Information Security

Data Privacy and Cybersecurity

Our Corporate Cybersecurity Approach and Services

As Türk Telekom, we manage customer personal data privacy and cybersecurity to the highest standards, ensuring full compliance with European Union’s GDPR, Turkish Personal Data Protection Law No. 6698, and regulations of the Information and Communication Technologies Authority, as well as national and international legislation. We protect personal data within an end-to-end security architecture and effectively manage cybersecurity incidents with data classification systems, encryption technologies, access control mechanisms, data loss prevention solutions, AI-powered breach detection systems, and 24/7 automated alarm mechanisms. We create policies and privacy notices, data breach response plans, personal data agreements, data inventory and disposal processes, requesting explicit consent from our customers when necessary.

We implement our information security policies, shaped by the ISO 27001 Information Security Management System, to cover both fixed and mobile networks. We also fully comply with the NIST Cybersecurity Framework, which provides global standards. We comply with these standards, particularly to ensure the security of payment transactions, with our PCI DSS Certification for mobile and broadband networks. We also offer and implement a supply chain security approach as standard for all our business partners and subsidiaries. We protect all data using advanced encryption techniques during transmission and while it is at rest. To protect the privacy of personal data, we implement strict access controls against access by anyone other than authorized employee through our “Zero Trust” approach and advanced identity management infrastructure, and we activate automatic security measures against the uncontrolled removal or leakage of data outside the company.

We have established PDPL Senior Committee and Sub-committees by board resolution to enable the management-level evaluation of processes related to personal data compliance within our company. These committees carry out compliance activities for our group companies that require alignment with the GDPR legislation as the Türk Telekom Group. We conduct Information Security Internal Audit activities regularly every year, and periodically perform penetration tests, source code analysis, secure software development (DevSecOps), (within the scope of SDLC), and vulnerability assessments. We share the findings and reports of the tests we conduct on the critical system inventory with senior management at the beginning of each month. We carry out all our processes in compliance with the Cybersecurity Law and the Information and Communication Security Guide of the Presidency Digital Transformation Office.

Our Security Approach and Practices

As Türk Telekom, we maximize system security by adopting a multi-layered cybersecurity strategy. To ensure the security of remote working processes, we implement Zero Trust Network Access (ZTNA), Virtual Private Networks (VPN), Privileged Access Management (PAM), Multi-Factor Authentication (MFA), and periodic security audits.

The Data Leakage Prevention (DLP) solution, one of the advanced security measures on end-user devices, prevents sensitive data from being taken outside the company without authorization, in accordance with the company policies. The DLP solution works actively not only within the company network but also on external networks such as home networks. Working at the operating system level, DLP agents prevent data leaks by identifying sensitive data that is intended to be taken out of the device. With our data classification solutions, we also categorize our critical data and track it.

The AI-powered systems and behavioural anomaly detection architecture enable us to detect and intervene in potential threats in advance. By detecting thousands of phishing, DDoS, and malware attacks every month through our telecom infrastructure, we provide effective protection against attacks exceeding 1 Gbps, which are classified within the critical attack category as of 2025. As Türkiye’s leading cybersecurity service provider, we offer more than 50 cybersecurity services at our cybersecurity centres in Istanbul and Ankara, covering all security needs of corporate customers within our extensive service portfolio. These services include comprehensive solutions such as incident response, digital forensics, cybersecurity maturity assessment audits, and workforce analysis. We also carry out regular security checks, including implementing antivirus solutions and removing outdated security policies.

We adopt an AI-based and fully automated proactive approach to identify and manage cybersecurity risks. Through Cybersecurity Committee meetings, we evaluate new regulations, threat intelligence developments, and zero-day vulnerabilities. We take the necessary precautions by strengthening security in cybersecurity systems and technical infrastructure, and we accelerate patch management processes.

Within the Company, Information Security Incident Management is managed by the Cyber Incident Response Team (SOME) in accordance with the Information Security Incident Tracking Procedure. All detected incidents are tracked using the Incident Response Form, and the latest technologies are used to prevent and detect data breaches. We evaluate detected breach incidents within the scope of Türk Telekom Information Security Policies and Procedures, and share them with the Ethics Committee, National Cyber Incident Response Centre, and relevant regulatory authorities when necessary.

Furthermore, in accordance with ISO 27001 and PCI DSS standards, we regularly provide information security awareness training to our employees. We organize these training sessions at regular intervals as part of our internal audits and ensure that all our employees are aware of current cyber threats. In addition, we include third-party business partners and suppliers in our security awareness Programmes, minimizing external risks. We provide training to increase our employees’ knowledge and awareness of information security. In 2025, Information Security Regulatory Compliance Training was assigned to 17,288 people, 14,107 people completed it, and the completion rate was 82%. Information Security and Awareness Training was assigned to 17,288 people, completed by 14,552 people, with a completion rate of 84%.

