Skip to Content

Cybersecurity Legislation in Türkiye and Local SIEM

Cybersecurity Legislation in Türkiye and Local SIEM: Achieving Regulatory Compliance and Operational Edge Under Law No. 7545, KVKK, and Law No. 5651
August 7, 2026 by
Cybersecurity Legislation in Türkiye and Local SIEM
İsmail İşler

In our previous article titled "What Do Organizations Using Local SIEM Gain?", we discussed gains such as data sovereignty, cost predictability, and rapid support for organizations using local SIEM. However, behind these gains lies an intense regulatory burden that most organizations fail to fully penetrate. The Cybersecurity Law No. 7545, KVKK's data breach notification regime, BDDK and SPK's sectoral information systems regulations, and the log retention obligations of Law No. 5651; although they all seem independent of each other, actually intersect at a single point: accurate, timely, and audit-ready log management and incident traceability.

In this article, we address the points where cybersecurity legislation in Türkiye intersects with SIEM point by point, along with their sanctions, and analyze why a local SIEM makes a practical difference in meeting these obligations.

Cybersecurity Law No. 7545: Scope and Organizational Structure

Published in the Official Gazette and entering into force on March 19, 2025, Cybersecurity Law No. 7545 serves as the first comprehensive legal framework regulating the field of cybersecurity in Türkiye. The scope of the Law is kept quite broad: public institutions and organizations that provide services or process data via information systems, professional organizations with public institution status, real and legal persons, and entities without legal personality directly fall within the scope of the law. This means that not only government offices, but also a broad range of the private sector operating in the digital environment are subject to regulation.

The Cyber Security Authority (Siber Güvenlik Başkanlığı) established by the Law is equipped with broad powers such as determining national cybersecurity policies, detecting threats, managing the Computer Security Incident Response Team (CSIRT / SOME) structure, and increasing the level of security for critical infrastructures. The Authority also holds the authorization to conduct audits on critical infrastructures, authorize independent auditors, and perform search and seizure procedures when necessary—under a judge's order or with prosecutor approval in cases where delay is harmful.

Three Obligations of the Law Directly Concerning SIEM

  • 1. Requirement to use authorized suppliers: Critical infrastructure institutions and companies are obliged to procure cybersecurity products and services only from providers authorized by the Authority. This provision directly affects the procurement process of all security products, including SIEM; in the preamble of the law, it is specifically stated that this article should be interpreted as the necessity of preferring domestic and national products among those with similar features and capacity.
  • 2. Mandatory incident notification: Institutions providing services over information systems have an obligation to report cybersecurity vulnerabilities and incidents to the Authority. Making this notification in a timely, accurate, and provable manner without a SIEM is extremely difficult; because at the core of the notification lies the ability to answer questions such as "when did the incident start, which systems did it affect, which data was at risk" with log-based, time-stamped evidence.
  • 3. Cooperation obligation in audits: Auditors of the Authority have the power to request access to physical or digital environments; the audited party is obliged to provide this access. Without a centralized SIEM, presenting logs scattered across different systems in a meaningful and consistent manner during an audit becomes a serious operational burden.

Sanctions: How Serious Are the Numbers?

The deterrence dimension of the Law is heavier than many organizations anticipate. In case of failure to provide cooperation during an audit, an administrative fine of up to five percent of the annual gross sales revenue certified by an independent audit may be imposed. In cases of non-compliance with specific obligations, administrative fines can range from 1 million TRY to 100 million TRY. If a benefit is obtained or damage is caused due to the commission of the misdemeanor, the fine can rise up to three to five times this benefit or damage.

Penal provisions are also too significant to ignore: prison sentences are foreseen for acts such as intentional data leaks or unauthorized access; violation of confidentiality obligations, unauthorized sharing or offering for sale of data within the scope of personal or critical public services, and spreading false cybersecurity data are also subject to imprisonment. In cybersecurity incidents that are not reported, sanctions such as disciplinary action and license cancellation may come to the fore alongside administrative fines.

This picture clearly demonstrates that this is not an area where organizations can maintain an approach of "let the fine come first, we will fix it later."

Key Takeaway — Law No. 7545 Severity

Law No. 7545 imposes administrative fines up to 5% of gross revenue or up to 100 Million TRY for non-compliance, alongside criminal liability for unauthorized data exposure. Centralized SIEM logging provides the timestamped evidence required to avoid these severe penalties.


