TÜRKİYE’S OFFICIAL CYBERSECURITY DOCTRINE: CYBER HOMELAND

upa-admin 09 Ekim 2026 85 Okunma 0
TÜRKİYE’S OFFICIAL CYBERSECURITY DOCTRINE: CYBER HOMELAND

Introduction

In the twenty-first century, state sovereignty is no longer limited to land, sea, and airspace in the classical sense. With the widespread adoption of information and communication technologies, cyberspace has become a fundamental dimension of national security. Today, states’ economic activities, financial systems, energy infrastructure, transportation networks, health services, defense systems, public administration, and communication with citizens depend heavily on digital networks. Protecting the digital infrastructure underpinning sovereignty has therefore become as strategically necessary as protecting territorial integrity and political sovereignty.

In Türkiye, this transformation has increasingly been expressed through the concepts of “Cyber Homeland” (Siber Vatan) and “Digital Homeland” (Dijital Vatan). Although closely related, the two concepts are not entirely synonymous. “Digital Homeland” can be understood as a broader concept encompassing the data, infrastructure, platforms, and technological capacity that the state and society possess in the digital environment. “Cyber Homeland”, by contrast, focuses particularly on the security, defense, sovereignty, resilience, and, when necessary, deterrent protection of that digital domain.

The concept of “Cyber Homeland” has become increasingly visible in Türkiye’s official documents, while its institutional and legal foundations have also been strengthened. Published on 7 September 2024, the National Cybersecurity Strategy and Action Plan (2024–2028) is one of the most important policy documents in this field. It identifies six strategic objectives: cyber resilience; proactive cyber defense and deterrence; human-centered cybersecurity; the secure use of technology; domestic and national technologies; and strengthening the Türkiye brand internationally.

A second major step was establishing the Cybersecurity Presidency (Siber Güvenlik Başkanlığı) under the Presidency of the Republic of Türkiye on 8 January 2025. The Presidency was created to protect Türkiye’s national power in cyberspace, identify threats, and coordinate national cybersecurity policies in an integrated manner.

A third, and perhaps most significant, development was the entry into force of Cybersecurity Law No. 7545 on 19 March 2025. The law explicitly positions cybersecurity as an integral part of national security and establishes a legal framework for protecting critical infrastructure, oversight, certification, standardization, threat intelligence, and enforcement mechanisms.

Taken together, these developments suggest that Türkiye’s cybersecurity approach is evolving beyond a purely technical information-security policy towards a more comprehensive doctrine that combines national security, economic security, technological independence, and strategic deterrence.

1. The Emergence of the Cyber Homeland Concept

Traditionally, “homeland” refers to political sovereignty over a defined geographical area. The modern state system has described sovereignty in terms of land borders, territorial waters, and airspace. Digitalization, however, has added a new dimension to how we understand state sovereignty.

Today, threats to a state’s security cannot be limited to those entering through border crossings, ports, or airspace. An attack on the electricity grid, banking system, telecommunications infrastructure, public databases, or military communications systems can also directly threaten national security.

The “Cyber Homeland” can therefore be understood as a complementary digital-age dimension of the traditional concept of homeland. An important theoretical distinction must nevertheless be made: the Cyber Homeland is not a new geography that replaces the physical homeland. Rather than being a physical sovereign domain like land or sea, cyberspace is a complex ecosystem formed by states’ physical infrastructure, data, communication networks, and digital services.

The main components of the Cyber Homeland can be listed as follows:

  1. National communications infrastructure,
  2. Public-sector information systems,
  3. Critical infrastructure,
  4. Financial and banking systems,
  5. Energy systems,
  6. Transportation systems,
  7. Health information infrastructure,
  8. Defense industry and military networks,
  9. Satellite and space communications systems,
  10. Data centers,
  11. Cloud infrastructure,
  12. Digital public services,
  13. Citizen and institutional data,
  14. Software and hardware ecosystems,
  15. Artificial intelligence and big-data infrastructure.

The Cyber Homeland is not limited to servers physically located in Türkiye. For example, digital systems operated globally by a Turkish company may be relevant to Türkiye’s critical economic interests. This illustrates how cyber sovereignty differs from the classical understanding of sovereignty.

