BGA Information Security
BGA Information Security is a Turkish cybersecurity firm founded in 2008 that delivers product-independent consulting (penetration testing, red teaming, forensics, SOC/CSIRT exercises) and internationally accredited training to enterprise and government clients in finance, energy, telecom, and defense across Turkey, Azerbaijan, and the United States.
- Company typePrivate
- Founded2008
- HeadquartersIstanbul
- Headcount51–100
- GTM typeB2B
- OfferingServices
What BGA Information Security does
BGA Information Security is a privately held Turkish cybersecurity consulting and training firm founded in 2008 and headquartered in Istanbul, with additional offices in Ankara, Baku, and the United States. The company delivers product-independent cybersecurity services to enterprise and government clients across four primary verticals: finance and banking, energy, telecommunications, and government and defense. Its core professional services portfolio includes strategic cybersecurity consulting, penetration testing (whitebox, blackbox, and graybox), red team operations, cyber crime investigation and computer forensics, and SOC/CSIRT (SOME) exercises and threat simulation.
BGA monetizes through two professional services streams: direct cybersecurity consulting engagements and internationally accredited training programs delivered to 14-person classroom cohorts. The training business is anchored by its position as an official EC-Council authorized training and exam center in Turkey, and staff hold a broad stack of certifications including CISSP, OSCP, OSCE, CEH, CHFI, CISA, and LPT. The firm operates with a ~50-person internationally accredited technical team and reports more than 1,000 cumulative training and consulting projects since 2008.
The commercial model is reinforced by a community and brand ecosystem operated under the Bilgi Güvenliği AKADEMİSİ sub-brand, which includes 15,000+ members across email communities (NetSec, CyberINTEL, CISSP-TR, DDoS/BotNet), a 98+ webinar catalog, the annual IstSec conference, university cybersecurity camps (since 2011), the BGA Staj Okulu internship school, and platforms such as BGA Wiki, BGA Bank, and Hack2Net. Leadership consists of General Manager Huzeyfe Önal, Training Coordinator Mehmet Ataş, and Managing Partner Ali Bay, with no disclosed external institutional investment.
BGA Information Security firmographics
Firmographics- Name
- BGA Information Security
- Legal name
- BGA Bilgi Güvenliği A.Ş.
- Website
- https://bgasecurity.com
- Company type
- Private
- Founded year
- 2008
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- BGA Information Security is a Turkish cybersecurity firm founded in 2008 that delivers product-independent consulting (penetration testing, red teaming, forensics, SOC/CSIRT exercises) and internationally accredited training to enterprise and government clients in finance, energy, telecom, and defense across Turkey, Azerbaijan, and the United States.
- Ownership category
- akta.pro rank
BGA Information Security industry classification
Industry- Product category
- Cybersecurity Consulting and Training Services
- NAICS
- Other Scientific and Technical Consulting Services (54169), Computer Training (61142), Professional and Management Development Training (61143)
- SIC
- Services-Management Consulting Services (8742), Services-Educational Services (8200)
- akta.pro primary industry
- Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing) (EDABAFAF)
- akta.pro secondary industry
- Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH)
Keywords
Where BGA Information Security is headquartered
LocationHeadquarters
- HQ city
- Istanbul
Offices4 records
Markets served
BGA Information Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Cybersecurity Consulting Services: Strategic cybersecurity consulting including penetration testing, security audits, CSIRT/SOME setup and management, SOC consulting, open-source security solutions deployment, big data security analytics, and incident response services delivered to enterprise clients across finance, energy, telecom, and government sectors
- Cybersecurity Training Services: International accredited cybersecurity training programs delivered in classroom settings of up to 14 participants per session, covering network and system security, information security certification, EC-Council certification, advanced cybersecurity, and corporate security training. Revenue generated through course fees for certification programs.
Go-to-market motion1 record
Distribution channels3 records
Marketing channels5 records
BGA Information Security product offering
Product offeringCore offering
BGA provides product-independent strategic cybersecurity consulting and internationally accredited cybersecurity training to enterprises. Core consulting services include penetration testing, red teaming, cyber crime investigation and forensics, SOC/CSIRT (SOME) exercises, incident response, and open-source security solution deployment. Training is delivered in 14-person classroom cohorts covering EC-Council certification programs, network and system security, and advanced cybersecurity topics.
