<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Ziya's Substack]]></title><description><![CDATA[My personal Substack]]></description><link>https://ziyagokalp.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!_fiE!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd44ce82-2356-4b09-b695-0f10941b8917_1006x1006.png</url><title>Ziya&apos;s Substack</title><link>https://ziyagokalp.substack.com</link></image><generator>Substack</generator><lastBuildDate>Mon, 27 Jul 2026 11:55:41 GMT</lastBuildDate><atom:link href="https://ziyagokalp.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Ziya Gokalp]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[ziyagokalp@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[ziyagokalp@substack.com]]></itunes:email><itunes:name><![CDATA[Ziya Gokalp]]></itunes:name></itunes:owner><itunes:author><![CDATA[Ziya Gokalp]]></itunes:author><googleplay:owner><![CDATA[ziyagokalp@substack.com]]></googleplay:owner><googleplay:email><![CDATA[ziyagokalp@substack.com]]></googleplay:email><googleplay:author><![CDATA[Ziya Gokalp]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Cognitive Ransomware: The Hijacking of Human Decision-Making Processes Through Generative and Agentic Artificial Intelligence]]></title><description><![CDATA[Thanks for reading Ziya's Substack!]]></description><link>https://ziyagokalp.substack.com/p/cognitive-ransomware-the-hijacking</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/cognitive-ransomware-the-hijacking</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Mon, 27 Jul 2026 09:45:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rl61!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea00976c-ccf7-45d3-a32f-6500a1bbe5ad_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rl61!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea00976c-ccf7-45d3-a32f-6500a1bbe5ad_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rl61!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea00976c-ccf7-45d3-a32f-6500a1bbe5ad_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!rl61!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea00976c-ccf7-45d3-a32f-6500a1bbe5ad_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!rl61!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea00976c-ccf7-45d3-a32f-6500a1bbe5ad_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!rl61!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea00976c-ccf7-45d3-a32f-6500a1bbe5ad_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rl61!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea00976c-ccf7-45d3-a32f-6500a1bbe5ad_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ea00976c-ccf7-45d3-a32f-6500a1bbe5ad_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2202120,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/208660799?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea00976c-ccf7-45d3-a32f-6500a1bbe5ad_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rl61!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea00976c-ccf7-45d3-a32f-6500a1bbe5ad_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!rl61!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea00976c-ccf7-45d3-a32f-6500a1bbe5ad_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!rl61!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea00976c-ccf7-45d3-a32f-6500a1bbe5ad_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!rl61!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea00976c-ccf7-45d3-a32f-6500a1bbe5ad_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Introduction</h1><p>For many years, the field of cybersecurity has approached cyberattacks primarily from a technical perspective.</p><p>Vulnerabilities were sought within software, attacks were analyzed through network traffic, and defense mechanisms were designed largely to protect systems. Firewalls became more sophisticated, antivirus solutions were widely deployed, authentication mechanisms were strengthened, and organizations invested heavily in building more resilient infrastructures.</p><p>Despite these efforts, cyberattacks have not only persisted but have also become increasingly sophisticated and impactful with each passing year.</p><p>This evolution has revealed a fundamental reality: an organization&#8217;s most valuable asset is not merely its data. Equally important are the people who interpret that data, make decisions based on it, and ultimately determine the organization&#8217;s response.</p><p><strong>Modern ransomware provides one of the clearest examples of this phenomenon.</strong></p><p>At first glance, the apparent target of a ransomware attack is the organization&#8217;s data. Files are encrypted, access to critical systems is denied, and payment is demanded in exchange for the decryption key.</p><p><strong>However, when the psychological dimension of such attacks is examined, a very different picture emerges.</strong></p><p>Two organizations exposed to the same ransomware attack may respond in entirely different ways. One may choose to pay the ransom, while the other refuses. Some recover and resume operations within days, whereas others remain unable to function for weeks. Even when the technical conditions are nearly identical, the decisions made are fundamentally different.</p><blockquote><p><strong>The difference does not lie in the encryption algorithm itself. The decisive factor is the psychological pressure imposed on people. Fear of prolonged downtime, concerns over losing customer trust, financial losses, reputational damage, and the uncertainty surrounding the incident ultimately determine the true impact of the attack.</strong></p></blockquote><p>In other words, ransomware does not merely encrypt data, <strong>it also places human decision-making under pressure.</strong></p><p>This leads to a fundamental question.</p><p>Must an attacker actually encrypt files to create the same psychological effect?</p><p>Put differently, if an attacker can directly influence the target&#8217;s decisions, is technical encryption still necessary?</p><p>This question has become increasingly relevant in light of the remarkable advances in generative artificial intelligence over the past few years.</p><blockquote><p><strong>The rapid advancement of large language models (LLMs), voice cloning technologies, deepfakes, and synthetic digital identities has provided threat actors with an unprecedented set of capabilities, enabling them to target not only computer systems but also human cognition and behavior.</strong></p></blockquote><p>Today, an individual&#8217;s writing style can be convincingly replicated, their voice can be synthesized with near-perfect realism, and entirely fictitious personas can be transformed into credible digital identities.</p><p>In such an environment, the focus of cyberattacks naturally shifts from technical systems to the <strong>cognitive processes of human beings.</strong></p><p>The concept of <strong>Cognitive Ransomware</strong> presented in this article is proposed as a conceptual framework for understanding and explaining this transformation. It describes a new class of cyber threats in which the primary objective is not to encrypt data, but to manipulate, coerce, and ultimately seize control of human decision-making processes.</p><blockquote><p><strong><span>It should be emphasized that </span>Cognitive Ransomware<span>, as discussed in this article, does not represent a formally recognized category of malware. Instead, it is proposed as a conceptual framework for understanding how AI-enabled manipulation techniques may evolve into a new class of cyber threats in the future.</span></strong></p></blockquote><p>In conventional ransomware attacks, the attacker denies the victim access to their data. In the <strong>Cognitive Ransomware</strong>paradigm, however, the primary target is the human cognitive process.</p><p>The objective is to narrow an individual&#8217;s range of perceived choices by exploiting fear, trust, perceived authority, time pressure, or social relationships.</p><p>As a result, although the victim may appear technically free to choose, they are psychologically guided toward making only the decision desired by the attacker.</p><p>This perspective highlights that cybersecurity is no longer solely about protecting information systems. Even the most advanced firewall cannot analyze an executive&#8217;s fears, and no intrusion detection system can recognize when an employee&#8217;s trust is being systematically exploited.</p><p>As technical defenses continue to improve, the transformation of human behavior into a primary attack surface demands a fundamental redefinition of cybersecurity itself.</p><p>At this point, it is reasonable to pose a critical question: <strong>Which is easier to compromise a system, or to alter the decisions of the person who operates it?</strong></p><p>If the latter becomes less costly, faster, and more difficult to detect, the hostages of future ransomware attacks will no longer be files or data, but human judgment itself.</p><p>It is precisely at this point that the true encryption will no longer occur within computers, it will take place in the human mind.</p><p></p><h1>Why Human Decision-Making Has Become the New Attack Surface</h1><p>Cyberattacks are often assumed to require sophisticated malware, zero-day vulnerabilities, or highly advanced exploitation tools to succeed.</p><p>However, numerous incidents in recent years have demonstrated that the most decisive factor in the success of a cyberattack is not technology, it is the human being. The reason is straightforward. Computers operate according to predefined rules, whereas <strong>humans make decisions based on their perceptions, experiences, emotions, and the circumstances in which they find themselves.</strong></p><p>This distinction elevates humans from being merely users of information systems to becoming the most critical link in the attack chain.</p><p>As discussed earlier, technical systems generally behave in predictable ways because they follow deterministic rules. <strong>Human behavior, by contrast, can vary significantly, even when individuals are confronted with the same situation.</strong></p><blockquote><p><strong>A decision made under intense stress is often very different from one made in a calm and controlled environment. Likewise, factors such as time pressure, perceived authority, fear, trust, and social pressure can lead individuals to make decisions they would not ordinarily make under normal circumstances.</strong></p></blockquote><p>This is precisely why cybercriminals have invested heavily in social engineering techniques for decades.</p><p>While bypassing a firewall requires technical expertise, deceiving a human being often requires nothing more than understanding how that person thinks. Consequently, successful cyberattacks exploit not only vulnerabilities in technical systems but also weaknesses in human decision-making.</p><p>The human brain is required to make thousands of decisions every day. Because it is impossible to analyze each decision in depth, it relies on mental shortcuts known in cognitive psychology as <strong>heuristics</strong>.</p><p>These cognitive mechanisms make everyday decision-making more efficient, but they also create vulnerabilities that can be exploited through manipulation.</p><blockquote><p><strong>An official-looking logo can instantly create a sense of trust. Instructions that appear to come from a senior executive may be executed without question. A task presented as urgent can cause routine verification procedures to be bypassed. Likewise, information perceived to be accepted by the majority is often adopted with little critical evaluation.</strong></p><p><strong>None of these outcomes result from technical vulnerabilities. Rather, they arise from predictable characteristics of human cognition characteristics that have become increasingly valuable targets for cyber adversaries.</strong></p></blockquote><p>All of these behaviors stem from the natural functioning of the human brain and should not, in themselves, be regarded as security weaknesses.</p><p>Precisely for this reason, modern cyberattacks increasingly focus not on bypassing technical security controls, but on exploiting these inherent decision-making mechanisms to their advantage.</p><blockquote><p><strong>In most cases, the attacker&#8217;s objective is not to compromise the victim&#8217;s computer. Rather, it is to induce the victim to voluntarily perform a specific action.</strong></p><p><strong>Clicking on a malicious link, approving a fraudulent payment request, disclosing sensitive credentials, or temporarily disabling security controls may appear to be technically simple actions. Yet these seemingly ordinary decisions often represent the critical point at which a cyberattack succeeds.</strong></p></blockquote><p>This phenomenon becomes even more pronounced in organizational environments. Employees who process hundreds of emails each day, move continuously between meetings, and simultaneously manage multiple operational decisions naturally operate under significant cognitive load.</p><p>In an environment where attention is constantly fragmented, it is impractical to verify every instruction in detail. This is precisely the working dynamic that threat actors seek to exploit. Security vulnerabilities, therefore, exist not only in software but also within organizational processes and human behavior.</p><p>Another characteristic that distinguishes humans from technical systems is their ability to establish relationships based on trust.</p><p><strong>Trust is an indispensable element of organizational life. Organizations thrive through collaboration, managers delegate authority to their teams, and employees routinely act on the assumption that their colleagues, supervisors, and business partners are operating in good faith.</strong></p><blockquote><p><strong>This assumption is what makes modern organizations function effectively, yet it also creates opportunities for malicious exploitation. By targeting trust rather than technical systems, an attacker can often achieve the same objective at a fraction of the cost and with far greater efficiency.</strong></p><p><strong>In many cases, compromising a trusted relationship is significantly easier than compromising a well-protected information system.</strong></p></blockquote><p>For this reason, today&#8217;s attack surface extends far beyond servers, endpoints, mobile devices, and cloud infrastructures. The people who make decisions have become security assets just as critical as the systems themselves.</p><p>This is particularly evident in critical infrastructure, financial institutions, energy facilities, healthcare organizations, and industrial control systems, where a single erroneous decision can have consequences far more severe than a technical vulnerability.</p><p>An approval granted at the wrong moment, an instruction accepted without verification, or sensitive information shared with someone mistakenly perceived as trustworthy can result in losses amounting to millions of dollars or even consequences that directly affect physical safety.</p><p>At this point, the key issue is not to characterize humans as the <em>weakest link</em> in the security chain. Such a perspective is incomplete. Humans can also represent its strongest line of defense. However, this requires recognizing that people are not merely operators of information systems but are themselves a critical attack surface that must be actively protected.</p><p>This recognition forms the conceptual foundation of <strong>Cognitive Ransomware</strong>.</p><p>If the attacker&#8217;s objective is to influence human decision-making, the attack has already moved beyond the boundaries of traditional social engineering. The goal is no longer simply to persuade a victim to perform a single action, but to systematically narrow the individual&#8217;s perceived choices until a particular decision becomes virtually inevitable.</p><p>The technological force that makes this transformation possible is, above all, <strong>Artificial Intelligence (AI)</strong>.</p><blockquote><p><strong>For the first time, Artificial Intelligence provides threat actors with the capability to analyze millions of individuals simultaneously, craft highly personalized attack scenarios for each target, and automate cognitive manipulation at an unprecedented scale.</strong></p></blockquote><p></p><h1>How Artificial Intelligence Is Transforming the Scale and Nature of Cyberattacks</h1><p>Throughout the history of cybersecurity, advances in technology have consistently reshaped the methods used by cyber adversaries. The widespread adoption of the Internet gave rise to network-based attacks, the proliferation of mobile devices introduced mobile malware, and the evolution of cloud computing created an entirely new class of threats targeting cloud infrastructures.</p><p>Today, a similar transformation is being driven by <strong>Artificial Intelligence (AI)</strong>.</p><p>Unlike previous technological shifts, however, AI is not merely introducing another attack tool. It is fundamentally redefining how cyberattacks are planned, prepared, and executed.</p><p>In the past, a successful social engineering campaign relied heavily on human effort. Attackers had to research their targets, understand the structure of the organization, develop a convincing pretext capable of establishing trust, and wait for the right opportunity. This process often took weeks or even months, and the same preparation had to be repeated for every new target. As a result, the scale of such operations was constrained by the attacker&#8217;s available human resources.