24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesIn the PressDSET in the national pressSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI

SMB Cybersecurity Maturity Test

Answer 12 quick questions and get a 0-100 maturity score, a level, a domain breakdown and prioritized recommendations. The basics that block most attacks, MFA, offline backups, patching and awareness, are weighted most.

Answer 12 quick questions about your security basics. The highest-ROI controls for a small business, MFA, offline backups, patching and awareness, are weighted most, because they block the majority of real attacks.

1. Backups & recovery: do you keep offline / immutable backups and test restores?An offline, tested backup is the single best defense against ransomware.
2. MFA & passwords: is multi-factor authentication enabled on email, VPN and admin accounts?MFA blocks the vast majority of account-takeover and phishing attacks.
3. Patching: are operating systems and software updated within days of a fix?Most breaches exploit known, already-patched vulnerabilities.
4. Endpoint protection: do all devices run modern EDR or at least managed AV?EDR catches behaviours that signature-based AV alone misses.
5. Email security: are SPF, DKIM and DMARC configured for your domain?SPF / DKIM / DMARC stop attackers spoofing your company domain.
6. Firewall & network: is traffic segmented and are inbound services minimised?Segmentation limits how far an attacker can move after a breach.
7. Awareness training: are staff trained and phishing-tested regularly?People are the most targeted layer; trained staff report attacks early.
8. Access control: do you apply least privilege and review accounts regularly?Least privilege shrinks the blast radius of any compromised account.
9. Incident plan: is there a written incident response plan with contacts and steps?A rehearsed plan turns chaos into a checklist when an attack hits.
10. KVKK / data protection: are personal data inventoried, minimised and encrypted?KVKK compliance reduces both breach impact and legal exposure.
11. Supplier / third party: do you assess the security of vendors with system access?Many breaches arrive through a trusted vendor's weaker security.
12. Logging & monitoring: are key logs collected, retained and reviewed for alerts?Without logs you cannot detect an intrusion or investigate it afterwards.

Your maturity result

Score: 0 / 100

Maturity level: Initial

Foundational gaps leave you exposed to common, automated attacks.

Domain breakdown

Backups
0%
MFA
0%
Patching
0%
Endpoint
0%
Email
0%
Firewall
0%
Awareness
0%
Access
0%
Incident
0%
KVKK
0%
Suppliers
0%
Logging
0%

Prioritized recommendations

  1. Set up offline or immutable backups and test a full restore at least quarterly.
  2. Enable multi-factor authentication on email, VPN and all admin accounts first.
  3. Adopt a patch policy that applies critical updates within days, not months.
  4. Run regular awareness training and simulated phishing for all staff.
  5. Deploy modern EDR (or at minimum centrally managed AV) on every endpoint and server.

Secret of strong SMB security: you do not need an enterprise budget. Multi-factor authentication, offline tested backups, fast patching and trained staff together block the majority of attacks that hit small businesses.

The highest-ROI basics that block most attacks

Most attacks on small businesses are opportunistic and automated. Multi-factor authentication, offline tested backups, fast patching and staff awareness stop the large majority of them without an enterprise budget. For a practical playbook see our guide on how to prevent insider cyber attacks and build corporate defense.

From a quick test to a managed security posture

A self-assessment shows where to start; sustaining maturity needs the right tools, monitoring and a tested incident plan. DSET designs and operates layered defenses sized for SMBs, see our corporate cybersecurity solutions.

KVKK compliance and protecting personal data

Security maturity and data protection go together: minimised, inventoried and encrypted personal data both lowers breach impact and meets KVKK obligations. For compliance support see our KVKK compliance and data security solutions.

DSET is an Ankara based cybersecurity, digital forensics and data recovery company. For a hands-on maturity assessment of your business, contact DSET on +90 536 662 38 09 or [email protected].

DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Press Room
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
Privacy
KVKK
GDPR
Cookies
Terms