Skip to content
HEM Bilişim
Scenarios

Representative scenarios

Eight situations we meet often in the field: what the problem was, how we approached it and what changed in the organisation. Drawn from several engagements, not from any single one.

These are not real customer case studies

The scenarios on this page are representative examples composed from more than one engagement; they do not belong to a single customer and contain no organisation names. We publish real case studies only with the customer's written consent and under their own name. When such a study is published it will be marked separately on this page.

ManufacturingIllustrative

The inventory is in a spreadsheet and nobody updates it

Situation
Consulting was bought two years ago, an inventory table was produced and placed in a folder. Since then two new systems went live, a unit closed, and retention periods were never applied. When a customer asked for an audit, the table was opened and found not to reflect reality.
Our approach
Rather than rewriting the table from scratch we started with verification: short sessions with each unit to confirm the existing rows and add what was missing. Then we defined retention periods and their bases, and put in writing who owns updates.
What changed
The inventory became a record that is updated alongside the process. Preparing for an audit request now takes hours, not days.

The certificate is there and the surveillance audit is coming

Situation
The ISO 27001 certificate was obtained, but most controls were produced during certification week. For a year the risk assessment was not updated, no access review was run, and no restore was tested. The surveillance audit was a few months away.
Our approach
We first established which controls actually operate — sorting them into those with records and those without. Then we tied the record-less controls to processes: the permission list goes to managers automatically, restore testing enters the quarterly calendar, the risk register gets owners. We ran the internal audit only after that was in place.
What changed
They entered the surveillance audit with records that had accumulated rather than been produced. Most findings were closed before the audit.
E-commerceIllustrative

The banner is there but consent cannot be proven

Situation
A cookie banner had been on the site for years. A visitor claimed they were tracked despite declining. The organisation did not know how to respond: which cookies actually ran was undocumented, and no consent record had ever been kept.
Our approach
We first scanned the site to establish which cookies were actually set; the inventory contained unexpected third-party scripts. We rebuilt the banner: accept and reject with equal weight, consent recorded with a timestamp and banner version, and tags in a declined category no longer firing through the tag manager.
What changed
There is now a record to show at the next question. The inventory stays current through periodic scanning.
HealthcareIllustrative

A leaver's account is still open

Situation
An internal audit found that several employees who had left still had open accounts. Staff who changed roles had kept their old permissions. With many systems in play, closing accounts one by one was nobody's job.
Our approach
We produced the permission inventory and put orphaned accounts on a separate list. We made the HR leaver event a trigger: when a departure is entered, account closure tasks open automatically. In the periodic review the permission list goes to the manager for approval; unapproved permissions are removed and the removal recorded.
What changed
The gap between departure and account closure closed at the process level. A review record now exists to show in an audit.
TelecommunicationsIllustrative

Requests land in personal inboxes

Situation
The site lists an address for data subject requests, but the mail arrives in one employee's inbox. When that person is on leave the request waits, the answer runs past thirty days, and two of them reached the Board as complaints.
Our approach
We moved the request off a person and onto a process: a shared channel, a log that numbers every incoming request, and a reminder as the deadline approaches. We prepared answer templates by request type and defined the identity verification step.
What changed
Where a request stands is visible, deadlines are not missed, and every answer is on record. In the complaint file, the organisation could show the process working.
LogisticsIllustrative

Data flows to headquarters abroad with no basis in writing

Situation
Operational data is copied every night to the group headquarters' system abroad. The legal ground for the transfer is not written down, there is no data transfer agreement between the parties, and the privacy notice says nothing about it.
Our approach
We mapped the flow first: which data, how often, to which country, through which system. Then we established the ground for the transfer and the safeguard required, prepared the contractual side, and updated the privacy notice so that it covers the transfer.
What changed
The basis for the transfer is written, the contract is signed, and the privacy notice describes what actually happens. The route to follow for any new transfer is defined too.
Public sectorIllustrative

Backups run, restores have never been tried

Situation
The backup job runs every night and its report comes back green. A restore, however, has never once been attempted, nobody knows how long one would take, and access rights on the backup storage have never been reviewed.
Our approach
We turned restoring into a drill: a timed restore of a chosen system, with the gaps written down. Access to the backup environment was narrowed and logged, and the drill went onto a quarterly calendar.
What changed
How long a restore takes is now a measured number. Who reaches the backups is visible, and the drill record serves as evidence in an audit.
EducationIllustrative

A team wants to start an AI pilot on real data

Situation
A team wants to trial an assistant that answers questions and plans to feed its real records straight to the model. Where the data goes, how long it is kept and whether it is used for training had not been discussed.
Our approach
Rather than stopping the pilot we cleared its path: we established which fields were genuinely needed, removed the rest, and masked what remained. We confirmed the provider's retention and training policy in writing and defined the points where a person signs off on the output.
What changed
The pilot ran without real data leaving as it stood. Because the reasoning is written down, a second AI trial can follow the same route.

Completed work

The engagements we have completed, with their scope, duration and outcome, are on a separate page.

See the references

See where you stand in 20 minutes

The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.

Look at it yourself first

A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.

Start the compliance test

Let's look together

We discuss your current state and work out which step comes first and how long it takes.

Request a conversation