by sector

The scope starts from the same framework in every sector; the controls that get most weight change with the nature of the data.
Sector Main data risk Controls prioritised in the package
E-commerce Customer contact and address details, order history, marketplace and shipping integrations Admin panel security, checkout script integrity, export files, plugin updates
Healthcare Special category personal data: diagnoses, tests, prescriptions, appointment details Encryption at rest, role-based access, access log retention, patient portal permission tests
Finance Identity, income, account and transaction data Privileged account management, API authorisation, transaction logs, supplier access
B2B SaaS Data from multiple customers in the same system Tenant data isolation, backup access, technical evidence for customer security questionnaires
What you have at the end of the package - Data Protection Compliance and Cyber Security Package

What you have at the end of the package

Deliverables

  • Personal data flow diagram and a system-by-system data inventory (technical input for your legal adviser’s inventory work)
  • Technical measures audit report: measures implemented, missing and partly implemented
  • Penetration test report: CVSS-scored findings, evidence and remediation recommendations
  • Retest results after remediation
  • Log collection and alert configuration, plus a monthly security summary
  • Breach response plan and escalation chain

Pricing

There is no fixed price published on the site for this package. The cost depends on the number of applications and servers to be tested, data sensitivity and the scope of monitoring. After a scoping meeting, a fixed-price proposal tailored to your project is sent within 24 hours; the audit and testing are shown as a one-off fee and monitoring as a monthly service, in separate line items.

For secure setup and ongoing management of your infrastructure, see DevOps Support, and to have all your systems managed externally, our IT Outsourcing service.

No. Privacy notices, explicit consent forms, registration with VERBİS (Turkey’s data controller registry) or its equivalent in your market, and the legal interpretation of data controller obligations are the job of your lawyer or data protection legal adviser. We take on the technical side: we audit and fix which systems hold personal data and how, who can access it, how it is protected and how a breach would be detected. We also prepare technical documentation that makes it easier for you to work from the same inventory as your legal adviser.

KVKK (Turkey’s data protection law), like the GDPR, expects data controllers to take appropriate technical measures to protect data; but whether a measure actually works cannot be established by reviewing documents alone. Penetration testing is the step where encryption, access control and authorisation are tested from an attacker’s point of view. When the two pieces of work are done by separate teams, the findings are never linked; in this package, every technical finding is mapped to the relevant data category and risk level.

Under the Turkish Personal Data Protection Board’s decision on breach notification, the data controller must notify the Board without delay and within 72 hours at the latest from the moment it becomes aware of the breach; the GDPR sets the same 72-hour window. Meeting that deadline requires detecting the breach quickly and being able to determine which data and which people are affected. The log monitoring and response plan in this package are designed precisely so that you can meet this deadline.

Yes. Even if card details stay with the payment provider, names, addresses, phone numbers, e-mail addresses and order history are personal data. Admin panel vulnerabilities, order export files exposed to unauthorised access, outdated plugins and malicious scripts injected into the checkout page are common breach routes in e-commerce. The package specifically tests these scenarios.

Health data is classed as a special category of personal data under KVKK, and the Board expects additional measures for it; in finance, the information systems requirements of sector regulators apply in addition to data protection law. In these sectors the audit scope widens: encryption, retention of access logs, privileged account management and supplier access are examined in more detail.

The audit and penetration test are periodic pieces of work; security monitoring is ongoing. Typically, monitoring continues after the initial audit and fixes, and the penetration test is repeated at set intervals (for example once a year or after a major release). You can choose which modules to take based on your needs.

The next success story
is yours.

The first consultation is free. We prepare a tailored proposal within 24 hours.

Get a free quote