</p><p><strong>Generative AI is fundamentally changing this equation.</strong></p><p><strong>With the emergence of large language models (LLMs), natural language processing (NLP) systems, and autonomous AI agents, many tasks that previously required extensive manual effort can now be performed automatically.</strong></p><blockquote><p><strong>Information about a target can now be gathered from open sources, analyzed, and used to identify the most effective communication style and generate highly tailored attack scenarios, all within a fraction of the time previously required.</strong></p><p><strong>As a result, the attacker&#8217;s greatest advantage is no longer technical expertise alone, but the ability to collect, interpret, and operationalize vast amounts of information.</strong></p></blockquote><p>The foundation of this transformation lies in <strong>Open-Source Intelligence (OSINT)</strong>.</p><p>Today, individuals and organizations unknowingly leave behind vast amounts of digital footprints. Social media activity, professional networking platforms, corporate websites, conference presentations, press releases, job postings, and publicly available documents can collectively provide a remarkably detailed profile of a target.</p><p>Artificial Intelligence does not merely collect this information; it also analyzes the relationships among disparate data points, transforming them into coherent and actionable intelligence.</p><p>For example, by examining an organization&#8217;s publicly available information, AI can identify which teams collaborate closely, who holds the greatest influence in decision-making processes, which executives maintain the highest public visibility, and what communication style is commonly adopted within the organization.</p><p>Similarly, at the individual level, AI-driven analysis can reveal a person&#8217;s professional interests, work habits, preferred terminology, and communication style.</p><p>None of this information is inherently harmful. However, when aggregated, correlated, and analyzed effectively, it enables the creation of highly convincing and context-specific attack scenarios.</p><p>One of the most significant capabilities introduced by Artificial Intelligence is its unprecedented capacity for personalization.</p><blockquote><p><strong>In the past, phishing campaigns typically relied on sending the same message to thousands of recipients. Today, however, AI makes it possible to generate unique content for every individual target.</strong></p><p><strong>Even two employees within the same organization may receive messages that differ entirely in language, technical terminology, tone, and attack scenario. This is possible because Artificial Intelligence can analyze and model each individual as a distinct behavioral profile.</strong></p></blockquote><p>This level of personalization is not limited to written communication.</p><p>Recent advances in voice synthesis and AI-generated imagery have fundamentally challenged the reliability of digital communications.</p><p>Using only a few minutes of recorded speech, it is now possible to replicate an individual&#8217;s voice, speaking style, and vocal inflections with remarkable accuracy. Likewise, advanced image and video generation systems can produce highly realistic videos that are increasingly difficult to distinguish from authentic recordings. As a result, technologies that were once considered reliable means of visual or auditory verification can no longer be assumed to be trustworthy.</p><p>More importantly, these technologies do not operate in isolation. Within a single attack campaign, <strong>Open-Source Intelligence (OSINT)</strong>, <strong>Large Language Models (LLMs)</strong>, voice cloning, AI-generated imagery, and automated content generation systems can be seamlessly integrated.</p><p>Rather than simply sending a fraudulent email, an attacker can orchestrate a sophisticated, multi-layered manipulation campaign tailored specifically to an individual target.</p><p>This transformation has also dramatically expanded the scale of cyberattacks. In the past, complex social engineering operations were typically reserved for high-value individuals or specific organizations because of the considerable human effort they required. With Artificial Intelligence, however, the same techniques can now be deployed efficiently across vastly larger target populations.</p><p>In other words, highly personalized attacks are no longer economically viable only against senior executives, they have become scalable and cost-effective even when directed at ordinary employees.</p><p>Another significant advantage provided by Artificial Intelligence is persistence.</p><p>In traditional cyberattacks, communication between the attacker and the target was typically brief and transactional. AI-powered systems, by contrast, can sustain coherent and context-aware interactions for weeks or even months, retain memory of previous conversations, and continuously refine their scenarios as new information becomes available.</p><p><strong>This capability makes attacks that rely on establishing trust significantly more effective.</strong></p><p>The transformation taking place, however, extends far beyond making cyberattacks more convincing.</p><blockquote><p><strong>The most profound change, however, is that cyberattacks are becoming dynamic rather than static. Artificial Intelligence can analyze every response from the target and adapt its next move accordingly.</strong></p><p><strong>Instead of following a fixed attack script, AI-driven systems can continuously refine their strategy based on the target&#8217;s behavior, making the manipulation process increasingly adaptive, personalized, and effective over time.</strong></p></blockquote><p>If the target becomes suspicious, the communication style can be adjusted, alternative communication channels can be employed, or additional elements of verification can be introduced. Consequently, the attack ceases to be a one-time attempt and instead evolves into a continuously adaptive process that responds to the target&#8217;s behavior in real time.</p><p>It is at this point that <strong>Cognitive Ransomware</strong> begins to diverge from traditional social engineering.</p><p>The objective is no longer merely to establish trust or persuade the target to perform a single action. Rather, the goal is to gradually shape the target&#8217;s decision-making process, systematically narrow the range of perceived alternatives, and ultimately lead the individual to regard a predetermined decision as a natural and self-directed choice.</p><p>Artificial Intelligence serves as the primary enabler of this transformation, accelerating, scaling, and continuously optimizing every stage of the manipulation process.</p><p></p><h1>Conclusion</h1><p>A review of the history of cybersecurity reveals a consistent pattern: attackers have always targeted the weakest point in the defense.</p><p>Early cyberattacks primarily exploited technical vulnerabilities. Over time, however, their focus expanded to financial systems, enterprise networks, and critical infrastructure. As defensive technologies evolved, attackers adapted their methods, recognizing that overcoming technical barriers was not always the most efficient path to success.</p><p>In many cases, influencing the decisions of the people operating a system proved easier than compromising the system itself.</p><p>Today, <strong>Generative AI</strong>, <strong>Large Language Models (LLMs)</strong>, voice cloning technologies, and synthetic digital identities are taking this evolution to an entirely new level. The success of cyberattacks no longer depends solely on software vulnerabilities or the sophistication of malicious code. Intelligence gathering, target profiling, trust-building, and persuasion can now be automated to a remarkable degree, making human-centric attacks both more scalable and significantly more convincing.</p><p>The concept of <strong>Cognitive Ransomware</strong> presented in this article should not be interpreted as a newly identified category of malware within the current cybersecurity literature. Rather, it is proposed as a <strong>conceptual framework</strong> for understanding the emerging class of AI-enabled threats that seek to manipulate human cognition rather than compromise information systems directly.</p><p><strong>The central argument advanced in this article is that future cyberattacks may rely less on technical encryption and increasingly on cognitive manipulation.</strong></p><p><strong>In other words, the objective may shift from rendering data inaccessible to influencing an individual&#8217;s decision-making process and psychologically constraining the range of perceived choices.</strong></p><p>It is important to emphasize that not every social engineering attack or AI-enabled fraud should be classified as <strong>Cognitive Ransomware</strong>.</p><p>Nevertheless, <strong>current trends indicate that cyberattacks are becoming increasingly personalized, leveraging trusted relationships and placing human behavior at the center of their operational strategy.</strong></p><p>From this perspective, <strong>Cognitive Ransomware</strong> provides a valuable conceptual lens through which emerging threats can be examined before they become widespread.</p><p><strong>This evolution also calls for a fundamental reassessment of organizational cybersecurity strategies.</strong></p><p>Building resilient infrastructures, maintaining secure and up-to-date systems, and protecting networks will remain indispensable. However, these technical safeguards alone will no longer be sufficient.</p><p>Equally critical are employees&#8217; critical thinking skills, verification habits, levels of digital awareness, and the resilience of organizational decision-making processes. Together, these human-centric capabilities are becoming integral components of modern cybersecurity.</p><p><strong>Ultimately, the defining characteristic of future cyberattacks may be that they target not only information systems, but also the people who make decisions on behalf of those systems.</strong></p><p>For decades, cybersecurity has been primarily understood as the discipline of protecting data. Today, however, that definition is expanding.</p><p>What must be protected is no longer information alone, but also the human capacity to interpret that information, evaluate it critically, and make informed decisions based upon it.</p><p>Consequently, the cybersecurity strategies of the coming years will need to integrate traditional technical controls with <strong>cognitive resilience</strong> as complementary pillars of defense.</p><p>The greatest cyber threat of the future may not be malware that encrypts our computers. Instead, it may be systems capable of influencing our decisions without encrypting a single file.</p><p>And if one day we believe we are making decisions freely, while every available option has already been invisibly shaped on our behalf, then what has been held hostage will not be our data, but our freedom to decide.</p><p><strong>Important Note:</strong></p><p>The term <strong>&#8220;Cognitive Ransomware&#8221;</strong>, as presented in this article, does <strong>not</strong> refer to an officially recognized attack category or malware classification within the current cybersecurity literature. Rather, it is a <strong>conceptual framework</strong> proposed by the author to describe a plausible future threat model, drawing upon recent advances in <strong>Generative AI</strong>, <strong>Agentic AI</strong>, social engineering, cognitive psychology, and decision-making manipulation.</p><p>Accordingly, the analyses and conclusions presented throughout this article should be understood as a forward-looking analytical perspective grounded in current technological trends, established research, and emerging threat patterns, rather than as a description of an existing or formally recognized class of cyberattacks.</p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor<br></strong><span>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,</span><br><span>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,</span><br><span>CompTIA Project+ Professional, CIW Security Analyst,</span><br><span>Certified Cyber Threat Intelligence Analyst,</span><br><span>Certified Information Security Executive&#8482;,</span><br><span>Senior Certified Leadership Practitioner.</span></p><p></p><h1>References</h1><ol><li><p>Anthropic. (2024). <em>Claude 3 model card</em>. </p><p>https://www.anthropic.com</p></li><li><p>Cialdini, R. B. (2021). <em>Influence: The psychology of persuasion</em> (Rev. ed.). Harper Business.</p></li><li><p>Kahneman, D. (2011). <em>Thinking, fast and slow</em>. Farrar, Straus and Giroux.</p></li><li><p>National Institute of Standards and Technology. (2024). <em>Artificial Intelligence Risk Management Framework (AI RMF 1.0)</em> (NIST AI 100-1). U.S. Department of Commerce. https://www.nist.gov/itl/ai-risk-management-framework</p></li><li><p>OpenAI. (2025). <em>GPT-4.1 system card</em>. </p><p>https://openai.com</p></li><li><p>OWASP Foundation. (2023). <em>OWASP Top 10 for Large Language Model Applications</em>. </p><p>https://owasp.org</p></li><li><p>Verizon. (2026). <em>2026 Data Breach Investigations Report (DBIR).</em>https://www.verizon.com/business/resources/reports/dbir/</p></li></ol><p></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Bilişsel Fidye Yazılımı (Cognitive Ransomware): Üretken ve Otonom Yapay Zeka ile İnsanın Karar Verme Süreçlerinin Rehin Alınması]]></title><description><![CDATA[(Agentic AI, Generative AI, Cognitive Ransomware)]]></description><link>https://ziyagokalp.substack.com/p/bilissel-fidye-yazlm-cognitive-ransomware</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/bilissel-fidye-yazlm-cognitive-ransomware</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Sat, 25 Jul 2026 23:27:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!55mD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5d852-181a-4900-81c3-a98d3fe7f2a0_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!55mD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5d852-181a-4900-81c3-a98d3fe7f2a0_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!55mD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5d852-181a-4900-81c3-a98d3fe7f2a0_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!55mD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5d852-181a-4900-81c3-a98d3fe7f2a0_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!55mD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5d852-181a-4900-81c3-a98d3fe7f2a0_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!55mD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5d852-181a-4900-81c3-a98d3fe7f2a0_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!55mD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5d852-181a-4900-81c3-a98d3fe7f2a0_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/08e5d852-181a-4900-81c3-a98d3fe7f2a0_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2293881,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/208465569?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5d852-181a-4900-81c3-a98d3fe7f2a0_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!55mD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5d852-181a-4900-81c3-a98d3fe7f2a0_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!55mD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5d852-181a-4900-81c3-a98d3fe7f2a0_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!55mD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5d852-181a-4900-81c3-a98d3fe7f2a0_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!55mD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5d852-181a-4900-81c3-a98d3fe7f2a0_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://creators.spotify.com/pod/profile/ziyagokalp/episodes/nsann-Karar-Verme-Srelerinin-Rehin-Alnmas-retken-ve-Otonom-Yapay-Zeka-ile-Bilisel-Fidye-Yazlm-e3mhqmc">PODCAST Linki</a></strong></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Giri&#351;</h1><p>Siber g&#252;venlik d&#252;nyas&#305; uzun y&#305;llar boyunca sald&#305;r&#305;lar&#305; teknik bir bak&#305;&#351; a&#231;&#305;s&#305;yla de&#287;erlendirdi. </p><p>G&#252;venlik a&#231;&#305;klar&#305; yaz&#305;l&#305;mlarda arand&#305;, sald&#305;r&#305;lar a&#287; trafi&#287;i &#252;zerinden analiz edildi ve savunma mekanizmalar&#305; b&#252;y&#252;k &#246;l&#231;&#252;de sistemleri korumaya odakland&#305;. G&#252;venlik duvarlar&#305; geli&#351;tirildi, antivir&#252;s yaz&#305;l&#305;mlar&#305; yayg&#305;nla&#351;t&#305;, kimlik do&#287;rulama y&#246;ntemleri g&#252;&#231;lendirildi ve kurumlar daha dayan&#305;kl&#305; altyap&#305;lar kurmaya ba&#351;lad&#305;. </p><p>Buna ra&#287;men sald&#305;r&#305;lar yaln&#305;zca devam etmekle kalmad&#305;, her ge&#231;en y&#305;l daha karma&#351;&#305;k ve daha etkili hale geldi.</p><p>Bu durum &#246;nemli bir ger&#231;e&#287;i ortaya &#231;&#305;kard&#305;; Bir kurumun en de&#287;erli varl&#305;&#287;&#305; yaln&#305;zca verileri de&#287;ildir. Ayn&#305; zamanda bu verileri y&#246;neten, yorumlayan ve onlar &#252;zerinden karar alan insanlard&#305;r.</p><p><strong>Modern fidye yaz&#305;l&#305;mlar&#305; bunun en &#231;arp&#305;c&#305; &#246;rneklerinden biridir. </strong></p><p>&#304;lk bak&#305;&#351;ta sald&#305;r&#305;n&#305;n hedefi dosyalard&#305;r. Veriler &#351;ifrelenir, sistemlere eri&#351;im engellenir ve &#231;&#246;z&#252;m anahtar&#305; kar&#351;&#305;l&#305;&#287;&#305;nda &#246;deme talep edilir. </p><p><strong>Ancak olay&#305;n psikolojik boyutuna bak&#305;ld&#305;&#287;&#305;nda farkl&#305; bir tablo ortaya &#231;&#305;kar</strong>. </p><p>Ayn&#305; sald&#305;r&#305;ya maruz kalan iki kurumdan biri fidyeyi &#246;derken di&#287;eri &#246;dememektedir. Baz&#305;lar&#305; birka&#231; g&#252;n i&#231;inde faaliyetlerine d&#246;nerken baz&#305;lar&#305; haftalarca operasyonlar&#305;n&#305; s&#252;rd&#252;remez. Teknik ko&#351;ullar benzer olsa bile verilen kararlar farkl&#305;d&#305;r.