2. The Difference Between “Digital Homeland” and “Cyber Homeland”

In Turkish discussions, “Digital Homeland” (Dijital Vatan) and “Cyber Homeland” (Siber Vatan) are sometimes used interchangeably. Analytically, however, it is useful to distinguish between them.

The Digital Homeland can be regarded as the broader framework encompassing all of a state’s digital assets. It includes:

  • Digital government,
  • e-Government (e-Devlet),
  • National data infrastructure,
  • The digital economy,
  • Artificial intelligence,
  • Big data,
  • Digital identity,
  • Electronic communications,
  • The software ecosystem,
  • Digital payment systems,
  • Cloud technologies.

The Cyber Homeland, by contrast, refers to the security of this digital ecosystem and the state’s capacity to exercise strategic control over it. The distinction can therefore be expressed as follows:

Digital Homeland = digital capacity and the domain of sovereignty.

Cyber Homeland = the security, defense, and deterrence of that domain.

This distinction helps explain Türkiye’s current cybersecurity policies. In the Cybersecurity Presidency’s institutional discourse, protecting the “digital homeland” is directly associated with national security. An official statement by the Presidency describes protecting the digital homeland as an “essential and indispensable component of national security.” This approach shows that cybersecurity is not merely about protecting computer systems.

3. The Institutional Evolution of Türkiye’s Cybersecurity Policy

Türkiye’s cybersecurity policy did not emerge recently. The first National Cybersecurity Strategy and Action Plan was prepared in 2013, followed by strategy documents for the periods 2016–2019 and 2020–2023. During this process, the National Cyber Incident Response Center (USOM) and Cyber Incident Response Teams (SOME) assumed important roles.

Initially, the approach largely followed a sequence: detect the threat → prevent the attack → restore the system → resume the service.

Over time, a more proactive approach emerged: anticipate the threat → produce intelligence → analyze the attacker’s capabilities → make critical infrastructure resilient → establish deterrence when necessary.

This transformation indicates the maturation of Türkiye’s cybersecurity policy. The 2024–2028 Strategy represents an important stage in this evolution. It identifies people, defense, deterrence, and cooperation as central themes, thereby treating cybersecurity not simply as an information-technology security issue but as part of state capacity.

4. The National Cybersecurity Strategy 2024–2028

The National Cybersecurity Strategy and Action Plan (2024–2028) underpins Türkiye’s current cybersecurity doctrine. Notably, it treats not only defense against attacks but also resilience and deterrence as strategic objectives.

The Strategy sets out six principal strategic objectives:

4.1. Cyber Resilience

The objective is not merely to prevent attacks. It is also to ensure that the state and the economy can continue operating when an attack occurs. Rather than making critical infrastructure “impossible to attack”, the aim is to make it capable of continuing to function even if attacked. This shift matters because absolute security in cyberspace is nearly impossible.

4.2. Proactive Cyber Defense and Deterrence

One of the most important changes in Türkiye’s approach is the move towards proactive defense. Whereas the traditional defensive model responds after an attack, proactive defense seeks to identify threat actors’ activities in advance. Cyber intelligence consequently acquires strategic importance.

4.3. Human-Centred Cybersecurity

The approach recognizes that cybersecurity cannot be achieved through technology alone. Even the most advanced security system can be compromised by human-related risks, including:

  • Social engineering,
  • Phishing,
  • Insider threats,
  • Weak passwords,
  • Misconfiguration.

Qualified human resources are therefore a critical component of Türkiye’s Cyber Homeland policy.

4.4. Secure Use of Technology

Technologies such as artificial intelligence, the Internet of Things, 5G, and big data create new opportunities while also generating new security vulnerabilities. Türkiye’s approach therefore calls for technological transformation to proceed in parallel with security.

4.5. Domestic and National Cybersecurity Technologies

This objective makes Türkiye’s cybersecurity approach part of a broader policy of technological independence. Excessive dependence on foreign software and hardware can create strategic risks. Dependencies involving source code, hardware supply chains, or update mechanisms can become direct national-security concerns.

4.6. Strengthening the Türkiye Brand Internationally

Türkiye aims not only to protect its own systems but also to become an international actor in cybersecurity. The 2024–2028 Strategy thus extends cybersecurity into foreign policy and international cooperation.

