USTKAB Reporting Guide: International Cyber Threat and Malicious Activity Notification

When a serious cyber incident hits an organization in Türkiye, patching internally and cleaning up the logs is no longer enough. Notification to the national coordination center has become mandatory. That center is USOM (the National Cyber Incident Response Center), and the mechanism operating under it is USTKAB (International Cyber Threat and Malicious Activity Notification).

In this guide we take a detailed look, from a digital forensics perspective, at what USTKAB is, which incidents must be reported, the threshold timelines, the notification format, and the consequences. To grasp the subject as a whole, let us first clarify the relevant legislation and the division of roles among the official authorities.

What USTKAB Is, and Its Relationship with USOM

USOM is the national CERT structure established in 2013 within the Information and Communication Technologies Authority (BTK). Operations are carried out through its official address at https://www.usom.gov.tr. USOM coordinates with the SOME teams (Sectoral and Corporate Incident Response Teams) in critical infrastructure sectors, and shares information with peer CERTs abroad and with the ENISA CSIRT Network.

USTKAB is the tip-off and intelligence flow channel within USOM. The full expansion of its name causes some confusion across the sector, but at its core it is simple: it is a platform for relaying observations to the center, such as cyberattacks originating abroad or extending abroad, malicious software, command-and-control servers, phishing campaigns, and state-sponsored APT activity. Not only the victim, but an observer can also file a notification. SOC teams sharing threat intelligence, MSSP firms, and academic researchers all use this channel.

USOM's legal basis is the "Regulation on the National Cyber Incident Response Center," dated 2013 and revised in 2020. Its scope of authority is issued by BTK. The point that is critical from a digital forensics standpoint is this: a notification submitted to USOM is treated as part of the chain of custody. For this reason, the timing and content of the notification must be kept meticulous. For the chain-of-custody side of the subject, you can refer to our digital forensics process pillar article.

Which Incidents Must Be Reported to USTKAB

In the legislation and USOM guidance, the types of incidents that exceed the notification threshold are grouped as follows:

1. Critical infrastructure attacks. Attacks that cause operational disruption in sectors such as energy, water, transportation, finance, healthcare, telecommunications, and public services. The Information and Communication Security Guide published by the Presidency's Digital Transformation Office (CBDDO) defines these sectors and imposes an even heavier notification obligation.

2. Ransomware incidents. System encryption, the combination of data theft and encryption (double extortion), and any incident involving a ransom note. We covered what must be done in the first 24 hours after a ransom event in a separate ransomware first 24 hours guide; the USTKAB notification is among the first three steps of that workflow.

3. Advanced persistent threats (APT). Long-running intrusion operations carried out by state-sponsored or organized threat groups. IOC (Indicator of Compromise) sharing is opened up via USOM to ENISA and friendly CERTs.

4. Data breach cases. Incidents in which personal data such as a user database, credit card details, or identity information has leaked. At this point, KVKK and USOM notifications are carried out in parallel; neither replaces the other.

5. Detection of command-and-control (C2) infrastructure. A SOC detecting, on its own network or in traffic it observes, a foreign C2 server, a malware distributor, or a domain hosting a phishing kit.

6. DDoS attacks. All volumetric attacks above 10 Gbps or that cause a service outage. Telecom operators already perform automatic reporting, and organizations can also file independently.

7. Supply chain breaches. Breaches arriving through software updates, libraries, or third-party integrations. Incidents of the SolarWinds and MOVEit type fall into this category.

Notification Threshold Timelines and the KVKK Difference

The most frequently confused topic here is the time thresholds. Three different pieces of legislation impose three different timelines, and each operates independently:

Incident Type Authority Timeline
Critical infrastructure incident USOM 3 hours
Normal cyber incident USOM 24 hours
Personal data breach KVKK 72 hours
EU citizen data (GDPR) Relevant EU DPA 72 hours

The 3-hour window for critical infrastructure operators is dramatically short. Waiting for the incident to be confirmed is not a luxury; a preliminary notification is filed and the details are completed afterward. For ordinary organizations the 24-hour rule applies, but as the impact of the incident grows, SOME and USOM in practice compress this window to between 6 and 12 hours.

KVKK's 72-hour notification form is entirely separate from USTKAB. Legal departments tend to confuse the two, so for the KVKK form process we recommend you also read our KVKK data breach notification guide. The USOM notification serves technical coordination, while the KVKK notification serves accountability toward the personal data subjects.

