Phone: 0 (552) 380 25 25  |  Weekdays 09:00–18:00 · Technical support 24/7

🇹🇷 TR

Cyber Security and Data Protection Guide for Businesses in Türkiye

Cyber Security & Compliance

KVKK compliance, VERBIS, breach notification, retention policy, SME cyber security, ransomware and penetration testing guides, gathered in one place.

Cyber security and personal data protection are no longer just an IT matter; they belong on the board agenda. A ransomware attack can halt production and invoicing for days, and a data breach brings both a duty to notify Türkiye's Personal Data Protection Authority (KVKK) and a loss of customer trust. The figures show this is far from rare. According to TurkStat's ICT Usage Survey in Enterprises 2026, 9.4% of Turkish enterprises experienced at least one ICT security incident in 2025. The KVKK 2025 Annual Report shows the Authority received 328 data breach notifications that same year.

This hub gathers our cyber security and data protection articles into a reading path from first steps to decision. On the compliance side, start with KVKK compliance steps, which sets out eight stages from data inventory to audit. Then check whether you must register with VERBIS, and read about the data retention and disposal policy that decides how long data is kept. So that you know what to do when a breach happens, keep our guide to breach notification within 72 hours to hand.

On the technical side, the SME cyber security checklist is a good place for small teams to start. To go deeper, read about business password security, 3-2-1 backups against ransomware and penetration testing, which tests your defences through an attacker's eyes. For manufacturers, OT security for SCADA networks is essential, and for anyone planning to move infrastructure, cloud migration cost is the key article at the decision stage.

For delivery, see our pages on data protection compliance, cyber security and cloud migration and infrastructure consultancy. Before you start, answer three questions. What personal data do you hold, and in which systems? When did you last actually restore something from your backups? And how many hours does it take to remove a leaver's access?

Reading list by topic

  • Email-borne risks: SPF, DKIM and DMARC, how to spot phishing emails and email archiving and data protection.
  • Identity and access: single sign-on (SSO), offboarding email access and biometric attendance and data protection.
  • AI and data: is it safe to put company data into ChatGPT?
Start here

KVKK Compliance in Turkey: An 8-Step Roadmap from Data Inventory to Internal Audit

How does KVKK compliance work in Turkey? An 8-step roadmap covering data inventory, privacy notices, VERBIS, retention, breach response and internal audit.

Read the guide

All guides in this topic (2)

Questions we hear most often

Frequently Asked Questions

Where should KVKK compliance begin?

It begins with a personal data inventory: what data you hold, for what purpose, on what legal basis, where, and for how long. Privacy notices, cases that need explicit consent, the retention and disposal policy, technical and organisational measures and, where required, VERBIS registration are all built on that inventory. Without it, compliance work stays incomplete.

How quickly must a data breach be notified?

Under the Board's decision, the data controller must notify the Personal Data Protection Board without delay and within 72 hours at the latest of becoming aware of the breach. Affected individuals must also be informed as soon as reasonably possible. Meeting that deadline requires a response plan, named owners and a notification template prepared in advance.

What are the top cyber security priorities for an SME?

Multi-factor authentication, up-to-date operating systems and software, tested backups kept separate from the network, email domain authentication and staff awareness come first. None of these needs a large budget, yet together they block a large share of common attacks. Next come a review of user permissions and a written incident response plan.

How often should we commission a penetration test?

As a general rule, at least once a year and after any major infrastructure or application change. Organisations with internet-facing systems, applications that process customer data or sector-specific regulatory requirements may test more often. The real value lies in fixing the findings in the report and then retesting to confirm they are closed.

Have a different question? Ask Us

Talk to an Engineer

Tell us what you need to solve. We'll come back with a written proposal.