forumNew topic

I want to hire a security consultant, what criteria should I use to choose, what's the price, how do I find a good one

TTolga K***ExpertCommunity member
Joined
Apr 2025
Message
24
#1

Should I choose a certified one? What's the fee? How do I find one?

EEmre G***MemberCommunity member
Joined
Dec 2022
Message
198
Most Helpful#2

When picking a security consultant: check for CEH/OSCP/CCNA certs. Ask for references. Experience (10+ years) matters. Fees: 3000-10000 TL/month — depends on business size.

OOkan K***MemberCommunity member
Joined
Mar 2026
Message
66
#3

we also struggled when choosing... we decided after checking the references

IIrmak V***Member
Job title
Front office accounting
Sector
E-commerce
Organization type
a company within a holding
Joined
Feb 2025
Message
312
#4

Let me speak from the other side; I'm on the supplier side. Taking measures without an inventory leaves doors you haven't seen open.

If you get three different answers on a topic, the question was asked wrong.

EElif V***Member
Job title
Quality control inspector
Sector
Machinery manufacturing
Organization type
20-person company
Joined
Nov 2025
Message
40
#5

could you elaborate on that? if you scold false alarms nobody will report again.

just leaving this note, it might be useful.

ZZerrin S***Member
Job title
Quality Assurance Manager
Sector
Insurance
Organization type
chain store
Joined
Jun 2024
Message
388

Doki · Backup setup · 2025

#6

There's one point I'm curious about. Everything goes well for the first three months; problems arise in the fourth.

I'm also curious if anyone does it differently.

AAyşe B***Member
Job title
Operations manager
Sector
Real estate
Organization type
two-branch business
Joined
Mar 2023
Message
20
#7

Quick summary for newcomers: An untested backup is not a backup.

Just leaving this note, it might be useful.

DDuyguMember
Job title
Market researcher
Joined
Jun 2024
Message
102
#8

I have an objection here. Payment information changes are never verified through the channel they came from.

If permission and scope aren't in writing, don't start that test. Proven by experience.

MMelis K***VeteranCommunity member
Joined
Dec 2025
Message
26
#9

I'm writing this so you don't make the same mistake. If you get three different answers on a topic, the question was asked wrong.

OOrhan O***Member
Job title
Board member
Sector
Seafood
Organization type
medium-sized business
Joined
Jun 2023
Message
17
#10

I'd appreciate it if you shared the outcome.

CCansu K***Member
Job title
Logistics planning
Sector
Printing
Organization type
sole proprietorship
Joined
Sep 2023
Message
1

Doki · Backup setup · 2023

#11

I went through the same thing two years ago. If 2FA is on, a stolen password alone is useless.

If I were you, I'd go this route.

EElif G***ExpertCommunity member
Joined
Mar 2025
Message
3
#12

I disagree with you on this point. Security isnt absolute; its about making attacks not worth the effort.

EemreMember
Job title
Founder · Logistics software
Joined
Feb 2024
Message
88

Doki · Infrastructure migration · 2026

#13

we experienced almost the exact same thing last year then mistakes made on the choosing a security consultant side are usually reversible but expensive.

BBora A***MemberCommunity member
Joined
Sep 2025
Message
118
#14

There's also a measurement aspect to this. Don't hesitate to ask; those who don't ask always pay more.

People defend habits, not processes. Resistance comes from there. This is my opinion, I'm not claiming it's absolute truth.

DDamla P***MemberCommunity member
Joined
May 2024
Message
191
#15

Thanks, that was the answer I was looking for.

YYağmur P***MemberCommunity member
Joined
Jun 2025
Message
286
#16

I'm a small business, let me explain from my side. The harder it is to reverse a decision, the slower you should make it.

If you have questions, write them; I'll answer as best I can.

SSinan K***Member
Job title
Country Manager
Sector
Construction
Organization type
workshop
Joined
Jan 2024
Message
335
#17

The discussion got scattered, let me summarize. Don't hesitate to ask; those who don't ask always pay more.

RRıdvan Ö***MemberCommunity member
Joined
Apr 2025
Message
5
#18

I agree, and I'd like to emphasize that. Don't hesitate to ask; those who don't ask always pay more.

Proven by experience.

LLevent Ö***Veteran
Job title
Production planning
Sector
Textile
Organization type
a company within a holding
Joined
Jan 2023
Message
13
#19

Let me share what happened to me; it might be useful. If 2FA is on, a stolen password alone is useless.

Trying to do this alone is the most expensive way. Hope this helps.

KKORİDoki team
Job title
Forum moderator
Sector
Cybersecurity and digital
Organization type
Doki
Joined
Jan 2023
Message
2,840
Sentinel#20

I'm keeping an eye on this, in a good way. The suggested approach above is correct; the only missing piece is a rollback plan. When applying a change, also document how to revert it if it doesn't work.

Reply