Cybersecurity Breaches and Legal Liability in Companies
Entrance
Cybersecurity breaches in companies are no longer just a problem for technical teams or IT departments. Theft of customer data, leakage of employee information, unauthorized access to payment systems, ransomware attacks, hijacking of company email accounts, data leakage through supplier systems, website hacking, deletion or rendering data inaccessible; all have direct legal, financial, and reputational consequences.
A cyberattack can damage not only a company's systems, but also its customers, employees, business partners, suppliers, public institutions, and shareholders. Especially in cases involving breaches of personal data, the Turkish Law No. 6698 on the Protection of Personal Data, the Turkish Penal Code, the Turkish Code of Obligations, the Turkish Commercial Code, labor law, consumer law, and contract law must be considered together.
According to the Personal Data Protection Authority, the data controller is obliged to take all necessary technical and administrative measures to ensure an appropriate level of security to prevent the unlawful processing of personal data, to prevent unlawful access to personal data, and to ensure the preservation of personal data. Furthermore, if personal data is processed by another natural or legal person on behalf of the data controller, the data controller is jointly responsible with these persons for taking the necessary measures.
Therefore, when a cybersecurity breach occurs in a company, the first question is not simply "who committed the attack?". The truly critical questions are: Did the company take the necessary technical and administrative measures? Did the breach affect personal data? Is notification required to the Board? Should the relevant individuals be notified? Was the evidence of the incident preserved? Should a criminal complaint be filed with the prosecutor's office? Is the supplier or employee at fault? Does the company face the risk of compensation or administrative fines?
What is a cybersecurity breach?
A cybersecurity breach is an unlawful, unauthorized, or compromising interference with a company's information systems, networks, data, software, user accounts, or digital assets. This breach can occur through an external hacker attack or internally by an employee, former employee, supplier, service provider, or an abuser.
Cybersecurity breaches can manifest in various ways. Ransomware attacks can encrypt company files, rendering them inaccessible. Phishing attacks can steal employees' email passwords. Business email fraud can involve withdrawing money from the company through fraudulent payment instructions. Data breaches can lead to third parties gaining access to customer, patient, employee, student, or membership information. Web application vulnerabilities can result in access to the company database. Misconfigured cloud services can make files publicly accessible.
Not every cyber incident is a data breach; however, every data breach can have serious legal consequences for a company. For example, if a company's website is temporarily inaccessible and personal data is not affected, this is primarily assessed in terms of service interruption and contractual liability. However, if customer data, employee payrolls, health information, payment information, or identity data are obtained by unauthorized persons, it constitutes a personal data breach under the Turkish Personal Data Protection Law (KVKK).
Companies' Data Security Obligations
Companies have a responsibility to protect the personal data they process. This obligation applies not only to large-scale technology companies, but also to e-commerce sites, clinics, law firms, educational institutions, hotels, logistics companies, manufacturers, software companies, call centers, consulting firms, and all businesses that process human resources data.
In accordance with Article 12 of the KVKK (Law on Protection of Personal Data), the company is obligated to take technical and administrative measures to prevent the unlawful processing and access of personal data, and to ensure the secure storage of data. The Authority states that a single standard model for data security cannot be foreseen; appropriate measures should be determined according to the size of the company, its activity, the nature of the data processed, and the level of risk.
Technical measures that can be taken in this context include a strong password policy, multi-factor authentication, access authorization, log recording, network security, up-to-date antivirus and EDR solutions, firewall, database security, backup, encryption, penetration testing, vulnerability scanning, secure software development, patch management, and cloud security.
Administrative measures are just as important as technical measures. A company should have an information security policy, a data processing inventory, employee training, confidentiality agreements, supplier agreements, a data breach response plan, an authorization matrix, disciplinary procedures, access restrictions for departing employees, a data retention and destruction policy, and a regular audit mechanism.
When should a data breach be reported to the Board?
If personal data is obtained by others through unlawful means, the data controller is obliged to notify the Board and the data subjects of this situation. The KVKK's recent public announcements also clearly state that, in accordance with the Board's decision dated January 24, 2019, and numbered 2019/10, data controllers must notify the Board without delay and within a maximum of 72 hours from the date they become aware of the breach.
