With internet access integrated into every aspect of our lives, network security and legal audits have become one of the most critical responsibilities of corporate structures. Law No. 5651, which determines the legal framework of this process in Turkey, ensures that internet access is provided in a more controlled, secure, and transparent manner.
This law aims to prevent cybercrimes that can be committed through online systems, to protect innocent users by identifying the culprit in the event of a cyberattack, and to block access to harmful content.
It should not be forgotten that the articles of Law No. 5651 are not mere recommendations, but mandatory legal requirements.
Who is Covered by Law No. 5651?
The law covers every institution and organization that provides internet access over a network connection to multiple users, regardless of whether it is paid or free. The law fundamentally divides these providers into two categories:
1. Those Providing Internet to Serve Visitors and Employees: Institutions providing internet access to ensure business continuity and serve their guests fall under this scope:
- Shopping Malls
- Schools and Universities
- Public Institutions and Organizations
- Hospitals
- Private Companies and Corporate Plazas
2. Those Providing Internet Access for Commercial Gain: Businesses that offer internet connection directly as a service or for a fee:
- Hotels and Accommodation Facilities
- Internet Cafes
- Restaurants and cafes offering paid Wi-Fi services
What are the General Obligations of Law No. 5651?
Under the law, the primary obligations that institutions providing internet access must fulfill are as follows:
- Content Filtering: Blocking user access to illegal, harmful, or criminal websites.
- Time-Stamped Logging: Recording access logs in the system immutably with a date and time stamp.
- Internal IP Logging: Recording the MAC and internal IP address matches of users connecting to the network.
- External Access Records: Securely storing external access records (logs) to the institution's website and servers.
What are the Penalties for Non-Compliance?
Businesses must store records of who used the network services they provide and at what times retroactively (between 6 months and 2 years). In case of partial or complete violation of the law's requirements, serious sanctions are applied:
- Administrative Fines: Fines applied to individuals or institutions start from 15,000 TL and can go up to 100,000 TL for service providers.
- Administrative Sanctions: Severe administrative penalties such as warnings, temporary suspension of business activities, access blocking, or closure of the business may be applied.
Law No. 5651 and Log Correlation (SIEM) Solutions with Oriana
Law No. 5651 mandates user authentication via a special interface (Hotspot) to identify users connecting to your network. However, modern cybersecurity and corporate logging needs are not limited to this alone.
As Oriana.tech, we go beyond standard logging and offer SIEM (Security Information and Event Management) solutions that make sense of all the data generated by your IT systems.
Why Should You Use SIEM Instead of Classic Logging?
Raw logs alone may not be sufficient for detecting cyberattacks and in digital forensic processes. With our professional SIEM solutions:
- Correlation Capability: You can detect potential cyberattacks in advance by establishing meaningful connections between seemingly independent system logs.
- Advanced Analysis: You can see through which channels, when, with which protocols, and where the attack started within seconds.
- Instant Alerting and Reporting: You gain the ability to deduplicate logs, perform fast searches, generate instant alarms based on predefined security rules, and create legally compliant reports.
Oriana ensures that your organization can seamlessly collect logs from all environments and instantly identify the source of the incident and the associated devices in emergency situations.