National Cybersecurity Strategy and Action Plan (2024–2028): Shaping Turkey’s Cyber Future
In today’s rapidly increasing digitalization, the concept of cybersecurity has become one of the most critical components of national…
National Cybersecurity Strategy and Action Plan (2024–2028): Shaping Turkey’s Cyber Future
In today’s rapidly increasing digitalization, the concept of cybersecurity has become one of the most critical components of national security. We all know that Turkey’s ability to maintain a strong stance in the field of cybersecurity depends on adopting a strategic approach. The Presidential Decree on the National Cybersecurity Strategy and Action Plan (2024–2028) was recently published in the Official Gazette. Accordingly, the NCSAP (2024–2028) aims to enhance Turkey’s resilience against cyber threats and sets forth its ambition to become a global leader in this field. In this article, I will humbly attempt to summarize Turkey’s cybersecurity vision by reviewing the goals, objectives, and concrete action plans outlined in this strategy, as made publicly available.

Taken from the Cover of the National Cybersecurity Strategy and Action Plan (2024–2028)
Strategic Goals
The strategic goals set out in the NCSAP (2024–2028) aim to define Turkey’s vision and objectives in the field of cybersecurity and guide efforts in this area. These strategic goals are grouped under six main headings aimed at contributing to the security and sustainability of national cybersecurity:
- Cyber Resilience: This goal aims to protect critical infrastructures, particularly information and communication technology infrastructures, against increasing cyber threats. Approaches such as risk-based analysis and emergency planning will be applied to enhance the resilience of institutions and critical infrastructures against cyber threats.
- Proactive Cyber Defense and Deterrence: This heading embraces a proactive cyber defense approach aimed at detecting and preventing threats before they occur. The goal is to strengthen defense against cyber threat actors and attacks, while enhancing cyber deterrence.
- Human-Centered Cybersecurity Approach: The critical importance of the human element in cybersecurity is emphasized, with a focus on reducing human-caused vulnerabilities through awareness-raising programs and training. The goal is to train and enhance the competencies of cybersecurity experts.
- Safe Use of Technology and Contribution to Cybersecurity: This goal aims to ensure the secure use of emerging technologies such as artificial intelligence, big data, and blockchain, while also adopting a “zero trust” approach to security measures against these technologies.
- Combating Cyber Threats with National and Indigenous Technologies: This goal focuses on developing and expanding the use of national and indigenous cybersecurity technologies. The strategy aims to reduce dependency on foreign technologies and build a stronger defense against cyber threats using local products and solutions.
- International Brand of Turkey in Cybersecurity: This goal seeks to increase Turkey’s international collaboration in cybersecurity and promote its expertise on a regional and global level. It aims to strengthen Turkey’s position as a prominent player in cybersecurity worldwide.
Objectives
Another major section of the NCSAP (2024–2028) is the objectives, which outline specific targets to achieve the strategic goals. These objectives play a crucial role in the success of Turkey’s cybersecurity policies by concretizing the steps needed to be taken. Let’s review the 18 objectives that are directly related to the strategic goals:
1- Cyber Resilience
- O1.1: Developing regulatory and oversight-based cybersecurity approaches in public institutions and critical infrastructure sectors.
- O1.2: Adopting a cybersecurity approach based on risk-based analysis and emergency planning at institutional, sectoral, and national levels.
- O1.3: Ensuring secure data sharing through secure infrastructures.
- O1.4: Developing national standardization and testing mechanisms.
2- Proactive Cyber Defense and Deterrence
- O2.1: Increasing the competency levels of cyber incident response teams.
- O2.2: Enhancing capabilities for detecting and reporting cyber risks, threats, and sharing cyber threat intelligence.
- O2.3: Increasing best practices in institutions and organizations for mitigating risks and threats.
- O2.4: Enhancing coordination regarding national cybersecurity as part of national security.
- O2.5: Improving gains in the fight against cybercrime.
3- Human-Centered Cybersecurity Approach
- O3.1: Raising individual and societal cyber awareness.
- O3.2: Establishing a corporate cybersecurity culture in institutions and organizations.
- O3.3: Strengthening and enhancing the competence of human resources in the field of cybersecurity.
4- Safe Use of Technology and Contribution to Cybersecurity
- O4.1: Ensuring the safe use of emerging technologies and taking preventive measures against potential risks.
- O4.2: Increasing the use of emerging technologies in cybersecurity efforts.
5- Combating Cyber Threats with National and Indigenous Technologies
- O5.1: Transforming innovative ideas into national and indigenous products and services.
- O5.2: Supporting R&D activities and promoting the development and dissemination of indigenous cybersecurity technologies.
6- International Brand of Turkey in Cybersecurity
- O6.1: Increasing information sharing and collaboration with international stakeholders.
- O6.2: Enhancing the global competitiveness of national and indigenous cybersecurity solutions.
Action Items
This section defines the concrete steps to be taken to achieve the strategic goals outlined in the NCSAP (2024–2028). These actions include the tasks to be carried out to achieve the objectives, as well as the responsibilities of the designated institutions. There are a total of 61 action items, which will guide cybersecurity efforts in line with the strategic goals.
