Korur

Get Cybersecurity Clarity in 48 Hours

Professional security scan with expert human analysis — not just automated tools.

Know exactly what risks you face, what to fix first, and how long each fix takes.

Why a Korur Scan

Automated tools find noise. Our experts find what actually matters to your business.

Expert Review

Every finding is validated by a senior engineer — no false positives, no filler.

Fast Results

Preliminary debrief on day one, full written report within 48 hours.

Actionable Insights

Prioritised fixes with effort estimates so you know exactly where to start.

Confidential & Trusted

NDA-protected engagement, encrypted European storage, GDPR-compliant handling.

How We Protect — Our Way of Working

An engineering mindset, applied to your security. We map it, we read it honestly, and we fix it.

  1. Map

    We draw it out first

    We start by sketching your architecture together at the table: network schema, IT systems, data flow, trust relationships and security layers.

  2. Analyze

    What you already do well

    We lead with the positives. Before any weakness, we point out what is already solid — the controls that work, the smart choices already made. Honest assessment starts with credit where it's due.

  3. Strengthen

    Where the real risks are

    Then we go to the gaps, calmly and without scare tactics. Each finding is prioritised by actual impact, so you know exactly what matters most and why.

  4. Protect

    We fix it, not just flag it

    We don't only advise. Where we can, we take responsibility and fix it right there at the table: hardening settings, closing gaps, setting things straight on the day.

  5. Deliver

    A report you can act on

    You leave with a clear, prioritised report and concrete next steps. We write it the way we'd hand it to a colleague: plainly, honestly, ready to use.

    See what clients receive

    View Example Report
  6. Onboard

    Welcome to your security portal

    We onboard you into our portal, where you see your cyber score in real time and exactly which tasks raise it. Every task is tailored to your industry, the regulations that apply to you, and the diagrams we drew together. You'll also find those diagrams in the portal.

  7. Monitor

    Real-time insight, continuous protection

    From there we run continuous, real-time checks. Your cyber score moves with every improvement, and you see step by step which actions strengthen your security. This makes protection an ongoing process, not a one-off snapshot.

Your expert

Merthan Tukuş

Merthan Tukuş

Senior Security Engineer

Merthan specialises in security assessments for organisations where security isn't an option but a requirement. With experience in mission-critical environments, he makes sure vulnerabilities aren't just found, but also fixed straight away — same day, at the table.

Meet our experts

What We Check

Eight critical security domains, assessed by hand — not just a vulnerability scanner dump.

  1. 01

    Network Security

    Firewalls, segmentation, exposed services, and remote access configuration.

  2. 02

    Access Controls

    MFA coverage, admin account hygiene, privileged access, and identity governance.

  3. 03

    Email Security

    SPF, DKIM, DMARC, phishing resilience, and mailbox protection settings.

  4. 04

    Cloud Infrastructure

    Microsoft 365 and cloud workloads — configuration, sharing, and conditional access.

  5. 05

    Application Security

    Public-facing apps, authentication flows, and common web exposure patterns.

  6. 06

    Data Protection

    Encryption, backup integrity, restore testing, and sensitive-data handling.

  7. 07

    Endpoint Security

    Device hardening, EDR/antivirus coverage, patch status, and disk encryption.

  8. 08

    Compliance & Incident Response

    Readiness against common frameworks and your ability to detect and respond.

See exactly what a finished report looks like

Browse a real, anonymised example report — findings, priorities, and remediation steps included.

Real Results

Numbers from hundreds of scans — and what they mean for organisations like yours.

500+

Companies Scanned

18,000+

Vulnerabilities Discovered

48 hours

Average Turnaround

73%

Average Risk Reduction

Featured case
Sensey logo

Sensey hardened a client's operations end to end

One of Sensey's clients needed certainty that its systems and data were protected. Our scan uncovered prioritised risks and a clear remediation path — implemented within weeks.

Read the full case
100%
Critical findings fixed
48h
To prioritised report
0
Repeat critical issues

Our Methodology

A repeatable, five-step process that turns raw findings into decisions you can act on.

  1. 01

    Scope & Kickoff

    We agree on systems in scope, access, and objectives before any testing begins.

  2. 02

    Active Scanning

    Hands-on assessment across network, identity, email, cloud, and endpoints.

  3. 03

    Analysis & Validation

    Every candidate finding is manually validated to remove false positives.

