Yasemin Ercan

Yasemin Ercan

Senior Security Analyst

  • Risk Management
  • Vulnerabilities
  • Threat Analysis

About

Has over 10 years of experience in security analysis and risk management. Expert in evaluating security vulnerabilities.

22 articles

Articles

SSL/TLS Certificates: Wildcard vs SAN vs Standard Security
October 13, 2025

SSL/TLS Certificates: Wildcard vs SAN vs Standard

SSL/TLS certificates are critical for ensuring website security. This blog post compares the features of Standard, Wildcard, and SAN (Subject Alternative Name) certificates to help businesses choose the certificate that best suits their needs.

SSL Certificate Checker: Testing Your SSL Installation Security
October 12, 2025

SSL Certificate Checker: Testing Your SSL Installation

This blog article delves into the concept of SSL Certificates, which are essential for ensuring the security of your website. We start by explaining what an SSL certificate is, how it works, and the various types available. Next, we present the necessary steps for installing an SSL certificate and tips to keep in mind.

Understanding How a Web Application Firewall (WAF) Works Security
October 10, 2025

Understanding How a Web Application Firewall (WAF) Works

Website security is critical in today’s digital landscape. This blog post elaborates on what a Web Application Firewall (WAF) is and how it operates, detailing its fundamental principles, types, and the advantages and disadvantages associated with its use.

Cross-Origin Resource Sharing (CORS) and Web Security Security
October 8, 2025

Cross-Origin Resource Sharing (CORS) and Web Security

This blog post provides a comprehensive overview of Cross-Origin Resource Sharing (CORS), a critical part of web security. It explains what CORS is and why it is important for web applications, while providing information about its history and development.

Methods for Automating the Renewal of SSL/TLS Certificates Security
October 5, 2025

Methods for Automating the Renewal of SSL/TLS Certificates

Automating the renewal of SSL/TLS certificates is critical for maintaining the security of your website and enhancing the user experience. In this blog post, we will delve into the reasons why you should automate your SSL/TLS certificate renewal, the necessary steps, best practices, and tools you can use.

Secure Server Access with SSH Key Authentication Security
October 5, 2025

Secure Server Access with SSH Key Authentication

This blog post takes a detailed look at SSH Key authentication, which plays a critical role in server security. It explains what SSH keys are, why they are more secure than password-based authentication, and their key features. It then provides a quick guide to creating an SSH key.

Increase Site Speed with Cloudflare Argo and Smart Routing Security
October 2, 2025

Increase Site Speed with Cloudflare Argo and Smart Routing

Improving site speed with Cloudflare Argo is critical in today s digital world. This blog post delves into why Cloudflare Argo is crucial for speed, methods for improving site speed, how Smart Routing works, and the benefits of using Cloudflare Argo.

DNS over HTTPS (DoH) and DNS over TLS (DoT) Security
September 16, 2025

DNS over HTTPS (DoH) and DNS over TLS (DoT)

This blog post provides a detailed examination of DNS over HTTPS (DoH) and DNS over TLS (DoT), technologies that are crucial components of internet security. It explains what DoH and DoT are, their key differences, and the security benefits they provide by encrypting DNS queries.

Web Security Basics: A Beginner's Guide to Protecting Your Site from Attacks Security
September 16, 2025

Web Security Basics: A Beginner's Guide to Protecting Your Site from Attacks

Web security is vital for websites today. This beginner s guide explains what web security is, its key components, and potential threats. It dispels common misconceptions and details the steps you need to take to protect your site, along with the tools and software available.

Implementing Single Sign-On (SSO) and Security Considerations Security
September 11, 2025

Implementing Single Sign-On (SSO) and Security Considerations

This blog post offers a comprehensive exploration of the concept of Single Sign-On (SSO), detailing what SSO is, its primary goals, and the steps involved in its implementation. It also addresses the requirements for SSO implementation, potential benefits, and associated drawbacks.

The Human Factor in Cybersecurity: Employee Training and Awareness Raising Security
August 28, 2025

The Human Factor in Cybersecurity: Employee Training and Awareness Raising

The human factor in cybersecurity can be a company s weakest link. Therefore, employee training and awareness-raising are critical to protecting against cyber threats. This blog post highlights the importance of the human factor in cybersecurity and details how to manage an effective training and awareness-raising process.

GDPR and Data Security: How to Ensure Compliance for Your Business Security
August 27, 2025

GDPR and Data Security: How to Ensure Compliance for Your Business

This blog article provides a comprehensive guide for businesses to become compliant with the General Data Protection Regulation (GDPR). Introducing GDPR and data security, it explains the fundamental principles of GDPR and the requirements necessary for data security.

Using Secure FTP: Ensuring Security in File Transfers Security
July 24, 2025

Using Secure FTP: Ensuring Security in File Transfers

This blog post provides an in-depth look at Secure FTP usage in today's world, where ensuring security in file transfers is critically important. It explains what Secure FTP is and why it’s essential, examines various Secure FTP protocols, and offers the best software options available.

Log Management and Security Analysis: Detecting Threats Early Security
June 13, 2025

Log Management and Security Analysis: Detecting Threats Early

This blog post examines the critical role of log management in early detection of cybersecurity threats. It details the fundamental principles of log management, critical log types, and methods for enhancing them with real-time analysis. It also addresses the strong relationship between common pitfalls and cybersecurity.

SIEM Systems: Security Information and Event Management Solutions Security
June 12, 2025

SIEM Systems: Security Information and Event Management Solutions

SIEM systems, as security information and event management solutions, are a cornerstone of modern cybersecurity strategies. This blog post explains in detail what SIEM systems are, why they are important, and their key components.

Remote Work Security: VPN and Beyond Security
April 8, 2025

Remote Work Security: VPN and Beyond

As remote work becomes increasingly common in today’s business world, the security risks it brings with it also increase. This blog post explains what remote work is, its importance, and its benefits, while also focusing on the basic elements of remote work security.

Security in DevOps: Building a Secure CI/CD Pipeline Security
April 8, 2025

Security in DevOps: Building a Secure CI/CD Pipeline

This blog post focuses on Security in DevOps, covering the basics and importance of creating a secure CI/CD pipeline. While examining in detail what a secure CI/CD pipeline is, the steps to create it, and its basic elements, it also focuses on best practices for security in DevOps and strategies to prevent security errors.

Threat Modeling with the MITRE ATT&CK Framework Security
March 14, 2025

Threat Modeling with the MITRE ATT&CK Framework

This blog post discusses the critical role of threat modeling in cybersecurity, detailing how the MITRE ATT&CK framework can be leveraged during this process. After providing an overview of the MITRE ATT&CK framework, it explains what threat modeling is, the methods used, and how threats are classified within this framework.

Cyber Insurance: Choosing the Right Policy for Your Business Security
March 13, 2025

Cyber Insurance: Choosing the Right Policy for Your Business

Cyber insurance is critical for businesses, providing protection against the financial consequences of cyber attacks. This blog post provides basic information about cyber insurance, explaining how policies work and the importance of cyber security risks.

Red Team vs Blue Team: Different Approaches to Security Testing Security
March 12, 2025

Red Team vs Blue Team: Different Approaches to Security Testing

In the world of cybersecurity, Red Team and Blue Team approaches offer different strategies for testing the security of systems and networks. This blog post provides an overview of security testing, explaining in detail what Red Team is and its purposes.