The structure of the action items covers the activities planned under the strategic goals. Each action item includes responsible institutions, collaborating institutions, and deadlines. While the action items are classified as Confidential, we can extract an overview of the items from the table linking the objectives with the action items in NCSAP (2024–2028).
Summary of Action Items
- E1-E19: These action items aim to increase cyber resilience. Measures will be taken to protect critical infrastructures, risk-based analyses will be conducted, and secure data-sharing infrastructures will be established. Developing national cybersecurity standardization and testing mechanisms are also included in these actions.
- E20-E30: These items focus on strengthening proactive cyber defense and deterrence, aiming to increase the competence of cyber incident response teams, improve threat intelligence, and enhance defense capacity against cyber attacks. Systems will be established to detect and report cyber threats, and significant steps will be taken in the fight against cybercrime.
- E31-E37: These actions aim to enhance a human-centered cybersecurity approach, focusing on raising individual and societal awareness. A corporate cybersecurity culture will be established in institutions, and the competence of human resources in the field of cybersecurity will be improved through training, awareness campaigns, and knowledge development efforts.
- E38-E42: These items relate to the secure use of technology, where necessary measures will be taken to ensure the safe use of new technologies, and the contributions of technological advancements to cybersecurity will be evaluated. This includes the secure integration of emerging technologies such as AI, big data, and blockchain.
- E43-E49: These actions aim to combat cyber threats using national and indigenous technologies. R&D activities will be supported to transform innovative ideas into national and indigenous products and services. These actions promote the development and use of indigenous cybersecurity technologies in critical infrastructures.
- E50-E61: These items focus on enhancing international collaboration and positioning Turkey as a brand in cybersecurity. Turkey’s visibility in international platforms will be increased, the global competitiveness of indigenous cybersecurity products will be enhanced, and cyber diplomacy will be developed to facilitate information sharing.
Performance criteria established for the implementation of action plans will be monitored, and the activities carried out by responsible institutions will be reported periodically. The Ministry of Transport and Infrastructure will play a central role in monitoring and evaluating these efforts, coordinating the execution of the action items in collaboration with the relevant institutions.
Implementation Approach
This section details how the objectives and action items defined in the NCSAP (2024–2028) will be implemented and monitored. The approach ensures that the planned activities are carried out effectively and efficiently to achieve tangible gains in line with the strategic goals.
Monitoring and Evaluation
The action items in the action plan are designed to achieve national cybersecurity goals. To ensure the success of these efforts and their contribution to strategic objectives, continuous monitoring and evaluation processes will be implemented. The key elements of these processes include:
- Performance Criteria: Performance criteria for each action item will be considered, and the progress made in the respective areas will be evaluated. This allows for the tracking of tangible gains towards strategic goals.
- Reporting: The activities carried out and the progress made by the responsible institutions will be periodically reported. These reports will be used to assess whether the actions are successful. Based on the reports, deficiencies or areas needing improvement will be identified.
- Responsible Institutions: The institutions responsible for each action item, as well as the other stakeholders they will collaborate with, will be accountable for the implementation of the plan. The Ministry of Transport and Infrastructure will play a central role in monitoring and evaluation and will coordinate with relevant stakeholders to ensure the completion of the action items.
Stakeholder Participation
Cybersecurity efforts will be carried out with the participation of public institutions, the private sector, universities, and civil society organizations. These stakeholders will collaborate to achieve national cybersecurity goals and contribute to the strategic objectives. In addition, private sector actors operating in critical infrastructures and international stakeholders will play significant roles in the process.
Update and Continuity
Strategic goals and action items may be updated according to technological developments and national needs. Items that could not be completed during the strategy period will be reviewed in the monitoring and evaluation process and may be transferred to the next strategy plan if necessary. This approach ensures the continuity and relevance of the strategic goals, aiming for sustainable success in the field of cybersecurity.
Conclusion
The National Cybersecurity Strategy and Action Plan (2024–2028) outlines the critical steps for Turkey to achieve a strong and secure position in the digital world. This strategy aims to build a secure future by increasing national resilience against cyber threats and leveraging technological advancements in a safe and effective manner.
Source: National Cybersecurity Strategy and Action Plan (2024–2028) https://www.uab.gov.tr/uploads/pages/siber-guvenligin-yol-haritasi-yerli-ve-milli-tekno/ulusal-siber-guvenlik-stratejisi
메타데이터
- post_id
- cbd0585d65d2
- slug
- national-cybersecurity-strategy-and-action-plan-2024-2028-shaping-turkeys-cyber-future-cbd0585d65d2
- url
- https://medium.com/@spaksu/national-cybersecurity-strategy-and-action-plan-2024-2028-shaping-turkeys-cyber-future-cbd0585d65d2
- canonical_url
- https://medium.com/@spaksu/national-cybersecurity-strategy-and-action-plan-2024-2028-shaping-turkeys-cyber-future-cbd0585d65d2
- author_url
- https://medium.com/@spaksu
- status
- ok
- fetched_at
- 2026-07-31 12:13:25