  4. 04

    Expert Review

    A second senior engineer reviews conclusions and prioritisation for quality.

  5. 05

    Reporting & Recommendations

    A clear, prioritised report with effort estimates and concrete next steps.

What Clients Say

Organisations that turned uncertainty into a clear, prioritised security plan.

Korur didn't just hand us a list of problems — they told us exactly what to fix first and how long it would take. That clarity was worth every euro.
Operations Lead
Sensey
The same-day debrief meant we could close our two most critical gaps before the report even arrived. Fast, professional, no jargon.
Managing Director
Fepatex
Every finding was validated by a real engineer. No false alarms, no padding — just the things that actually mattered to our business.
IT Manager
Plusboekhouden

Scan Readiness

Everything you need to prepare for a smooth, productive scan.

Legal & Compliance

Your data is protected at every step. Here is exactly how we handle it.

Confidentiality (NDA-protected)

We sign a standard NDA before every engagement. Your sensitive data stays yours.

Encrypted European Storage

Reports are stored encrypted on European servers; working copies are deleted after 30 days.

Professional Standards

Assessments follow industry standards and are performed by certified engineers.

Terms & Conditions

1. Scope of Inspection

The Cybersecurity Inspection is a structured evaluation of your IT environment performed on-site in one business day. This includes: network security, MFA and authentication, cloud solutions (Microsoft 365), endpoint protection, backup and recovery, and security awareness. The inspection focuses on the ten critical security areas relevant to Turkish SMEs. Before the inspection, we align the scope based on your business situation so we work with precision.

2. Price and Payment

The fixed price for the Cybersecurity Inspection is € 450. This price includes all evaluations, direct fixes on-site, verbal briefing, and digital report. Travel costs outside Turkey or beyond 200 km from Düzce are calculated separately and communicated transparently in advance. Invoicing takes place within 5 business days of completion with a payment term of 30 days. Payment by bank transfer or credit card.

3. Execution and Preparation

The inspection is performed by a certified security professional from Korur at your location. Planning takes place at least 3 weeks in advance. We require: full administrator rights for one person, uninterrupted access to your IT environment, and a quiet space for the end-of-day briefing. Findings are discussed verbally with you on the same day. The written report (PDF) is sent to you by email within 2 business days.

4. Payment, Invoicing and Terms

Payment proceeds following invoicing with a net 30-day payment term. Acceptable payment methods are bank transfer and credit card. For international clients outside the EU, separate payment arrangements can be made. In case of non-payment after reminder, interest and collection costs may be charged in accordance with Turkish law.

5. Liability and Warranty

Korur performs the inspection with professional diligence in accordance with industry standards. If a critical security flaw within our scope is missed, we will identify it at no cost and advise how to remediate it. This Care Guarantee applies for the first 30 days after the report. Korur is not liable for: indirect damage, loss of profits, data breaches outside our findings, or implementation errors by third parties of our recommendations.

6. Confidentiality and Data

All information Korur collects and processes is confidential. We always sign a standard NDA. Your report is stored on encrypted European servers and is only accessible to your designated contact person and our engineer. Working copies of sensitive data are deleted 30 days after the report. Data processing complies with GDPR. We never share data with third parties without explicit consent.

7. Cancellation and Postponement

Cancellation up to 3 weeks before the scheduled date: full refund of the amount. Cancellation between 3 weeks and 1 week before the date: 50% of the costs is refunded to you. Cancellation less than 1 week before the date: you pay the full amount. In case of unforeseen circumstances (pandemic, security situation), Korur may propose postponement. This always happens with full transparency and the ability to request a refund.

8. Governing Law and Dispute Resolution

These terms are governed by Turkish law. Both parties endeavor to resolve disputes amicably. If this fails, disputes fall under the jurisdiction of the courts of Düzce.

Simple, Flat Pricing

One clear price. No hidden fees, no surprise add-ons.

Flat rate
€ 450excl. VAT

What's included

  • On-site scan (6–8 hours)
  • Expert analysis & validation
  • Written report (PDF + web)
  • 30-minute follow-up call

Optional add-ons

  • Remediation support
  • Follow-up scan (6–12 months later)

Get Security Clarity in 48 Hours

Stop guessing about your security posture. One day on-site, expert analysis, actionable report. No jargon, no surprises — just the truth about your risks and how to fix them first.

More Questions

The deeper details, answered straight.