</p><blockquote><p><strong>Bu farkl&#305;l&#305;&#287;&#305;n nedeni kullan&#305;lan &#351;ifreleme algoritmas&#305; de&#287;ildir. As&#305;l belirleyici unsur, sald&#305;r&#305;n&#305;n insanlar &#252;zerinde olu&#351;turdu&#287;u bask&#305;d&#305;r. Zaman kaybetme korkusu, m&#252;&#351;teri g&#252;venini yitirme endi&#351;esi, finansal kay&#305;p, itibar riski ve belirsizlik hissi, teknik sald&#305;r&#305;n&#305;n ger&#231;ek etkisini belirleyen unsurlard&#305;r</strong>. </p></blockquote><p>Ba&#351;ka bir ifadeyle, fidye yaz&#305;l&#305;m&#305; yaln&#305;zca verileri de&#287;il, <strong>insanlar&#305;n karar verme s&#252;recini de bask&#305; alt&#305;na almaktad&#305;r.</strong></p><p>Buradan hareketle yeni bir soru ortaya &#231;&#305;kmaktad&#305;r.</p><p>Bir sald&#305;rgan ayn&#305; psikolojik bask&#305;y&#305; olu&#351;turabilmek i&#231;in ger&#231;ekten dosyalar&#305; &#351;ifrelemek zorunda m&#305;d&#305;r?</p><p>Ba&#351;ka bir ifadeyle, hedefin kararlar&#305;n&#305; do&#287;rudan etkileyebiliyorsa teknik &#351;ifrelemeye ihtiya&#231; kal&#305;r m&#305;?</p><p>Bu soru, &#252;retken yapay zekan&#305;n son y&#305;llarda g&#246;sterdi&#287;i geli&#351;imle birlikte her zamankinden daha anlaml&#305; hale gelmi&#351;tir. </p><blockquote><p><strong>B&#252;y&#252;k dil modelleri, ses klonlama sistemleri, deepfake teknolojileri ve sentetik dijital kimlikler, sald&#305;rganlar&#305;n yaln&#305;zca bilgisayarlar&#305; de&#287;il, insan davran&#305;&#351;lar&#305;n&#305; da hedef alabilecek yeni ara&#231;lara sahip olmas&#305;n&#305; sa&#287;lamaktad&#305;r</strong>. </p></blockquote><p>Bug&#252;n bir ki&#351;inin yaz&#305;&#351;ma tarz&#305; taklit edilebilmekte, sesi ger&#231;e&#287;inden ay&#305;rt edilemeyecek kadar ba&#351;ar&#305;l&#305; bi&#231;imde &#252;retilebilmekte ve hi&#231; var olmam&#305;&#351; insanlar g&#252;venilir dijital kimliklere d&#246;n&#252;&#351;t&#252;r&#252;lebilmektedir. </p><p>B&#246;yle bir ortamda sald&#305;r&#305;n&#305;n oda&#287;&#305; do&#287;al olarak teknik sistemlerden <strong>insan&#305;n bili&#351;sel s&#252;re&#231;lerine kaymaktad&#305;r.</strong></p><p>Bu makalede ele al&#305;nan <strong>Cognitive Ransomware</strong> kavram&#305;, tam olarak bu d&#246;n&#252;&#351;&#252;m&#252; a&#231;&#305;klamak amac&#305;yla &#246;nerilen kavramsal bir &#231;er&#231;evedir. </p><blockquote><p><strong>Burada s&#246;z edilen kavram, bug&#252;n resmi olarak tan&#305;mlanm&#305;&#351; yeni bir zararl&#305; yaz&#305;l&#305;m ailesini ifade etmemektedir. Bunun yerine, yapay zeka destekli manip&#252;lasyon tekniklerinin gelecekte alabilece&#287;i y&#246;n&#252; anlamaya yard&#305;mc&#305; olacak bir d&#252;&#351;&#252;nce modeli sunmaktad&#305;r.</strong></p></blockquote><p>Klasik ransomware sald&#305;r&#305;lar&#305;nda sald&#305;rgan, kurban&#305;n verilerine eri&#351;imini engeller. <strong>Cognitive Ransomware</strong> yakla&#351;&#305;m&#305;nda ise hedef, <strong>insan&#305;n bili&#351;sel s&#252;re&#231;leridir</strong>. </p><p>Ama&#231;; <strong>korku, g&#252;ven, otorite alg&#305;s&#305;, zaman bask&#305;s&#305; veya sosyal ili&#351;kiler &#252;zerinden bireyin karar se&#231;eneklerini daraltmakt&#305;r</strong>. </p><p>B&#246;ylece kurban teknik olarak &#246;zg&#252;r g&#246;r&#252;nse bile, psikolojik olarak yaln&#305;zca sald&#305;rgan&#305;n istedi&#287;i se&#231;ene&#287;i uygulamaya y&#246;nlendirilir.</p><p>Bu yakla&#351;&#305;m, siber g&#252;venli&#287;in yaln&#305;zca bilgi i&#351;lem sistemlerini korumaktan ibaret olmad&#305;&#287;&#305;n&#305; g&#246;stermektedir. <strong>Nitekim en geli&#351;mi&#351; g&#252;venlik duvar&#305; bile bir y&#246;neticinin korkular&#305;n&#305; analiz edemez, hi&#231;bir sald&#305;r&#305; tespit sistemi bir &#231;al&#305;&#351;an&#305;n g&#252;ven duygusunun istismar edildi&#287;ini anlayamaz.</strong> </p><p>Teknik savunmalar g&#252;&#231;lenirken insan davran&#305;&#351;lar&#305;n&#305;n sald&#305;r&#305; y&#252;zeyine d&#246;n&#252;&#351;mesi, g&#252;venlik anlay&#305;&#351;&#305;n&#305;n da yeniden tan&#305;mlanmas&#305;n&#305; zorunlu hale getirmektedir.</p><p>Bu noktada analiz edilmesi gereken konu i&#231;in &#351;u ifadeleri kullanmak ve sorgulamalar&#305; yapmak yanl&#305;&#351; olmayacakt&#305;r;<strong> Bir sistemi ele ge&#231;irmek mi daha kolayd&#305;r, yoksa o sistemi y&#246;neten insan&#305;n kararlar&#305;n&#305; de&#287;i&#351;tirmek mi?</strong></p><p>&#350;ayet ikinci se&#231;enek daha d&#252;&#351;&#252;k maliyetli, daha h&#305;zl&#305; ve daha g&#246;r&#252;nmez hale gelirse, gelece&#287;in fidye sald&#305;r&#305;lar&#305;nda rehin al&#305;nan &#351;ey dosyalar de&#287;il, <strong>insanlar&#305;n muhakeme yetene&#287;i olacakt&#305;r.</strong></p><p>Tam da bu noktada ger&#231;ek &#351;ifreleme, bilgisayarlarda de&#287;il, <strong>insan zihninde ger&#231;ekle&#351;ecektir.</strong></p><p></p><h1>&#304;nsan&#305;n Karar Verme S&#252;re&#231;leri Neden Yeni Sald&#305;r&#305; Y&#252;zeyidir?</h1><p>Bir siber sald&#305;r&#305;n&#305;n ba&#351;ar&#305;l&#305; olmas&#305; i&#231;in mutlaka karma&#351;&#305;k zararl&#305; yaz&#305;l&#305;mlara, s&#305;f&#305;r&#305;nc&#305; g&#252;n a&#231;&#305;klar&#305;na veya geli&#351;mi&#351; sald&#305;r&#305; ara&#231;lar&#305;na ihtiya&#231; duyuldu&#287;u d&#252;&#351;&#252;n&#252;l&#252;r. </p><p>,Oysa son y&#305;llarda ya&#351;anan bir&#231;ok olay, sald&#305;r&#305;lar&#305;n ba&#351;ar&#305;s&#305;n&#305; belirleyen en &#246;nemli unsurun teknoloji de&#287;il, insan oldu&#287;unu g&#246;stermektedir. Bunun nedeni olduk&#231;a basittir. Bilgisayarlar kurallara g&#246;re &#231;al&#305;&#351;&#305;r, insano&#287;lu ise <strong>alg&#305;lar&#305;, deneyimleri, duygular&#305; ve i&#231;inde bulunduklar&#305; ko&#351;ullar do&#287;rultusunda karar verir.</strong></p><p>Bu fark, insan&#305; yaln&#305;zca sistemlerin kullan&#305;c&#305;s&#305; olmaktan &#231;&#305;kar&#305;p sald&#305;r&#305; zincirinin en kritik halkas&#305; haline getirmektedir. </p><p>Nitekim yukar&#305;da ifade etmeye &#231;al&#305;&#351;t&#305;&#287;&#305;m gibi teknik sistemler belirli kurallar &#231;er&#231;evesinde &#246;ng&#246;r&#252;lebilir davran&#305;&#351;lar sergilerken, <strong>insan davran&#305;&#351;&#305; ayn&#305; durum kar&#351;&#305;s&#305;nda bile de&#287;i&#351;kenlik g&#246;sterebilir</strong>.</p><blockquote><p><strong>Yo&#287;un stres alt&#305;nda verilen bir karar ile sakin bir ortamda verilen karar &#231;o&#287;u zaman ayn&#305; de&#287;ildir. Benzer &#351;ekilde zaman bask&#305;s&#305;, otorite alg&#305;s&#305;, korku, g&#252;ven duygusu veya sosyal bask&#305; gibi fakt&#246;rler, bireyin normal ko&#351;ullarda almayaca&#287;&#305; kararlar&#305; almas&#305;na neden olabilir.</strong></p></blockquote><p><strong>Siber su&#231;lular&#305;n uzun y&#305;llard&#305;r sosyal m&#252;hendislik y&#246;ntemlerine yat&#305;r&#305;m yapmas&#305;n&#305;n temel nedeni de budur</strong>. </p><p>Bir g&#252;venlik duvar&#305;n&#305; a&#351;mak i&#231;in teknik uzmanl&#305;k gerekirken, bir insan&#305; yan&#305;ltmak &#231;o&#287;u zaman onun nas&#305;l d&#252;&#351;&#252;nd&#252;&#287;&#252;n&#252; anlamay&#305; gerektirir. <strong>Bu nedenle ba&#351;ar&#305;l&#305; sald&#305;r&#305;lar yaln&#305;zca sistemlerdeki a&#231;&#305;klar&#305; de&#287;il, insanlar&#305;n karar verme al&#305;&#351;kanl&#305;klar&#305;n&#305; da hedef al&#305;r.</strong></p><p><span>&#304;nsan beyni her g&#252;n binlerce karar vermek zorundad&#305;r. Bu kararlar&#305;n tamam&#305;n&#305; ayr&#305;nt&#305;l&#305; analiz ederek vermek m&#252;mk&#252;n olmad&#305;&#287;&#305; i&#231;in beyin, bili&#351;sel psikolojide </span><em><strong>heuristics</strong></em><span> olarak adland&#305;r&#305;lan zihinsel kestirme yollar&#305; kullan&#305;r. </span></p><p><span>Bu mekanizmalar g&#252;nl&#252;k ya&#351;am&#305; kolayla&#351;t&#305;r&#305;r, ancak ayn&#305; zamanda </span><strong><span>manip&#252;lasyona a&#231;&#305;k zay&#305;fl&#305;klar da olu&#351;turur</span></strong><span>. </span></p><blockquote><p><strong><span>Resm&#238; g&#246;r&#252;nen bir logo g&#252;ven hissi yaratabilir. &#220;st d&#252;zey bir y&#246;neticiden geldi&#287;i d&#252;&#351;&#252;n&#252;len bir talimat sorgulanmadan uygulanabilir. Acil oldu&#287;u belirtilen bir i&#351;lem, normalde yap&#305;lacak kontrollerin atlanmas&#305;na neden olabilir. Kalabal&#305;klar&#305;n do&#287;ru kabul etti&#287;i bir bilgi daha kolay benimsenebilir.</span></strong><span> </span></p></blockquote><p><span>B&#252;t&#252;n bunlar, insan beyninin do&#287;al &#231;al&#305;&#351;ma bi&#231;iminden kaynaklan&#305;r ve tek ba&#351;&#305;na bir g&#252;venlik zaaf&#305; olarak de&#287;erlendirilmemelidir.</span></p><p>Tam da bu nedenle modern siber sald&#305;r&#305;lar, teknik g&#252;venlik kontrollerini a&#351;maktan &#231;ok, bu do&#287;al karar mekanizmalar&#305;n&#305; kendi lehine kullanmaya &#231;al&#305;&#351;maktad&#305;r. </p><blockquote><p><strong>Sald&#305;rgan&#305;n amac&#305; &#231;o&#287;u zaman kurban&#305;n bilgisayar&#305;n&#305; ele ge&#231;irmek de&#287;ildir. Kurban&#305;n belirli bir davran&#305;&#351;&#305; kendi iste&#287;iyle ger&#231;ekle&#351;tirmesini sa&#287;lamakt&#305;r. Zararl&#305; bir ba&#287;lant&#305;ya t&#305;klamak, sahte bir &#246;deme talimat&#305;n&#305; onaylamak, kimlik bilgilerini payla&#351;mak ya da g&#252;venlik prosed&#252;rlerini ge&#231;ici olarak devre d&#305;&#351;&#305; b&#305;rakmak gibi eylemler, teknik a&#231;&#305;dan basit g&#246;r&#252;nse de &#231;o&#287;u sald&#305;r&#305;n&#305;n ba&#351;ar&#305; noktas&#305;d&#305;r.</strong></p></blockquote><p></p><p>Kurumsal ortamlarda bu durum daha da belirgin hale gelir. G&#252;n i&#231;inde y&#252;zlerce e-posta alan, s&#252;rekli toplant&#305;lar aras&#305;nda &#231;al&#305;&#351;an ve ayn&#305; anda bir&#231;ok operasyonel karar&#305; y&#246;netmek zorunda kalan &#231;al&#305;&#351;anlar, do&#287;al olarak bili&#351;sel y&#252;k alt&#305;nda g&#246;rev yapmaktad&#305;r. </p><p>Dikkatin s&#252;rekli b&#246;l&#252;nd&#252;&#287;&#252; bu ortamda her talimat&#305; ayr&#305;nt&#305;l&#305; bi&#231;imde do&#287;rulamak pratik de&#287;ildir. &#304;&#351;te sald&#305;rganlar da tam olarak bu &#231;al&#305;&#351;ma d&#252;zenini avantaja &#231;evirmektedir. <strong>Nitekim g&#252;venlik a&#231;&#305;klar&#305; yaln&#305;zca yaz&#305;l&#305;mlarda de&#287;il, i&#351; s&#252;re&#231;lerinde ve insan davran&#305;&#351;lar&#305;nda da ortaya &#231;&#305;kmaktad&#305;r.</strong></p><p><strong>&#304;nsan&#305; di&#287;er sistemlerden ay&#305;ran bir ba&#351;ka &#246;zellik ise g&#252;ven ili&#351;kisi kurabilmesidir. </strong></p><p><strong>G&#252;ven, i&#351; hayat&#305;n&#305;n vazge&#231;ilmez unsurlar&#305;ndan biridir. Kurumlar ekip &#231;al&#305;&#351;mas&#305; sayesinde &#252;retken olur, y&#246;neticiler &#231;al&#305;&#351;anlar&#305;na yetki devreder, &#231;al&#305;&#351;anlar ise birlikte &#231;al&#305;&#351;t&#305;klar&#305; ki&#351;ilerin iyi niyetli oldu&#287;una dair varsay&#305;mlarla hareket eder. </strong></p><blockquote><p><strong>Bu varsay&#305;m i&#351; ya&#351;am&#305;n&#305; m&#252;mk&#252;n k&#305;lar, ancak ayn&#305; zamanda k&#246;t&#252; niyetli ki&#351;iler taraf&#305;ndan istismar edilebilir. Bir sald&#305;rgan teknik sistemleri kand&#305;rmak yerine &#246;nce g&#252;ven ili&#351;kisini hedef ald&#305;&#287;&#305;nda, &#231;o&#287;u zaman &#231;ok daha d&#252;&#351;&#252;k maliyetle ayn&#305; sonuca ula&#351;abilir.</strong></p></blockquote><p>Bu nedenle g&#252;n&#252;m&#252;zde sald&#305;r&#305; y&#252;zeyi yaln&#305;zca sunucular, istemciler, mobil cihazlar veya bulut altyap&#305;lar&#305;yla s&#305;n&#305;rl&#305; de&#287;ildir. Karar veren insanlar da en az bu sistemler kadar kritik bir g&#252;venlik unsurudur. </p><p>&#214;zellikle <strong>kritik altyap&#305;lar, finans kurulu&#351;lar&#305;, enerji tesisleri, sa&#287;l&#305;k kurumlar&#305;</strong> ve <strong>end&#252;striyel kontrol sistemleri</strong> d&#252;&#351;&#252;n&#252;ld&#252;&#287;&#252;nde, tek bir yanl&#305;&#351; karar&#305;n teknik bir g&#252;venlik a&#231;&#305;&#287;&#305;ndan &#231;ok daha b&#252;y&#252;k sonu&#231;lar do&#287;urabilece&#287;i a&#231;&#305;kt&#305;r. </p><p>Yanl&#305;&#351; zamanda verilen bir onay, do&#287;rulanmadan kabul edilen bir talimat veya g&#252;venilir san&#305;lan bir ki&#351;iyle payla&#351;&#305;lan bilgi, milyonlarca dolarl&#305;k zarara ya da fiziksel g&#252;venli&#287;i etkileyen sonu&#231;lara yol a&#231;abilir.</p><p>Bu noktada &#246;nemli olan, insan&#305;n g&#252;venlik zincirinin "<strong>en zay&#305;f halkas&#305;</strong>" oldu&#287;unu s&#246;ylemek de&#287;ildir. <strong>B&#246;yle bir yakla&#351;&#305;m eksik kal&#305;r</strong>. &#304;<strong>nsan ayn&#305; zamanda g&#252;venlik zincirinin en g&#252;&#231;l&#252; savunma mekanizmas&#305; da olabilir</strong>. Ancak bunun i&#231;in &#246;nce insan&#305;n yaln&#305;zca sistemleri kullanan bir akt&#246;r de&#287;il, <strong>do&#287;rudan korunmas&#305; gereken bir sald&#305;r&#305; y&#252;zeyi oldu&#287;unun kabul edilmesi gerekir.</strong></p><p><span>Bu kabul, </span><strong>Cognitive Ransomware</strong><span> kavram&#305;n&#305;n temelini olu&#351;turmaktad&#305;r. </span></p><p><span>&#350;ayet sald&#305;rgan&#305;n amac&#305; insan&#305;n kararlar&#305;n&#305; y&#246;nlendirmekse, bu s&#252;re&#231; art&#305;k klasik sosyal m&#252;hendisli&#287;in &#246;tesine ge&#231;mektedir. Nitekim hedef yaln&#305;zca bir eylem yapt&#305;rmak de&#287;il, bireyin se&#231;eneklerini daraltarak belirli bir karar&#305; ka&#231;&#305;n&#305;lmaz hale getirmektir. </span></p><p><strong><span>Bu d&#246;n&#252;&#351;&#252;m&#252; m&#252;mk&#252;n k&#305;lan en &#246;nemli unsur ise hi&#231; &#351;&#252;phesiz AI yani Yapay Zekad&#305;r.</span></strong><span> </span></p><blockquote><p><strong><span>Yapay zeka, sald&#305;rganlara ilk kez milyonlarca ki&#351;iyi ayn&#305; anda analiz etme, her hedef i&#231;in farkl&#305; bir senaryo olu&#351;turma ve manip&#252;lasyonu b&#252;y&#252;k &#246;l&#231;&#252;de otomatikle&#351;tirme imkan&#305; sunmaktad&#305;r.</span></strong></p></blockquote><p></p><h1>Yapay Zeka Sald&#305;r&#305;lar&#305;n &#214;l&#231;e&#287;ini ve Niteli&#287;ini Nas&#305;l De&#287;i&#351;tiriyor?</h1><p>Siber g&#252;venlik tarihinde kullan&#305;lan ara&#231;lar de&#287;i&#351;tik&#231;e sald&#305;r&#305; y&#246;ntemleri de de&#287;i&#351;mi&#351;tir. &#304;nternetin yayg&#305;nla&#351;mas&#305; a&#287; tabanl&#305; sald&#305;r&#305;lar&#305;, mobil cihazlar&#305;n hayat&#305;n merkezine yerle&#351;mesi mobil zararl&#305; yaz&#305;l&#305;mlar&#305;, bulut bili&#351;imin geli&#351;mesi ise bulut altyap&#305;lar&#305;n&#305; hedef alan yeni tehditleri ortaya &#231;&#305;karm&#305;&#351;t&#305;r. </p><p>Bug&#252;n ise benzer bir d&#246;n&#252;&#351;&#252;m yapay zeka ile ya&#351;anmaktad&#305;r. </p><p>Ancak &#246;nceki teknolojik de&#287;i&#351;imlerden farkl&#305; olarak yapay zeka yaln&#305;zca yeni bir sald&#305;r&#305; arac&#305; sunmamakta, sald&#305;r&#305;lar&#305;n planlanma, haz&#305;rlanma ve y&#252;r&#252;t&#252;lme bi&#231;imini k&#246;kten de&#287;i&#351;tirmektedir.</p><p>Ge&#231;mi&#351;te ba&#351;ar&#305;l&#305; bir sosyal m&#252;hendislik operasyonu &#246;nemli &#246;l&#231;&#252;de insan eme&#287;ine dayan&#305;yordu. Sald&#305;rgan&#305;n hedefini ara&#351;t&#305;rmas&#305;, kurumun yap&#305;s&#305;n&#305; &#246;&#287;renmesi, g&#252;ven olu&#351;turacak bir senaryo haz&#305;rlamas&#305; ve do&#287;ru zaman&#305; beklemesi gerekiyordu. Bu s&#252;re&#231; haftalar, hatta aylar s&#252;rebiliyor; her yeni hedef i&#231;in ayn&#305; &#231;al&#305;&#351;malar&#305;n yeniden yap&#305;lmas&#305;n&#305; gerektiriyordu. Dolay&#305;s&#305;yla sald&#305;r&#305;lar&#305;n &#246;l&#231;e&#287;i, sald&#305;rgan&#305;n sahip oldu&#287;u insan kayna&#287;&#305;yla s&#305;n&#305;rl&#305;yd&#305;.</p><p><strong>&#220;retken yapay zeka bu dengeyi de&#287;i&#351;tirmektedir.</strong> </p><p><strong>B&#252;y&#252;k dil modelleri, do&#287;al dil i&#351;leme sistemleri ve otonom yapay zeka ajanlar&#305; sayesinde daha &#246;nce manuel olarak y&#252;r&#252;t&#252;len bir&#231;ok s&#252;re&#231; art&#305;k otomatik hale getirilebilmektedir.</strong> </p><blockquote><p><strong>Bir hedef hakk&#305;nda a&#231;&#305;k kaynaklardan bilgi toplanmas&#305;, bu bilgilerin analiz edilmesi, hedefe uygun ileti&#351;im dili belirlenmesi ve farkl&#305; senaryolar&#305;n olu&#351;turulmas&#305; art&#305;k &#231;ok daha k&#305;sa s&#252;rede ger&#231;ekle&#351;tirilebilmektedir. </strong></p><p><strong>B&#246;ylece sald&#305;rgan&#305;n en &#246;nemli avantaj&#305; teknik bilgi de&#287;il, b&#252;y&#252;k miktarda veriyi anlamland&#305;rabilme kapasitesi haline gelmektedir.</strong></p></blockquote><p>Bu d&#246;n&#252;&#351;&#252;m&#252;n temelini <strong>a&#231;&#305;k kaynak istihbarat&#305; (OSINT)</strong> olu&#351;turmaktad&#305;r. </p><p><strong>G&#252;n&#252;m&#252;zde bireyler ve kurumlar, fark&#305;nda olmadan dijital ortamda b&#252;y&#252;k miktarda iz b&#305;rakmaktad&#305;r. Sosyal medya payla&#351;&#305;mlar&#305;, profesyonel a&#287;lar, &#351;irket internet siteleri, konferans konu&#351;malar&#305;, bas&#305;n a&#231;&#305;klamalar&#305;, i&#351;e al&#305;m ilanlar&#305; ve kamuya a&#231;&#305;k belgeler bir araya getirildi&#287;inde, hedef hakk&#305;nda olduk&#231;a ayr&#305;nt&#305;l&#305; bir profil olu&#351;turulabilmektedir.