Law No. 5651, the Law on the Regulation of Publications on the Internet and Combating Crimes Committed Through Such Publications (official text), imposes additional log retention and content filtering obligations on content and access providers. In an attack, log evidence must be retained for up to 2 years under Law No. 5651, and the reference to these records is provided when the USTKAB notification is filed.

Notification Format: STIX/TAXII or a Manual Form

USOM offers two separate notification channels:

STIX/TAXII automated channel. For mature SOC teams and MSSPs. IOC packages in the STIX (Structured Threat Information Expression) standard are pushed to a TAXII (Trusted Automated Exchange of Intelligence Information) server. The machine-readable format is ideal for scalable sharing. ENISA promotes this standard within the CSIRT Network.

Manual web form. The traditional workflow. You go to the "Report Incident" page via the USOM portal, the organization's authorized representative logs in via e-Devlet, and the form is filled out. The form fields are roughly as follows:

  • Notifying organization details
  • Incident start and detection time (in UTC+3)
  • Affected systems and services
  • Attack type (DDoS, ransomware, APT, phishing, etc.)
  • IOC list (IP, domain, hash, email address)
  • TTP description (a MITRE ATT&CK mapping is preferred)
  • Response steps
  • Status of available evidence and logs
  • Whether a KVKK notification was filed (yes/no)
  • Whether a complaint was filed with the judicial authorities

The email notification address is iletisim [at] usom.gov.tr and the 24/7 tip-off line is +90 850 277 USOM (for the record). In an emergency, the recommended route is a preliminary notification by phone, followed by the written form.

Preparing the technical evidence package you will attach during notification falls within the digital forensics discipline. The hashes of evidence such as a memory dump, disk image, packet captures, and EDR telemetry must be referenced in the form. For the structure of the report your digital forensics team prepares, you can review the expert witness report format guide.

The Process After Notification

The moment a notification reaches USOM, the following parallel workflows are triggered:

Actors triggered. The relevant sector's SOME is informed. In critical infrastructure, the BTK audit team is informed. If there is an element of unlawful conduct, the option of filing a criminal complaint with the Public Prosecutor's Office is flagged. The IOC package is anonymized and published as an early warning to other organizations.

Feedback and follow-up. A case number is issued by USOM. Within the following 48 hours, a remote technical interview and, if necessary, an on-site visit may be requested. If your response team is receiving support from an external, third-party digital forensics firm, the firm's authorization document is shared.

Communication layer. In sensitive cases, USOM anonymizes the notifier's identity in its ENISA sharing, and only the IOCs and TTPs are shared. This is a critical assurance, especially for organizations concerned about trade secrets.

To discipline your incident response workflow, you can refer to our NIST 800-61-based IR playbook article. Within that framework, the USTKAB notification is positioned between the Identification and Containment phases.

TÜBİTAK BİLGEM and Certified Response

The Cyber Security Institute within TÜBİTAK BİLGEM works side by side with USOM at the technical capacity level. For personnel required to have penetration testing and digital forensics competence at critical infrastructure operators, BİLGEM certifications are required. We covered the detail of penetration testing legislation in our pentest process guide.

BİLGEM can also provide an independent expert opinion in post-incident technical analysis, and the weight of this opinion is significant in cases that go to court. At critical infrastructure operators, BİLGEM audit reports are submitted annually to BTK, and when the vulnerabilities in these reports are not closed, the determination that "the incident was foreseeable" is made at the moment of the breach, and the burden of fault increases. For this reason, closing the BİLGEM compliance framework before an incident prevents the most expensive surprises afterward.

Notification Readiness: What to Do Before an Incident

A USTKAB notification is not prepared at the moment of the incident; it is prepared before the incident. The fundamental steps for this are:

  • An authorized person and a backup must be designated, and e-Devlet access must be matched to the organization's account.
  • The corporate SOC address must be added to the USOM mailing list.
  • The IOC sharing format (STIX/JSON or CSV) must be made automatically generatable by internal tools.
  • An incident classification table must be prepared, and which incident falls under which threshold timeline must be documented in writing.
  • A drill must be conducted at least once a year to test the process, and a post-drill report must be presented to senior management.

Without preparation, the 24-hour window easily melts away during the first real incident amid the chaos of data collection and form filling. At organizations that run drills, the same process compresses to between 2 and 4 hours, and the preliminary notification is completed the same day.

