A quarter century of engineering · Ankara

The partner that builds,
operates and defends
critical infrastructure.

From the first feasibility report of a data centre to the last cable in the rack, from network architecture to SOC operations, from custom software to the ISO 27001 certificate — we run every interdependent piece under a single project management.

  • ISO/IEC 27001:2023
  • 7 management system certificates
  • Vendor-neutral
  • Domestic capital

Layered approach · 25 service families

An organisation has
six layers. We work
in all six.

From site and facility to people and capability — we exist to close the gaps where the electrical team waits on the systems team, and the systems team waits on security.

  • 6 katman
  • 25 service families
  • One project manager
  • Written deliverables

Our own products · R&D

We make your shadow
assets visible.

MonPulse, PASI and Forensica are domestic platforms we contribute R&D to. That means direct access to the source for data residency, customisation and support.

  • CTEM
  • Predictive intelligence
  • Digital forensics
  • Domestic development
01 / 03
Data centre consultancyTurnkey constructionHVAC and mechanicalExtra-low voltageIT infrastructureNetwork solutionsSecurity productsPenetration testingRed teamingDigital forensicsOT / ICS securityMSSP / SOCMonPulse CTEMPASI forecastingForensica DFIRISMS certificationKVKK / GDPR complianceMaturity modelCloud and virtualisationMigration projectsCustom softwareAI and analyticsModelling and simulationSystems architectureONGSEC Academy
0+

Years of industry experience. More than a quarter century of field and project knowledge.

0

Service families, all of which can run under a single project management.

0

Active management system certificates: ISO 27001, 9001, 14001 and four more.

0+

Supported technology brands. Selection is made on technical grounds, never commercial ones.

Service families

Four main branches, one point of contact.

Where organisations lose most time is the gap between disciplines: the project stretches while the electrical contractor waits for the systems team, and the systems team waits for security. ONGSEC exists to close that gap.

A layered approach

An organisation has six layers.
We work in all six.

That is where our name comes from: Onion based Next Generation Security. Security is not the outermost shell; it is the responsibility of every layer.

Site and Facility

It begins by questioning whether the investment is needed at all. Location risk, zoning, power and fibre access are scored; capacity scenarios are modelled. Once the decision is made, the same team builds the facility — from shell and core to raised floor, from fire compartments to the mantrap.

  • Feasibility and TCO
  • Site scoring
  • Concept and detailed design
  • Turnkey construction
  • Raised floor
  • Fire compartments
  • Physical access control
  • Modular / container DC
Uptime Tier I–IVTIA-942EN 50600ANSI/BICSI 002

Power and Cooling

Most of a data centre’s availability is decided in this layer. The whole chain — from the medium-voltage entry to the A/B feed at the rack socket — is engineered, installed and tested under real load with load banks. Heat load is modelled with CFD and PUE is made measurable.

  • MV/LV distribution
  • UPS and battery autonomy
  • Generators and fuel
  • ATS / STS
  • Precision cooling
  • InRow and liquid cooling
  • Containment
  • Free cooling
  • VESDA and gas suppression
  • Black building test
ASHRAE TC 9.9TS EN 15004NFPA 2001TS EN 62305

Network and Cabling

From copper and fibre backbone to campus networking, from branch SD-WAN to high-density Wi-Fi design. Every cable is tested and certified, measurement reports are delivered, and the manufacturer system warranty application is managed.

  • Cat6A / Cat8 and fibre
  • MPO/MTP backbone
  • Campus LAN
  • Data centre fabric
  • SD-WAN and branch
  • Wi-Fi 6/6E site survey
  • Segmentation and NAC
  • IP telephony / UC
  • NOC and network monitoring
TIA-568 / 606ISO/IEC 11801EN 50173ONVIF

Systems, Data and Cloud

The server, storage, virtualisation, directory and backup layer. Backup here is designed not as a copying task but as the last line of defence against ransomware: immutable repositories, air-gapped copies, regular restore tests.

  • HCI and HA clusters
  • SAN / NAS / object storage
  • VMware · Proxmox · Hyper-V
  • OpenStack and KVM
  • Kubernetes
  • 3-2-1-1-0 backup
  • Immutable repository
  • DR site and drills
  • Active Directory / PKI
RPO / RTO drivenWindows ServerRHEL · Debian · Rocky

Security and Compliance

The protection layer from endpoint to cloud, with continuous visibility, testing and regulatory compliance on top. Every control we deploy is expected to produce audit evidence — to stand up in an audit rather than merely look good on a screen.

  • EDR / XDR
  • NGFW and WAF
  • PAM / IGA
  • DLP and data discovery
  • SIEM and SOAR
  • 24/7 SOC
  • Penetration testing and red teaming
  • OT / ICS monitoring
  • Digital forensics
  • MonPulse CTEM
ISO/IEC 27001KVKK · GDPRSOC 2PCI DSSNIST CSFIEC 62443BİGR

People and Capability

Even the best architecture will not run with a team that cannot operate it. Our goal is that at the end of a project your own staff can take the system over; creating dependency is not our business model. Training is tailored to the organisation’s own infrastructure.

  • SOC analyst training
  • Penetration testing training
  • Digital forensics training
  • Linux and virtualisation
  • Network expertise
  • Awareness and phishing simulation
  • CSIRT establishment
  • Executive crisis drills
  • Handover training
Hands-on laboratoryAssessment and measurementCertificate of attendance

Who we are

Security is not a project;
it is part of the corporate culture.