5. The Cybersecurity Presidency: Institutionalizing the Doctrine

The establishment of the Cybersecurity Presidency under the Presidency of the Republic of Türkiye on 8 January 2025 was one of the most important institutional changes in Türkiye’s Cyber Homeland approach. The Presidency coordinates national cybersecurity policies and strategies.

The strategic significance of this structure can be explained in several ways. First, cybersecurity has been positioned at the highest level of state administration. Second, the capacity to coordinate responsibilities previously distributed among different institutions has been strengthened. Third, cybersecurity has become an institutional part of the national-security architecture rather than a concern confined to telecommunications or information technology.

The Presidency’s remit includes securing public institutions and critical infrastructure, threat intelligence, incident response, vulnerability management, digital-asset inventories, and defining and implementing standards. More importantly, the Cybersecurity Board’s structure demonstrates the integration of cybersecurity with traditional security institutions. In addition to the President, the Board includes the Vice President; the ministers of Justice, Foreign Affairs, Interior, National Defense, Industry and Technology, and Transport and Infrastructure; the Secretary-General of the National Security Council; the Director of the National Intelligence Organization (MİT); the President of Defense Industries; and the President of Cybersecurity.

This structure sends a clear message: Türkiye no longer regards cybersecurity as merely a technical security issue. It is considered alongside defense, intelligence, foreign policy, internal security, industrial policy, and technology policy. The Cyber Homeland doctrine can therefore be understood as the digital dimension of an integrated national-security doctrine.

6. Cybersecurity Law No. 7545 and Digital Sovereignty

Cybersecurity Law No. 7545, which entered into force on 19 March 2025, has significantly strengthened the legal foundations of Türkiye’s Cyber Homeland approach. Its central premise is that cybersecurity is integral to national security. The law can be understood as serving three principal functions.

First, protection: safeguarding critical infrastructure and information systems.

Second, regulation: developing standards, certification, and oversight in cybersecurity.

Third, deterrence: establishing administrative and criminal sanctions for those who fail to comply with cybersecurity obligations.

The cybersecurity system in Türkiye has thus moved beyond merely issuing recommendations. When necessary, the Presidency can inspect the activities of institutions and organizations covered by the law. This reveals another dimension of the Cyber Homeland: cyber sovereignty is not only the ability to defend against attacks but also the state’s capacity to regulate the national cyber domain. The concept of the Cyber Homeland is therefore closely connected to “digital sovereignty”.

7. Critical Infrastructure and the Cyber Homeland

One of the most important elements of the Cyber Homeland doctrine is protecting critical infrastructure. In modern economies, energy, finance, communications, transportation, and healthcare systems are largely connected to digital networks. For example, a large-scale cyberattack on an electricity grid can affect not only computer systems but also physical infrastructure.

The same applies to banking, air-traffic management, railways, ports, natural gas, oil, hospitals, and telecommunications. One core objective of the Cyber Homeland doctrine is therefore to increase the cyber resilience of critical infrastructure.

The concept of resilience is particularly important here. Completely eliminating cyberattacks is unrealistic. The real objective is to establish a comprehensive security cycle:

prevent → detect → respond → maintain services → recover → prevent recurrence.

Türkiye’s cyber-resilience approach in the 2024–2028 Strategy reflects this understanding.

8. Cyber Deterrence: The Most Critical Dimension of Türkiye’s Doctrine

A Cyber Homeland approach based solely on defense is insufficient. If an attacker believes that the cost of an attack will be low, the likelihood of an attack may increase. Cyber deterrence is therefore critically important.

Cyber deterrence can be considered through three main methods:

Deterrence by denial: making it technically more difficult for an attacker to carry out an attack.

Deterrence by punishment: increasing the cost of an attack.

Deterrence through norm-building: ensuring that cyberattacks generate political costs within the frameworks of international law and diplomacy.

Türkiye’s 2024–2028 Strategy explicitly identifies “proactive cyber defense and deterrence” as one of its strategic objectives. This shows that Türkiye’s cybersecurity policy is not purely defensive.

