TÜRKIYE Law and Practice Contributed by: Bora Yazıcıoğlu, Alper Işık, Emre Öntekin and Ferat Gümüş, YAZICIOGLU Legal
3.6 Threat-Led Penetration Testing According to the Cybersecurity Act, one of the duties of the Directorate is to conduct vulnerability and pen - etration tests in order to prevent cyber-attacks against critical infrastructures and information systems. In addition, the Financial NIS imposes penetration test - ing obligations for their respective financial sector institutions, as detailed below. For detailed information on the scope of the Financial NIS, see 3.1 Scope of Financial Sector Operational Banks must have annual penetration tests performed by independent teams that are not involved in the information systems operations. Banks’ Institutional CERTs must also conduct routine penetration tests on IT assets, routinely monitor trace records and check for correlations that may lead to meaningful results. The Communiqué on Payment Services The Communiqué mandates that payment and elec - tronic money institutions must: • conduct annual penetration tests for scenarios covering possible internal and external threats (pursuant to the procedure provided under Annex 5 therein); • have the penetration tests conducted by accred - ited, independent third parties (natural or legal entities) with no involvement in information security operations; and • submit annual reports to the TRCB, detailing breaches, test results, critical vulnerabilities identi - fied and remediation measures. The CMB Communiqué Resilience Regulation . The By-Law ISBEBS The information systems of the related institutions and organisations must have annual penetration tests pur - suant to the procedure provided under the Annex 1 of the CMB Communiqué. The reports related to the penetration tests must be submitted to the CMB each year by January 31st. Penetration tests must be conducted by independ - ent third parties (natural or legal entities) who are not
involved in information security operations and are certified nationally or internationally.
4. Cyber-Resilience 4.1 Cyber-Resilience Legislation There is no general legislative instrument on cyber resilience in Türkiye. Currently, the main regulations on managing cyber incidents are the Communiqué on the Procedures and Principles Regarding the Establishment, Duties and Activities of CERTs and MTI’s guidelines on establish - ing institutional and sectoral CERTs. For further infor - mation on CERTs, see 1.3 Cybersecurity Regulators . However, the Presidency Programme for 2026 includes a plan to enact legislation in line with the EU’s Cyber Resilience Act (CRA). Cyber resilience regula - tion is anticipated, since cyber resilience is listed as a core objective of the NCS 2024. In this regard, the Cybersecurity Act objective of “establishing principles to mitigate the possible impacts of cyber incidents” indicates cyber resilience. According to the Cybersecurity Act, “activities aimed at detecting attacks and cyber incidents, activating response and alert mechanisms, and restoring the situation to its state prior to the cyber incident” are considered as part of cybersecurity, which seems to imply cyber resilience. 4.2 Key Obligations Under Legislation The Cybersecurity Act delegates a specific duty to the Directorate for “increasing the cyber resilience of criti - cal infrastructures and information systems through vulnerability and penetration tests and risk analysis, cyber-threat intelligence, and malware inspection operations”. Currently, the Institutional CERTs must ensure resil - ience during and after cyber incidents by: • co-ordinating with their sectoral CERTs to prevent or mitigate damage;
429 CHAMBERS.COM
Powered by FlippingBook