Product overview
BGA Information Security operates as a cybersecurity consulting and training services company, not a software product company. Its offering consists of professional security services combined with training programs and community initiatives. The core services include strategic cybersecurity consulting, penetration testing (whitebox/blackbox/graybox), red teaming operations, cyber crime investigation/forensics, and SOC/CSIRT exercises. The training portfolio encompasses certification programs (EC-Council authorized), corporate SOC training, penetration testing professional courses, and network security training. Additionally, BGA supports the cybersecurity community through educational programs including cybersecurity camps (since 2011), internship schools, practice platforms (BGA Bank, Hack2Net), knowledge resources (BGA Wiki, blog), and professional email communities (NetSec, CyberINTEL, CISSP-TR, DDoS/BotNet lists) serving over 15,000 community members. The company operates with an internationally certified 50-person technical team across Ankara, Istanbul, Azerbaijan, and USA offices since 2008.
Differentiator
Problem solved
Functional benefit
Brands
- Bilgi Güvenliği AKADEMİSİ: Training and social responsibility brand of BGA Bilgi Güvenliği A.Ş., responsible for organizing commercial and volunteer training and activities to increase cybersecurity awareness.
Products and services
- Strategic Cybersecurity Consulting (Siber Güvenlik Danışmanlığı) Product-independent strategic cybersecurity consulting that helps organizations understand and anticipate their security needs and invest in the right areas, covering risk assessment and policy development. Targeted at enterprise and public-sector organizations.
- Penetration Testing (Sızma Testleri / Pentest) Professional penetration testing using whitebox, blackbox, and graybox methodologies to identify and assess security vulnerabilities in client systems. Targeted at enterprise and government organizations.
- Red Teaming (Red Team Operations) Advanced red team operations in which highly trained security consultants execute attack scenarios to uncover physical, hardware, software, and human vulnerabilities in organizations. Targeted at enterprises seeking realistic adversary emulation.
- Cyber Crime Investigation & Computer Forensics (Siber Suç İnceleme / Adli Bilişim) Digital forensics and cyber crime investigation service that combines computer forensics with criminal psychology to produce undeniable, concrete evidence for clients. Targeted at organizations needing incident attribution and legal-grade evidence.
- SOC/CSIRT Exercises and Threat Simulation (SOME Tatbikatı) Security Operations Center (SOC) / SOME exercises and threat simulation services that measure the effectiveness of security measures and the security team, with results reported as concrete values. Targeted at enterprise and government SOC/CSIRT teams.
- Information Security Training (Bilgi Güvenliği Eğitimleri) Internationally accredited cybersecurity training programs delivered in 14-person classroom settings with senior instructors, including certification preparation courses aligned to PCI, SOX, ISO 27001, and HIPAA. Targeted at enterprise security teams and individual professionals.
- EC-Council Certification Training (EC-Council Sertifikasyon Eğitimleri) Official EC-Council authorized training and exam center services in Turkey, providing internationally recognized certification programs such as CEH (Certified Ethical Hacker). Targeted at individual professionals and corporate trainees seeking globally valid certifications.
- Corporate SOC/CSIRT Training (Kurumsal SOME Eğitimleri) Customized training programs for establishing and managing Corporate CSIRT (SOME) teams, delivered for government and private-sector organizations that need to build or formalize incident response capability.
- Penetration Testing Professional Training (Sızma Testleri Uzmanlık Eğitimleri) Advanced penetration testing professional training aligned with PCI, SOX, ISO 27001, and HIPAA compliance requirements, designed to develop specialist offensive security capability. Targeted at security practitioners and corporate penetration testing teams.
- Network and System Security Training (Ağ ve Sistem Güvenliği Eğitimleri) Network security and cyber defense training covering layered security architecture and the appropriate solutions for each layer, designed to build practical defensive capability. Targeted at IT and security operations staff.
Companies that use BGA Information Security
Customer profileNamed customers4 records
Segments1 record
Ideal customer profiles1 record
BGA Information Security technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
BGA Information Security partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and minor.
- EC-CouncilcoreBGA is an official EC-Council training institution and official exam center in Turkey, providing internationally recognized certification programs including CEH (Certified Ethical Hacker).
- TÜBİTAK-BİLGEMcoreTÜBİTAK-BİLGEM (Cybersecurity Institute) partnered with BGA Bilgi Güvenliği AKADEMİSİ to jointly organize Cybersecurity Summer Camps for university students.
- Sakarya UniversityminorBGA partnered with Sakarya University for Cybersecurity Winter Camp 2016 organized for university students interested in cybersecurity careers.
