About Members News Events Trainings Career Catalog Log In Join TR

THE 50TH PUBLIC SECTOR CYBERSECURITY DAY WAS HELD

THE 50TH PUBLIC SECTOR CYBERSECURITY DAY WAS HELD

The Turkish Cyber Security Cluster continues to connect its members with public institutions.

The Turkish Cyber Security Cluster continues its work to strengthen the domestic cybersecurity ecosystem by bringing its members together with public institutions. These meetings aim to provide domestic solutions to the cybersecurity needs of both the public and private sectors and increase Türkiye's independence in cybersecurity.

The 50th Public Sector Cybersecurity Day, organised by the Turkish Cyber Security Cluster, was held at the State Supply Office on 29 July 2026.

C-PROT PRESENTED DOMESTIC ENDPOINT SECURITY TECHNOLOGIES

C-Prot presented its domestic solutions for endpoint security, mobile application protection and removable media inspection in isolated networks. The presentation covered its platform architecture, independent international test results and scaling approach in large organisations. It emphasised that blocking a threat alone is insufficient: organisations must be able to establish how an incident unfolded using evidence, and telemetry depth is fundamental to this capability.

CEO S. Bilgehan Üstündağ presented the capabilities of the C-Prot Endpoint Security Platform (AV/EDR). He explained that process, file, registry, network and user session events are recorded continuously at endpoints and correlated centrally to reconstruct attack timelines, map activity to MITRE ATT&CK techniques and enable retrospective IOC searches.

The platform uses a single-agent architecture with low resource consumption and supports Windows, Linux, macOS, Android and iOS. Endpoints can be managed through C-Prot Security Center either on-premises or in the cloud. On-premises deployments retain full functionality in air-gapped environments. Server components can run on the organisation's own Kubernetes infrastructure, and threat intelligence integration is available.

Telemetry depth was central to the presentation. Üstündağ noted that many products leave limited records after blocking a threat. Answers to questions about how the threat entered, where it spread and which data it accessed are limited by the depth of endpoint records.

The presentation reported that C-Prot ranked first worldwide on Linux and Windows and second on macOS in the EDR-Telemetry evaluation, making it one of the few solutions placed highly across all three operating systems. It stated that Linux scores across the industry indicate a platform-specific visibility gap and that this is a priority for critical infrastructure and organisations using Pardus.

https://www.edr-telemetry.com/scores

The presentation also stated that the platform has repeatedly achieved VB100 certification, received consecutive international product excellence awards and reached Platinum status in the OPSWAT programme. It recalled that the platform had been delivered to the Ministry of National Defence during SAHA 2026 as Türkiye's first domestic AV/EDR solution.

Another area of interest was C-Prot AppDefense, a mobile application security solution. Operating as a software development kit embedded in an organisation's own applications, it provides visibility on devices outside the organisation's management and detects mobile fraud attempts before a transaction takes place.

A separate section addressed the needs of large organisations. The presentation explained that solutions are deployed in banking channels accessed by millions of users without affecting user experience, while tens of thousands of endpoints can be managed from one central console. Its multi-tenant architecture can define separate management domains for a ministry and affiliated bodies, with role-based access control (RBAC), VDI and high availability (HA) support.

The C-Prot Cybersecurity Kiosk, designed for removable media inspection, also attracted attention. USB drives, memory cards and optical media are scanned on a separate physical device before connecting to the network. Malware detection triggers automatic quarantine, closing a common infection route in isolated networks. Üstündağ stated that C-Prot is one of only two manufacturers worldwide developing a solution in this category.

The presentation briefly addressed the risks posed by smart televisions connected to corporate networks but absent from security inventories, along with C-Prot's solution for these devices.

Üstündağ commented:

“Collecting and processing telemetry at this scale is the hardest engineering problem in a security product. Very few companies worldwide can develop every layer internally: collecting data at kernel level, transporting it without reducing endpoint performance and turning it into meaningful information. C-Prot is one of those companies. We present this as a measured result, not merely a claim, because we regularly participate in independent international tests. These tests and the international collaborations they bring are not simply about a certificate for us; they are the most reliable source of feedback on where the product should go. We believe it is important for our public institutions to consider such independent measurements when evaluating security products.”

