INFORMATION SECURITY INVESTMENTS

Zero risk in data, limitless trust in trade

Viewing the confidentiality of customer data as its most valuable asset, Türk Ticaret Bankası balances the pace of digitalization with its uncompromising security standards.

Secure and Innovative Solutions Centered on Digitalization

While offering digital and innovative solutions to its customers in line with its strategic goals, Türk Ticaret Bankası considers ensuring the confidentiality, integrity, and availability of customer information and corporate data at the highest level to be a fundamental priority. With its competent, experienced, and development-oriented staff, the Bank undertook comprehensive initiatives in 2025 within the framework of its Information Security policies.

Information Security Governance and Architecture

Throughout the 2025 operating period, information security governance and architecture processes were matured by considering industry standards, the evolving threat landscape, and regulatory requirements, establishing a security architecture aligned with the Bank’s strategic goals.

The “Information Security Standards Document,” which covers the fundamental security requirements to be applied across the Bank, was completed and put into effect. Following international standards, the CIS 8.1 (Critical Security Controls) assessment was completed, and areas for improvement in critical controls were identified and prioritized. To enhance data security, the Data Loss Prevention (DLP) system was switched to blocking mode; controls were strengthened by defining preventive rules against the risk of data leakage. Additionally, to increase the traceability of critical databases, the scope of the Database Activity Monitoring (DAM) infrastructure was expanded; rule sets and correlation logic were made more sensitive to suspicious query behaviors and high-risk transaction activities.

Phishing simulations and regular training were continued to increase corporate awareness. Significant competency was gained in preventing vulnerabilities at their source through the “Secure Code Development” training provided to software teams.

Furthermore, the expertise capacity of the information security organization was increased with the participation of experienced and competent experts; corporate knowledge was expanded through internal knowledge sharing, technical training, and certification efforts.

Information Security Risk Management

Risk management activities continued in 2025 with a focus on a risk-based approach, ensuring the proactive management of security risks for the Bank’s critical assets and business processes. Regular risk analyses were conducted on information assets, processes, and systems; identified risks were rated using an impact-probability methodology, and action plans were created.

As part of third-party risk management, risk assessments were conducted for suppliers and external service providers, and the security maturity levels of critical service providers were monitored. Risk mitigation activities were regularly monitored and presented to senior management through periodic reports.

Identity and Access Management

Throughout 2025, identity and access management (IAM) processes were restructured based on the “Zero Trust” architecture. A project was initiated to manage onboarding, position change, and offboarding processes across the Bank through full integration and end-to-end automation with Human Resources systems.

To secure privileged accounts that provide access to critical infrastructure components, the scope of the Privileged Access Management (PAM) infrastructure was expanded, and all administrative access was logged to maximize traceability. The use of Multi-Factor Authentication (MFA) was transformed into a risk-based and adaptive structure. Additionally, SSL/TLS certificates used in applications were migrated to the implemented “Centralized Certificate Management Platform,” eliminating the risk of outages.

Application Security and Vulnerability Management

As part of Application Security and Vulnerability Management efforts, comprehensive scans and tests were conducted to increase the Bank’s security maturity and proactively detect vulnerabilities. Periodic vulnerability scans were performed on all networks, operating systems, and applications, particularly critical systems; the level of hardening was increased through CIS compliance scans.

SSL/TLS certificates used in applications were migrated to the implemented “Centralized Certificate Management Platform,” eliminating the risk of outages.

INFORMATION SECURITY INVESTMENTS

A proactive approach to digital security

Comprehensive scans and tests were conducted to increase Türk Ticaret Bankası’s security maturity and proactively detect vulnerabilities.

Security controls were applied at every stage of the Software Development Life Cycle (SDLC). Code analyses were performed for critical applications using manual and static code analysis (SAST) tools; the secure transfer of the codebase to the production environment was ensured through security steps integrated into the CI/CD processes. In addition, container security scans were performed during deployments to the production environment. In line with BRSA regulations and risk-based prioritization, penetration tests for web and mobile applications were successfully completed following the OWASP methodology.

Cyber Incident Response Management and Reporting

To enhance its cybersecurity resilience, Türk Ticaret Bankası elevated its operational processes and incident response structure to a more mature level in 2025. To increase traceability, a “Log Gap Analysis” was carried out, and missing log sources were incorporated into the central system. Detection capabilities were enhanced by optimizing SIEM and SOC rule sets.

The effectiveness of cybersecurity response processes was validated through active attack simulations and playbook scenario tests. Rapid detection and blocking actions were implemented through SIEM/Firewall automation efforts.

Additionally, research was conducted on the concepts of “SEC FOR AI” (Security of AI Systems) and “AI FOR SEC” (Use of AI in Security Operations) regarding the use of artificial intelligence. In line with the goal of transitioning to an AI-assisted analyst structure in SOC operations, preliminary preparations for the “SOC AI Analyst” project have been completed.

Fraud Risk Management

To protect both itself and its customers from external fraud risks, Türk Ticaret Bankası completed the integration of fraud detection and prevention software and initiated real-time monitoring activities on its internet and mobile banking channels. The Bank has implemented mechanisms to generate instant alarms and halt suspicious transactions, thanks to its capabilities in real-time transaction monitoring, risk scoring, and rule-based scenario execution.

The Bank periodically conducts awareness campaigns for its employees and customers and regularly informs them about social engineering, phishing, and fraudulent phone call attempts.

Closely monitoring national and international fraud trends, Türk Ticaret Bankası continues to develop proactive prevention mechanisms based on this data.

General Assessment and Future Targets

Treating information security management as a constantly evolving discipline, Türk Ticaret Bankası has matured its security culture throughout the organization by strengthening its human resources and continuing awareness initiatives.

Türk Ticaret Bankası aims to maintain a management program that ensures the highest level of data security within a fully automated, fast, and accurate decision-making structure by integrating artificial intelligence and machine learning technologies, adhering to the “Zero Trust” principle of not admitting any resource into its information systems without verification.

INFORMATION SECURITY INVESTMENTS