Ankara Cyber Security: Corporate Pentesting, KVKK Compliance, and the KAOS Domestic AI Engine

TL;DR: DSET has been providing cyber security services from its headquarters at Hacettepe Teknokent, Ankara since 2003. The team is led by Hamza Aytaç Doğanay, who spent 6 years at the Cybercrime Department of the Turkish National Police (Emniyet Genel Müdürlüğü) and holds a thesis-track master's degree in Digital Forensics from Ankara University. Services include penetration testing, ISO/IEC 27001 compliance consulting, KVKK technical-measures auditing, post-ransomware response, and USOM incident-reporting coordination. The most critical capability that sets DSET apart is its domestically developed KAOS AI engine. Data stays within Turkey's borders, and the model runs MITRE ATT&CK techniques as an agentic AI.

Why does the Ankara cyber security ecosystem matter?

Ankara is not only Turkey's center of justice and regulation; it is also the heart of the defense industry, critical infrastructure, and academic cyber security research. This density elevates cyber risk for organizations operating in the city from an ordinary IT matter to a national-security level concern.

The city's ecosystem consists of the following components:

  • Defense industry: ASELSAN, ROKETSAN, HAVELSAN, STM, and TUSAŞ are headquartered in Ankara. The subcontractor network of these organizations spans thousands of SMEs, all of which are highly sensitive from a supply chain security standpoint.
  • State technical expertise: TÜBİTAK BİLGEM is in Ankara; domestic cryptography, national SOC (SOME) support, and standards development work are conducted from here. The CBDDO (Presidency's Digital Transformation Office) and USOM coordinate from Ankara.
  • Academia: The cyber security laboratories of Hacettepe, METU (ODTÜ), and Bilkent are active. Hacettepe Teknokent and Cyberpark Bilkent bring cyber startups together under a single roof.
  • Regulatory hub: BDDK, SPK, BTK, and the KVKK Authority are in Ankara. Communication with this structure is a live, everyday agenda in the financial sector and other regulated sectors.
  • Regulatory density: The BTK information and communication security guide, KVKK secondary legislation, and the banking BDDK framework are all defined through Ankara.

This density requires that a cyber security firm operating in Ankara perform at a technical level above the ordinary market standard. DSET's position within Hacettepe Teknokent is strategic, both because it sits within the campus security corridor and because of its proximity to this ecosystem.

Which sectors do we serve?

Defense industry subcontractors

Many of the SMEs tied to the supply chains of ASELSAN, ROKETSAN, HAVELSAN, STM, and TUSAŞ are contractually required to provide ISO 27001 certification, proof of KVKK compliance, and regular penetration test reports. DSET handles this trio in a single package.

Banking and finance

The BDDK and SPK regulatory framework requires independent penetration testing and compliance auditing every year. For finance groups in Ankara and participation-bank infrastructure providers, we run web application, mobile banking, and API security tests.

Healthcare and private hospital groups

Patient data is special-category personal data under the KVKK definition. Hospital information systems (HIS), the PACS imaging archive, and mobile health applications are among the most frequently targeted areas.

Public sector and municipalities

Independent security audits for municipal e-government integrations, citizen portals, and payment systems. We also provide coordination support to public institutions on USOM incident-reporting processes.

Law firms and family businesses

Leakage of client data and sensitive correspondence is one of the highest risks for a law firm in terms of reputation and liability. We offer appropriately scaled packages, from small offices to large partnerships.

E-commerce and software companies

Regulatory thresholds tied to annual revenue and large customer contracts often require ISO 27001 and a pentest report. Software startups within Cyberpark and Hacettepe Teknokent benefit from neighborly support on this.

Our service lines

Penetration testing (pentest)

For web applications, network infrastructure, mobile applications, cloud environments, and wireless networks. Methodology within the OWASP Top 10 and NIST SP 800-115 frameworks. In black box, gray box, and white box modes. For the detailed process, see our pentest process and pricing guide.

ISO/IEC 27001 compliance consulting

For ISO/IEC 27001 Information Security Management System (ISMS) certification: setup from scratch, GAP analysis, risk assessment, procedure writing, internal audit, and preparation for the certification audit. See our ISO 27001 implementation guide for reference.

KVKK technical-measures auditing

Organization-specific auditing, and remediation of gaps, against the technical-measure headings in the data security guide published by the KVKK Authority (penetration testing, log management, authorization, encryption, anti-malware, backup).

Post-ransomware response

Hour-by-hour emergency response in the event of encrypted systems, stolen data, and operational disruption. For a first-24-hour plan, see our ransomware first 24 hours article.