C-Prot stated that, as a manufacturer whose R&D and engineering workforce is based entirely in Türkiye, it will continue contributing to endpoint and isolated-network security in public institutions.

BINALYZE EXPLAINED ITS EVIDENCE-CENTRED SOC APPROACH

Speaking at the event, Binalyze Country Manager for Türkiye and CIS Hasan Hüseyin Özbenli emphasised that traditional SOC models are insufficient in today's threat environment and that a transition from an alert-centred to an evidence-centred approach is inevitable.

Özbenli said modern attackers move faster and hide within legitimate system processes, evading conventional security tools. He stated that 79% of attacks use no malware, while a SOC faces more than 3,000 alerts daily, a significant proportion of them false positives. This creates “alert fatigue” that distracts analysts from the real threat.

Explaining Binalyze's SOC approach, Özbenli said Binalyze AIR goes beyond alerts to establish “exactly what happened” through automated forensics and AI-assisted analysis. Capabilities include continuous endpoint scanning, reconstructing attack timelines using more than 750 forensic artefacts and turning threat intelligence reports into organisation-wide scans within minutes. He said these reduce dependence on senior DFIR specialists and enable Level 1 and Level 2 analysts to conduct advanced investigations.

Özbenli commented: “Continuous compromise assessment, proactive threat hunting and incident response are moving beyond manual efforts to become automated, continuous cycles operating at machine speed. The next SOC will be defined not by the number of alerts it generates, but by how quickly it establishes the truth, proves the scope of an attack and automates the response.”

The 50th Public Sector Cybersecurity Day was organised by the Turkish Cyber Security Cluster with support from the Secretariat of Defence Industries and the Cybersecurity Directorate. Senior executives, specialists and decision-makers attended from the Ministry of Justice; Disaster and Emergency Management Authority; Anadolu Agency; Information and Communication Technologies Authority; Naval Forces Command; General Directorate of State Airports Authority; Presidency of Religious Affairs; General Directorate of Security; its Department of Combating Cybercrime; Electricity Generation Corporation; General Staff Communications, Electronics and Information Systems Department; Air Forces Command; Ministry of Treasury and Finance; Ministry of Interior; Gendarmerie General Command and its Communications, Electronics and Information Systems Department; Public Procurement Authority; Land Forces Command; General Directorate of Highways; Turkish Red Crescent; Personal Data Protection Authority; Machinery and Chemical Industry Corporation; Turkish State Meteorological Service; Ministry of National Education; Ministry of National Defence; General Directorate of Mineral Research and Exploration; General Directorate of Population and Citizenship Affairs; Nuclear Regulatory Authority; General Directorate of Forestry; PTT; Competition Authority; Radio and Television Supreme Council; Coast Guard Command; Ministry of Industry and Technology; Secretariat of Defence Industries; Cybersecurity Directorate; Insurance Information and Monitoring Centre; Social Security Institution; Ministry of Agriculture and Forestry; Turkish Electricity Transmission Corporation; Turkish Grain Board; TRT Information Technologies Department; Turkish Standards Institution; TÜBİTAK; Turkish Patent and Trademark Office; Turkish Employment Agency; Turkish Petroleum Corporation; Health Institutes of Türkiye; Türkiye Sugar Factories; Türksat; VakıfBank; and the Supreme Election Council.

Gallery

THE 50TH PUBLIC SECTOR CYBERSECURITY DAY WAS HELD - 1 THE 50TH PUBLIC SECTOR CYBERSECURITY DAY WAS HELD - 2 THE 50TH PUBLIC SECTOR CYBERSECURITY DAY WAS HELD - 3 THE 50TH PUBLIC SECTOR CYBERSECURITY DAY WAS HELD - 4 THE 50TH PUBLIC SECTOR CYBERSECURITY DAY WAS HELD - 5 THE 50TH PUBLIC SECTOR CYBERSECURITY DAY WAS HELD - 6