An important strategic problem remains: it is extremely difficult to identify a cyberattack’s perpetrator with certainty. An attacker may use servers in other countries, compromised computers, botnets, false identities, or proxy groups. For cyber deterrence to succeed, Türkiye must therefore develop not only its technical capabilities but also its cyber-intelligence and attribution capabilities.

9. Domestic and National Technology: The Economic Dimension of the Cyber Homeland

Another important feature of Türkiye’s Cyber Homeland policy is its integration of cybersecurity with industrial and technology policy. The emphasis on domestic and national technologies is not merely an economic preference; supply-chain security is strategically important for cybersecurity. As a country becomes more dependent on foreign sources for operating systems, security software, network devices, cryptographic products, cloud infrastructure, data centers, and artificial-intelligence systems, its strategic autonomy may decline.

Technological independence and cybersecurity are thus complementary policy areas for Türkiye. The 2024–2028 Strategy also identifies developing domestic and national technologies as an explicit strategic objective in combating cyber threats. The localization process experienced in the defense industry could be replicated in cybersecurity. In other words, protecting the Cyber Homeland requires not only cyber-defense capabilities but also the capacity to produce cyber technologies.

10. Artificial Intelligence and the Future of the Cyber Homeland

Artificial intelligence is one of the most significant transformations affecting cybersecurity in the second half of the 2020s. AI increases the capabilities of both defenders and attackers.

For defense, AI can support anomaly detection, threat intelligence, attack-pattern analysis, automated incident response, and malware analysis. Attackers, however, can also use AI for phishing, social engineering, automated vulnerability scanning, synthetic-content production, and information operations. Protecting the Cyber Homeland in the future will therefore involve much more than firewalls and antivirus systems.

The Cybersecurity Presidency also treats artificial intelligence, data analytics, and trustworthy AI as policy areas relevant to public information systems. The Cyber Homeland doctrine of the future may consequently be expected to rest on three pillars: artificial intelligence + cyber intelligence + autonomous defense.

11. The Cyber Homeland and Foreign Policy

Cybersecurity is also a new domain of foreign policy. States no longer compete only through diplomatic channels or military power. Cyber espionage, disinformation, attacks on critical infrastructure, and interference in electoral processes have become part of international politics.

Türkiye’s geopolitical position is particularly significant in this respect. Türkiye is a NATO member, maintains close economic ties with Europe, plays an important role in Black Sea security, occupies a strategic position in the Middle East, and has strong connections with the Caucasus and Central Asia.

Türkiye’s cybersecurity policy therefore has both regional and national-security dimensions. The 2024–2028 Strategy’s objective of strengthening the Türkiye brand internationally is notable in this regard. Türkiye may be expected to deepen cooperation with NATO cyber-defense mechanisms, the Organization of Turkic States, European institutions, and regional cybersecurity mechanisms.

12. Strengths of the Cyber Homeland Doctrine

Türkiye’s current approach has several important strengths.

First, integrating cybersecurity with national security: treating cybersecurity as more than a technical matter is a significant advantage.

Second, institutional centralization: establishing the Cybersecurity Presidency has strengthened coordination capacity.

Third, a stronger legal framework: Law No. 7545 provides an important legal basis for implementing the strategy.

Fourth, a proactive approach: Türkiye is moving toward a model that identifies threats in advance rather than merely responding to attacks.

Fifth, domestic technology: reducing technological dependence in cybersecurity may strengthen strategic autonomy over the long term.

Sixth, human resources: the Strategy’s emphasis on the human factor demonstrates recognition that cybersecurity is not limited to technical infrastructure.

13. Problems and Risks of the Cyber Homeland Doctrine

Nevertheless, Türkiye’s Cyber Homeland approach faces important issues that must be addressed.

13.1. Balancing Cybersecurity and Digital Freedoms

Expanding state powers in cybersecurity may spark new debates about the relationship between security and privacy, freedom of expression, data protection, and individual rights. A successful Cyber Homeland doctrine must therefore be robust and consistent with the rule of law and the principle of proportionality.

13.2. Public–Private Sector Coordination

A significant share of Türkiye’s critical digital infrastructure is operated by the private sector. Therefore, it is essential to integrate the state’s cybersecurity capacity with that of private-sector organizations.

