Debian Information Technologies
  1. Home
  2. Services
  3. What We Do

What We Do

We group our work into nine areas. Several of them usually run at once in a single project, and whichever one we start from, one team carries the work.

Consulting & Roadmap

Before the transformation decision is made, we set out what will be done, in what order and at what cost. The output is an executable plan, not a deck.

  • Current-state and maturity assessment
  • Feasibility and cost comparison
  • Phased roadmap and budget
  • Vendor and technology selection

Audit & Penetration Testing

We verify that your defence works in the field rather than on paper, using the attacker's own methods — and hand findings over with a remediation plan.

  • External and internal network penetration testing
  • Web and mobile application testing
  • Configuration and hardening review
  • Source code security review

Training & Awareness

In-depth programmes for technical teams, short and measured ones for everyone else. We report how much of it actually stuck.

  • In-house technical training
  • Information security awareness programme
  • Phishing simulation and measurement
  • Executive-level cyber crisis exercise

Software Development

Where off-the-shelf products fall short we build custom applications. Source code and documentation are handed over at the end of the project.

  • Software architecture and design
  • Web, mobile and integration development
  • Legacy system modernisation
  • API design and system integration

AI & Data

We do not build models without a measurable business problem. First we calculate the benefit, then build the smallest thing that works.

  • Assistants that run on your own data
  • Anomaly and fraud detection
  • Computer vision for quality control
  • Data engineering and reporting infrastructure

Systems & Infrastructure

Design, deployment and handover of infrastructure from the data centre to the endpoint. A zero-downtime migration plan is part of the job.

  • Data centre and network design
  • Virtualisation and container platform
  • Backup and disaster recovery
  • Monitoring, logging and alerting

SOC & Continuous Monitoring

We build your own security operations centre, train its team, and provide 24/7 monitoring support where you want it.

  • SOC deployment and detection rules
  • SIEM and log management
  • Threat hunting sessions
  • Managed detection and response

Incident Response

Support that preserves evidence during an incident, restores the business safely and writes down what was learned.

  • Emergency response and containment
  • Digital forensic examination
  • Ransomware recovery
  • Root cause analysis and reporting

R&D Advisory

Technical advisory that carries an idea to prototype and a prototype to product, including the technical file for grant applications.

  • Technical feasibility and literature review
  • Prototyping and test rigs
  • Technology readiness level plan
  • Project documentation and reporting

How we work

How does a project start?

Whatever the subject, we follow the same four steps — and what each step delivers is written down before it begins.

  1. 01

    Listening and discovery

    We write the problem down in your words and walk the site and the existing systems together. This step is free of charge.

  2. 02

    Proposal and scope

    Scope, timeline, shared responsibilities and acceptance criteria in a single document — including what is explicitly out of scope.

  3. 03

    Delivery

    We work in two-week cycles and show a working piece at the end of each. No surprises saved for the end.

  4. 04

    Handover and support

    A project is not finished without documentation, training and source code handover. Support levels are agreed afterwards.

2016 Founded
0 Service areas
0 Products we built
0 Technical articles

Our services

Areas of expertise

Cybersecurity Consulting

From penetration testing to SIEM correlation, from malware analysis to threat hunting — security consulting and delivery across fifteen disciplines.

Details

AI Integration

AI applications that run on your own data, are measured against clear targets and respect data protection law.

Details

Hardware Development

Embedded systems, sensors and purpose-built devices — from schematic to prototype, production and field service.

Details

Data Protection (KVKK / GDPR) Consulting

Building a data inventory, implementing technical and administrative measures, compliance auditing and staff training under Turkish data protection law.

Details

Contact us for details on activity areas we could not fit on this page