The "learning" phase here is crucial. When a company suspects a cyberattack, it must immediately initiate a technical investigation. However, the 72-hour notification period comes into play when there is reasonable evidence that personal data has been unlawfully obtained, leaked, accessed, deleted, or made available to unauthorized persons.
It is risky for the company to delay notification for an extended period on the grounds that "we do not yet know all the details." In practice, the initial notification can be made first, and then additional notifications or updates can be submitted as the technical review progresses. The important thing is that the Board and the affected parties are informed in a timely manner so that they can mitigate the negative consequences of the violation.
What should be included in the notification to the relevant parties?
Notification to individuals affected by a data breach is not merely a formal announcement. According to the Board's decision dated September 18, 2019, and numbered 2019/271, the breach notification to the data subject must be prepared in clear and simple language and include at least the following elements: when the breach occurred, which categories of personal data were affected, the potential consequences of the breach, measures taken or proposed to mitigate negative impacts, and contact persons or communication channels from which information can be obtained.
For example, if an e-commerce company's customer data has been leaked, simply telling the affected person, "We've experienced a security incident," may not be sufficient. It must be clearly stated which data has been affected: name, phone number, email address, physical address, order history, card information, IP address, or password? Does the user need to change their password? Are bank or card details at risk? Should they be vigilant against phishing attacks?
The language of the notification should be simple but honest, avoiding panic. The company should not conceal the extent of the incident; it should not make definitive statements about things it doesn't know; and it should offer users concrete protective measures.
What should be done in the first 24 hours of a cybersecurity breach?
In cyber incidents, the first few hours are critical, both in terms of technical response and legal accountability. The company's initial reflex should not be simply to shut down the system or negotiate with the attacker. Evidence of the incident must be preserved, a qualified team must be formed, and the possibility of legal action should be considered.
The first step is to form an incident response team. This team should include IT specialists, cybersecurity experts, legal representatives, GDPR officers, senior management, communications personnel, and external consultants if necessary. The type of incident should be identified; if the attack is ongoing, its spread should be prevented; and log records, system images, network traffic, access logs, email headers, and malware samples should be preserved.
Evidence preservation is crucial. Panic-driven actions like formatting servers, deleting logs, randomly closing accounts, or losing correspondence with the attacker are detrimental to both technical analysis and criminal investigation. Particularly in cybercrimes under the Turkish Penal Code, IP addresses, logs, devices, timestamps, payment traces, and access records can be crucial in the prosecution process.
Cybercrimes under the Turkish Penal Code
Cyberattacks targeting companies may constitute a crime under the Turkish Penal Code. Article 243 of the Turkish Penal Code criminalizes unlawfully accessing and remaining in all or part of an information system. Article 244 of the Turkish Penal Code punishes acts of obstructing, disrupting, destroying, or altering data within a system. The text of the article stipulates that a person who obstructs or disrupts the functioning of an information system will be punished; and a person who corrupts, destroys, alters, renders inaccessible, inserts data into, or sends data to another location within the system will also be punished.
In this context, unauthorized access to the company server, copying the database, exporting customer information, locking the system, deleting files, rendering data inaccessible with ransomware, placing malicious code on the website, or disrupting the company's operations are evaluated under Articles 243 and 244 of the Turkish Penal Code.
If the attack resulted in money being demanded from the company, unauthorized access to bank accounts being gained, payment instructions being altered, or company data being used for blackmail purposes, other crimes such as fraud, blackmail, threats, and the unlawful disclosure or acquisition of personal data may also come into play.
Legal Procedures in Ransomware Attacks
In ransomware attacks, company data is encrypted, and the attacker demands payment to unlock it. In some cases, the attacker not only encrypts the system but also extracts the data and threatens to publish it if payment is not made. In this situation, both blocking the system/making data inaccessible under Article 244 of the Turkish Penal Code and a personal data breach may occur.
