The USOM notification form is submitted via sg.usom.gov.tr within 3 hours at the latest after a cyber incident is detected. The form consists of five main sections: institution information, incident type, impact level, IOCs (observed indicators) and the actions taken. For critical-infrastructure sectors, notification is mandatory within the framework of Council of Ministers Decision (BKK) No. 2012/3842 dated 11/06/2012 and BKK No. 2013/4890.

TL;DR

  • Notification portal: sg.usom.gov.tr (the Cyber Incident Reporting and Notification System).
  • Deadline: 3 hours at the latest from the detection of the incident.
  • Five main fields: institution, incident type, impact, IOCs, action.
  • For critical infrastructure, BKK 2013/4890 makes it an obligation.
  • It is carried out in parallel with the KVKK 72-hour process; one does not replace the other.

Detailed Answer

What Is USOM, and Which Incidents Are Reported?

USOM (the National Cyber Incident Response Center) is the national CSIRT operating within the BTK. It is at the center of the SOME (Sectoral/Institutional Cyber Incident Response Teams) structure. Incidents subject to notification:

  • Cyberattacks affecting the availability of a critical system
  • Data-leak and ransomware cases
  • DDoS and service-interruption incidents
  • Unauthorized access, malware findings
  • Supply-chain compromises

Legal Framework

  • Electronic Communications Law No. 5809
  • BKK No. 2012/3842 (Conduct of National Cybersecurity Work)
  • BKK No. 2013/4890 (Coordination of critical-infrastructure sectors with USOM/SOME)
  • KVKK No. 6698 (the parallel data-breach notification)

Form Fields and a Filling Guide

Section Field Description
1. Institution Name, MERSİS, sector, SOME official Via the registered institution account
2. Incident type Ransomware, DDoS, unauthorized access, etc. Multiple selection possible
3. Impact Low/Medium/High/Critical Duration of service interruption, affected users
4. IOCs Hash, IP, domain, URL, file name A STIX/CSV attachment can be uploaded
5. Action Isolation, backup, external support With a timeline

The 3-Hour Flow

  1. 0-30 minutes: incident confirmation, scope estimation, informing the teams.
  2. 30-60 minutes: initial isolation (disconnecting from the network, locking accounts).
  3. 60-120 minutes: IOC collection (EDR, SIEM, firewall logs).
  4. 120-180 minutes: filling out the form, uploading attachments, submission.

This flow is exactly aligned with the "Hour 1-3" time slot in the ransomware first-24-hours action timeline.

What Is Written as IOCs?

USOM accepts IOC sharing in STIX 2.1 or CSV format. The fields:

  • IP address (source or C2)
  • Domain or FQDN
  • URL
  • File hash (MD5, SHA-1, SHA-256)
  • Email sender, phishing subject
  • Malware family name (if any)

For hash-calculation details, you can see our what is hash verification MD5 SHA-1 SHA-256 article.

The Post-Notification Process

Depending on the severity of the case, USOM:

  • Sends a response and a request for additional information.
  • Informs the sector SOME (for example, the BDDK SOME for finance).
  • Shares it with international CSIRTs if necessary (the FIRST network).
  • Issues an early-warning IOC bulletin to other institutions.

On the institution's side:

  • The KVKK Board notification (if there is a personal-data breach) is carried out with the KVKK 72-hour data-breach notification template.
  • Legal and PR coordination is maintained.
  • If a legal process is to be initiated, ISO/IEC 27037 compliant evidence collection is performed.

Common Mistakes

  • Making the notification with a delay exceeding 3 hours; a risk of an administrative fine.
  • Sending an empty form without sharing IOCs; the response is delayed.
  • Counting the KVKK notification in place of the USOM notification; the two are different.
  • Skipping the sectoral SOME; in some sectors there is a path of first the sector SOME, then USOM.
  • Reinstalling systems without taking a backup and a forensic image; loss of evidence.

Our cyber incident response playbook NIST 800-61 checklist article prevents these mistakes with a permanent process.

The Sectoral SOME Obligation

Under BKK 2013/4890, the following sectors are considered critical infrastructure and are obliged to establish a sectoral SOME:

  • Energy (under EPDK coordination)
  • Electronic communications (BTK)
  • Finance (BDDK, SPK, TCMB)
  • Transport
  • Critical public services
  • Water management

In these sectors, an incident is conveyed first to the sector SOME, and from there to USOM.

Three Parallel Notification Channels

Fully compliant institutions manage three notification channels simultaneously:

Channel Deadline Authority Subject
USOM 3 hours BTK / USOM Cyber incident, general
KVKK 72 hours KVKK Board Personal-data breach
Sectoral regulator 24-48 hours BDDK, EPDK, BTK Service interruption, business continuity

It is not possible to combine the three channels into a single form; their contents differ. The incident manager must assign a separate owner for each of the three and track them with a calendar. For this reason, it is good practice to include all three processes in the scenario injects of the pre-incident tabletop exercise and to verify their owners.

FAQ

Is USOM notification voluntary or mandatory?

In critical-infrastructure sectors it is mandatory under BKK 2013/4890. For other institutions it is recommended, but incident sharing is the foundation of the early-warning ecosystem.

Within how many hours must the notification be made?

The USOM guide stipulates that it be reported within 3 hours at the latest from the detection of the incident. It must not be confused with the KVKK's 72-hour deadline; the two are separate obligations.

How is the confidentiality of the form protected?

The USOM portal operates over TLS, and login is made with the institution account. The information shared is shared only with the relevant sector SOME and international partners within the framework of TLP (Traffic Light Protocol) rules.

Is there a risk of penalty after notification?

There is no direct penalty for the institution that reports the incident; on the contrary, notification provides protection. Not reporting or delaying gives rise to a risk of an administrative fine and audit for critical-infrastructure operators.

Does DSET provide support in the USOM notification process?

Yes. DSET provides 24/7 incident-response support for preparing the USOM notification form, packaging IOCs and coordinating with the sectoral SOME. Contact: Hacettepe Teknokent Beytepe, +90 536 662 38 09, [email protected]. DSET, since 2003, Ankara Hacettepe Teknokent Beytepe; +90 536 662 38 09.