- ERÜ (Erciyes University)minorBGA collaborated with ERÜ Information Security Club for Cybersecurity Winter Camp in Kayseri 2015.
Scale indicators5 records
Recent moves6 records
Expansion highlights5 records
BGA Information Security competitors and assessment
Company assessmentBroad incumbents
- (ISC)²: Global cybersecurity certification body (CISSP, CCSP, SSCP). BGA's instructors and consultants hold (ISC)² credentials and BGA offers CISSP prep — making it directly comparable as a provider of certified cybersecurity professional development.
- Mandiant (Google Cloud): Global incident response, threat intelligence, and cybersecurity consulting firm. Directly comparable to BGA's consulting line (penetration testing, red teaming, CSIRT/SOME, forensics, incident response), albeit at much larger scale.
- NCC Group: UK-listed cybersecurity consulting and software firm with global delivery. Comparable to BGA's pen testing, red teaming, and managed security consulting services for enterprise and government clients.
- EC-Council: Owner of the CEH/ECSA certification frameworks that BGA delivers as Turkey's authorized training and exam center. Comparable as the certification body whose programs BGA teaches, and a broader incumbent in the same training ecosystem.
- Deloitte (Turkey Cyber): Big 4 firm operating a managed cyber, risk, and compliance practice in Turkey. Directly comparable to BGA's strategic consulting, security audits, and compliance-driven engagements with regulated Turkish enterprises.
- KPMG (Turkey Cyber Practice): Big 4 advisory with a cybersecurity and risk consulting practice in Turkey serving banks, energy, telecom, and government. Comparable as an enterprise-focused cyber advisory competitor in BGA's core verticals.
Direct peers
- Picus Security: Turkish-origin cybersecurity firm specializing in breach and attack simulation and security validation. Closely comparable to BGA as a Turkish-rooted cybersecurity specialist with international footprint.
- SANS Institute: Global leader in cybersecurity training and certification. Comparable to BGA's training business — both deliver internationally recognized cybersecurity courses (SANS via GIAC, BGA via EC-Council/OSCP/OSCE prep) to enterprise and government clients.
- Labris Networks: Turkish cybersecurity company focused on DDoS protection, network security, and threat intelligence. Comparable to BGA as a domestic Turkish cybersecurity specialist serving telecom, ISPs, and enterprise.
Regional players
- HAVELSAN: Turkish defense and technology company with a cybersecurity division serving government, defense, and critical infrastructure. Comparable to BGA's CSIRT/SOME and government/defense consulting work in the Turkish public sector.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
BGA Information Security social profiles
Digital presenceBGA Information Security compliance and trust
Trust signalCompliance18 records
BGA Information Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
BGA Information Security leadership team
Management profileNumber of profiles
Profiles3 records
BGA Information Security subsidiaries and ownership
Company hierarchySubsidiaries3 records
BGA Information Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
BGA Information Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about BGA Information Security
What does BGA Information Security do?
BGA provides product-independent strategic cybersecurity consulting and internationally accredited cybersecurity training to enterprises. Core consulting services include penetration testing, red teaming, cyber crime investigation and forensics, SOC/CSIRT (SOME) exercises, incident response, and open-source security solution deployment. Training is delivered in 14-person classroom cohorts covering EC-Council certification programs, network and system security, and advanced cybersecurity topics.
Is BGA Information Security a public or private company?
BGA Information Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was BGA Information Security founded?
BGA Information Security was founded in 2008. It employs 51 to 100 people.
Where is BGA Information Security based?
BGA Information Security is headquartered in Istanbul.
How does BGA Information Security make money?
Two revenue lines are on record. Cybersecurity Consulting Services are the primary driver. The others are cybersecurity Training Services.
Who are BGA Information Security's main competitors?
Broad incumbents on record are (ISC)², Mandiant (Google Cloud), NCC Group, EC-Council, Deloitte (Turkey Cyber) and KPMG (Turkey Cyber Practice). Direct peers are Picus Security, SANS Institute and Labris Networks. HAVELSAN is listed as a regional player.
Does BGA Information Security have an API?
No public API is recorded for BGA Information Security.
What industry is BGA Information Security in?
BGA Information Security's product category is Cybersecurity Consulting and Training Services. Its primary akta.pro industry code is EDABAFAF, Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing), with a secondary code of EDAOAIAH, Penetration Testing, Red Team & Ethical Hacking. Its NAICS code is 54169 and its SIC code is 8742.