The company should assess the legal, financial, and technical risks before making a ransom payment. Paying does not guarantee the data will be recovered. Furthermore, it cannot be guaranteed that the attacker will not copy or publish the data. Money laundering, sanctions lists, internal authorization, and insurance policy provisions should also be considered during the ransom payment process.
In ransomware attacks, a backup policy is crucial. Operational damage is reduced if the company has regular, offline, and tested backups. However, having backups does not automatically eliminate the obligation to report a data breach. If personal data has been obtained by unauthorized persons, or if such a risk has been identified, the GDPR notification must be evaluated separately.
Responsibility of the Board of Directors and Senior Management
Company management may also be held responsible in cybersecurity breaches. Cybersecurity is not just a technical operation, but a matter of corporate risk management. The governing body should ensure that an information security management system is established that is appropriate to the company's field of activity, data processing volume, and risk profile.
Data security should be addressed at the board level, especially in companies operating in healthcare, finance, e-commerce, education, logistics, software, human resources, and those handling large customer databases. Failure to allocate budget, implement basic security measures, update systems, conduct vulnerability testing, train employees, or audit suppliers can all lead to discussions about "predictable and preventable risks" after a breach.
From the perspective of the Turkish Personal Data Protection Law (KVKK), administrative fines are imposed on the data controller company. However, if there is a negligent employee or manager within the company, internal recourse, disciplinary action, labor law liability, or compensation liability may be considered separately.
The Role of Current and Former Employees
A significant portion of cybersecurity breaches stem from employee error or insider threats. Using weak passwords, clicking on phishing emails, installing unauthorized software, sending company data to personal emails, using USB drives, failing to revoke access for former employees, or having excessive privileges can all lead to data breaches.
Employers must provide information security training to employees, document confidentiality obligations in writing, restrict access rights to job descriptions, immediately terminate access for departing employees, and initiate disciplinary procedures in the event of data breaches.
However, employee error does not automatically absolve a company of responsibility. If the company has not provided necessary training, taken technical precautions, maintained access logs, or performed authorization checks, the defense of "the employee made a mistake" may not be sufficient.
Supplier and Cloud Service Provider Responsibility
Companies often store their data in cloud services, accounting software, CRM systems, email providers, call center infrastructure, payment institutions, or external software companies. In this case, the responsibility of the data processor and supplier becomes crucial.
According to the institution's statement, if personal data is processed by other persons on behalf of the data controller, the data controller may be jointly responsible with these persons for taking the necessary precautions. Therefore, when choosing a supplier, the company should not only consider price and service quality; it should also regulate information security, data protection, certification, access rights, international transfer, subcontractor use, incident reporting, and audit rights in the contract.
In the case of a supplier-originated data breach, the company cannot absolve itself of all responsibility by simply stating that "the data leaked from the supplier's system." The data controller must exercise reasonable care when selecting and overseeing the data processor. Service agreements should clearly state short deadlines for cyber incident notification, log sharing, technical support, compensation for damages, and GDPR compliance provisions.
Risk of Administrative Fines
Companies may face administrative fines in cases of personal data breaches. The Personal Data Protection Law (KVKK) stipulates administrative fines for failure to fulfill data security obligations, non-compliance with Board decisions, violation of the duty to inform, and violation of obligations related to the data controllers' registry. The KVKK has published an official table showing the increased amounts of administrative fines under Article 18 of Law No. 6698 for the years 2017-2026, based on revaluation rates.
The important point here is that the company's notification of the breach to the Board alone does not absolve it of responsibility. After the notification, the Board may examine whether the company has taken the necessary technical and administrative measures, the vulnerabilities that caused the breach, the scope of the breach, the number of affected individuals, the nature of the data, the speed of response to the breach, and the adequacy of the information provided to the relevant individuals. The KVKK's public announcement also states that the Board may decide to conduct an investigation after the notification obligation has been fulfilled.
Liability for Damages
If individuals suffer financial or emotional distress due to a cybersecurity breach, they may face compensation claims against the company. For example, someone whose personal information was leaked may have been defrauded; someone whose health information was disclosed may have suffered emotional distress; credit card or account information may have been misused; or an employee whose personal information was published may claim that their privacy has been violated.