13.3. Qualified Human Resources

Global demand for cybersecurity specialists is very high. Türkiye’s education system needs to train not only computer engineers but also cyber-intelligence specialists, cryptography experts, malware analysts, cyber-law specialists, and cyber strategists.

13.4. External Dependence

Although domestic technology production is increasing, complete independence from global technology supply chains is not possible. The objective should therefore be to manage strategic dependencies rather than pursue “full independence”.

13.5. The Cross-Border Nature of Cyberattacks

Protecting Türkiye’s own systems is not sufficient on its own. Since attacks often originate through global networks, international intelligence and judicial-cooperation mechanisms are also important.

14. How Can Türkiye Develop a New Cyber Homeland Doctrine?

Türkiye should focus on five main areas to advance its Cyber Homeland approach in the coming period.

14.1. National Cyber-Intelligence Capacity

Threat actors need to be tracked before a cyberattack occurs. Cyber intelligence should therefore be integrated more closely with the traditional intelligence architecture.

14.2. A “Zero Trust” Approach for Critical Infrastructure

The Zero Trust model, in which no user or device inside an organization is automatically trusted, should be expanded. The 2024–2028 Strategy also emphasizes the Zero Trust approach.

14.3. National Cyber Exercises

Türkiye should conduct regular national cyber-crisis exercises covering the energy, finance, healthcare, transportation, and telecommunications sectors.

14.4. The Cybersecurity Industry

Cybersecurity is not only a field that must be protected; it is also a high-value-added technology sector. Developing globally competitive products in this area could strengthen the economic pillar of Türkiye’s Cyber Homeland policy.

14.5. Cyber Diplomacy

Türkiye should play a more active role in shaping international cyber norms. This is particularly important in the context of NATO, the United Nations, and regional organizations.

Conclusion

Türkiye’s “Cyber Homeland” approach can be understood as the result of national cybersecurity policies that began in the 2010s and developed into a more comprehensive national-security doctrine during the 2020s. This transformation has taken shape in three main stages.

The first stage involved developing national cybersecurity strategies and institutional structures such as USOM and SOME. The second involved bringing cyber resilience, proactive defense, deterrence, human resources, domestic technology, and international cooperation together under the National Cybersecurity Strategy 2024–2028. The third involved establishing the Cybersecurity Presidency in 2025 and strengthening cybersecurity’s institutional and legal foundation through Cybersecurity Law No. 7545.

As a result, Türkiye’s emerging approach can be described as “active cyber sovereignty”. Under this approach, the state does not merely seek to protect its own systems from attacks; it also develops its cyber infrastructure, protects critical infrastructure, builds cyber-intelligence capabilities, seeks to detect attacks in advance, develops deterrence, encourages domestic technology production, expands the cybersecurity sector, and participates in the development of international cyber norms.

It would therefore be a serious mistake to view the Cyber Homeland merely as a project to protect Türkiye’s computers. More broadly, it is a project to preserve and develop Türkiye’s digital-age sovereignty. While the Digital Homeland refers to Türkiye’s broader digital economic, technological, and data ecosystem, the Cyber Homeland refers to that domain’s security and strategic sovereignty. Türkiye’s central objective is to build comprehensive state capacity by integrating cybersecurity with technological independence, economic security, national defense, intelligence, and foreign policy.

In conclusion, although Türkiye’s cybersecurity policy has not yet been formulated in a single document as a fully consolidated doctrine formally titled the “Cyber Homeland Doctrine”, the combination of the 2024–2028 Strategy, the Cybersecurity Presidency, and Cybersecurity Law No. 7545 has established much of the institutional and legal foundation for such a doctrine. In analyzing Türkiye’s national-security architecture in the second half of the 2020s, cyberspace should therefore be added as an independent strategic dimension alongside land, sea, air, and space. In a broader theoretical framework, Türkiye’s security outlook can be expressed as follows: the Blue Homeland represents sovereignty at sea, the Space Homeland represents strategic capacity in outer space, and the Cyber Homeland represents digital sovereignty and security. In this respect, the Cyber Homeland is not merely a technological security policy; it is an important part of Türkiye’s redefinition of sovereignty in the twenty-first century.

Prof. Dr. Ozan ÖRMECİ

REFERENCES

Leave A Response »

Time limit is exhausted. Please reload the CAPTCHA.