</strong> </p><p><strong>Yapay zeka bu bilgileri yaln&#305;zca toplamakla kalmaz, aralar&#305;ndaki ili&#351;kileri de analiz ederek anlaml&#305; bir b&#252;t&#252;n haline getirir.</strong></p><p>&#214;rne&#287;in bir kurumun &#231;al&#305;&#351;an profili incelendi&#287;inde hangi ekiplerin birlikte &#231;al&#305;&#351;t&#305;&#287;&#305;, karar s&#252;re&#231;lerinde kimlerin etkili oldu&#287;u, hangi y&#246;neticilerin kamuoyunda daha g&#246;r&#252;n&#252;r oldu&#287;u ve kurum i&#231;inde hangi ileti&#351;im dilinin benimsendi&#287;i &#231;&#305;kar&#305;labilir. </p><p><strong>Ayn&#305; &#351;ekilde bireysel d&#252;zeyde yap&#305;lan analizler, ki&#351;inin mesleki ilgi alanlar&#305;n&#305;, &#231;al&#305;&#351;ma al&#305;&#351;kanl&#305;klar&#305;n&#305;, kulland&#305;&#287;&#305; terminolojiyi ve ileti&#351;im tarz&#305;n&#305; ortaya koyabilir. </strong></p><p>Bu bilgiler tek ba&#351;&#305;na zararl&#305; de&#287;ildir, ancak do&#287;ru &#351;ekilde bir araya getirildi&#287;inde son derece ikna edici senaryolar&#305;n olu&#351;turulmas&#305;na imkan sa&#287;lar.</p><p><span>Yapay zekan&#305;n en dikkat &#231;ekici katk&#305;lar&#305;ndan biri de </span><strong>ki&#351;iselle&#351;tirme kapasitesidir</strong><span>. </span></p><blockquote><p><strong><span>Ge&#231;mi&#351;te binlerce ki&#351;iye ayn&#305; i&#231;erikte oltalama e-postalar&#305; g&#246;nderilirken, bug&#252;n her hedef i&#231;in farkl&#305; i&#231;erikler &#252;retilebilmektedir.</span></strong><span> </span></p><p><strong><span>Ayn&#305; kurumda &#231;al&#305;&#351;an iki ki&#351;iye g&#246;nderilen mesajlar&#305;n dili, kullan&#305;lan teknik ifadeler, hitap bi&#231;imi ve senaryo birbirinden tamamen farkl&#305; olabilir. Bunun nedeni, yapay zekan&#305;n her bireyi ayr&#305; bir profil olarak de&#287;erlendirebilmesidir.</span></strong></p></blockquote><p>Bu ki&#351;iselle&#351;tirme yaln&#305;zca yaz&#305;l&#305; i&#231;eriklerle s&#305;n&#305;rl&#305; de&#287;ildir. </p><p>Son y&#305;llarda <strong>ses sentezi</strong> ve <strong>g&#246;r&#252;nt&#252; &#252;retim teknolojileri</strong>ndeki geli&#351;meler, dijital ileti&#351;imin g&#252;venilirli&#287;ini de sorgulan&#305;r hale getirmi&#351;tir. </p><p>Birka&#231; dakikal&#305;k ses kayd&#305; kullan&#305;larak bir ki&#351;inin ses tonu, konu&#351;ma bi&#231;imi ve vurgular&#305; y&#252;ksek do&#287;rulukla taklit edilebilmektedir. Benzer &#351;ekilde geli&#351;mi&#351; g&#246;r&#252;nt&#252; &#252;retim sistemleri, ger&#231;ek ki&#351;ilerle ay&#305;rt edilmesi olduk&#231;a g&#252;&#231; videolar olu&#351;turabilmektedir. <strong>Bu teknolojiler, g&#246;rsel veya i&#351;itsel do&#287;rulamaya duyulan g&#252;veni &#246;nemli &#246;l&#231;&#252;de azaltmaktad&#305;r.</strong></p><p>Daha da &#246;nemlisi, bu teknolojiler birbirinden ba&#287;&#305;ms&#305;z kullan&#305;lmamaktad&#305;r. Ayn&#305; operasyon i&#231;erisinde <strong>a&#231;&#305;k kaynak istihbarat&#305;</strong>, <strong>b&#252;y&#252;k dil modelleri</strong>, <strong>ses klonlama</strong>, <strong>g&#246;r&#252;nt&#252; &#252;retimi</strong> ve <strong>otomatik i&#231;erik olu&#351;turma</strong> sistemleri birlikte &#231;al&#305;&#351;abilmektedir. </p><p><strong>B&#246;ylece sald&#305;rgan yaln&#305;zca sahte bir e-posta g&#246;ndermek yerine, hedefe &#246;zel haz&#305;rlanm&#305;&#351; &#231;ok katmanl&#305; bir manip&#252;lasyon s&#252;reci olu&#351;turabilmektedir.</strong></p><p>Bu d&#246;n&#252;&#351;&#252;m, sald&#305;r&#305;lar&#305;n &#246;l&#231;e&#287;ini de &#246;nemli &#246;l&#231;&#252;de de&#287;i&#351;tirmektedir. Ge&#231;mi&#351;te karma&#351;&#305;k sosyal m&#252;hendislik operasyonlar&#305; belirli ki&#351;i veya kurumlara y&#246;nelik y&#252;r&#252;t&#252;l&#252;rken, yapay zeka sayesinde ayn&#305; y&#246;ntemlerin &#231;ok daha geni&#351; hedef kitlelerine uygulanmas&#305; m&#252;mk&#252;n hale gelmektedir. </p><p><strong>Bir ba&#351;ka ifadeyle, ki&#351;iye &#246;zel sald&#305;r&#305;lar art&#305;k yaln&#305;zca &#252;st d&#252;zey y&#246;neticiler i&#231;in de&#287;il, s&#305;radan &#231;al&#305;&#351;anlar i&#231;in de ekonomik olarak uygulanabilir hale gelmektedir.</strong></p><p>Yapay zekan&#305;n sundu&#287;u bir di&#287;er avantaj ise <strong>s&#252;rekliliktir</strong>. </p><p>Geleneksel sald&#305;r&#305;larda sald&#305;rgan ile hedef aras&#305;ndaki ileti&#351;im &#231;o&#287;unlukla k&#305;sa s&#252;reliydi. <strong>Oysa yapay zeka destekli sistemler haftalar hatta aylar boyunca tutarl&#305; ileti&#351;im kurabilir, &#246;nceki konu&#351;malar&#305; hat&#305;rlayabilir ve yeni bilgileri kullanarak senaryolar&#305;n&#305; g&#252;ncelleyebilir.</strong> </p><p><strong>Bu durum &#246;zellikle g&#252;ven ili&#351;kisi kurulmas&#305;na dayanan sald&#305;r&#305;lar&#305; &#231;ok daha etkili hale getirmektedir.</strong></p><p>Bu noktada ortaya &#231;&#305;kan de&#287;i&#351;im, yaln&#305;zca sald&#305;r&#305;lar&#305;n daha inand&#305;r&#305;c&#305; hale gelmesi de&#287;ildir. </p><blockquote><p><strong>As&#305;l de&#287;i&#351;im, sald&#305;r&#305;n&#305;n dinamik bir yap&#305;ya kavu&#351;mas&#305;d&#305;r. Yapay zeka, hedefin verdi&#287;i her tepkiyi analiz ederek bir sonraki ad&#305;m&#305; buna g&#246;re belirleyebilir</strong>. </p></blockquote><p>&#350;ayet hedef &#351;&#252;phe duyuyorsa ileti&#351;im dili de&#287;i&#351;tirilebilir, farkl&#305; kanallar kullan&#305;labilir veya yeni do&#287;rulama unsurlar&#305; eklenebilir. B&#246;ylece sald&#305;r&#305; tek seferlik bir giri&#351;im olmaktan &#231;&#305;kar, <strong>hedefin davran&#305;&#351;&#305;na g&#246;re s&#252;rekli uyum sa&#287;layan bir s&#252;rece d&#246;n&#252;&#351;&#252;r</strong>.</p><p><span>Bu noktada </span><strong>Cognitive Ransomware</strong><span>, klasik sosyal m&#252;hendislikten ayr&#305;lmaya ba&#351;lar. </span></p><p><span>Nitekim burada ama&#231; yaln&#305;zca g&#252;ven olu&#351;turmak ya da tek bir eylemi ger&#231;ekle&#351;tirmek de&#287;ildir. Ama&#231;, hedefin d&#252;&#351;&#252;nce s&#252;recini a&#351;ama a&#351;ama y&#246;nlendirmek, alternatiflerini daraltmak ve sonunda belirli bir karar&#305; do&#287;al bir se&#231;im gibi g&#246;rmesini sa&#287;lamakt&#305;r. </span></p><p><span>Yapay zeka, bu s&#252;recin her a&#351;amas&#305;n&#305; h&#305;zland&#305;ran ve &#246;l&#231;eklendiren temel unsur olarak &#246;ne &#231;&#305;kmaktad&#305;r.</span></p><p></p><h1>Sonu&#231;</h1><p>Siber g&#252;venlik tarihi incelendi&#287;inde, sald&#305;r&#305;lar&#305;n s&#252;rekli olarak savunman&#305;n en zay&#305;f noktas&#305;na y&#246;neldi&#287;i g&#246;r&#252;lmektedir. </p><p>&#304;lk d&#246;nemlerde teknik a&#231;&#305;klardan yararlanan sald&#305;r&#305;lar zamanla finansal sistemleri, kurumsal a&#287;lar&#305; ve kritik altyap&#305;lar&#305; hedef ald&#305;. Savunma teknolojileri geli&#351;tik&#231;e sald&#305;rganlar da y&#246;ntemlerini de&#287;i&#351;tirdi ve teknik engelleri a&#351;man&#305;n her zaman en verimli yol olmad&#305;&#287;&#305;n&#305; fark etti. </p><p>&#199;o&#287;u durumda, bir sistemi k&#305;rmaktan daha kolay olan &#351;ey, o sistemi y&#246;neten insan&#305;n kararlar&#305;n&#305; etkilemekti.</p><p>Bug&#252;n &#252;retken yapay zeka, b&#252;y&#252;k dil modelleri, ses klonlama teknolojileri ve sentetik dijital kimlikler bu d&#246;n&#252;&#351;&#252;m&#252; yeni bir boyuta ta&#351;&#305;maktad&#305;r. Art&#305;k sald&#305;r&#305;lar&#305;n ba&#351;ar&#305;s&#305; yaln&#305;zca yaz&#305;l&#305;m a&#231;&#305;klar&#305;na veya zararl&#305; kodlar&#305;n karma&#351;&#305;kl&#305;&#287;&#305;na ba&#287;l&#305; de&#287;ildir. Bilgi toplama, hedef analizi, g&#252;ven olu&#351;turma ve ikna s&#252;re&#231;leri b&#252;y&#252;k &#246;l&#231;&#252;de otomatikle&#351;tirilebilmekte, <strong>bu da insan odakl&#305; sald&#305;r&#305;lar&#305; hem daha &#246;l&#231;eklenebilir hem de daha inand&#305;r&#305;c&#305; hale getirmektedir.</strong></p><p>Bu makalede ele ald&#305;&#287;&#305;m <strong>Cognitive Ransomware</strong>, mevcut literat&#252;rde tan&#305;mlanm&#305;&#351; yeni bir zararl&#305; yaz&#305;l&#305;m t&#252;r&#252; olarak de&#287;il, <strong>gelece&#287;in tehditlerini anlamaya yard&#305;mc&#305; olabilecek kavramsal bir model olarak de&#287;erlendirilmelidir.</strong> </p><p>Bu makalemdeki yakla&#351;&#305;m&#305;n temel iddias&#305;, gelecekte baz&#305; sald&#305;r&#305;lar&#305;n teknik &#351;ifreleme yerine bili&#351;sel manip&#252;lasyona dayanabilece&#287;idir. </p><p><strong>Ba&#351;ka bir ifadeyle ama&#231;, verileri eri&#351;ilemez hale getirmekten &#231;ok, bireyin karar verme s&#252;recini y&#246;nlendirmek ve se&#231;eneklerini psikolojik olarak daraltmak olabilir.</strong></p><p>Hi&#231; &#351;&#252;phesiz bug&#252;n ya&#351;anan her sosyal m&#252;hendislik sald&#305;r&#305;s&#305;n&#305; veya her yapay zeka destekli doland&#305;r&#305;c&#305;l&#305;&#287;&#305; <strong>Cognitive Ransomware</strong> olarak tan&#305;mlamak do&#287;ru de&#287;ildir. </p><p>Ancak <strong>mevcut e&#287;ilimler, sald&#305;r&#305;lar&#305;n giderek daha fazla ki&#351;iselle&#351;ti&#287;ini, g&#252;ven ili&#351;kilerinden yararland&#305;&#287;&#305;n&#305; ve insan davran&#305;&#351;lar&#305;n&#305; merkeze ald&#305;&#287;&#305;n&#305; g&#246;stermektedir.</strong> </p><p><strong>Bu nedenle kavram, gelecekte kar&#351;&#305;la&#351;abilece&#287;imiz tehditleri bug&#252;nden tart&#305;&#351;abilmek i&#231;in yararl&#305; bir d&#252;&#351;&#252;nce &#231;er&#231;evesi sunmaktad&#305;r.</strong></p><p>Bu durum, kurumlar&#305;n g&#252;venlik anlay&#305;&#351;&#305;n&#305; da yeniden de&#287;erlendirmesini gerektirmektedir. </p><p>G&#252;&#231;l&#252; altyap&#305;lar kurmak, sistemleri g&#252;ncel tutmak ve a&#287;lar&#305; korumak her zamankinden daha &#246;nemli olmaya devam edecektir. </p><p>Ancak bunlara ek olarak, &#231;al&#305;&#351;anlar&#305;n <strong>ele&#351;tirel d&#252;&#351;&#252;nme becerileri, do&#287;rulama al&#305;&#351;kanl&#305;klar&#305;, dijital fark&#305;ndal&#305;k d&#252;zeyleri ve kurumsal karar mekanizmalar&#305;n&#305;n dayan&#305;kl&#305;l&#305;&#287;&#305; da g&#252;venli&#287;in ayr&#305;lmaz bir par&#231;as&#305; haline gelmektedir</strong>. </p><p>Nitekim gelece&#287;in sald&#305;r&#305;lar&#305; yaln&#305;zca sistemlere de&#287;il, <strong>sistemler ad&#305;na karar veren insanlara y&#246;nelme e&#287;ilimindedir.</strong></p><p>Siber g&#252;venlik uzun y&#305;llar boyunca verileri koruma disiplini olarak tan&#305;mland&#305;. G&#252;n&#252;m&#252;zde ise bu tan&#305;m giderek geni&#351;lemektedir. </p><p><strong>Korunmas&#305; gereken yaln&#305;zca bilgi de&#287;il, o bilgiyi yorumlayan, de&#287;erlendiren ve ona g&#246;re hareket eden insan&#305;n muhakeme yetene&#287;idir.</strong> </p><p>Bu nedenle &#246;n&#252;m&#252;zdeki y&#305;llarda g&#252;venlik stratejileri <strong>teknik kontroller ile bili&#351;sel dayan&#305;kl&#305;l&#305;&#287;&#305; birlikte ele almak zorunda kalacakt&#305;r.</strong></p><p>Gelece&#287;in en b&#252;y&#252;k siber tehdidi, bilgisayarlar&#305;m&#305;z&#305; kilitleyen zararl&#305; yaz&#305;l&#305;mlar olmayacakt&#305;r. Tehdit, hi&#231;bir dosyay&#305; &#351;ifrelemeden bize yanl&#305;&#351; kararlar ald&#305;rabilen sistemler olacakt&#305;r.</p><p>Ve &#351;ayet bir g&#252;n &#246;zg&#252;rce se&#231;im yapt&#305;&#287;&#305;m&#305;z&#305; d&#252;&#351;&#252;n&#252;rken asl&#305;nda b&#252;t&#252;n se&#231;enekler g&#246;r&#252;nmez bi&#231;imde bizim ad&#305;m&#305;za belirlenmi&#351;se, o g&#252;n rehin al&#305;nan &#351;ey verilerimiz de&#287;il, <strong>karar verme &#246;zg&#252;rl&#252;&#287;&#252;m&#252;z olacakt&#305;r !</strong></p><p></p><p><strong>&#214;nemli Bilgi:</strong> Bu makalede tan&#305;mlad&#305;&#287;&#305;m &#8220;<strong>Cognitive Ransomware</strong>&#8220; kavram&#305;, mevcut literat&#252;rde yer alan resm&#238; bir sald&#305;r&#305; s&#305;n&#305;fland&#305;rmas&#305;n&#305; ifade etmemektedir. Kavram, &#252;retken yapay zeka (Generative AI), otonom yapay zeka ajanlar&#305; (Agentic AI), sosyal m&#252;hendislik, bili&#351;sel psikoloji ve karar verme manip&#252;lasyonu alanlar&#305;ndaki g&#252;ncel geli&#351;imlerden hareketle gelece&#287;e y&#246;nelik olas&#305; bir tehdit modelini a&#231;&#305;klamak amac&#305;yla taraf&#305;mca &#246;nerilen kavramsal bir &#231;er&#231;evedir.</p><p>&#214;te yandan makalede yer alan t&#252;m de&#287;erlendirmelerim, mevcut teknolojik e&#287;ilimler ve literat&#252;rde tan&#305;mlanan tehditler temel al&#305;narak gelece&#287;e y&#246;nelik analitik bir perspektif sunma ama&#231;l&#305;d&#305;r. </p><p><strong><br></strong></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br><span>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,</span><br><span>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,</span><br><span>CompTIA Project+ Professional, CIW Security Analyst,</span><br><span>Certified Cyber Threat Intelligence Analyst,</span><br><span>Certified Information Security Executive&#8482;,</span><br><span>Senior Certified Leadership Practitioner.</span></p><p></p><h1>Kaynak&#231;a:</h1><p><strong>1. Kahneman, D. (2011).</strong><br><em>Thinking, Fast and Slow.</em><br>New York: Farrar, Straus and Giroux.<br><em>&#304;nsan karar verme s&#252;re&#231;leri, bili&#351;sel &#246;nyarg&#305;lar (cognitive biases), sezgisel d&#252;&#351;&#252;nme (heuristics) ve karar mekanizmalar&#305; i&#231;in temel kaynak olarak kullan&#305;lm&#305;&#351;t&#305;r.</em></p><p><strong>2. Cialdini, R. B. (2021).</strong><br><em>Influence: The Psychology of Persuasion</em><span> (Revised Edition).</span><br><span>Harper Business.<br></span><em><span>G&#252;ven olu&#351;turma, otorite, sosyal kan&#305;t, k&#305;tl&#305;k ve ikna psikolojisi &#252;zerine &#231;al&#305;&#351;malar </span>kaynak olarak kullan&#305;lm&#305;&#351;t&#305;r<span>.</span></em></p><p><strong>3. OWASP Foundation. (2023).</strong><br><em>OWASP Top 10 for Large Language Model Applications.<br>LLM tabanl&#305; g&#252;venlik riskleri, prompt injection, model manip&#252;lasyonu ve yapay zeka g&#252;venli&#287;i a&#231;&#305;s&#305;ndan g&#252;ncel ve teknik bir kaynak olarak kullan&#305;lm&#305;&#351;t&#305;r.</em></p><p><strong>4. National Institute of Standards and Technology (NIST). (2024).</strong><br><em>Artificial Intelligence Risk Management Framework (AI RMF 1.0).</em><br><span>NIST.<br></span><em><span>Yapay zeka sistemlerinin riskleri, g&#252;venilirli&#287;i ve y&#246;neti&#351;imi konusunda otoriter bir referans </span>olarak kullan&#305;lm&#305;&#351;t&#305;r.</em></p><p><strong>5. OpenAI. (2025).</strong><br><em>GPT-4.1 System Card</em> (veya makaleyi yay&#305;mlad&#305;&#287;&#305;n tarihte en g&#252;ncel System Card).<br><em>&#220;retken Yapay Zeka&#8217;n&#305;n (Generative AI) yetenekleri, s&#305;n&#305;rlar&#305; ve olas&#305; riskleri i&#231;in teknik dayanak sa&#287;lamak &#252;zere kullan&#305;lm&#305;&#351;t&#305;r.</em></p><p><strong>6. Anthropic. (2024).</strong><br><em>The Claude 3 Model Card.<br>Agentic AI, geli&#351;mi&#351; muhakeme, uzun s&#252;reli g&#246;rev y&#252;r&#252;tme ve otonom davran&#305;&#351; yetenekleri &#252;zerine g&#252;ncel bilgiler i&#231;ermektedir, bu nedenle bir referans olarak kullan&#305;lm&#305;&#351;t&#305;r.</em></p><p><strong>7. Verizon. (2026).</strong><br><em>2026 Data Breach Investigations Report (DBIR).<br>&#304;nsan fakt&#246;r&#252;, sosyal m&#252;hendislik ve kimlik bilgilerinin k&#246;t&#252;ye kullan&#305;lmas&#305;yla ilgili g&#252;ncel istatistikler sunmaktad&#305;r. Bu rapor, makalemde &#8220;insan yeni sald&#305;r&#305; y&#252;zeyidir&#8221; arg&#252;man&#305;n&#305; desteklemek ad&#305;na kullan&#305;lm&#305;&#351;t&#305;r.</em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Maritime Cyber Security: Dijital Denizlerde Görünmeyen Savaş]]></title><description><![CDATA[PODCAST LinkiThanks for reading Ziya's Substack!]]></description><link>https://ziyagokalp.substack.com/p/maritime-cyber-security-dijital-denizlerde</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/maritime-cyber-security-dijital-denizlerde</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Sat, 18 Jul 2026 11:05:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!XuO3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c4713-1716-469c-932b-910ee9153611_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XuO3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c4713-1716-469c-932b-910ee9153611_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XuO3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c4713-1716-469c-932b-910ee9153611_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!XuO3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c4713-1716-469c-932b-910ee9153611_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!XuO3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c4713-1716-469c-932b-910ee9153611_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!XuO3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c4713-1716-469c-932b-910ee9153611_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XuO3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c4713-1716-469c-932b-910ee9153611_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0a3c4713-1716-469c-932b-910ee9153611_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2613855,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/207304095?