Actualités & Publications

blog-post
AUG 24, 2026

Cyberattacks Against Companies: The Notification Obligation and Administrative Fine Exposure Under Turkish Law

Introduction

Cyberattacks have become an increasingly common risk for businesses operating in Türkiye. These incidents may result in unauthorised access to information systems, compromised corporate accounts, deleted or altered data, ransomware-encrypted systems, and inaccessible servers or network infrastructure. However, a cyberattack against a company in Türkiye may also trigger significant legal obligations. In particular, failure to notify the competent authority of a cybersecurity incident may expose companies to administrative fines of up to TRY 10,000,000.

Turkish Cybersecurity Law No. 7545 (the “Law”), which entered into force on 19 March 2025, requires persons providing services through information systems, collecting or processing data, or carrying out similar activities to notify the Cybersecurity Presidency (the “Presidency”) of identified cybersecurity incidents and vulnerabilities without delay.

In practice, the time between an incident being detected by a company’s information technology (“IT”) department and its escalation to management may be extended by internal reporting procedures, organisational structures or the IT team’s immediate focus on containing the attack. For international businesses, coordination with overseas headquarters or external service providers may also cause additional delays. Accordingly, responding to a cyberattack requires more than restoring the affected systems. Companies must also promptly assess their legal obligations and, where required, notify the Presidency.

Scope of the Notification Obligation

Under the Law, persons providing services through information systems, collecting or processing data, or carrying out similar activities must notify the Presidency without delay of cybersecurity incidents or vulnerabilities identified in connection with the services they provide. The Law defines a cybersecurity incident as a breach of the confidentiality, integrity or availability of information systems or data. Accordingly, unauthorised access to company systems, compromised corporate accounts, deleted or altered data, ransomware attacks and disruptions to digital services may trigger a notification obligation. The obligation is not limited to cyberattacks that have already occurred. Security vulnerabilities identified within the relevant service environment may also require notification, depending on their nature, associated risks and potential impact.

Timing and Procedure for Notification

The Law does not prescribe a specific notification deadline expressed in hours or days. Instead, it requires relevant cybersecurity incidents and vulnerabilities to be reported to the Presidency “without delay”. This means that the company should complete its preliminary assessment as soon as reasonably practicable after detecting the incident and should not postpone notification without a valid reason. The fact that the source of the attack has not yet been identified, the resulting losses have not been fully quantified, or the technical investigation remains ongoing will not, in itself, justify delaying notification. Internal approval processes or coordination with overseas headquarters should likewise be managed in a manner that does not result in undue delay. The notification should be submitted to the Presidency in a manner that allows its timing and content to be documented. Where available, it should include the date and time of detection, the affected systems, the actual or potential impact of the incident and the initial security measures taken.

Records and Documents to Be Preserved

Following a cybersecurity incident, the Presidency may request information and documents concerning the source of the attack, how it occurred, the affected systems and the security measures implemented. Companies should therefore preserve relevant server, firewall, network traffic and user access logs, together with source and destination IP addresses, suspicious session records, malware findings and technical investigation reports. Evidence of security measures implemented before the incident may also be relevant. Such measures may include access controls, firewalls, multi-factor authentication, regular backups, system updates and vulnerability monitoring. Maintaining these records may assist companies in responding to requests from the Presidency and demonstrating that appropriate security measures were in place before the incident.

Administrative Fine Exposure

Failure to notify the Presidency of a reportable cybersecurity incident or vulnerability, or an unjustified delay in doing so, may expose companies to significant administrative fines. The Law provides for an administrative fine ranging from TRY 1,000,000 to TRY 10,000,000 for failure to comply with the notification obligation. Accordingly, a cyberattack may result not only in operational disruption and financial losses but also in substantial regulatory exposure if the associated notification requirements are not properly addressed.

Anaylsis

As company records, customer information and commercial data are increasingly maintained in digital environments, cyberattacks have become a material risk for businesses of all sizes. For companies operating in Türkiye, an effective response requires more than technical containment and restoration of affected systems. The incident should also be promptly escalated to management, assessed from a legal perspective and, where required, reported to the Presidency. Timely notification and proper preservation of relevant records are therefore essential to reducing administrative fine exposure. Where the incident also results in a personal data breach, additional obligations under Turkish data protection legislation should be assessed separately.

For any questions on this topic, please feel free to get in touch with our team.

The above information reflects the general assessments of YılmazÜlker Attorney Partnership ("YılmazÜlker") regarding the subject matter and does not constitute legal opinion or legal consultancy services. Before taking any action based on the matters stated herein, it is recommended to seek professional legal advice by considering the specific circumstances of the case. YılmazÜlker shall not be held liable for any consequences arising from or in connection with the content of this document.