24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesIn the PressDSET in the national pressSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI

Pentest Readiness Assessment

Answer 10 questions to score how ready you are for a penetration test, and see exactly what a professional firm checks before it ever sends a single packet.

1. Do you have an up to date inventory of all assets in scope (IP, domain, application, API)?
2. Has the test scope (targets, exclusions, depth) been clearly defined in writing?
3. Has written authorization and rules of engagement (ROE) been signed?
4. Has it been decided whether the test runs on production or a test/staging environment?
5. Have verified, restorable backups been taken before the test?
6. Is there a reachable point of contact and an escalation chain defined for the test window?
7. Is a change freeze window planned for the duration of the test?
8. Have WAF, EDR and SOC teams been informed of the test (alerting/blocking decisions agreed)?
9. Have known findings from previous tests or scans been remediated?
10. Is there a legal agreement on sensitive data handling, KVKK and confidentiality terms?
0/100 · Not Ready

0/10 questions answered. Answer all items for a precise readiness score.

Fix these before the test starts:
  • Do you have an up to date inventory of all assets in scope (IP, domain, application, API)?
  • Has the test scope (targets, exclusions, depth) been clearly defined in writing?
  • Has written authorization and rules of engagement (ROE) been signed?
  • Has it been decided whether the test runs on production or a test/staging environment?
  • Have verified, restorable backups been taken before the test?
  • Is there a reachable point of contact and an escalation chain defined for the test window?
  • Is a change freeze window planned for the duration of the test?
  • Have WAF, EDR and SOC teams been informed of the test (alerting/blocking decisions agreed)?
  • Have known findings from previous tests or scans been remediated?
  • Is there a legal agreement on sensitive data handling, KVKK and confidentiality terms?
Request a pentest

Preparation before a pentest

The most valuable work happens before the test. A clear asset inventory, defined scope, verified backups and a change freeze turn a risky exercise into a controlled one. If your defensive teams are blindsided, you waste the engagement chasing your own alerts.

Pentest process, pricing and when it is needed

ROE and authorization

No reputable firm tests without written rules of engagement. The ROE names the targets, the permitted techniques, the schedule, the exclusions and the emergency contacts. It is the legal and operational backbone of the whole engagement and protects both the client and the testers.

How to choose a penetration testing firm

Defining the scope

Scope decides whether the test runs on production or staging, how deep it goes, and what stays off limits. A tight, written scope keeps the test focused on the assets that matter and prevents accidental impact on systems that were never meant to be touched.

Talk to DSET, Ankara based cybersecurity company. Phone: +90 536 662 38 09 · Email: [email protected]
DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Adli Bilişim
  • Veri Kurtarma
  • KAOS Yerel Yapay Zekâ
  • Siber Güvenlik
  • KVKK-GDPR Danışmanlık
  • DSET Akademi
  • Olay Simülatörü & Tehdit Heatmap
  • Web Sitesi Güvenliği
  • Bilgi Güvenliği
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Press Room
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
Privacy
KVKK
GDPR
Cookies
Terms