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c4713-1716-469c-932b-910ee9153611_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XuO3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c4713-1716-469c-932b-910ee9153611_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!XuO3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c4713-1716-469c-932b-910ee9153611_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!XuO3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c4713-1716-469c-932b-910ee9153611_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!XuO3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c4713-1716-469c-932b-910ee9153611_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><strong><a href="https://creators.spotify.com/pod/profile/ziyagokalp/episodes/Dijital-Denizlerde-Grnmeyen-Sava-Maritime-Cyber-Security-e3m818v">PODCAST Linki</a></strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h1>D&#252;nya Ticaretinin En Kritik Altyap&#305;s&#305; Neden Siber Sald&#305;r&#305;lar&#305;n Yeni Hedefi?</h1><p>Y&#252;zy&#305;llar boyunca denizler devletlerin ekonomik g&#252;c&#252;n&#252;, ticaret yollar&#305;n&#305; ve askeri &#252;st&#252;nl&#252;&#287;&#252;n&#252; belirleyen en &#246;nemli stratejik alanlardan biri oldu. Bug&#252;n de bu ger&#231;ek de&#287;i&#351;mi&#351; de&#287;il ! </p><p>K&#252;resel ticaret hacminin yakla&#351;&#305;k %80&#8217;i deniz yoluyla ta&#351;&#305;n&#305;rken, limanlar, konteyner terminalleri, tanker filolar&#305; ve a&#231;&#305;k deniz enerji platformlar&#305; d&#252;nya ekonomisinin g&#246;r&#252;nmeyen omurgas&#305;n&#305; olu&#351;turmaktad&#305;r.</p><p>Ancak son yirmi y&#305;lda denizcilik sekt&#246;r&#252; yaln&#305;zca mekanik ve fiziksel sistemlerden olu&#351;an bir yap&#305; olmaktan &#231;&#305;km&#305;&#351;t&#305;r.</p><p>Modern gemiler art&#305;k <strong>y&#252;zlerce sens&#246;r, uydu haberle&#351;me sistemleri, bulut tabanl&#305; filo y&#246;netimi, otomatik rota planlama yaz&#305;l&#305;mlar&#305;</strong> ve <strong>Operasyonel Teknoloji (OT)</strong> altyap&#305;lar&#305;yla &#231;al&#305;&#351;an hareketli veri merkezlerine d&#246;n&#252;&#351;m&#252;&#351;t&#252;r.</p><p>Bu dijital d&#246;n&#252;&#351;&#252;m operasyonel verimlili&#287;i art&#305;r&#305;rken, beraberinde &#231;ok daha b&#252;y&#252;k bir riski de ortaya &#231;&#305;kard&#305; ki buna bug&#252;n &#8216;<strong>Maritime Cyber Security&#8217; </strong>ad&#305; veriyoruz.</p><p>Hepimizin bildi&#287;i &#252;zere art&#305;k bir siber sald&#305;r&#305;n&#305;n amac&#305; yaln&#305;zca &#351;irket verilerini ele ge&#231;irmek de&#287;ildir. </p><p><strong>G&#252;n&#252;m&#252;zde bir sald&#305;rgan, geminin rotas&#305;n&#305; de&#287;i&#351;tirebilir, elektronik seyir haritalar&#305;n&#305; manip&#252;le edebilir, liman vin&#231;lerini durdurabilir, <span>geminin</span></strong><span> </span><strong>dengesini, trimini ve yap&#305;sal y&#252;k da&#287;&#305;l&#305;m&#305;n&#305; kontrol eden balast sistemlerini etkileyebilir veya k&#252;resel tedarik zincirini g&#252;nlerce fel&#231; edebilir.</strong></p><p></p><h1>Maritime Cyber Security Nedir?</h1><p><strong>Uluslararas&#305; Denizcilik &#214;rg&#252;t&#252; (IMO-International Maritime Organization)</strong>, <strong>Maritime Cyber Risk</strong>&#8217;i; Gemi ve liman operasyonlar&#305;n&#305;n g&#252;venli&#287;ini, emniyetini veya s&#252;reklili&#287;ini etkileyebilecek bilgi ve operasyonel sistemlere y&#246;nelik tehditlerin olu&#351;turdu&#287;u risk olarak tan&#305;mlamaktad&#305;r.</p><p>Bu nedenle siber risk y&#246;netimi, yaln&#305;zca IT sistemlerini de&#287;il, operasyonel teknolojileri de kapsayan b&#252;t&#252;nc&#252;l bir yakla&#351;&#305;m gerektirir.</p><p>Bu kapsamda <strong>Maritime Cyber Security</strong>; Gemiler, limanlar, a&#231;&#305;k deniz platformlar&#305;, lojistik &#351;irketleri, uydu haberle&#351;me altyap&#305;lar&#305;, denizcilik OT sistemleri gibi t&#252;m dijital ekosistemin korunmas&#305;n&#305; ama&#231;layan disiplin olarak tan&#305;mlanabilir.</p><p></p><h1>Modern Gemiler Art&#305;k Birer &#8220;OT&#8221; Ekosistemidir</h1><p>Bir&#231;ok ki&#351;i gemileri hala mekanik sistemlerden olu&#351;an yap&#305;lar olarak d&#252;&#351;&#252;nmektedir. Oysa g&#252;n&#252;m&#252;zde b&#252;y&#252;k bir konteyner gemisinde onlarca kritik <strong>OT sistemi</strong> bulunmaktad&#305;r.</p><p>Bunlardan baz&#305;lar&#305;n&#305; &#351;u &#351;ekilde s&#305;ralayabiliriz:  </p><ul><li><p><strong>Electronic Chart Display and Information System (ECDIS)</strong></p></li><li><p><strong>Automatic Identification System (AIS)</strong></p></li><li><p><strong>GPS (Global Positioning System) / GNSS (Global Navigation Satellite System)</strong></p></li><li><p><strong>Radar</strong></p></li><li><p><strong>Dynamic Positioning (DP)</strong></p></li><li><p><strong>GMDSS (Global Maritime Distress and Safety System)</strong></p></li><li><p><strong>Engine Control System</strong></p></li><li><p><strong>Ballast Water Management</strong></p></li><li><p><strong>Cargo Management System</strong></p></li><li><p><strong>Integrated Bridge System</strong></p></li><li><p><strong>Power Management System</strong></p></li></ul><p>Bu sistemlerin b&#252;y&#252;k b&#246;l&#252;m&#252; do&#287;rudan geminin g&#252;venli seyrini etkiledi&#287;inden, klasik bilgi g&#252;venli&#287;i olaylar&#305;n&#305;n &#246;tesinde fiziksel sonu&#231;lar do&#287;urabilecek sald&#305;r&#305; senaryolar&#305; ortaya &#231;&#305;kmaktad&#305;r.</p><p></p><h1>Neden Denizcilik Sekt&#246;r&#252; Hedefte?</h1><p>Denizcilik sekt&#246;r&#252;, dijital d&#246;n&#252;&#351;&#252;m&#252;n h&#305;z kazanmas&#305;yla birlikte siber sald&#305;rganlar a&#231;&#305;s&#305;ndan en cazip kritik altyap&#305; alanlar&#305;ndan biri haline gelmi&#351;tir. </p><p>Ge&#231;mi&#351;te gemiler b&#252;y&#252;k &#246;l&#231;&#252;de mekanik ve izole sistemlerle &#231;al&#305;&#351;&#305;rken, g&#252;n&#252;m&#252;zde modern ticaret gemileri, limanlar ve lojistik merkezleri; <strong>Bilgi teknolojileri (IT)</strong>, <strong>operasyonel teknolojiler (OT), bulut servisleri, uydu haberle&#351;mesi</strong> ve <strong>nesnelerin interneti (IoT)</strong> &#231;&#246;z&#252;mlerinin i&#231; i&#231;e ge&#231;ti&#287;i karma&#351;&#305;k dijital ekosistemler olarak faaliyet g&#246;stermektedir. </p><p>Bu d&#246;n&#252;&#351;&#252;m operasyonel verimlili&#287;i, yak&#305;t optimizasyonunu ve filo y&#246;netimini &#246;nemli &#246;l&#231;&#252;de geli&#351;tirirken, ayn&#305; zamanda sald&#305;r&#305; y&#252;zeyini de benzeri g&#246;r&#252;lmemi&#351; &#246;l&#231;&#252;de geni&#351;letmi&#351;tir.</p><p>Denizcilik sekt&#246;r&#252;n&#252;n sald&#305;rganlar i&#231;in &#246;ncelikli hedef olmas&#305;n&#305;n en &#246;nemli nedenlerinden biri, k&#252;resel ekonomide &#252;stlendi&#287;i kritik rold&#252;r. <strong>D&#252;nya ticaretinin yakla&#351;&#305;k y&#252;zde 80&#8217;i hacim baz&#305;nda deniz yoluyla ger&#231;ekle&#351;tirilmektedir.</strong> </p><p>Bir konteyner terminalinin, b&#252;y&#252;k bir liman&#305;n veya uluslararas&#305; ta&#351;&#305;mac&#305;l&#305;k yapan bir filonun birka&#231; g&#252;n boyunca hizmet verememesi, yaln&#305;zca ilgili &#351;irket i&#231;in de&#287;il, k&#252;resel tedarik zinciri boyunca &#252;reticiler, ihracat&#231;&#305;lar, ithalat&#231;&#305;lar ve t&#252;keticiler i&#231;in de ciddi ekonomik kay&#305;plara neden olabilir. </p><p>Bu nedenle sald&#305;rganlar, y&#252;ksek finansal bask&#305; olu&#351;turabilecek sekt&#246;rleri &#246;zellikle tercih etmekte ve fidye yaz&#305;l&#305;m&#305; (<strong>ransomware</strong>) gibi sald&#305;r&#305;larla operasyonlar&#305; durdurarak h&#305;zl&#305; &#246;deme almay&#305; hedeflemektedir.</p><p>Bir di&#287;er &#246;nemli fakt&#246;r ise denizcilik sekt&#246;r&#252;nde halen yayg&#305;n olarak kullan&#305;lan <strong>eski nesil (legacy) operasyonel teknoloji</strong> sistemleridir. </p><p>Bir&#231;ok gemi 20 ila 30 y&#305;l boyunca hizmet vermekte olup, &#252;zerindeki otomasyon sistemleri, <strong>PLC (Programmable Logic Controller)'ler, navigasyon cihazlar&#305;</strong> ve <strong>makine kontrol altyap&#305;lar&#305;</strong> uzun y&#305;llar boyunca de&#287;i&#351;tirilmeden kullan&#305;lmaktad&#305;r. </p><p>Bu sistemlerin &#246;nemli bir k&#305;sm&#305; tasarland&#305;klar&#305; d&#246;nemde internet ba&#287;lant&#305;s&#305; veya siber sald&#305;r&#305;lar dikkate al&#305;narak geli&#351;tirilmedi&#287;inden, g&#252;n&#252;m&#252;z tehdit ortam&#305;na kar&#351;&#305; yeterli g&#252;venlik mekanizmalar&#305;na sahip de&#287;ildirler. </p><p>&#214;te yandan bu sistemlerin de&#287;i&#351;tirilmesi veya g&#252;ncellenmesi, geminin operasyon d&#305;&#351;&#305; kalmas&#305;na neden olabilece&#287;i i&#231;in g&#252;venlik yamalar&#305;n&#305;n uygulanmas&#305; &#231;o&#287;u zaman ertelenmektedir.</p><p>Modern gemilerin s&#252;rekli ba&#287;lant&#305; ihtiyac&#305; da &#246;nemli bir risk olu&#351;turmaktad&#305;r. G&#252;n&#252;m&#252;zde gemiler yaln&#305;zca limandayken de&#287;il, okyanusun ortas&#305;nda seyir halindeyken dahi uydu haberle&#351;me sistemleri arac&#305;l&#305;&#287;&#305;yla &#351;irket merkezleriyle s&#252;rekli veri al&#305;&#351;veri&#351;i yapmaktad&#305;r. </p><p><strong>Rota planlar&#305;, makine performans verileri, yak&#305;t t&#252;ketimi, y&#252;k bilgileri, bak&#305;m kay&#305;tlar&#305;</strong> ve <strong>m&#252;rettebat ileti&#351;imi</strong> gibi <strong>kritik bilgiler</strong> ger&#231;ek zamanl&#305; olarak k&#305;y&#305;daki operasyon merkezlerine aktar&#305;lmaktad&#305;r. </p><p>Bu durum operasyonel verimlilik a&#231;&#305;s&#305;ndan b&#252;y&#252;k avantaj sa&#287;larken, ayn&#305; zamanda <strong>sald&#305;rganlar i&#231;in uzaktan eri&#351;im sa&#287;layabilecek</strong> yeni giri&#351; noktalar&#305; ve sald&#305;r&#305; y&#252;zeyleri olu&#351;turmaktad&#305;r.</p><p>Denizcilik ekosisteminin &#231;ok say&#305;da &#252;&#231;&#252;nc&#252; taraf tedarik&#231;iye ba&#287;&#305;ml&#305; olmas&#305; da sald&#305;r&#305; riskini art&#305;rmaktad&#305;r. </p><p>Gemi &#252;reticileri, otomasyon firmalar&#305;, navigasyon yaz&#305;l&#305;m&#305; geli&#351;tiricileri, uzaktan bak&#305;m sa&#287;lay&#305;c&#305;lar&#305;, uydu haberle&#351;me &#351;irketleri ve liman otomasyon hizmeti sunan bir&#231;ok farkl&#305; kurulu&#351; ayn&#305; dijital ekosistemin par&#231;as&#305;d&#305;r. </p><p>Bu tedarik&#231;ilerden yaln&#305;zca birinin g&#252;venli&#287;inin ihlal edilmesi, sald&#305;rganlar&#305;n do&#287;rudan hedef kurulu&#351;a ula&#351;mas&#305;n&#305; sa&#287;layabilecek bir tedarik zinciri sald&#305;r&#305;s&#305;na d&#246;n&#252;&#351;ebilir. </p><p>Son y&#305;llarda bir&#231;ok sekt&#246;rde g&#246;r&#252;len yaz&#305;l&#305;m g&#252;ncellemesi veya uzaktan bak&#305;m altyap&#305;s&#305; &#252;zerinden ger&#231;ekle&#351;tirilen sald&#305;r&#305;lar, denizcilik sekt&#246;r&#252;nde de benzer risklerin bulundu&#287;unu g&#246;stermektedir.</p><p>Bunun yan&#305;s&#305;ra gemilerde <strong>Bilgi teknolojileri (IT)</strong> ile <strong>Operasyonel teknolojiler (OT)</strong> aras&#305;ndaki s&#305;n&#305;rlar giderek ortadan kalkmaktad&#305;r. </p><p>Eskiden birbirinden fiziksel olarak ayr&#305;lm&#305;&#351; sistemler bug&#252;n bak&#305;m kolayl&#305;&#287;&#305;, uzaktan izleme, optimizasyon, konfig&#252;rasyon ve veri analiti&#287;i amac&#305;yla ayn&#305; a&#287; &#252;zerinde veya birbirine ba&#287;l&#305; &#351;ekilde &#231;al&#305;&#351;abilmektedir. </p><p><strong>&#214;rne&#287;in makine kontrol sistemlerinden al&#305;nan veriler filo y&#246;netim yaz&#305;l&#305;mlar&#305;na, bulut platformlar&#305;na veya yapay zeka tabanl&#305; bak&#305;m uygulamalar&#305;na aktar&#305;lmaktad&#305;r. </strong></p><p>Bu entegrasyon operasyonel fayda sa&#287;lasa da, kurumsal <strong>BT</strong> a&#287;&#305;nda ba&#351;layan bir sald&#305;r&#305;n&#305;n uygun g&#252;venlik kontrolleri bulunmad&#305;&#287;&#305; takdirde geminin kritik <strong>OT</strong> sistemlerine kadar ilerleyebilme riskini de beraberinde getirmektedir.</p><p>&#214;te yandan, insan fakt&#246;r&#252; de denizcilik sekt&#246;r&#252;ndeki en &#246;nemli zafiyetlerden biri olmaya devam etmektedir. </p><p>M&#252;rettebat &#252;yeleri s&#305;k s&#305;k de&#287;i&#351;ebilmekte, farkl&#305; &#252;lkelerden gelen personel farkl&#305; siber g&#252;venlik k&#252;lt&#252;rlerine sahip olabilmekte ve gemiler aylar boyunca denizde kald&#305;klar&#305; i&#231;in d&#252;zenli g&#252;venlik e&#287;itimlerine eri&#351;im her zaman m&#252;mk&#252;n olmayabilmektedir. </p><p><strong>Kimlik av&#305; sald&#305;r&#305;lar&#305;, ta&#351;&#305;nabilir USB cihazlar&#305;n&#305;n kontrols&#252;z kullan&#305;m&#305;, zay&#305;f parola politikalar&#305; ve uzaktan bak&#305;m s&#305;ras&#305;nda uygulanan ge&#231;ici eri&#351;im izinleri, sald&#305;rganlar&#305;n en s&#305;k kulland&#305;&#287;&#305; y&#246;ntemler aras&#305;nda yer almaktad&#305;r.</strong></p><p>Son olarak, <strong>denizcilik sekt&#246;r&#252;n&#252;n yaln&#305;zca ekonomik de&#287;il, ayn&#305; zamanda jeopolitik ve stratejik bir &#246;neme sahip olmas&#305; da onu devlet destekli tehdit akt&#246;rleri i&#231;in cazip hale getirmektedir.</strong> </p><p><strong>Enerji ta&#351;&#305;mac&#305;l&#305;&#287;&#305; yapan tankerler, LNG terminalleri, askeri lojistik limanlar&#305;, denizalt&#305; haberle&#351;me kablolar&#305; ve stratejik bo&#287;azlardan ge&#231;en ticaret yollar&#305;, ulusal g&#252;venlik a&#231;&#305;s&#305;ndan kritik altyap&#305;lar olarak de&#287;erlendirilmektedir. </strong></p><p><strong>Bu nedenle denizcilik sekt&#246;r&#252;ne y&#246;nelik siber sald&#305;r&#305;lar yaln&#305;zca finansal kazan&#231; amac&#305;yla de&#287;il, istihbarat toplama, sabotaj, ekonomik bask&#305; olu&#351;turma veya hibrit sava&#351; stratejilerinin bir par&#231;as&#305; olarak da ger&#231;ekle&#351;tirilebilmektedir.</strong></p><p><span>Uluslararas&#305; denizcilik kurulu&#351;lar&#305; da bu risklere dikkat &#231;ekmektedir. </span></p><p><strong>BIMCO (Baltic and International Maritime Council)</strong><span>, gemilerde bilgi teknolojileri ile operasyonel teknolojilerin giderek daha fazla b&#252;t&#252;nle&#351;ti&#287;ini, gemi-k&#305;y&#305; aras&#305;ndaki s&#252;rekli veri al&#305;&#351;veri&#351;inin ba&#287;lant&#305;l&#305; sistem say&#305;s&#305;n&#305; art&#305;rd&#305;&#287;&#305;n&#305; ve buna ba&#287;l&#305; olarak sald&#305;r&#305; y&#252;zeyinin &#246;nemli &#246;l&#231;&#252;de geni&#351;ledi&#287;ini vurgulamaktad&#305;r. </span></p><p><span>Benzer &#351;ekilde </span><strong>Uluslararas&#305; Denizcilik &#214;rg&#252;t&#252; (IMO-International Maritime Organization)</strong><span> da siber risk y&#246;netiminin art&#305;k gemi emniyeti ve g&#252;venli&#287;inin ayr&#305;lmaz bir unsuru oldu&#287;unu kabul ederek, &#351;irketlerin siber riskleri emniyet y&#246;netim sistemlerinin (</span><strong><span>Safety Management System - SMS</span></strong><span>) bir par&#231;as&#305; olarak ele almas&#305;n&#305; tavsiye etmektedir. </span></p><p><span>Bu geli&#351;meler, denizcilik sekt&#246;r&#252;nde siber g&#252;venli&#287;in art&#305;k yaln&#305;zca </span><strong><span>BT</span></strong><span> departmanlar&#305;n&#305;n sorumlulu&#287;u de&#287;il; </span><strong><span>Operasyon, m&#252;hendislik, emniyet</span></strong><span> ve </span><strong><span>&#252;st y&#246;netimin</span></strong><span> birlikte ele almas&#305; gereken stratejik bir konu haline geldi&#287;ini a&#231;&#305;k&#231;a g&#246;stermektedir.</span></p><p></p><h1>En B&#252;y&#252;k Tehditler</h1><h3>GPS Spoofing</h3><p>GPS Spoofing, sald&#305;rgan&#305;n ger&#231;ek <strong>GPS (Global Positioning System)</strong> uydu sinyallerini taklit eden sahte sinyaller &#252;retmesi ve geminin navigasyon sistemlerini bu sahte sinyalleri ger&#231;ekmi&#351; gibi kabul etmeye y&#246;nlendirmesi y&#246;ntemidir. <strong>GPS</strong> al&#305;c&#305;s&#305;, en g&#252;&#231;l&#252; ve en tutarl&#305; sinyali do&#287;ru kabul etti&#287;inden, yeterince g&#252;&#231;l&#252; bir sahte sinyal ger&#231;ek uydu sinyalinin &#246;n&#252;ne ge&#231;ebilir. </p><p>Bunun sonucunda gemi, bulundu&#287;u ger&#231;ek konum yerine sald&#305;rgan&#305;n belirledi&#287;i sahte koordinatlarda oldu&#287;unu hesaplamaya ba&#351;lar.</p><p>Bu t&#252;r bir sald&#305;r&#305;, geminin elektronik seyir haritalar&#305;nda <strong>ECDIS (Electronic Chart Display and Information System</strong>) yanl&#305;&#351; konumda g&#246;r&#252;nmesine, <strong>AIS (Automatic Identification System)</strong> &#252;zerinden hatal&#305; konum bilgisi yay&#305;nlamas&#305;na ve otopilot sisteminin yanl&#305;&#351; rota takip etmesine neden olabilir. </p><p>&#214;zellikle dar bo&#287;azlar, yo&#287;un trafik b&#246;lgeleri veya liman yakla&#351;malar&#305; s&#305;ras&#305;nda <strong>GPS spoofing</strong>; &#199;arp&#305;&#351;ma, karaya oturma (grounding), yanl&#305;&#351; manevra ve operasyonel gecikme risklerini &#246;nemli &#246;l&#231;&#252;de art&#305;rabilir.</p><p><strong>GPS spoofing</strong> sald&#305;r&#305;lar&#305; yaln&#305;zca ticari gemiler i&#231;in de&#287;il; askeri gemiler, a&#231;&#305;k deniz platformlar&#305; ve otonom deniz ara&#231;lar&#305; a&#231;&#305;s&#305;ndan da ciddi bir tehdit olu&#351;turmaktad&#305;r. </p><p>Son y&#305;llarda Karadeniz, Do&#287;u Akdeniz ve Basra K&#246;rfezi gibi b&#246;lgelerde raporlanan &#231;ok say&#305;da <strong>GPS spoofing</strong> olay&#305;, bu y&#246;ntemin art&#305;k teorik bir risk olmaktan &#231;&#305;k&#305;p ger&#231;ek operasyonlar&#305; etkileyebilen bir tehdit haline geldi&#287;ini g&#246;stermektedir.</p><p>Bu nedenle modern denizcilikte <strong>GPS</strong> verileri tek ba&#351;&#305;na mutlak do&#287;ru kabul edilmemekte; <strong>Radar, AIS, Ataletsel navigasyon sistemleri (INS), g&#246;rsel seyir y&#246;ntemleri</strong> ve farkl&#305; <strong>GNSS (Global Navigation Satellite System)</strong> tak&#305;my&#305;ld&#305;zlar&#305;ndan elde edilen bilgilerle do&#287;rulanarak g&#252;venli seyir sa&#287;lanmaya &#231;al&#305;&#351;&#305;lmaktad&#305;r.