KVKK and SIEM: Log Data is at the Center of the 72-Hour Race

Another regulation as critical as Law No. 7545 is the Personal Data Protection Law No. 6698 (KVKK). Paragraph five of Article 12 of the Law stipulates that in the event personal data is obtained by others through unlawful means, the data controller shall notify the data subject and the Board as soon as possible. By the decision of the Personal Data Protection Board dated January 24, 2019, and numbered 2019/10, this period has been concrete framework set to 72 hours.

This 72-hour window, while simple in theory, is practically one of the toughest tests for a SOC team. Examples from Board decisions highlight this point strikingly: In decision 2020/715, an e-commerce company detected an account takeover attack on the same day and reported it to the Board within three days, which was found appropriate in terms of notification timeframe; however, it was hit with an administrative fine of 165,000 TRY due to the lack of a mechanism limiting failed login attempts prior to the attack and an adequate web application firewall. In decision 2020/905, an insurance company received a fine of 300,000 TRY for not having conducted its annual penetration testing and leaving a test server open to the internet, plus an additional 30,000 TRY for not fully complying with the notification timeframe, totaling 330,000 TRY in fines.

Both examples demonstrate the same reality: The core question asked by the Board is not merely "Did you notify within 72 hours?", but "Did you have a monitoring infrastructure capable of detecting and proving the breach in real-time?" Without a SIEM, it becomes difficult for an organization to legally defend even "when it learned of the breach"; because what documents the moment of detection is mostly the alarm log generated by the correlation engine itself.

Furthermore, KVKK's cross-border data transfer regime directly impacts SIEM selection. According to the official guide of the Personal Data Protection Authority, transferring data to a country without an adequacy decision is only possible through additional safeguard mechanisms such as standard contracts, binding corporate rules, or Board-approved commitments. Since log data is voluminous and flows continuously, establishing these safeguard mechanisms separately for every cross-border SIEM integration represents a burden that is entirely unneeded in a local solution, as the data stays in Türkiye from the outset.

Sectoral Regulations: BDDK and SPK's Indirect Mandate for SIEM

On top of the general legislation comes a sectoral layer. The Banking Regulation and Supervision Agency's (BDDK) Regulation on Information Systems of Banks and Electronic Banking Services determines the minimum procedures and principles to be taken as a basis in managing information systems risks of banks. The regulation contains explicit provisions regarding the transmission and security of personal and sensitive data, the retention of records regarding queries made to this data, and the restriction of cross-border transfers. In practice, these provisions are requirements that banks cannot meet without a centralized log management and correlation system.

The Capital Markets Board's (SPK) Communiqué on Information Systems Management moves along a similar line; it mandates that time information used in the information systems of institutions, entities, and partnerships be synchronized according to a single reference source and obtained via atomic clocks. The Information and Communications Security Guide of the Presidential Digital Transformation Office similarly foresees that all network-connected systems (servers, workstations, security products, network devices) use regular and synchronized time information. This is actually a direct regulatory equivalent of timestamped, integrity-protected log collection—which is already one of the core functions of SIEMs.

In other critical sectors such as energy and telecommunications, secondary legislation from EPDK and BTK similarly introduces continuous monitoring, event logging, and reporting obligations. The common denominator of these sector-specific regulations is not "the existence of the log," but that "the log is accurate, complete, and accessible in a timely manner."

Law No. 5651: Impact of Log Retention Periods on SIEM Architecture

Although Law No. 5651 was enacted to regulate publications made on the Internet, it is a regulation that directly shapes SIEM architecture in terms of log retention periods. According to paragraph two of Article 5 of the Law, hosting providers are obliged to retain traffic information regarding the services they provide for the period specified in the regulation—not less than one year and not more than two years—and to ensure the accuracy, integrity, and confidentiality of this information. For access providers, this period ranges between six months and two years. In case records are not kept, administrative fines from ten thousand TRY to one hundred thousand TRY can be applied.

At this point, organizations face a two-way pressure: While Law No. 5651 mandates keeping logs for a certain period, one of KVKK's core principles—the principle of "purpose limitation and proportionality"—requires that data no longer serving a purpose should not be retained unnecessarily, and expired records should be securely destroyed. Balancing these two obligations simultaneously with manually managed, scattered log files is practically almost impossible. SIEM platforms, precisely at this point, make it possible to meet both legislations simultaneously by automating retention policies—both guaranteeing the legal minimum duration and systematically destroying expired data.