Threat intelligence and continuous monitoring

Monitoring of brand, domain, leaked user data, open source, and the dark web. Findings are handled in coordination with USOM.

EDR and endpoint security consulting

EDR selection, deployment, and tuning consulting for organizations that want to go beyond antivirus on corporate endpoints. For a comparison, see our EDR vs AV article.

Digital forensics integration

When court-admissible evidence is needed after a cyber attack, our Ankara digital forensics line operates under the same roof; evidence is preserved without breaking the chain of custody.

Data recovery integration

For restoring data after ransomware or hardware failure, our Ankara data recovery lab is brought in.

The KAOS domestic AI engine: the technology that sets DSET apart

As AI-based cyber security tools spread on a global scale, the vast majority of these tools run on overseas cloud services. For regulated-sector customers in Turkey, this creates two problems: first, the scanned traffic and leaked findings are processed on foreign infrastructure; second, the foreign model is unfamiliar with Turkey-specific threat actors, legislation, and the local technology stack.

To fill this gap, DSET is developing a domestic AI penetration and security engine called KAOS. KAOS's standout features:

  • Data stays in Turkey: KAOS runs on infrastructure located within Turkey's borders, under DSET's control. Customer data, target system information, and finding reports are not sent to any overseas cloud service.
  • Agentic AI architecture: KAOS is not a classic "scanner plus report generator." It is a multi-agent orchestration in which multiple specialist tools take turns performing tasks, context-aware, under a single coordinator. The recon, web-scanning, network-assessment, exploit-validation, OSINT, and reporting agents run in sequence.
  • MITRE ATT&CK mapping: Findings are mapped to MITRE ATT&CK techniques and NIST CSF functions (Identify, Protect, Detect, Respond, Recover). This way the report becomes more than a list of vulnerabilities; it makes clear where in the organization's defensive matrix the fix needs to be applied.
  • Generate-and-verify engine: KAOS automatically verifies its vulnerability claims in a test environment or against the target within safe boundaries. It issues a CONFIRMED or REJECTED verdict; there is a policy layer against the risk of hallucination.
  • OWASP, USOM, and vendor PSIRT feed integration: The OWASP Top 10, USOM bulletins, and vendor vulnerability advisories are continuously fed into KAOS.
  • Under human oversight: KAOS is not an autonomous attacker. Hamza Aytaç Doğanay and the DSET team verify every finding the engine produces and stand behind every line of the report delivered to the customer.

This architecture allows DSET's pentest service to rise above the ordinary market standard. In the same amount of time, a broader scope is examined, more manual verification is performed, and the report is delivered to the customer within the framework of local legislation.

The process: how does a pentest project proceed?

  1. Pre-meeting and scope definition (free): target asset list (URL, IP, mobile app, cloud account), test type (black/gray/white), constraints (production-environment windows), and the expected deliverable.
  2. NDA and test authorization agreement: both a confidentiality agreement and an authorization document under Articles 243-244 of the Turkish Penal Code.
  3. Recon and mapping: passive intelligence, open source scanning, and target surface enumeration.
  4. Active testing: manual and KAOS-assisted vulnerability detection following the OWASP Top 10 and NIST SP 800-115 methodologies.
  5. Exploitation validation: the real-world exploitability of the discovered vulnerabilities is proven within safe boundaries. No data is exfiltrated; only proof-of-concept screenshots are taken.
  6. Post-exploitation assessment: privilege escalation, lateral movement, and persistence potential.
  7. Reporting: executive summary, technical findings, risk score (CVSS), evidence screenshots, remediation recommendations, and MITRE ATT&CK mapping.
  8. Presentation: face-to-face with executive and technical teams (at the Ankara office) or an online presentation.
  9. Retest: a free or discounted retest after the customer completes the remediation.

The duration ranges from 5 to 25 business days depending on scope. Pricing is determined by the number of assets, the depth of testing, and the level of reporting detail; the first meeting is free, after which a written proposal is provided.

KVKK and regulatory compliance

The data security guide published by the KVKK Authority defines technical measures for all organizations that process personal data. The principal ones are:

  • Regular penetration testing
  • Log management and retention
  • Authorization and access control
  • Encryption (data at rest and in transit)
  • Anti-malware and endpoint security
  • Backup and recovery testing
  • Data breach notification readiness

BTK also publishes additional information security guides for the electronic communications and critical infrastructure sectors. On the banking side, the BDDK information systems regulation applies, as do the TCMB and BKM rules for payment services. DSET experiences these frameworks as a daily agenda for regulated customers in Ankara.

ISO/IEC 27001 certification is the single most practical roof that addresses much of KVKK compliance on the technical infrastructure side. DSET provides setup-from-scratch consulting for the certification process; full follow-through including internal audit, all the way to the certification audit.