</p><h3>AIS Manip&#252;lasyonu</h3><p><strong>AIS (Automatic Identification System)</strong>, gemilerin kimlik, konum, h&#305;z, rota ve di&#287;er seyir bilgilerinin &#231;evredeki gemiler ve k&#305;y&#305; istasyonlar&#305;yla otomatik olarak payla&#351;&#305;lmas&#305;n&#305; sa&#287;layan kritik bir denizcilik haberle&#351;me sistemidir. </p><p>&#199;arp&#305;&#351;malar&#305;n &#246;nlenmesi, trafik y&#246;netimi, arama-kurtarma faaliyetleri ve deniz g&#252;venli&#287;i a&#231;&#305;s&#305;ndan b&#252;y&#252;k &#246;nem ta&#351;&#305;r.</p><p><strong>AIS manip&#252;lasyonu</strong>, sald&#305;rganlar&#305;n veya k&#246;t&#252; niyetli akt&#246;rlerin bu sistem &#252;zerinden yay&#305;mlanan bilgileri kas&#305;tl&#305; olarak de&#287;i&#351;tirmesi, yan&#305;lt&#305;c&#305; veriler &#252;retmesi veya yay&#305;nlar&#305; gizlemesi anlam&#305;na gelir. Bu ama&#231;la AIS mesajlar&#305; sahte olarak &#252;retilebilir, mevcut veriler de&#287;i&#351;tirilebilir veya sistem tamamen devre d&#305;&#351;&#305; b&#305;rak&#305;labilir.</p><p>B&#246;yle bir manip&#252;lasyon sonucunda <strong>hayalet gemiler (ghost ships)</strong> olu&#351;turulabilir; ger&#231;ekte bulunmayan gemiler <strong>AIS</strong> ekranlar&#305;nda g&#246;r&#252;nerek deniz trafi&#287;i yan&#305;lt&#305;labilir. Ayn&#305; &#351;ekilde bir geminin <strong>MMSI (Maritime Mobile Service Identity) </strong>numaras&#305;, <strong>IMO (International Maritime Organization)</strong> numaras&#305;, ad&#305; veya &#231;a&#287;r&#305; i&#351;areti de&#287;i&#351;tirilerek farkl&#305; bir gemi gibi g&#246;r&#252;nmesi sa&#287;lanabilir. Bunun yan&#305;nda geminin ger&#231;ek rotas&#305; ve konumu gizlenebilir veya sahte koordinatlar yay&#305;nlanarak elektronik seyir sistemlerinde yanl&#305;&#351; bir trafik resmi olu&#351;turulabilir.</p><p><strong>AIS manip&#252;lasyonu</strong> yaln&#305;zca navigasyon g&#252;venli&#287;ini tehdit etmekle kalmaz. Yapt&#305;r&#305;mlardan ka&#231;&#305;nma, yasa d&#305;&#351;&#305; petrol ta&#351;&#305;mac&#305;l&#305;&#287;&#305;, ka&#231;ak&#231;&#305;l&#305;k, sigorta doland&#305;r&#305;c&#305;l&#305;&#287;&#305;, yasa d&#305;&#351;&#305; bal&#305;k&#231;&#305;l&#305;k ve askeri veya istihbarat ama&#231;l&#305; faaliyetlerde de kullan&#305;labilmektedir. </p><p>&#214;zellikle son y&#305;llarda &#8220;<strong>Shadow Fleet (G&#246;lge Filo)</strong>&#8221; olarak adland&#305;r&#305;lan baz&#305; tankerlerin AIS yay&#305;nlar&#305;n&#305; kapatmalar&#305;, farkl&#305; kimlikler kullanmalar&#305; veya konum bilgilerini de&#287;i&#351;tirmeleri, bu y&#246;ntemin ger&#231;ek operasyonlarda nas&#305;l kullan&#305;ld&#305;&#287;&#305;n&#305; g&#246;stermektedir.</p><p>Bu nedenle g&#252;n&#252;m&#252;zde denizcilik otoriteleri ve liman i&#351;letmeleri, AIS verilerini tek ba&#351;&#305;na g&#252;venilir kabul etmemekte, radar sistemleri, uydu g&#246;r&#252;nt&#252;leri, Sentetik A&#231;&#305;kl&#305;kl&#305; Radar (SAR), optik uydular ve yapay zeka destekli davran&#305;&#351; analizleri ile &#231;apraz do&#287;rulama yaparak &#351;&#252;pheli gemi hareketlerini tespit etmeye &#231;al&#305;&#351;maktad&#305;r.</p><h3>Ransomware</h3><p><strong>Fidye yaz&#305;l&#305;mlar&#305; (Ransomware)</strong>, g&#252;n&#252;m&#252;zde denizcilik sekt&#246;r&#252;n&#252; hedef alan en yayg&#305;n ve en y&#305;k&#305;c&#305; siber tehditlerden biri haline gelmi&#351;tir. Bu sald&#305;r&#305;lar &#231;o&#287;u zaman kimlik av&#305; (phishing) e-postalar&#305;, g&#252;venli&#287;i zay&#305;f uzaktan eri&#351;im servisleri, tedarik zinciri zafiyetleri veya ele ge&#231;irilmi&#351; kullan&#305;c&#305; hesaplar&#305; &#252;zerinden &#351;irket a&#287;lar&#305;na s&#305;zarak ba&#351;lar. </p><p>Sald&#305;rganlar, a&#287; i&#231;erisinde <strong>yatay hareket (lateral movement)</strong> ger&#231;ekle&#351;tirerek kritik sunuculara, dosya sistemlerine ve operasyonel uygulamalara eri&#351;im sa&#287;lamaya &#231;al&#305;&#351;&#305;r. Son a&#351;amada ise veriler &#351;ifrelenir ve &#231;o&#287;u zaman hassas bilgiler &#231;al&#305;narak fidye talebinde bulunulur (<strong>&#231;ifte &#351;antaj - </strong><em><strong>double extortion</strong></em>).</p><p>Denizcilik sekt&#246;r&#252;nde fidye yaz&#305;l&#305;mlar&#305;n&#305;n etkisi, yaln&#305;zca kurumsal bilgi sistemleriyle s&#305;n&#305;rl&#305; de&#287;ildir. Liman operasyonlar&#305;n&#305;n b&#252;y&#252;k b&#246;l&#252;m&#252; <strong>Terminal Operating System (TOS)</strong>, konteyner y&#246;netim yaz&#305;l&#305;mlar&#305;, r&#305;ht&#305;m planlama sistemleri, g&#252;mr&#252;k entegrasyonlar&#305; ve lojistik platformlar&#305; &#252;zerinden dijital olarak y&#252;r&#252;t&#252;lmektedir. </p><p>Bu sistemlerin devre d&#305;&#351;&#305; kalmas&#305;, fiziksel ekipmanlar &#231;al&#305;&#351;abilir durumda olsa bile operasyonlar&#305;n &#246;nemli &#246;l&#231;&#252;de yava&#351;lamas&#305;na veya tamamen durmas&#305;na neden olabilir.</p><p>Bir fidye yaz&#305;l&#305;m&#305; sald&#305;r&#305;s&#305;n&#305;n liman ve denizcilik operasyonlar&#305; &#252;zerindeki olas&#305; etkilerini analiz etti&#287;imizde ortaya &#231;&#305;kan potansiyel zafiyetleri ve tehditleri &#351;u &#351;ekilde s&#305;ralayabiliriz.  </p><ul><li><p><strong>Konteyner y&#252;kleme ve bo&#351;altma operasyonlar&#305;n&#305;n durmas&#305;,</strong></p></li><li><p><strong>Terminal Operating System (TOS) ve liman planlama yaz&#305;l&#305;mlar&#305;n&#305;n kullan&#305;lamaz hale gelmesi,</strong></p></li><li><p><strong>Gemi yana&#351;ma ve ayr&#305;lma planlar&#305;n&#305;n aksamas&#305;,</strong></p></li><li><p><strong>G&#252;mr&#252;k i&#351;lemleri ve dijital evrak y&#246;netim s&#252;re&#231;lerinin kesintiye u&#287;ramas&#305;,</strong></p></li><li><p><strong>Depolama, envanter ve y&#252;k takip sistemlerinin &#231;al&#305;&#351;mamas&#305;,</strong></p></li><li><p><strong>Kamyon, demiryolu ve lojistik ba&#287;lant&#305;lar&#305;nda gecikmeler ya&#351;anmas&#305;,</strong></p></li><li><p><strong>Tedarik zincirinde zincirleme operasyonel aksakl&#305;klar ve ciddi ekonomik kay&#305;plar&#305;n olu&#351;mas&#305;.</strong></p></li></ul><p>Denizcilik sekt&#246;r&#252; a&#231;&#305;s&#305;ndan fidye yaz&#305;l&#305;m&#305; sald&#305;r&#305;lar&#305;n&#305;n en &#246;nemli &#246;zelli&#287;i, <strong>tek bir &#351;irketi de&#287;il, birbirine ba&#287;l&#305; t&#252;m lojistik ekosistemini etkileyebilmesidir</strong>. Bir liman&#305;n veya b&#252;y&#252;k bir denizcilik &#351;irketinin faaliyetlerinin durmas&#305;; ithalat&#231;&#305;lar, ihracat&#231;&#305;lar, ta&#351;&#305;y&#305;c&#305;lar, lojistik firmalar&#305; ve &#252;retim tesisleri &#252;zerinde domino etkisi yaratabilir.</p><h3>OT Sald&#305;r&#305;lar&#305;</h3><p><strong>Maritime Cyber Security</strong> a&#231;&#305;s&#305;ndan en kritik tehditlerden biri, gemilerin operasyonel s&#252;re&#231;lerini y&#246;neten <strong>Operasyonel Teknoloji (Operational Technology - OT)</strong> sistemlerine y&#246;nelik siber sald&#305;r&#305;lard&#305;r. </p><p>Kurumsal BT sistemlerinden farkl&#305; olarak OT sistemleri do&#287;rudan fiziksel ekipmanlar&#305; kontrol eder. Bu nedenle OT ortam&#305;nda meydana gelen bir siber olay yaln&#305;zca veri kayb&#305;na de&#287;il, geminin g&#252;venli i&#351;letilmesini, m&#252;rettebat&#305;n emniyetini ve &#231;evresel g&#252;venli&#287;i etkileyebilecek fiziksel sonu&#231;lara yol a&#231;abilir.</p><p>Modern ticaret gemilerinde <strong>ana makine kontrol sistemleri, g&#252;&#231; &#252;retim ve da&#287;&#305;t&#305;m sistemleri, balast suyu y&#246;netimi, y&#252;k y&#246;netimi (Cargo Management System), yak&#305;t transferi, sintine pompalar&#305;, HVAC, yang&#305;n alg&#305;lama ve s&#246;nd&#252;rme sistemleri</strong> ile <strong>&#231;e&#351;itli otomasyon s&#252;re&#231;leri PLC&#8217;ler (Programmable Logic Controllers), SCADA sistemleri, da&#287;&#305;t&#305;k kontrol sistemleri (DCS) ve HMI aray&#252;zleri</strong> taraf&#305;ndan y&#246;netilmektedir. </p><p>Bu sistemlerin b&#252;y&#252;k b&#246;l&#252;m&#252;, operasyonel verimlili&#287;i art&#305;rmak amac&#305;yla &#351;irket merkezleriyle, uzaktan bak&#305;m altyap&#305;lar&#305;yla ve di&#287;er bilgi sistemleriyle ba&#287;lant&#305;l&#305; &#231;al&#305;&#351;maktad&#305;r. Ancak bu entegrasyon, sald&#305;r&#305; y&#252;zeyini de &#246;nemli &#246;l&#231;&#252;de geni&#351;letmektedir.</p><p>Bir sald&#305;rgan&#305;n OT a&#287;&#305;na eri&#351;im sa&#287;lamas&#305; durumunda, yaln&#305;zca dijital sistemleri de&#287;il fiziksel s&#252;re&#231;leri de manip&#252;le etmesi m&#252;mk&#252;nd&#252;r. </p><p>&#214;rne&#287;in <strong>motor kontrol sistemlerinin &#231;al&#305;&#351;ma parametreleri de&#287;i&#351;tirilebilir, jenerat&#246;rlerin senkronizasyonu bozulabilir, balast tanklar&#305;ndaki su seviyeleri yanl&#305;&#351; y&#246;netilebilir veya y&#252;k transfer s&#252;re&#231;leri kesintiye u&#287;rat&#305;labilir.</strong> </p><p><strong>G&#252;&#231; y&#246;netim sistemlerine y&#246;nelik bir sald&#305;r&#305; gemide elektrik kesintisine neden olabilirken, balast sistemlerinin manip&#252;le edilmesi geminin dengesini ve stabilitesini olumsuz etkileyebilir. Benzer &#351;ekilde y&#252;k y&#246;netim sistemlerinin hedef al&#305;nmas&#305;, &#246;zellikle petrol tankerleri, LNG ta&#351;&#305;y&#305;c&#305;lar&#305; ve kimyasal tankerlerde ciddi operasyonel ve &#231;evresel riskler do&#287;urabilir.</strong></p><p>OT sistemlerine y&#246;nelik sald&#305;r&#305;lar&#305;n en &#246;nemli &#246;zelli&#287;i, etkilerinin yaln&#305;zca siber ortamla s&#305;n&#305;rl&#305; kalmamas&#305;d&#305;r. Ba&#351;ar&#305;l&#305; bir sald&#305;r&#305;, geminin manevra kabiliyetini azaltabilir, limana yana&#351;mas&#305;n&#305; engelleyebilir, y&#252;k operasyonlar&#305;n&#305; durdurabilir, &#231;evresel kirlili&#287;e neden olabilir ve en &#246;nemlisi insan hayat&#305;n&#305; tehlikeye atabilir. </p><p><strong>Bu nedenle OT g&#252;venli&#287;i, Maritime Cyber Security&#8217;nin yaln&#305;zca bir alt ba&#351;l&#305;&#287;&#305; de&#287;il, en kritik bile&#351;enlerinden biri olarak kabul edilmektedir.</strong></p><p>Denizcilik sekt&#246;r&#252;nde OT sistemlerinin korunmas&#305;, a&#287; segmentasyonu, g&#252;venli uzaktan eri&#351;im, varl&#305;k envanteri, g&#252;venlik izleme, d&#252;zenli zafiyet de&#287;erlendirmeleri, PLC programlar&#305;n&#305;n b&#252;t&#252;nl&#252;k kontrol&#252; ve <strong>IEC 62443</strong> gibi end&#252;striyel siber g&#252;venlik standartlar&#305;na uygun g&#252;venlik kontrollerinin uygulanmas&#305;n&#305; gerektirir. </p><p>G&#252;n&#252;m&#252;zde denizcilik sekt&#246;r&#252;ndeki en &#246;nemli g&#252;venlik anlay&#305;&#351;&#305;, <strong>IT ve OT g&#252;venli&#287;inin birbirinden ba&#287;&#305;ms&#305;z de&#287;il, b&#252;t&#252;nle&#351;ik bir siber dayan&#305;kl&#305;l&#305;k yakla&#351;&#305;m&#305;yla y&#246;netilmesi</strong> gerekti&#287;idir.</p><p></p><h1>Vaka Analizi (2025&#8211;2026 D&#246;nemi)</h1><p>Son d&#246;nemde yay&#305;mlanan sekt&#246;r analizleri, raporlanan denizcilik siber olaylar&#305;n&#305;n &#246;nemli &#246;l&#231;&#252;de artt&#305;&#287;&#305;n&#305; ve &#246;zellikle <strong>DDoS, fidye yaz&#305;l&#305;m&#305;, GPS spoofing, GNSS kar&#305;&#351;t&#305;rma</strong> ve <strong>AIS manip&#252;lasyonu</strong> gibi tehditlerin &#246;ne &#231;&#305;kt&#305;&#287;&#305;n&#305; g&#246;stermektedir. </p><p>Ancak bu t&#252;r istatistiklerin b&#252;y&#252;k b&#246;l&#252;m&#252; &#246;zel sekt&#246;r tehdit istihbarat&#305; raporlar&#305;na dayand&#305;&#287;&#305;ndan, kaynak ve metodolojileri dikkatle de&#287;erlendirilmelidir.</p><h3>Long Beach Liman&#305; GNSS Anomalisi (2026): Navigasyon Sistemlerine Olan Ba&#287;&#305;ml&#305;l&#305;k</h3><p>2026 y&#305;l&#305;n&#305;n Ocak ay&#305;nda ABD&#8217;nin Kaliforniya eyaletindeki Long Beach Liman&#305;&#8217;na yakla&#351;an yedi ticari gemide ayn&#305; zaman diliminde ola&#287;an d&#305;&#351;&#305; <strong>GNSS (Global Navigation Satellite System)</strong> anomalileri tespit edildi. </p><p>Olay s&#305;ras&#305;nda gemilerin elektronik seyir sistemlerinde ciddi konum tutars&#305;zl&#305;klar&#305; olu&#351;urken, <strong>AIS (Automatic Identification System)</strong> kay&#305;tlar&#305;nda baz&#305; gemilerin ger&#231;ek konumlar&#305;ndan kilometrelerce uzakta g&#246;r&#252;nd&#252;&#287;&#252; belirlendi. Baz&#305; sistemler ise gemilerin k&#305;sa s&#252;reli&#287;ine <strong>100 knot&#8217;&#305;n &#252;zerinde</strong> h&#305;zla seyir yapt&#305;&#287;&#305; izlenimini olu&#351;turdu. Ger&#231;ekte ise gemiler normal h&#305;zlar&#305;nda ve rotalar&#305;nda ilerlemeye devam ediyordu.</p><p>&#304;lgin&#231; olan nokta, benzer <strong>GNSS</strong> d&#252;zensizliklerinin yaln&#305;zca gemilerde de&#287;il, ayn&#305; b&#246;lgede faaliyet g&#246;steren <strong>NOAA (National Oceanic and Atmospheric Administration)</strong> g&#246;zlem istasyonlar&#305;nda ve baz&#305; hava ara&#231;lar&#305;n&#305;n navigasyon sistemlerinde de kaydedilmi&#351; olmas&#305;yd&#305;. Bu durum olay&#305;n tek bir gemiye &#246;zg&#252; olmad&#305;&#287;&#305;n&#305;, daha geni&#351; bir co&#287;rafi alan&#305; etkileyen bir sinyal bozulmas&#305; ya&#351;and&#305;&#287;&#305;n&#305; ortaya koydu.</p><p>Yetkili kurumlar taraf&#305;ndan yap&#305;lan de&#287;erlendirmelerde olay&#305;n en olas&#305; nedenlerinden birinin b&#246;lgede ger&#231;ekle&#351;tirilen planl&#305; <strong>GPS</strong> testleri veya <strong>GNSS</strong> sinyal giri&#351;imleri olabilece&#287;i ifade edildi. Herhangi bir k&#246;t&#252; niyetli siber sald&#305;r&#305; kesin olarak do&#287;rulanmam&#305;&#351; olsa da, olay modern denizcilik operasyonlar&#305;n&#305;n uydu tabanl&#305; konumlama sistemlerine ne derece ba&#287;&#305;ml&#305; oldu&#287;unu a&#231;&#305;k bi&#231;imde g&#246;sterdi.</p><p>Bu vaka, yaln&#305;zca <strong>GPS spoofing</strong> veya <strong>GNSS jamming</strong> gibi tehditlerin teorik riskler olmad&#305;&#287;&#305;n&#305;, tek bir sinyal bozulmas&#305;n&#305;n dahi <strong>elektronik haritalama sistemleri (ECDIS)</strong>, <strong>otomatik tan&#305;mlama sistemi (AIS)</strong>, <strong>rota planlama</strong> ve <strong>&#231;arp&#305;&#351;ma &#246;nleme s&#252;re&#231;lerini</strong> do&#287;rudan etkileyebilece&#287;ini ortaya koymu&#351;tur. </p><p>&#214;zellikle gelecekte yayg&#305;nla&#351;mas&#305; beklenen otonom gemiler a&#231;&#305;s&#305;ndan <strong>GNSS</strong> <strong>(Global Navigation Satellite System)</strong> g&#252;venli&#287;i, denizcilik sekt&#246;r&#252;n&#252;n en kritik siber g&#252;venlik konular&#305;ndan biri olmaya devam edecektir.</p><h3>Shadow Fleet ve AIS Manip&#252;lasyonu (2025&#8211;2026): Dijital Kimliklerin Gizlendi&#287;i Denizler</h3><p>Rusya&#8217;ya y&#246;nelik uluslararas&#305; yapt&#305;r&#305;mlar&#305;n ard&#305;ndan &#8220;<strong>Shadow Flee</strong>t&#8221; veya &#8220;<strong>G&#246;lge Filo</strong>&#8221; olarak adland&#305;r&#305;lan y&#252;zlerce tanker, k&#252;resel denizcilik g&#252;venli&#287;i a&#231;&#305;s&#305;ndan &#246;nemli bir tart&#305;&#351;ma konusu haline gelmi&#351;tir. </p><p>Bu gemiler genellikle yapt&#305;r&#305;mlar&#305; a&#351;mak, ger&#231;ek sahipliklerini gizlemek veya yasakl&#305; y&#252;k ta&#351;&#305;mac&#305;l&#305;&#287;&#305; yapmak amac&#305;yla farkl&#305; y&#246;ntemler kullanmaktad&#305;r.</p><p>2025 ve 2026 y&#305;llar&#305;nda Tayvan ba&#351;ta olmak &#252;zere &#231;e&#351;itli &#252;lkelerin y&#252;r&#252;tt&#252;&#287;&#252; soru&#351;turmalar, baz&#305; g&#246;lge filo gemilerinin <strong>AIS (Automatic Identification System)</strong> sistemlerini bilin&#231;li olarak manip&#252;le etti&#287;ini ortaya koydu. </p><p>Yap&#305;lan analizlerde ayn&#305; geminin farkl&#305; zamanlarda birden fazla <strong>Maritime Mobile Service Identity (MMSI)</strong> kulland&#305;&#287;&#305;, farkl&#305; <strong>IMO (International Maritime Organization)</strong> numaralar&#305;yla yay&#305;n yapt&#305;&#287;&#305; veya <strong>AIS</strong> yay&#305;nlar&#305;n&#305; tamamen kapatt&#305;&#287;&#305; belirlendi. </p><p>Baz&#305; durumlarda ise gemiler olduklar&#305; yerden y&#252;zlerce deniz mili uzakta g&#246;r&#252;nerek dijital izlerini kas&#305;tl&#305; olarak de&#287;i&#351;tirdi.</p><p>Bu teknikler klasik anlamda bir zararl&#305; yaz&#305;l&#305;m sald&#305;r&#305;s&#305; olmasa da, denizcilikte kullan&#305;lan en kritik g&#252;venlik sistemlerinden biri olan <strong>AIS</strong>&#8217;in k&#246;t&#252;ye kullan&#305;lmas&#305;n&#305;n operasyonel ve g&#252;venlik a&#231;&#305;s&#305;ndan ne kadar ciddi sonu&#231;lar do&#287;urabilece&#287;ini g&#246;stermektedir. </p><p>Sahte <strong>AIS</strong> verileri yaln&#305;zca yapt&#305;r&#305;mlar&#305;n delinmesine de&#287;il, ka&#231;ak petrol ta&#351;&#305;mac&#305;l&#305;&#287;&#305;na, yasa d&#305;&#351;&#305; y&#252;k transferlerine, sigorta doland&#305;r&#305;c&#305;l&#305;&#287;&#305;na ve deniz g&#252;venli&#287;i risklerine de zemin haz&#305;rlamaktad&#305;r.</p><p>Bu nedenle g&#252;n&#252;m&#252;zde bir&#231;ok &#252;lke, AIS verilerini uydu g&#246;r&#252;nt&#252;leri, radar sistemleri, sentetik a&#231;&#305;kl&#305;kl&#305; radar (SAR) ve yapay zeka destekli davran&#305;&#351; analizleriyle birlikte de&#287;erlendirerek &#351;&#252;pheli gemileri tespit etmeye &#231;al&#305;&#351;maktad&#305;r.</p><h3>Adriatic Port Authority Ransomware Sald&#305;r&#305;s&#305; (2026): Kritik Liman Altyap&#305;lar&#305; Hedefte</h3><p>2026 y&#305;l&#305;nda Avrupa&#8217;n&#305;n Adriyatik b&#246;lgesindeki &#246;nemli liman otoritelerinden biri, Anubis fidye yaz&#305;l&#305;m&#305; grubu taraf&#305;ndan ger&#231;ekle&#351;tirilen bir sald&#305;r&#305;n&#305;n hedefi oldu. Sald&#305;r&#305; sonucunda liman&#305;n kurumsal bilgi sistemleri ile baz&#305; operasyonel y&#246;netim uygulamalar&#305; ciddi &#351;ekilde etkilendi.