Practical content from industry professionals on digital forensics · data recovery · cyber security · KVKK compliance.
The right to compensation under KVKK Article 14. The difference between an administrative fine (the Board) and compensation (the court). Competent courts (Civil Court of First Instance + Labor + Consumer). Pecuniary vs. non-pecuniary damages. A comparison with GDPR Art. 82. The four elements of the burden of proof under HMK 190. Types of evidence (Board decision, Court of Cassation precedent, forensic report, email header, HIBP, device image). Three scenarios (phishing, identity theft, health data). Coordinated litigation.
Read moreTBK 49 is the general provision on tort compensation. Four elements (unlawful act, fault, harm, causation). Six examples of digital tort (social media defamation, deepfake, doxxing, hacking, commercial reputation, IP theft). Pecuniary vs non-pecuniary damages. HMK 187 documentary evidence. Combining TCK 132-135 with TBK 49. Its relation to KVKK Article 14. Six factors in the amount of damages. Eight recommendations for victims.
Read moreWhen you build or assess a data recovery lab, two names dominate: PC-3000 and the DeepSpar Disk Imager. The right question is not which is better, but which one shines in which case. A field comparison from DSET's Ankara lab.
Read moreNIS2 Directive 2022/2555 (October 2024). The Essential Entities (EE) and Important Entities (IE) distinction. 18 sectors. 10 minimum security measures (Art. 21). 24-hour / 72-hour / 1-month reporting (Art. 23). Board accountability (Art. 20). Maximum fines: EE EUR 10M or 2% of turnover, IE EUR 7M or 1.4% of turnover. A mapping table to ISO 27001, ISO 27701, NIST CSF and KVKK. A 12-month roadmap for Turkish companies.
Read moreBug bounty vs pentest difference. Public vs Private. Platform (HackerOne, Bugcrowd, Intigriti, Immunefi Web3) vs self-hosted. Scope definition, severity matrix CVSS 4.0, reward table, triage SLA, Coordinated Disclosure. TCK 243-245 + safe harbor in Turkey. Self-discovery with the KAOS engine (pre-BB cleanup). A 30-day starter plan.
Read more16 artifact categories extracted from a RAM dump: process tree, loaded modules, network connections, file handles, registry hives, command-line history, browser cache, cryptographic keys (BitLocker FVEK), clipboard, URL/path strings, decrypted messages (WhatsApp/Signal/Telegram Desktop), VAD tree, cached credentials, Mimikatz NTLM/Kerberos, PowerShell decoded payload, C2 beacons.
Read moreTBW (Total Bytes Written), JEDEC JESD218 client 1 DWPD + enterprise 3-10 DWPD. DWPD to TBW formula. Reading from SMART parameters (Samsung 0xF1, Crucial 0xF6/0xF7, Kingston 0xF1, WD 0xFB). TBW table for 6 brands at 1TB/2TB. Wear leveling + over-provisioning. Backblaze AFR. Enterprise vs consumer 9x difference. Data recovery on a TBW-exhausted drive (DeepSpar to PC-3000 to chip-off to metadata).
Read moreChip-off means thermally removing the NAND flash chip from the PCB and placing it in a programmer to read raw data. BGA reflow with the JEDEC J-STD-020 thermal profile. The SLC/MLC/TLC/QLC and eMMC/UFS/raw NAND distinctions. Up-828, RT809H, PC-3000 Flash programmers. XOR descrambling, ECC decode, and logical mapping. The Apple Silicon Secure Enclave wall. Vendor scrambling (Samsung, Toshiba, Micron, SK Hynix).
Read moreCellebrite UFED (Israel, 1999), the leader of mobile forensics. UFED Touch 2, 4PC, Premium, Endpoint Inspector. Logical/File System/Physical extraction. iOS BFU/AFU + Android EDL/Download/BROM. Premium Advanced Services, locked iPhone bypass. Competitors: Magnet AXIOM, Oxygen Forensic Detective, MSAB XRY, ElcomSoft. Open source: MVT (Pegasus), ALEAPP/iLEAPP. KVKK art. 28 + CMK art. 116 legal framework.
Read moreThe 8 factors that determine the cost of data recovery: an ISO 14644-1 cleanroom, PC-3000/DeepSpar/Atola equipment, a stock of donor parts, the hours of a trained engineer, vendor-specific licenses (Samsung/WD/Seagate), case duration, data-protection-compliant air-gap destruction under NIST 800-88, and the 'no data, no fee' risk premium. The hidden cost of cheap data recovery. The balance between the price of the device and the value of the data. An insurance and data-protection-breach perspective.
Read moreSOC 2 (AICPA), the audit report that opens sales to the US market for SaaS/cloud/MSP/fintech companies. The SOC 1/2/3 difference, Type I (point-in-time) vs Type II (6-12 months). 5 Trust Services Criteria (Security mandatory + Availability, Processing Integrity, Confidentiality, Privacy). ISO 27001 comparison. 12-18 months of preparation. Choosing a Big 4 vs Tier 2 vs niche CPA audit firm.
Read moreThe "castle and moat" model is dead. Learn what Zero Trust really is, NIST SP 800-207, the CISA five pillars, BeyondCorp, Microsoft Entra, and a 90-day roadmap for SMEs.
Read more