Administrative sanctions under the Personal Data Protection Law (KVKK) constitute a public law dimension. In addition, individuals concerned can claim material and moral damages within the framework of the Turkish Code of Obligations and the provisions of personal rights. The company's fault, the security measures taken, the foreseeability of the breach, the causal link between the damage and the breach, and the company's manner of intervention are all important factors in assessing compensation.
The risk of compensation claims is higher, especially in cases of breaches of sensitive personal data. The leakage of health data, biometric data, criminal record information, financial information, or data belonging to children can have serious consequences.
USOM and Cyber Incident Response
In Türkiye, USOM is a crucial institution in terms of coordinating national cyber incident response. According to the BTK (Information and Communication Technologies Authority), the National Cyber Incident Response Center was established to identify threats to Türkiye's cybersecurity, mitigate or eliminate the effects of potential cyber attacks and incidents, and conducts national and international coordination efforts regarding cyber incident response 24/7.
Not every private company may have the same reporting obligation to USOM in every incident; however, coordination with USOM and relevant sectoral SOME structures may be necessary in cases involving critical infrastructure, sectoral regulation, public services, telecommunications, finance, energy, or large-scale cyber incidents. Companies should also analyze their cyber incident reporting and response obligations according to their field of activity.
Cybersecurity Compliance Checklist for Companies
Companies should prepare before experiencing a cybersecurity breach. The first step is to inventory the personal data being processed and the critical systems. Questions such as: What data is being processed, where is it stored, who has access to it, to which suppliers is it transferred, is data being sent abroad, which systems are critical, and what backup measures are in place must be answered.
Secondly, technical measures must be established. Multi-factor authentication, regular backups, access logs, patch management, encryption, network segmentation, firewalls, EDR (Electronic Data Protection), penetration testing, and vulnerability scanning are fundamental security layers.
Thirdly, administrative measures must be taken. An information security policy, employee training, a data breach response plan, supplier audits, confidentiality agreements, an authorization matrix, and a data retention and destruction policy should be prepared.
Fourthly, the incident response plan should be tested. It should be determined in advance who will make decisions in the event of a data breach, who will notify the Board, who will prepare statements for relevant individuals, who will preserve technical evidence, who will file a complaint with the prosecutor's office, and who will manage media relations.
Fifth, the company should examine the scope of its cyber insurance policy, if one exists. It's essential to know in advance what the policy covers and excludes in terms of ransomware, business interruption, data recovery, legal advice, third-party claims, and administrative fines.
Conclusion
Cybersecurity breaches in companies should not be viewed as a simple technical malfunction or IT problem. A cyberattack can have multifaceted consequences, including GDPR notifications, administrative fines, criminal investigations, customer and employee compensation claims, loss of commercial reputation, breach of contract, business interruption, and management liability.
Companies are obligated to take the necessary technical and administrative measures to prevent the unlawful processing and access of personal data, to ensure the preservation of data, and to provide an appropriate level of security. This obligation is assessed specifically according to the company's size, field of activity, and the nature of the data being processed.
In the event of a personal data breach, the company must notify the Board without delay and no later than 72 hours from the date it becomes aware of the breach. Furthermore, as soon as affected individuals are identified, they must receive clear, simple, and informative notifications as soon as reasonably possible.
Cyberattacks can also give rise to crimes under Articles 243 and 244 of the Turkish Penal Code, namely unauthorized access to, obstruction of, disruption of, destruction of, alteration of data, or rendering inaccessible to an information system. Therefore, companies should protect technical evidence, store log records, and file a criminal complaint with the Public Prosecutor's Office when necessary.
In conclusion, cybersecurity is not just a technical investment for companies, but also a matter of legal compliance and corporate governance. A strong cybersecurity policy, GDPR compliance, incident response plan, employee training, supplier audits, regular penetration testing, secure backups, and a rapid notification mechanism make the company more resilient against attacks and help reduce legal liability in the event of a breach.