TÜRKIYE Law and Practice Contributed by: Bora Yazıcıoğlu, Alper Işık, Emre Öntekin and Ferat Gümüş, YAZICIOGLU Legal
1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy Cybersecurity has been at the forefront of Türkiye’s strategic policies over the last decade, as an integral part of its national security. The results are showcased in the Global Cybersecurity Index 2024 published by the International Telecommunication Union, which ranked Türkiye as a Tier-1 Role-modelling coun - try globally and awarded a full score in all areas of strength. The National Cybersecurity Strategy for 2024–2028 (“NCS 2024”) Since 2012, the Ministry of Transport and Infrastruc - ture (MTI) has published four mid-term strategic plans for cybersecurity. The most is the NCS 2024, accord - ing to which Türkiye’s cybersecurity strategy for the next four years is based on six objectives: • cyber-resilience; • proactive cyber-defence and deterrence; • a human-centred cybersecurity approach; • secure use of technology and its contribution to cybersecurity; • use of domestic and national technologies for combating cyber threats; and • international reputation. The 12th Development Programme (2024–2028) The 12th Development Programme sets out the fol - lowing general policy goals for information technolo - gies, as well as sector-specific policies: • strategic, regulatory and technological efforts to ensure national cybersecurity and strengthen insti - tutional structures; • updating national strategies in the context of new- generation cyber threats and technological devel - opments; • enacting regulations in line with the EU’s “NIS 2 Directive” and the best international practices; • administrative structuring for high-level co-ordina - tion of national cybersecurity activities; • strengthening threat intelligence through AI and big data analytics;
• strengthening the national cybersecurity infrastruc - ture; • enacting procedures and principles on the estab - lishment of an information security system in criti - cal infrastructures; • introducing cybersecurity standards; • improving the domestic cybersecurity ecosystem; • supporting the global competitiveness of domestic solutions; • developing test infrastructures for cybersecurity; • increasing the use of domestic cybersecurity prod - ucts; • expanding cybersecurity awareness, workforce training and new business models, and building programmes to that end; and • improving the content, quality and environment for training personnel. The Medium-Term Programme (2025–2027) The Medium-Term Programme provides the following policy objectives: • fully utilising digital technologies to strengthen cybersecurity through policies, to enhance the efficiency of public administration, and to develop public services; • enacting dedicated legislation on cybersecurity and secondary regulations in line with the relevant EU legislation; • implementing public–university–private sector co- operation programmes to train qualified personnel in strategic fields, including cybersecurity; and • enhancing resilience in payment and electronic institutions’ cybersecurity. The Presidency Programme for 2026 The Presidency Programme for 2026 sets out more specific plans based upon the six objectives set out in the NCS 2024, including: • legislative works in line with the EU legal frame - work; • enhancement of technical infrastructure to counter cybercrime; • development of domestic cybersecurity solutions; • defining roles and qualifications for cybersecurity professionals;
416 CHAMBERS.COM
Powered by FlippingBook