ENISA CSIRT Network and the EU NIS2 Reflection

Türkiye is not an EU member, but for digital infrastructure alignment it conducts information sharing with the ENISA CSIRT Network. The NIS2 directive (Network and Information Systems 2), which came into force in 2023, tightened incident notification thresholds within the EU: it requires an "early warning" within 24 hours, an incident notification within 72 hours, and a final report within 1 month for critical and important sectors.

A parallel structure is visible in Türkiye's CBDDO Information and Communication Security Guide. The legislation is not yet a one-to-one match with NIS2, but the implementation thresholds are converging. Turkish companies that hold EU citizen data or serve the EU must comply with both frameworks at once. In that case, the USTKAB notification plus notifications to the relevant EU CERT via ENISA are made simultaneously.

The Consequences of Failing to Report

The sanctions for failing to comply with the notification obligation are multilayered:

Administrative fine. BTK can apply administrative sanctions on the scale of millions of lira at critical infrastructure operators. For repeated breaches, it can go as far as license revocation.

Separate KVKK sanction. If a personal data breach has not been reported, KVKK separately applies its own penalty framework.

Criminal liability. The destruction or non-retention of logs that must be kept under Law No. 5651 also constitutes a separate offense under the Turkish Penal Code.

Executive liability. The executive responsible for information security, senior management, and the data controller individuals are personally accountable. In judicial proceedings, the answer to the question "did they know about the incident" is read through the date of the USTKAB notification.

Insurance impact. Cyber insurance policies write incident notification as a precondition. If a notification was not filed, denial of payment is a commonly encountered outcome.

Frequently Asked Questions (FAQ)

1. When filing a USTKAB notification, does the organization's information remain confidential? Anonymization is applied in ENISA sharing. Domestically, the relevant SOME and audit authorities see the information. It is not a fully anonymous notification; the chain of responsibility is preserved.

2. If the incident has not yet been confirmed, should I wait? No. If the suspicion level is high, a preliminary notification is filed. Consuming the 24-hour window waiting for confirmation is risky, and you may then fall behind.

3. Are the USTKAB and KVKK notifications filed at the same time? The two are parallel but independent. USOM is notified within 24 hours and KVKK within 72 hours. The KVKK form is much more detailed and the legal department drives it.

4. How do I get the STIX/TAXII channel enabled? The organization's authorized representative submits a written application to USOM, and the TAXII endpoint is shared via certificate-based authentication. It is generally used at organizations with MSSP or SOC maturity above level 3.

5. Can an individual user file a notification? Yes. Incidents such as phishing, fraud, and malware infection can also be reported individually. The form is on the same portal.

6. Will USOM send a team after the notification? In critical infrastructure or widely impactful incidents, on-site support can be requested. In standard cases, remote coordination is carried out, and the response is performed by the organization's own digital forensics team or an external expert.

7. From a judicial standpoint, does a USTKAB notification carry evidentiary value? Not direct evidence, but it is documentation that the incident was detected and reported in a timely manner. It is used in lawsuits against an allegation of negligence on the organization's part.

8. Is sharing external threat intelligence appropriate for USTKAB? Yes. SOC teams disseminate to the community, via USTKAB, the C2, malware distributor, and phishing kit information they observe. Such sharing is a cornerstone of community defense.

USTKAB Coordination and Digital Forensics with DSET

At DSET Bilişim, from our headquarters in Hacettepe Teknokent Ankara, we deliver in a combined manner, to organizations that need a response team, the services of incident management, USTKAB and KVKK notification coordination, and digital forensics reporting. Weekend, night, or public holiday makes no difference; we work around the attack's timing, file the preliminary notification without missing the first 3-hour window, and start the chain of custody in parallel.

If you are under attack or unsure about the notification threshold, you can reach our senior incident response team directly on the +90 536 662 38 09 line. The conversation is not recorded; before you share sensitive information, we define the scope. If you prefer a face-to-face meeting, you can book an appointment at our Hacettepe Teknokent office.

The work does not end when the incident is over. For a lasting solution, we offer threat modeling, segmentation, EDR/XDR deployment, employee training, and regular penetration testing packages. Rather than filing a one-off notification, we recommend that you establish a security program disciplined before the incident. As part of this program, we conduct annual penetration tests and digital forensics readiness audits.

A USTKAB notification is not a bureaucratic chore. It is a contribution to Türkiye's national defense intelligence, and it protects your organization in both legal and technical terms. Not missing the thresholds and preparing the report correctly requires a disciplined process, which in turn requires being prepared.