SCNET · Enterprise IT · Ankara, Türkiye

Sanal Çekirdek

Not how secure you are — how quickly you recover.

Resilience is about standing up during and after an attack, not only about preventing one. Sanal Çekirdek builds the assessment around that question: how long until a critical service returns, and who makes which call.

A maturity score on its own says little. What matters is which gap produced the score and what closing that gap would change.

Scope and critical service selection

An assessment does not survey the whole organization at equal depth; it starts from critical services. Which service stopping stops the business is answered by the business, and technical scope is derived from that answer.

  • Criticality is the business's call, technical scope is ours
  • Whatever is excluded is recorded with its reason
  • Third-party dependencies belong inside the scope
  • Depth is proportional to the criticality of the service

Measuring capability

Measurement covers four areas: detect, respond, recover and learn. For each, what the organization can do today is established from evidence — observed behavior rather than written procedure.

  • Evidence comes from records, not from procedure documents
  • Detection time is calculated from past incidents
  • Recovery capability is confirmed by rehearsal records
  • Learning is measured by the rate of findings closed

Scenario work

Concrete scenarios replace abstract maturity: what happens if ransomware spreads, if a privileged account is taken, if a supplier reports a breach. A scenario makes visible who actually holds each decision.

  • Scenarios run against your real architecture
  • Decision points and decision owners are marked
  • The communication chain is exercised inside the scenario
  • Output feeds directly into a plan update

Roadmap and ownership

A findings list produces no work by itself. Each finding is ranked by impact and cost to close, then tied to an owner and a date. A finding without an owner disappears when the report closes.

  • Ranking weighs impact and cost together
  • Every finding has exactly one owner
  • Quick wins are collected on a separate list
  • Progress is remeasured on the same scale

How we work

  1. Identify critical services with the business
  2. Measure current capability from evidence
  3. Run scenarios against the real architecture
  4. Tie findings to an owner and a date
  5. Remeasure and compare at intervals

How success is measured

  • All critical services are inside the scope
  • Detection time can be calculated from records
  • Every scenario decision point has a named owner
  • A greater proportion of findings closes each period

Frequently asked questions

How is this different from penetration testing?

A penetration test shows whether a path is open; a resilience assessment measures what the organization does once that path is used. They complement each other and neither replaces the other.

Is it based on a framework?

Common frameworks are used to organize the measurement areas, but the result is not a statement of conformity. The goal is a list of findings that can be closed, not a certificate.

When should the assessment be repeated?

As the architecture changes and as major findings close. Rather than a fixed calendar, remeasuring once the previous round's findings are closed gives a more meaningful comparison.

Share your critical service list; we will measure today's resilience from evidence and turn it into a roadmap you can actually close.

Share your critical service list