Skip to main content

infosecacademy Eğitim Danışmanlık Hizmetleri

About Infosec Academy

About Infosec Academy and our principal consultant

An information security consultancy, training provider and audit practice based in Istanbul, working with clients across the European Union, Türkiye and the Gulf. A specialist practice, not a generalist IT firm — every engagement is led personally by our founder.

The practice

Built by someone who has been audited

Infosec Academy (legal name: infosecacademy Eğitim Danışmanlık Hizmetleri) provides consulting, training and audit services in information security, business continuity, privacy and IT service management, from its office in Ataşehir, Istanbul.

Our founder has built the kind of programmes we now assess, and has sat on the receiving end of audits himself. Clients get a consultant who knows what a certification body will actually accept as evidence, and what an operations team will actually be able to run on a Monday morning.

Deliverables are produced in English to international documentation standards, in the formats your auditors, regulators and group headquarters expect.

Coverage

Standards
ISO/IEC 27001, 27701, 22301, 20000-1, 42001 and ISO 9001 — Lead Auditor certified in all six
Regulation
NIS2 and its national transpositions, GDPR, DORA-adjacent resilience work, Turkish KVKK, UAE and Qatar data protection law
Frameworks
NIST CSF and the SP 800 series, CIS Controls, ITIL, COBIT — applied as implementation vehicles
Neutrality
We do not issue certificates; accredited certification bodies do (ISO/IEC 17021-1)
Principal consultant

Kuzey AKSU

Founder and Principal Consultant · GRC Consultant and multi-standard ISO Lead Auditor

Over 25 years in IT and information security, fifteen of them leading security and infrastructure functions inside multinational organisations in banking, insurance, online financial services, industrial holdings, port operations, aviation maintenance and manufacturing.

He has built and run information security programmes from the ground up five times, managing cross-functional teams, global vendors and multi-million-dollar budgets, and holding accountability during internal and external audits rather than advising from beside them.

Today he delivers NIS2 and ISO compliance programmes for EU clients through Infosec Academy — with programmes in Slovakia and Romania worked to the national transpositions — alongside training, audit, and supplier assessment and contract remediation on both sides of the EU–Türkiye border.

Having built the kind of programmes I now assess changes what I look for — and what I am willing to accept as evidence.

Core expertise

  • NIS2 and national transpositions
  • ISO management system implementation and audit
  • GDPR, KVKK and cross-border data transfers
  • OT/ICS security governance and supply chain risk
  • Risk management — ISO/IEC 27005, NIST SP 800-30 and 800-37
  • Business continuity and crisis management
  • NIST CSF, CIS Controls, ITIL, COBIT
  • Security programme build, vCISO and board advisory
Career

Career timeline

The organisations below are employers from our founder’s career, not client references.

  1. Infosec Academy · Founder and Principal Consultant · present

    Information security consulting, training and audit: ISO/IEC 27001-based ISMS consultancy, NIS2 programmes for EU clients, data protection programmes, ITIL-based IT governance and standards training from awareness to internal auditor level.

  2. Coral Travel Group · Senior Quality Assurance Manager · 2024–2025

    Istanbul and Antalya.

  3. ATP Software and Technology · Information Security Manager · 2023–2024

    ISMS design and implementation; security initiatives prioritised against business risk and regulatory obligation; compliance metrics; audit finding remediation; application, API and container vulnerability management with development teams.

  4. BSH Home Appliances Group · PCM Shape Global Security Manager · 2023–2024

    Manufacturing.

  5. myTECHNIC · Information Security Manager · 2023

    Aviation maintenance, repair and overhaul (MRO).

  6. Mersin International Port (MIP) · IT Project Governance and Compliance Manager · 2022–2023

    Critical infrastructure.

  7. Yıldırım Holding · Global Information Security Senior Manager · 2018–2022

    Built and ran the group’s global information security and risk management programme: strategy, metrics and reporting, maturity model and roadmap, budget, building the security organisation, and primary control point during significant incidents.

  8. GKFX · Information Security Manager · 2016–2018

    Multinational financial services, reporting to the CTO. Security management framework aligned to ISO/IEC 27002, PCI-DSS, NIST SP 800-53 and CIS Controls across UK, German, Spanish and Chinese branches; IT risk framework on ISO/IEC 27005 and NIST SP 800-37.

  9. Habboush Group · IT Manager · 2013–2014

    Türkiye and Dubai: infrastructure design, vendor and service-agreement negotiation, corporate IT policy, COBIT and ITIL practice, business continuity and ISO/IEC 27001 ISMS directives.

  10. Citibank · Senior Infrastructure Systems Engineer · 2005–2011

    ISMS management and audit evidence owner.

  11. Earlier roles · 1998–2012

    CIGNA Life Insurance, HP Türkiye, Erenet Computer, Reysaş Logistics, Batısan Logistics, and independent consulting.

Credentials

Certifications, education and languages

ISO Lead Auditor

  • ISO/IEC 27001
  • ISO/IEC 27701
  • ISO 22301
  • ISO/IEC 20000-1
  • ISO/IEC 42001
  • ISO 9001

Professional

  • ISACA CISM
  • ISACA CDPSE
  • ITIL v3 and v4 Foundation
  • CEH v9

Earlier technical

  • MCSE
  • Cisco CCNA
  • Cisco CCNP
  • HP ASE

Education

  • MSc Cyber Security — Ahmet Yesevi University, 2020–2021. Thesis: CIS Controls implementation and maturity assessment in Turkish organisations
  • MSc Information Technology — Preston University, 2007–2010. Thesis: ITIL-based IT service management
  • BA Business Administration — Anadolu University

Languages

  • Turkish — native
  • English — professional
Career organisations

Organisations where our founder held roles

  • Citibank
  • CIGNA Life Insurance
  • GKFX
  • Yıldırım Holding
  • Mersin International Port (MIP)
  • myTECHNIC
  • BSH Home Appliances Group
  • HP Türkiye
  • Habboush Group
  • Coral Travel
  • ATP

These organisations are not client references. They are organisations where our founder was employed during his career.

Let us start with a scoping conversation

Thirty to forty-five minutes is usually enough to establish scope, a realistic timeline, and whether we are the right people for the work.