Cybersecurity 2026

TÜRKIYE Law and Practice Contributed by: Bora Yazıcıoğlu, Alper Işık, Emre Öntekin and Ferat Gümüş, YAZICIOGLU Legal

• General Directorate of Public AI; • General Directorate of Digital State; • General Directorate of Administrative Services; • Strategy Development Department; and • Office of the Private Secretary. However, the Directorate has not yet become fully operational or published any regulation. Moreover, it has been reported that the Directorate was involved in joint cyber operations against a net - work attempting to gain unauthorised access to data belonging to public institutions. The Ministry of Transport and Infrastructure The Council of Ministers Decision on Cybersecurity authorises the MTI to govern national cybersecurity strategy and implementation, with strategic oversight provided by the TR-CERT. The Cybersecurity Act del - egates MTI’s cybersecurity-related responsibilities to the Directorate. The Cybersecurity Board The Cybersecurity Board is presided over by the Pres - ident of the Republic of Türkiye and tasked with: • adopting resolutions regarding cybersecurity poli - cies, strategies, action plans and other regulatory measures; • adopting resolutions for the implementation of the cybersecurity technology roadmap prepared by the Directorate; • identifying priority areas for incentives in cyberse - curity; • adopting resolutions for the development of human resources in the cybersecurity field; • determining critical infrastructure sectors; and • resolving disputes between the Directorate and public institutions. The Information Technologies and Communication Authority ICTA is an independent administrative institution that regulates telecommunications, closely monitors cybersecurity incidents, and audits and warns private companies concerning cybersecurity threats and vul - nerabilities.

The Cybersecurity Act restricts ICTA’s general cyber - security-related powers and limits its duties to the data systems within its own competency. However, ICTA will continue carrying out its duties until the Directorate’s organisation becomes fully operational. The Digital Transformation Office (DTO) The DTO has played an active role in cybersecurity, big data, artificial intelligence and digital transforma - tion since its establishment in 2018. However, the DTO was abolished with a Presidency Decree on 28 March 2025, and its cybersecurity-related duties and assets have been transferred to the Directorate. National Cyber Incidents Response Centre In 2013, the TR-CERT was established under ICTA to identify emerging threats, take measures to elimi - nate the effects of attacks and incidents on national cyberspace and share them with the relevant actors. The TR-CERT oversees the management of response to cybersecurity incidents from the beginning until the resolution. It co-ordinates with CERTs, which are required to report cyber incidents to the TR-CERT. The TR-CERT also carries out awareness-raising and guidance activities to increase the awareness of public institutions and organisations against cyber-attacks. Cyber Incidents Response Teams Sectoral CERTs Sectoral CERTs are established under: • the regulatory and supervisory bodies; or • the relevant ministries of critical sectors, which are: (a) the Ministry of Interior; (b) the Ministry of Justice; (c) the Ministry of Treasury and Finance; (d) the Ministry of Environment, Urbanisation and Climate Change; (e) the Ministry of Labour and Social Security; (f) the Ministry of Agriculture and Forestry; and (g) the Ministry of Health. Sectoral CERTs are responsible for co-ordination, regulation and supervision of cybersecurity in their respective critical sectors. They act in co-ordination with the TR-CERT and institutional CERTs operating in the sectors concerned.

420 CHAMBERS.COM

Powered by