As of 2025, our cyber incident response teams have directly and automatically responded to a total of 87,155 incidents, producing effective solutions against a 489% increase in cyberattacks. Through our 24/7 Cybersecurity Centre, we continuously improve our incident monitoring, testing, response, training, and consulting services; we continue to strengthen the security architectures of organizations and maintain our position as a globally respected service provider.

Our Corporate Security Approach in Customer Privacy

We place cybersecurity at the forefront of our priorities in the digital ecosystem. With a broad cybersecurity portfolio comprising over 50 products and services for nearly 5 thousand organizations, we support the customer experience with maximum continuity and operational efficiency.

We are also committed to customer privacy in targeted advertising systems. We anonymised customer identities using Unique IDs without sharing customer mobile subscriber information (MSISDN) with advertisers. This way, advertisers only see Unique IDs. We carefully evaluate advertising categories and block ads in categories deemed risky. We only show ads to customers who have given permission for digital data processing.

As a company prioritizing public health, we ensure that the electromagnetic field intensity at our base stations remains below the limits set by the Information and Communication Technologies Authority.

These limits are based on the threshold values adopted by the World Health Organization and determined by the International Commission on Non-Ionizing Radiation Protection, and are applied at lower levels in accordance with the precautionary principle.

Our International Integrations and Collaborations

We reinforce our global credibility through our international integrations and accreditations. According to IDC reports, we have maintained our market leadership position for the past five years and hold the distinction of being the first and only Turkish company accredited in three different categories under CREST. Furthermore, The Company, which gained membership in FIRST (Forum of Incident Response Teams) in 2024, operates as the only service provider accredited by the Global Computer Emergency Response Team (TF/CERT) and the Turkish Standards Institute (TSE).

Our Advanced Technology Solutions

In line with developments in cloud computing, artificial intelligence, automation, and mobility, we offer advanced technological security solutions by transitioning to the Next-Generation Security Operations Centre (NextGen SOC) concept. Our solutions in this field include:

• EDR – Endpoint Detection and Response

• XDR – Extended Detection and Response

• MDR – Managed Detection and Response

• SOAR – Security Orchestration, Automation, and Response

• CTI – Cyber Threat Intelligence

• IR – Incident Response

• ASM – Attack Surface Management and Detection Engineering

• Shared SIEM - Security information and event management (centralized logging systems and incident monitoring infrastructure)

• DLP - Data Loss Prevention (Data Security and Integrity)

• Cloud-based security services

In 2025, we doubled our L3/L4 DDoS protection capacity with additional investments. With our AI-powered DDoS analysis infrastructure, we provided effective protection against a total of 2,825 DDoS attacks of 1 Gbps and above in 2025. In addition, we increased capacity and carried modernisation activities across inline DDoS7+, next-generation firewalls, Web Application Firewalls (WAF), VPN, and Network Access Control (NAC) infrastructures. We also automated processes by investing in attack surface analysis.

Focusing on efficiency and sustainability in our cybersecurity operations, we continued automation efforts across many of our services. This enabled us to achieve an operational structure that can respond rapidly to today’s complex attack types, minimize human error, and easily handle very large-scale operations, both within Türk Telekom and in the services we provide to our customers. Furthermore, we continue to develop technologies such as API Security, Zero Trust Network Access (ZTNA), Operational Technology (OT) and IoT Security, Private Cloud (Enterprise DDoS Cloud Services), and Secure Access Service Edge (SASE) that we have introduced to our company.

As part of our Development Hub Programmes in the fields of cybersecurity and cloud computing, we organized two separate camps in 2025. From the 1,350 applicants in 2024, we selected 32 finalists, hiring 14 as interns and 2 fulltime employees, thereby contributing to the development of qualified talent in the sector. Through these Programmes, we supported participants in developing their technical skills and adaptability to innovation.

We Have Been the Leader in Türkiye’s Cybersecurity Sector for 5 Consecutive Years

As the leading service provider with global and local accreditations in cybersecurity, we offer a comprehensive security approach covering network, application, endpoint, data security, and consulting services. With our product and service enrichment approach and investments in new-generation technology, we have added self-learning AI-based solutions to our portfolio, enabling us to deliver faster and more agile services in incident management, endpoint incident detection and response, and intelligence.

With the first telco SASE infrastructure we launched in 2025, we have started offering enduser security, identity, and access management solutions across different verticals in line with remote working models.