Why Does Local SIEM Make a Difference in Meeting These Obligations?

All obligations listed up to this point are actually technology-agnostic; meaning theoretically they can be met with any SIEM. However, in practice, there are several concrete points that highlight local SIEM:

  • Default configuration shaped around local legislation: Domestic vendors can design correlation rules and reporting templates directly referencing Law No. 7545, KVKK, and BDDK/SPK communiqués; in a global product, this customization must be performed by the organization itself or an integrator.
  • Local support line accelerating the 72-hour notification process: In a process where hours are critical during a data breach, proceeding with a support team working in the same time zone and language directly affects the speed of accurately determining the scope of the breach and preparing the notification text.
  • Simplification brought by data localization: Since log data remains in Türkiye from the start, there is no need to separately establish KVKK's cross-border transfer safeguard mechanisms (standard contracts, undertakings, etc.) specifically for SIEM integration.
  • Audit-ready reporting: Being able to generate reports in the format and speed requested during audits by the Authority, BDDK, SPK, or KVKK is directly related to local vendors' familiarity with local audit practices.

Practical Compliance Steps for Organizations

To avoid getting lost in regulatory complexity, concrete steps that organizations can take can be summarized as follows:

  • Taking inventory: Inventory existing log sources and retention periods; clarify which law (5651, KVKK, sectoral communiqués) foresees how much retention time for which data.
  • Supplier confirmation: If holding critical infrastructure status, follow the authorized supplier list published by the Cyber Security Authority and confirm the SIEM vendor's compliance with this list.
  • Drills: Regularly test the data breach response plan through tabletop exercises in a way that actually tests the 72-hour notification process.
  • Automated disposal policy: Establish a policy ensuring automatic and secure destruction of logs whose retention period has expired; do not leave this to manual processes.
  • Up-to-date tracking: Regularly reflect current communiqués and guides of sectoral regulators (BDDK, SPK, EPDK, BTK) into SIEM correlation and reporting rules.

Conclusion: Regulatory Compliance is Now at the Center of SIEM Selection

The four regulations discussed in this article—Cybersecurity Law No. 7545, KVKK's notification regime, BDDK and SPK's sectoral communiqués, and Law No. 5651's log retention mandates—although enacted for different reasons and on different dates, all intersect at the same operational question: During an audit or a data breach, can your organization present the right log, at the right time, in a provable manner?

The answer to this question cannot be given with manually managed, scattered log files; but rather with a centralized, timestamped, and audit-ready log management infrastructure. This is precisely where local SIEM stands out: Beyond being merely a choice of "national technology", it becomes an operational decision that combines Law No. 7545's authorized supplier requirement, KVKK's data localization pressure, and sectoral audit readiness in a single investment.

Frequently Asked Questions

Which organizations are required to use SIEM under Law No. 7545?

The Law does not contain an explicit article directly titled "obligation to use SIEM"; however, the obligations imposed on critical infrastructure providers to take measures, report incidents, and cooperate in audits cannot practically be fulfilled without a centralized log management and correlation system. Therefore, SIEM becomes de facto mandatory for organizations in critical infrastructure status.

When exactly does KVKK's 72-hour notification period begin?

The period runs not from the moment the breach is definitively proven, but from the moment reasonable suspicion arises—that is, when the breach is learned. For this reason, an approach of "waiting until the log analysis is completed" carries the risk of missing the notification deadline.

Do the retention periods of Law No. 5651 and KVKK conflict?

They do not conflict, but they need to be balanced. While Law No. 5651 sets a minimum-maximum retention range, KVKK requires the destruction of data whose retention period has expired and no longer serves a purpose. The practical way to manage both together is to establish a log management system that automates retention and disposal policies.

Do BDDK and SPK regulations concern only large banks?

No. BDDK's information systems regulation covers all banks and institutions offering electronic banking services; SPK's communiqué includes a broad section of institutions, entities, and partnerships. Although audit frequency varies as scale decreases, core obligations remain valid.

References

in News
Cybersecurity Legislation in Türkiye and Local SIEM
İsmail İşler August 7, 2026
Share this post
Our blogs