SPK-Compliant Service

Information Systems under the SPK Framework
Penetration Tests

Nesil Teknoloji – SPK Independent Auditor Licensed

For capital market institutions and portfolio management companies, we perform Information Systems Penetration Tests, with full compliance to the procedures and principles defined in the relevant Communiqué.

Purpose (compliant with the Communiqué)

The purpose of penetration tests is the detection of potential security weaknesses in the information systems of Institutions, Organisations and Partnerships before penetration attempts, the analysis of combined risks and the determination of remedial activities.

Scope (Minimum)

Communication Infrastructure and Active Devices

Firewall/Router/Switch configurations, DMZ

DNS Services

Domain name services security

Domain & User Computers

AD, endpoint policies

E-mail Services

Content security, phishing scenarios

Database Systems

Authorisation, query security

Web Applications

Application/API reviews

Mobile Applications

iOS/Android security controls

Wireless Network Systems

WLAN encryption and isolation

Distributed Denial of Service

DDoS tests (coordinated)

Social Engineering

Phishing, fake verification

These headings are the minimum scope in the Communiqué; they can be expanded according to the organisation's scale and risks.

Methodology – Access Points & User Profiles

Access Points

  • Internet: Testing the organisation's internet-facing servers/services from an external location
  • Internal Network: Testing the servers on the organisation's internal network by accessing from within

User Profiles

  • Anonymous user: Non-member external user
  • Customer profile: User authorised to log in to web applications
  • Employee profile: The most common user + local admin

System Identification

Determination of the system/configuration information of servers and network devices.

Service Identification

Port scanning and inventory of externally exposed services.

Vulnerability Scanning

Scanning of components against current vulnerabilities.

Finding Severity Levels (Communiqué)

LevelDefinition
EmergencyWeaknesses allowing an unqualified attacker to completely take over the system from the external network
CriticalWeaknesses allowing a qualified attacker to completely take over the system from the external network
HighLimited privilege escalation/denial of service from the external network, or privilege escalation locally
MediumWeaknesses leading to denial of service from the local network/server
LowSituations whose impact cannot be fully determined; stemming from hardening deficiencies

Reporting & Follow-up (compliant with the Communiqué)

Report Content

  • Findings under each heading and a combined risk assessment
  • Finding Format: Reference No, Name, Severity Level, Impact, Component(s), Remediation Recommendation
  • Test team information and relevant competency certificates

Process & Notification

  • After the report is completed, within 1 month ready for submission to the Board
  • Board-approved action plan
  • Prompt closure of "Emergency" and "Critical" findings

Why Nesil Teknoloji?

SPK Independent Auditor Licence

Official competence; a process and reporting fully compliant with the Communiqué

Finance Sector Focus

Experience in portfolio management, brokerage and fintech

Audit-Usable Report

Finding format and severity levels compliant with the Communiqué

Confidentiality & Security

A method that does not jeopardise business continuity; coordinated tests

Expert Team & Accreditations

TSE-Certified Penetration Testing Company
Certificate No: TSE-STF-065
Nesil Teknoloji A.S. is certified by the Turkish Standards Institution as an TS 13638/T2 "Approved Penetration Testing Company" under the standard.

Certificates Held by Our Team

International Certificates
CEHCertified Ethical HackerEC-Council
OSCPOffensive Security Certified ProfessionalOffensive Security
Security+CompTIA Security+CompTIA
CISSPCertified Information Systems Security Professional(ISC)²
CISACertified Information Systems AuditorISACA
GPENGIAC Penetration TesterSANS/GIAC
LPTLicensed Penetration TesterEC-Council
TSE Penetration Testing Experts
2
Senior Penetration Testing ExpertTSE Certified
4
Certified Penetration Testing ExpertTSE Certified
3
Registered Penetration Testing ExpertTSE Registered
All Our Certificates and Documents Click for detailed information and to view documents

Our References

Tera Portföy Yönetimi A.S
Tera Yatırım Menkul Değerler A.S

SPK-scope tests completed; reports accepted.

IKON Menkul Değerler A.S.

Internet & internal network, web/API and e-mail tests; combined risk analysis.

Perform Portföy Yönetimi A.S.

Web/mobile, database and wireless network tests.

Due to confidentiality agreements, the sharing of names is limited; a detailed list is provided on request.

SPK-Compliant Penetration Testing – Get a Quote

Let's plan the test scope, methodology and reporting process together.

Uygar Aydın – Cybersecurity Team
Cybersecurity Team – Online Meeting with Uygar Aydın
Let's define the scope of the SPK Information Systems Penetration Tests together. In a 30-minute online meeting, let's determine the Communiqué-compliant scope, test schedule and delivery processes, and share our quote.
  • Preliminary reconnaissance & scope verification (specific to your organisation)
  • Communiqué-compliant notification and reporting plan
  • Rapid quoting and a start date
You can fill in the form and send it to [email protected] .