</p><p>Liman operasyonlar&#305;n&#305; destekleyen lojistik planlama sistemleri, belge y&#246;netimi uygulamalar&#305; ve y&#252;k hareketlerini takip eden dijital platformlarda kesintiler ya&#351;and&#305;. Konteyner hareketlerinin planlanmas&#305;nda gecikmeler meydana gelirken, baz&#305; operasyonlar&#305;n manuel s&#252;re&#231;lerle y&#252;r&#252;t&#252;lmesi gerekti. Bunun sonucunda y&#252;k kabul&#252;, sevkiyat planlamas&#305; ve evrak i&#351;lemleri yava&#351;lad&#305;; liman hizmetlerinde zincirleme gecikmeler olu&#351;tu.</p><p>Her ne kadar limandaki fiziksel ekipmanlar&#305;n tamam&#305;n&#305;n do&#287;rudan etkilendi&#287;ine dair resmi bir do&#287;rulama bulunmasa da, bu olay limanlar&#305;n yaln&#305;zca vin&#231;lerden ve konteyner sahalar&#305;ndan ibaret olmad&#305;&#287;&#305;n&#305;, dijital altyap&#305;lar&#305;n operasyonlar&#305;n ayr&#305;lmaz bir par&#231;as&#305; haline geldi&#287;ini a&#231;&#305;k&#231;a g&#246;stermektedir. </p><p>G&#252;n&#252;m&#252;zde bir liman&#305;n bilgi sistemlerinin devre d&#305;&#351;&#305; kalmas&#305;, fiziksel ekipmanlar &#231;al&#305;&#351;maya devam etse bile operasyonlar&#305;n b&#252;y&#252;k &#246;l&#231;&#252;de yava&#351;lamas&#305;na neden olabilmektedir.</p><p>Bu sald&#305;r&#305;, kritik liman altyap&#305;lar&#305;n&#305;n fidye yaz&#305;l&#305;m&#305; gruplar&#305; i&#231;in y&#252;ksek ekonomik de&#287;ere sahip hedefler aras&#305;nda yer ald&#305;&#287;&#305;n&#305; bir kez daha ortaya koymu&#351;tur.</p><h3>Shipping Association of New York &amp; New Jersey (2026): Liman Ekosistemine Y&#246;nelik Veri Odakl&#305; Sald&#305;r&#305;lar</h3><p>Haziran 2026&#8217;da Qilin fidye yaz&#305;l&#305;m&#305; grubu, Amerika Birle&#351;ik Devletleri&#8217;nin en yo&#287;un ticaret merkezlerinden biri olan New York ve New Jersey Liman&#305;&#8217;n&#305;n faaliyetlerini destekleyen Shipping Association of New York &amp; New Jersey&#8217;i hedef ald&#305;&#287;&#305;n&#305; duyurdu.</p><p>Sald&#305;rgan grup, kuruma ait <strong>&#231;e&#351;itli belgeleri ele ge&#231;irdi&#287;ini iddia ederek bunlar&#305;n bir b&#246;l&#252;m&#252;n&#252; karanl&#305;k a&#287; &#252;zerindeki veri s&#305;z&#305;nt&#305;s&#305; platformlar&#305;nda yay&#305;mlad&#305;</strong>. Olay sonras&#305;nda kurum kapsaml&#305; bir inceleme ba&#351;lat&#305;rken, olay&#305;n liman operasyonlar&#305; &#252;zerindeki ger&#231;ek etkisini belirlemek amac&#305;yla dijital adli analiz &#231;al&#305;&#351;malar&#305; y&#252;r&#252;t&#252;ld&#252;.</p><p>Bu olay&#305;n en dikkat &#231;ekici y&#246;n&#252;, sald&#305;r&#305;n&#305;n do&#287;rudan gemi navigasyon sistemlerini veya liman otomasyonunu hedef almamas&#305;d&#305;r. Bunun yerine liman ekosisteminin idari ve operasyonel koordinasyonunu sa&#287;layan bir kurulu&#351; hedef al&#305;nm&#305;&#351;t&#305;r. </p><p>Modern denizcilik operasyonlar&#305;nda gemiler, terminal i&#351;letmecileri, liman otoriteleri, acenteler, lojistik firmalar&#305; ve g&#252;mr&#252;k sistemleri s&#252;rekli veri payla&#351;&#305;m&#305; i&#231;erisinde &#231;al&#305;&#351;maktad&#305;r. Bu yap&#305;lardan herhangi birinin siber sald&#305;r&#305;ya u&#287;ramas&#305;, do&#287;rudan fiziksel sistemler etkilenmese bile t&#252;m operasyonel s&#252;recin aksamas&#305;na neden olabilmektedir.</p><p>Bu vaka, denizcilik sekt&#246;r&#252;nde siber g&#252;venli&#287;in yaln&#305;zca gemilerin veya liman otomasyon sistemlerinin korunmas&#305;ndan ibaret olmad&#305;&#287;&#305;n&#305;; tedarik zincirinde yer alan t&#252;m payda&#351;lar&#305;n ortak bir siber dayan&#305;kl&#305;l&#305;k anlay&#305;&#351;&#305;yla hareket etmesi gerekti&#287;ini g&#246;stermektedir.</p><h3>Bu d&#246;rt vakan&#305;n ortak mesaj&#305;</h3><p>Bu olaylar farkl&#305; teknik y&#246;ntemler i&#231;erse de ortak bir ger&#231;e&#287;i ortaya koymaktad&#305;r: <strong>Denizcilik sekt&#246;r&#252;ndeki siber risk art&#305;k yaln&#305;zca &#8220;bilgisayar korsanlar&#305;n&#305;n &#351;irket a&#287;lar&#305;na girmesi&#8221; meselesi de&#287;ildir.</strong> </p><p><strong>GNSS ve AIS gibi navigasyon sistemlerinden liman bilgi sistemlerine, OT altyap&#305;lar&#305;ndan lojistik koordinasyon platformlar&#305;na kadar geni&#351; bir sald&#305;r&#305; y&#252;zeyi olu&#351;mu&#351;tur.</strong> </p><p>Bu nedenle <strong>Maritime Cyber Security; IT, OT, uydu haberle&#351;mesi, tedarik zinciri g&#252;venli&#287;i ve tehdit istihbarat&#305;n&#305; birlikte ele alan &#231;ok katmanl&#305; bir g&#252;venlik yakla&#351;&#305;m&#305; gerektirmektedir.</strong> </p><p>&#214;zellikle yapay zeka destekli sald&#305;r&#305; tekniklerinin ve otonom denizcilik teknolojilerinin yayg&#305;nla&#351;mas&#305;yla birlikte, bu alan&#305;n &#246;n&#252;m&#252;zdeki y&#305;llarda kritik altyap&#305; g&#252;venli&#287;inin en &#246;nemli &#231;al&#305;&#351;ma ba&#351;l&#305;klar&#305;ndan biri olmaya devam edece&#287;i &#246;ng&#246;r&#252;lmektedir.</p><p></p><h1>Sonu&#231;</h1><p>Denizcilik sekt&#246;r&#252;, k&#252;resel ticaretin en &#246;nemli ta&#351;&#305;y&#305;c&#305;s&#305; olmas&#305;n&#305;n yan&#305;nda, giderek daha fazla dijital sistemlere, uydu haberle&#351;mesine ve operasyonel teknolojilere ba&#287;&#305;ml&#305; hale gelmektedir. </p><p>Bu d&#246;n&#252;&#351;&#252;m; verimlilik, h&#305;z ve otomasyon sa&#287;larken, gemilerden limanlara, navigasyon sistemlerinden lojistik platformlar&#305;na kadar geni&#351; bir siber sald&#305;r&#305; y&#252;zeyi olu&#351;turmaktad&#305;r.</p><p><strong>GPS/GNSS bozma ve aldatma giri&#351;imleri, AIS manip&#252;lasyonu, fidye yaz&#305;l&#305;mlar&#305; ve OT sistemlerine y&#246;nelik sald&#305;r&#305;lar, siber olaylar&#305;n art&#305;k yaln&#305;zca veri kayb&#305;yla s&#305;n&#305;rl&#305; olmad&#305;&#287;&#305;n&#305;, seyir emniyetini, insan hayat&#305;n&#305;, &#231;evresel g&#252;venli&#287;i ve k&#252;resel tedarik zincirini do&#287;rudan etkileyebilece&#287;ini g&#246;stermektedir.</strong></p><p>Bu nedenle Maritime Cyber Security, yaln&#305;zca BT ekiplerinin sorumlulu&#287;unda olan teknik bir konu olarak g&#246;r&#252;lmemelidir. </p><p><strong>IT ve OT g&#252;venli&#287;i, insan fakt&#246;r&#252;, tedarik zinciri, uzaktan eri&#351;im, tehdit istihbarat&#305; ve i&#351; s&#252;reklili&#287;i birlikte ele al&#305;nmal&#305;d&#305;r. </strong></p><p>Denizcilik sekt&#246;r&#252;n&#252;n gelecekteki g&#252;venli&#287;i, sald&#305;r&#305;lar&#305; tamamen &#246;nlemekten &#231;ok, tehditleri erken tespit edebilen, etkilerini s&#305;n&#305;rland&#305;rabilen ve operasyonlar&#305;n&#305; h&#305;zla s&#252;rd&#252;rebilen siber dayan&#305;kl&#305; yap&#305;lar olu&#351;turmas&#305;na ba&#287;l&#305; olacakt&#305;r.</p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br><span>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,</span><br><span>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,</span><br><span>CompTIA Project+ Professional, CIW Security Analyst,</span><br><span>Certified Cyber Threat Intelligence Analyst,</span><br><span>Certified Information Security Executive&#8482;,</span><br><span>Senior Certified Leadership Practitioner.</span></p><p></p><h1>Kaynak&#231;a</h1><ol><li><p>International Maritime Organization (IMO). (2021). <em>Guidelines on Maritime Cyber Risk Management (MSC-FAL.1/Circ.3).</em> London: IMO.</p></li><li><p>International Maritime Organization (IMO). (2017). <em>Resolution MSC.428(98): Maritime Cyber Risk Management in Safety Management Systems.</em> London: IMO.</p></li><li><p>BIMCO, CLIA, ICS, INTERCARGO, INTERTANKO &amp; OCIMF. (2024). <em>The Guidelines on Cyber Security Onboard Ships (Version 5).</em> Copenhagen: BIMCO.</p></li><li><p><span>Cybersecurity and Infrastructure Security Agency (CISA). </span><em>Maritime Transportation System Cybersecurity Resources.</em></p></li><li><p>The Record by Recorded Future. (2026). <em>Coverage of Qilin Ransomware and Shipping Association of New York &amp; New Jersey Incident.</em></p></li><li><p>United States Coast Guard Navigation Center. (2026). <em>GNSS Interference and Navigation Safety Advisories.</em></p></li></ol><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Maritime Cyber Security: The Invisible War in Digital Seas]]></title><description><![CDATA[Thanks for reading Ziya's Substack!]]></description><link>https://ziyagokalp.substack.com/p/maritime-cyber-security-the-invisible</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/maritime-cyber-security-the-invisible</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Sat, 18 Jul 2026 11:00:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!w2_B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1c9997d-8b73-4aa2-b5e4-cb6b10ed90ee_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w2_B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1c9997d-8b73-4aa2-b5e4-cb6b10ed90ee_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w2_B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1c9997d-8b73-4aa2-b5e4-cb6b10ed90ee_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!w2_B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1c9997d-8b73-4aa2-b5e4-cb6b10ed90ee_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!w2_B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1c9997d-8b73-4aa2-b5e4-cb6b10ed90ee_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!w2_B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1c9997d-8b73-4aa2-b5e4-cb6b10ed90ee_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w2_B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1c9997d-8b73-4aa2-b5e4-cb6b10ed90ee_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a1c9997d-8b73-4aa2-b5e4-cb6b10ed90ee_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2408818,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/207533746?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1c9997d-8b73-4aa2-b5e4-cb6b10ed90ee_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!w2_B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1c9997d-8b73-4aa2-b5e4-cb6b10ed90ee_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!w2_B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1c9997d-8b73-4aa2-b5e4-cb6b10ed90ee_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!w2_B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1c9997d-8b73-4aa2-b5e4-cb6b10ed90ee_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!w2_B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1c9997d-8b73-4aa2-b5e4-cb6b10ed90ee_1672x941.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Why Has the World&#8217;s Most Critical Trade Infrastructure Become the New Target of Cyber Attacks?</h1><p>For centuries, the world&#8217;s oceans have been among the most strategic domains, shaping nations&#8217; economic power, trade routes, and military superiority. That reality has not changed today.</p><p>With approximately <strong>80% of global trade</strong> transported by sea, ports, container terminals, tanker fleets, and offshore energy platforms form the invisible backbone of the global economy.</p><p>Over the past two decades, however, the maritime industry has evolved far beyond a sector driven solely by mechanical and physical systems.</p><p>Modern vessels have become <strong>floating data centers</strong>, equipped with hundreds of sensors, satellite communication systems, cloud-based fleet management platforms, automated voyage planning software, and sophisticated <strong>Operational Technology (OT)</strong> infrastructures.</p><p>While this digital transformation has significantly improved operational efficiency, it has also introduced an entirely new category of risk one that is now recognized as <strong>Maritime Cyber Security</strong>.</p><p>As we all know, the objective of a cyber attack is no longer limited to stealing corporate data.</p><p><strong>Today, a threat actor can alter a vessel&#8217;s course, manipulate Electronic Chart Display and Information System (ECDIS) data, disrupt port crane operations, compromise ballast systems that control a vessel&#8217;s stability, trim, and structural load distribution, or even paralyze the global supply chain for days.</strong></p><p>In other words, modern cyber attacks no longer target only information systems they have the potential to directly impact physical operations, maritime safety, environmental protection, and the continuity of international trade.</p><p></p><h1>What Is Maritime Cyber Security?</h1><p>The <strong>International Maritime Organization (IMO)</strong> defines <strong>Maritime Cyber Risk</strong> as the risk arising from threats to information and operational technology systems that could compromise the safety, security, or operational continuity of ships and port facilities.</p><p>For this reason, effective cyber risk management requires a holistic approach that extends beyond traditional IT systems to include <strong>Operational Technology (OT)</strong> environments that support critical maritime operations.</p><p>Within this context, <strong>Maritime Cyber Security</strong> can be defined as the discipline dedicated to protecting the entire digital maritime ecosystem&#8212;including ships, ports, offshore energy platforms, logistics operators, satellite communication infrastructures, and maritime Operational Technology (OT) systems&#8212;from cyber threats while ensuring the resilience, safety, and continuity of maritime operations.</p><p></p><h1>Modern Vessels Are Now Complex Operational Technology (OT) Ecosystems</h1><p>Many people still think of ships as being composed primarily of mechanical systems. In reality, today&#8217;s large commercial vessels operate as highly integrated <strong>Operational Technology (OT)</strong> environments, containing dozens of mission-critical digital control systems.</p><p>Some of the most important systems include:</p><ul><li><p><strong>Electronic Chart Display and Information System (ECDIS)</strong></p></li><li><p><strong>Automatic Identification System (AIS)</strong></p></li><li><p><strong>Global Positioning System (GPS) / Global Navigation Satellite System (GNSS)</strong></p></li><li><p><strong>Radar</strong></p></li><li><p><strong>Dynamic Positioning (DP)</strong></p></li><li><p><strong>Global Maritime Distress and Safety System (GMDSS)</strong></p></li><li><p><strong>Engine Control System</strong></p></li><li><p><strong>Ballast Water Management System</strong></p></li><li><p><strong>Cargo Management System</strong></p></li><li><p><strong>Integrated Bridge System (IBS)</strong></p></li><li><p><strong>Power Management System (PMS)</strong></p></li></ul><p>Because many of these systems directly influence a vessel&#8217;s navigation, stability, propulsion, and overall operational safety, cyber attacks against them can have consequences that extend far beyond traditional information security incidents. In the maritime domain, a successful cyber attack may lead not only to data compromise but also to physical damage, operational disruption, environmental incidents, and risks to human life.</p><p></p><h1>Why Is the Maritime Industry a Prime Target?</h1><p>As the maritime sector continues to embrace digital transformation, it has become one of the most attractive targets for cyber attackers seeking to disrupt critical infrastructure.</p><p>In the past, ships operated largely as isolated mechanical environments. Today, however, modern commercial vessels, ports, and logistics hubs function as highly interconnected digital ecosystems where <strong>Information Technology (IT)</strong>, <strong>Operational Technology (OT)</strong>, cloud computing, satellite communications, and <strong>Internet of Things (IoT)</strong> technologies converge.</p><p>While this transformation has significantly improved operational efficiency, fuel optimization, predictive maintenance, and fleet management, it has also expanded the cyber attack surface to an unprecedented scale.</p><p>One of the primary reasons the maritime industry has become a high-value target is its indispensable role in the global economy. Approximately <strong>80% of global trade by volume</strong> is transported by sea, making maritime transportation the backbone of international commerce.</p><p>As a result, even a short disruption can have far-reaching consequences. If a major container terminal, international port, or global shipping fleet becomes unable to operate for just a few days, the impact extends well beyond the affected organization. Manufacturers, exporters, importers, logistics providers, retailers, and ultimately consumers can all experience significant economic losses as disruptions cascade throughout the global supply chain.</p><p>For cybercriminals and nation-state actors alike, the maritime sector offers a uniquely attractive target: a successful attack has the potential to create operational disruption, financial damage, geopolitical pressure, and widespread supply chain instability on a global scale.</p><p>For this reason, cyber attackers deliberately target industries where operational disruption can generate significant financial pressure. By deploying <strong>ransomware</strong>, they aim to halt critical operations and force organizations to make rapid ransom payments in order to restore business continuity.</p><p>Another major factor is the widespread use of <strong>legacy Operational Technology (OT)</strong> systems throughout the maritime industry.</p><p>Many commercial vessels remain in service for <strong>20 to 30 years</strong>, with their automation systems, <strong>Programmable Logic Controllers (PLCs)</strong>, navigation equipment, and engine control infrastructures operating for decades without significant modernization.</p><p>A substantial number of these systems were designed long before internet connectivity and modern cyber threats became a reality. Consequently, they were not built with cybersecurity in mind and often lack the security controls necessary to withstand today&#8217;s evolving threat landscape.