Hamza Aytaç Doğanay's background

Hamza Aytaç Doğanay is a senior expert with over 20 years of field experience in cyber security, digital forensics, and data recovery in Turkey.

  • 6 years as a digital forensics expert at the Cybercrime Department of the Turkish National Police (Emniyet Genel Müdürlüğü). During this period, he handled digital evidence in hundreds of criminal cases, conducted post-attack investigations, and responded to ransomware cases.
  • Thesis-track master's graduate in Digital Forensics from Ankara University. His thesis addressed the chain of custody in mobile device forensics and the current challenges encountered. The thesis can be searched through the YÖK National Thesis Center.
  • Winner of the ACELab Greatest Data Recovery 2023 award (international).
  • Chief architect of the KAOS domestic AI engine. The technical designer of Turkey's domestic, agentic AI-based penetration engine.
  • The technical lead of the cyber security, digital forensics, and data recovery services DSET has provided since 2003.

This background represents a rare profile combining both technical depth and awareness of legal process and regulation. The report delivered to the customer can be shaped to be both court-compliant and regulator-compliant.

Where do we meet physically in Ankara?

The DSET office is inside Hacettepe Teknokent. Campus entry control, the physical security provided by Teknokent management, and the in-office locked analysis laboratory provide three layers of protection. The Ankara Courthouse, the Söğütözü business district corridor, and the Çankaya regulatory line (KVKK, BDDK, BTK) are within reasonable travel distance. For cases outside Ankara, field deployments can be planned.

Frequently Asked Questions (FAQ)

Is having a pentest done legally safe?

Yes. As long as a written authorization agreement (NDA + test authorization document) is signed, it falls outside the scope of Articles 243-244 of the Turkish Penal Code. DSET begins every project with a written authorization document. No test is conducted without an authorization document.

Is there a risk of breaking my production system?

A pentest is carried out within the agreed window and the agreed constraints. Destructive tests (denial of service, data deletion) are out of scope by default; they are performed only at the customer's explicit request and in a test environment. The KAOS engine is configured to perform exploitation validation without exfiltrating data, limited to proof-of-concept screenshots.

Does the KAOS AI engine send customer data abroad?

No. KAOS runs on infrastructure located within Turkey's borders, under DSET's control. Scanning traffic, findings, reports, and target system information are not sent to foreign cloud services. This architecture is a critical design decision, especially for defense industry subcontractors and regulated-sector customers.

How long does it take to obtain our ISO 27001 certificate?

It ranges from 4 to 12 months depending on the size of the organization. For an SME starting from scratch, 6-9 months on average; for organizations with existing procedures, 4-6 months is typical. DSET provides a clear timeline after a GAP analysis.

We were hit by ransomware, what should we do?

First shut down the systems, disconnect the network connections, and start the steps in the ransomware first 24 hours guide. Then contact the DSET emergency response line. The USOM report, the KVKK 72-hour notification, and the digital forensics report are carried out in parallel.

Can I receive the continuous monitoring service from outside Ankara?

Yes. Continuous monitoring and threat intelligence can be provided remotely, with monthly or quarterly reporting. A physical meeting in Ankara is needed only at the contract stage or at the annual review meeting.

Should we get EDR, or is antivirus enough?

In a corporate environment, EDR (Endpoint Detection and Response) is now the standard. Classic antivirus is signature-based only and is not sufficient against modern attacker behavior. For a comparison, our EDR vs AV article is detailed.

Who should make the USOM report?

For critical infrastructure sectors (energy, finance, transportation, healthcare, water, electronic communications), the USOM report is a legal obligation. For other organizations it is recommended, and through the sharing of example incidents it increases sectoral immunity. DSET accompanies you in report coordination.

Working with DSET (Ankara office)

In Ankara, the heart of Turkey's justice, regulation, and defense industry; within the campus security corridor of Hacettepe Teknokent, our team has been operating since 2003, delivering both the classic penetration testing discipline and the domestically developed KAOS AI engine under the same roof. Data never leaves Turkey's borders, and the report is compliant with both the regulator and the court.

Address: Hacettepe Teknokent, Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok, Beytepe / Çankaya / Ankara. Phone: +90 536 662 38 09 Email: [email protected]

The process works as follows: scheduled meeting, signing of the NDA, scope definition, written proposal, acceptance, and the start of the work. The first meeting is free.

Our related resources:


Sources: USOM, BTK, KVKK, ISO/IEC 27001, NIST CSF, OWASP Top 10, TÜBİTAK BİLGEM, MITRE ATT&CK