ONGSEC is an Ankara-based, multi-disciplinary technology company delivering enterprise-grade services in information technology and cyber security, with more than twenty-five years of accumulated experience. Our specialists produce integrated solutions for public institutions, the defence industry, financial institutions, industrial facilities and large private sector companies.

This breadth is a significant operational advantage for organisations that want to run a project end to end with a single partner: the time normally lost in the gaps between disciplines disappears.

About the company

At a glance

  • Headquarters
    Ankara Social Sciences University – Sosyokent, Ankara
  • Focus
    IT · critical infrastructure · cyber security
  • Team
    12 multi-disciplinary specialists
  • Products
    MonPulse · PASI · Forensica

Our references

From public sector to defence,
from industry to finance.

A significant share of our clients prefer their names not to be shared, given their field of activity and security requirements. We honour that without exception — which is itself the evidence of the discretion your own project will receive.

  • Public Sector

    IT infrastructure, data centre, extra-low voltage and cyber security services for ministries, municipalities and public institutions.

  • Defence and Industry

    OT/SCADA security, network and infrastructure solutions for the defence industry, industrial facilities and manufacturers.

  • Finance and Services

    ISMS, SOC and compliance consultancy for banks, financial institutions and the service sector.

Our reference approach and PoC option

Our certificates

Seven active management system certificates.

We apply the requirements of the standards we advise on to our own processes first. Certificates are issued by BELCERT under ILAS accreditation.

ISO/IEC 27001:2023ISO/IEC 27001:2023

Information Security Management System

BELCERTVALID 2027
ISO 9001:2015ISO 9001:2015

Quality Management System

BELCERTVALID 2027
ISO 14001:2026ISO 14001:2026

Environmental Management System

BELCERTVALID 2027
ISO 45001:2018ISO 45001:2018

Occupational Health and Safety

BELCERTVALID 2027
ISO 10002:2018ISO 10002:2018

Customer Satisfaction Management

BELCERTVALID 2027
ISO 31000:2018ISO 31000:2018

Risk Management

BELCERTVALID 2027
ISO 26000:2021ISO 26000:2021

Social Responsibility Guidance

BELCERTVALID 2027

Technology partners

We work vendor-neutral: the recommended solution is determined by technical requirement, not by a commercial partnership.

How we work

Progress is measured in
deliverables, not statements.

Every project has one assigned project manager through whom the organisation reaches all disciplines. Each stage has a written output, and the next stage does not begin until that output is delivered.

  1. 01

    Discovery

    Current state assessment, site survey, stakeholder interviews.

    Discovery report · requirements
  2. 02

    Design

    Architecture design, calculations, technology selection.

    Design document · specification
  3. 03

    Planning

    Work breakdown, schedule, resource and risk plan.

    Project plan · RACI · risk register
  4. 04

    Delivery

    Installation, construction, development, configuration.

    Progress reports · quality records
  5. 05

    Testing

    Functional and integrated testing, punch list closure.

    Test protocol · acceptance record
  6. 06

    Handover

    Documentation, training, capability transfer.

    As-built · manuals · training record
  7. 07

    Support

    Warranty, maintenance, periodic review.

    Maintenance report · improvement advice

Service levels

Response priority is
a number in the contract.

Response and resolution times are defined numerically in the contract, according to service scope and the chosen support package. The priority classification below is the common backbone of every support agreement.

P1Critical

Production or service completely down; suspected security breach.

Immediate response · continuous work · executive notification

PRIORITY 100/100

P2High

Significant loss of function or loss of redundancy.

Priority response · work within the same business day

PRIORITY 72/100

P3Medium

Limited impact, workaround available.

Planned response within an agreed schedule

PRIORITY 46/100

P4Low

Information request or improvement suggestion.

Handled within the routine workflow

PRIORITY 24/100

Why ONGSEC

Eight concrete differences.

  • 01

    End-to-end delivery

    From feasibility to construction, from deployment to operation and training, every stage runs with one partner. The burden of inter-discipline coordination is lifted off the organisation.

  • 02

    Multi-disciplinary team

    Systems, network, electrical, mechanical, security and software in the same project, around the same table. No work stalls waiting on another discipline.

  • 03

    Domestic and independent

    An Ankara-based company established in Türkiye. Where the data sits and who provides support are never in doubt.

  • 04

    Vendor-neutral

    Recommendations are shaped by technical requirement, not by commercial partnership. A comparative evaluation is always provided.

  • 05

    Our own products

    MonPulse, PASI and Forensica — domestic platforms we contribute R&D to. Direct access to the source when customising.

  • 06

    Documented discipline

    A written output at every stage: design document, test protocol, as-built package, audit evidence. Traceable records instead of verbal agreement.

  • 07

    Respect for confidentiality

    Client names, project scope and technical data are never shared without written consent — marketing material included.

  • 08

    Lasting capability transfer

    The goal is that your own team can operate the system when the project ends; creating dependency is not our business model.

Get started

Let us talk about your project.

The first meeting is a discovery session, not a sales pitch. You are also welcome to evaluate our capability directly through a short pilot or proof of concept (PoC) in your own environment.

Fill in the enquiry form

WhatsApp