</p><p>At the same time, replacing or upgrading these systems is rarely straightforward. Modernization often requires a vessel to be taken out of service, resulting in operational downtime and considerable financial cost. As a result, software updates and security patches are frequently postponed, leaving critical systems exposed to known vulnerabilities for extended periods.</p><p>The constant connectivity of modern vessels also represents a significant cybersecurity challenge. Today, ships exchange data with their headquarters not only while in port but also when operating in the middle of the ocean through satellite communication systems.</p><p>Critical information including voyage plans, engine performance data, fuel consumption, cargo information, maintenance records, and crew communications is transmitted in real time to shore-based operations centers.</p><p>While this level of connectivity delivers substantial improvements in operational efficiency, fleet management, and predictive maintenance, it also creates additional entry points and expands the attack surface available to cyber adversaries seeking remote access to critical systems.</p><p>The maritime ecosystem&#8217;s heavy reliance on third-party suppliers further increases cyber risk.</p><p>Shipbuilders, automation vendors, navigation software developers, remote maintenance providers, satellite communication companies, and port automation service providers all play essential roles within the same interconnected digital ecosystem.</p><p>As a result, the compromise of just one supplier can become the starting point of a <strong>supply chain attack</strong>, enabling threat actors to gain indirect access to shipping companies, ports, or other critical maritime organizations through trusted business relationships.</p><p>Recent cyber incidents across multiple industries have demonstrated that software update mechanisms and remote maintenance infrastructures can themselves become attack vectors. The maritime sector faces similar risks, particularly as organizations increasingly rely on trusted vendors to maintain and support critical systems remotely.</p><p>At the same time, the traditional boundary between <strong>Information Technology (IT)</strong> and <strong>Operational Technology (OT)</strong>onboard vessels is rapidly disappearing.</p><p>Systems that were once physically isolated are now frequently interconnected to support remote monitoring, maintenance, optimization, configuration management, and advanced data analytics.</p><p>For example, data collected from engine control systems may be transmitted to fleet management platforms, cloud-based applications, or AI-driven predictive maintenance solutions.</p><p>Although this integration delivers significant operational benefits, it also introduces new cybersecurity challenges. Without robust network segmentation and appropriate security controls, an attack that initially compromises the corporate IT environment could potentially propagate into the vessel&#8217;s mission-critical OT systems, where the consequences extend beyond data loss to include operational disruption and physical safety risks.</p><p>Beyond technological vulnerabilities, the <strong>human factor</strong> remains one of the maritime industry&#8217;s most significant cybersecurity challenges. Even the most advanced security technologies can be undermined by phishing attacks, social engineering, compromised credentials, or human error, making cybersecurity awareness and continuous training essential components of an effective maritime cyber resilience strategy.</p><p>Crew rotation also presents a significant cybersecurity challenge. Seafarers frequently change assignments, crew members often come from different countries with varying levels of cybersecurity awareness, and vessels may remain at sea for months, making regular security training and awareness programs difficult to deliver consistently.</p><p>As a result, <strong>phishing attacks</strong>, the uncontrolled use of removable USB devices, weak password practices, and temporary remote access permissions granted to third-party maintenance providers remain among the most common techniques exploited by cyber adversaries.</p><p>Finally, the maritime sector&#8217;s importance extends far beyond its economic value. It also plays a vital geopolitical and strategic role, making it an attractive target for <strong>nation-state and state-sponsored threat actors</strong>.</p><p>Oil tankers, LNG terminals, military logistics ports, submarine communication cables, and major international shipping routes passing through strategic maritime chokepoints are widely recognized as critical national infrastructure.</p><p>Consequently, cyber attacks against the maritime sector are not conducted solely for financial gain. They may also be intended to support intelligence collection, sabotage, economic coercion, geopolitical influence, or broader <strong>hybrid warfare</strong> strategies.</p><p>Recognizing these evolving threats, international maritime organizations have repeatedly emphasized that cybersecurity is no longer merely an IT concern it has become a fundamental component of maritime safety, operational resilience, and global supply chain security.</p><p><strong>BIMCO (Baltic and International Maritime Council)</strong> emphasizes that the increasing convergence of <strong>Information Technology (IT)</strong> and <strong>Operational Technology (OT)</strong> onboard vessels, together with the continuous exchange of data between ships and shore-based facilities, has significantly expanded the number of interconnected systems and, consequently, the overall cyber attack surface.</p><p>Similarly, the <strong>International Maritime Organization (IMO)</strong> recognizes cyber risk management as an integral component of maritime safety and security. Accordingly, the IMO recommends that shipping companies incorporate cyber risk management into their <strong>Safety Management System (SMS)</strong> to ensure that cybersecurity is embedded within their overall operational safety framework.</p><p>These developments clearly demonstrate that cybersecurity in the maritime industry is no longer solely the responsibility of IT departments. Instead, it has evolved into a strategic business priority that requires close collaboration among operations, engineering, safety, cybersecurity, and executive leadership to protect vessels, ports, and the broader maritime ecosystem against increasingly sophisticated cyber threats.</p><p></p><h1>Major Cyber Threats</h1><h3>GPS Spoofing</h3><p><strong>GPS spoofing</strong> is a cyber attack in which an attacker transmits counterfeit <strong>Global Positioning System (GPS)</strong> signals that imitate legitimate satellite transmissions, causing a vessel&#8217;s navigation systems to accept the fake signals as authentic. Since GPS receivers typically rely on the strongest and most consistent signal available, a sufficiently powerful spoofed signal can override the genuine satellite signal.</p><p>As a result, the vessel calculates its position based on false coordinates determined by the attacker rather than its actual location.</p><p>Such an attack can cause the vessel to appear at an incorrect position on the <strong>Electronic Chart Display and Information System (ECDIS)</strong>, broadcast inaccurate location data through the <strong>Automatic Identification System (AIS)</strong>, and lead the autopilot to follow an incorrect course.</p><p>The consequences can be particularly severe in confined waterways, congested shipping lanes, or during port approaches, where GPS spoofing may significantly increase the risk of <strong>collisions, groundings, navigational errors, and operational delays</strong>.</p><p>Unlike conventional cyber attacks that primarily target data confidentiality, GPS spoofing directly threatens navigational safety and may result in physical damage, environmental incidents, cargo losses, and risks to human life.</p><p>GPS spoofing poses a serious threat not only to commercial shipping but also to <strong>naval vessels, offshore energy platforms, and autonomous maritime systems</strong>.</p><p>The growing number of GPS spoofing incidents reported in regions such as the <strong>Black Sea</strong>, the <strong>Eastern Mediterranean</strong>, and the <strong>Persian Gulf</strong> demonstrates that this technique is no longer merely a theoretical concern. It has evolved into a real-world operational threat capable of disrupting navigation and maritime operations.</p><p>For this reason, modern maritime navigation no longer relies exclusively on GPS as a single source of truth. Instead, navigational data is validated through multiple independent sources, including <strong>radar</strong>, the <strong>Automatic Identification System (AIS)</strong>, <strong>Inertial Navigation Systems (INS)</strong>, visual navigation techniques, and alternative <strong>Global Navigation Satellite System (GNSS)</strong> constellations. This multi-layered approach enhances navigational resilience and helps ensure the safe operation of vessels even when satellite navigation signals are compromised.</p><h3>AIS Manipulation</h3><p>The <strong>Automatic Identification System (AIS)</strong> is a critical maritime communication system that enables vessels to automatically exchange information such as identity, position, speed, course, and navigational status with nearby ships and shore-based stations.</p><p>AIS plays a vital role in <strong>collision avoidance, vessel traffic management, search and rescue (SAR) operations, and overall maritime safety</strong>.</p><p><strong>AIS manipulation</strong> refers to the deliberate alteration, falsification, or suppression of AIS transmissions by malicious actors. This may involve generating counterfeit AIS messages, modifying legitimate vessel data, or disabling AIS transmissions altogether.</p><p>Such manipulation can have serious operational consequences. Attackers may create <strong>ghost ships</strong>&#8212;non-existent vessels that appear on AIS displays and mislead maritime traffic. They may also alter a vessel&#8217;s <strong>Maritime Mobile Service Identity (MMSI)</strong>, <strong>International Maritime Organization (IMO) number</strong>, vessel name, or call sign, causing it to impersonate another ship. Likewise, a vessel&#8217;s actual position and voyage can be concealed by broadcasting false coordinates, creating a deceptive maritime traffic picture within electronic navigation systems.</p><p>AIS manipulation extends far beyond navigational safety concerns. It has been associated with <strong>sanctions evasion, illicit oil transportation, smuggling, insurance fraud, illegal fishing, and military or intelligence operations</strong>.</p><p>In recent years, the activities of certain tanker fleets commonly referred to as the <strong>&#8220;Shadow Fleet&#8221;</strong> have demonstrated how AIS manipulation can be exploited in real-world operations. Some vessels have intentionally disabled AIS transmissions, assumed false identities, or broadcast misleading location data in an effort to conceal their activities and circumvent international monitoring.</p><p>As a result, maritime authorities and port operators no longer regard AIS data as a standalone trusted source. Instead, AIS information is routinely cross-validated using <strong>radar systems</strong>, <strong>satellite imagery</strong>, <strong>Synthetic Aperture Radar (SAR)</strong>, <strong>optical satellite observations</strong>, and <strong>AI-powered behavioral analytics</strong> to detect anomalous vessel movements and identify potentially deceptive maritime activities.</p><h3>Ransomware</h3><p><strong>Ransomware</strong> has become one of the most widespread and destructive cyber threats facing the maritime industry. These attacks typically begin with <strong>phishing emails</strong>, insecure remote access services, supply chain compromises, or compromised user credentials that provide attackers with an initial foothold inside a corporate network.</p><p>Once inside, threat actors perform <strong>lateral movement</strong> to gain access to critical servers, file systems, and operational applications. In the final stage of the attack, data is encrypted and, in many cases, sensitive information is exfiltrated before the attackers demand payment&#8212;a tactic commonly known as <strong>double extortion</strong>.</p><p>In the maritime sector, the impact of ransomware extends far beyond traditional corporate IT systems. Modern port operations rely heavily on <strong>Terminal Operating Systems (TOS)</strong>, container management platforms, berth planning applications, customs integration systems, and digital logistics platforms to coordinate daily activities.</p><p>Consequently, even if cranes, vehicles, and other physical equipment remain fully operational, the loss of these digital systems can significantly slow down or completely halt port operations.</p><p>The potential consequences of a ransomware attack on ports and maritime operations include:</p><ul><li><p>Suspension of container loading and unloading operations.</p></li><li><p>Loss of availability of the <strong>Terminal Operating System (TOS)</strong> and port planning applications.</p></li><li><p>Disruption of vessel berthing and departure schedules.</p></li><li><p>Interruption of customs processing and digital documentation workflows.</p></li><li><p>Failure of warehousing, inventory management, and cargo tracking systems.</p></li><li><p>Delays affecting trucking, rail transportation, and multimodal logistics operations.</p></li><li><p>Cascading supply chain disruptions resulting in significant financial and operational losses.</p></li></ul><p>One of the most critical characteristics of ransomware attacks in the maritime sector is that their impact rarely remains confined to a single organization. Because ports, shipping companies, logistics providers, customs authorities, freight forwarders, and manufacturers operate within a highly interconnected ecosystem, the disruption of a major port or shipping operator can trigger a <strong>domino effect</strong> across the global supply chain, affecting importers, exporters, carriers, logistics companies, manufacturing facilities, and ultimately consumers worldwide.</p><h3>Operational Technology (OT) Attacks</h3><p>One of the most critical threats in <strong>Maritime Cyber Security</strong> is cyber attacks targeting <strong>Operational Technology (OT)</strong>systems that control a vessel&#8217;s essential operational processes.</p><p>Unlike traditional <strong>Information Technology (IT)</strong> systems, OT systems directly control physical equipment and industrial processes. Consequently, a cyber incident affecting an OT environment can result not only in data loss but also in physical consequences that may compromise vessel operations, crew safety, and environmental protection.</p><p>On modern commercial vessels, critical functions such as <strong>main engine control</strong>, <strong>power generation and distribution</strong>, <strong>ballast water management</strong>, <strong>Cargo Management Systems (CMS)</strong>, <strong>fuel transfer</strong>, <strong>bilge pumping</strong>, <strong>HVAC</strong>, <strong>fire detection and suppression systems</strong>, and numerous automation processes are managed by <strong>Programmable Logic Controllers (PLCs)</strong>, <strong>Supervisory Control and Data Acquisition (SCADA)</strong> systems, <strong>Distributed Control Systems (DCS)</strong>, and <strong>Human-Machine Interface (HMI)</strong> platforms.</p><p>To improve operational efficiency, many of these systems are now connected to shore-based headquarters, remote maintenance infrastructures, and enterprise information systems. While this integration delivers significant operational benefits, it also considerably expands the cyber attack surface.</p><p>If an attacker gains access to a vessel&#8217;s OT network, the consequences can extend far beyond digital systems. Physical processes themselves may be manipulated.</p><p>For example, attackers could modify engine operating parameters, disrupt generator synchronization, alter ballast tank water levels, interfere with cargo transfer operations, or manipulate other mission-critical control systems.</p><p>A cyber attack against the <strong>Power Management System (PMS)</strong> could trigger a vessel-wide blackout, while manipulation of ballast management systems could compromise the vessel&#8217;s stability and seaworthiness. Likewise, attacks targeting cargo management systems may create severe operational, safety, and environmental risks&#8212;particularly aboard oil tankers, LNG carriers, and chemical tankers transporting hazardous cargo.</p><p>The defining characteristic of OT cyber attacks is that their consequences are not confined to cyberspace. A successful compromise may reduce a vessel&#8217;s maneuverability, prevent safe port entry or departure, interrupt cargo operations, cause environmental pollution, damage critical equipment, and, most importantly, place human lives at risk.</p><p>For this reason, OT security is not merely a subsection of Maritime Cyber Security&#8212;it is widely recognized as one of its most critical pillars.</p><p>Protecting maritime OT environments requires a comprehensive, defense-in-depth strategy that includes <strong>network segmentation</strong>, <strong>secure remote access</strong>, <strong>asset inventory and visibility</strong>, <strong>continuous security monitoring</strong>, <strong>regular vulnerability assessments</strong>, <strong>PLC program integrity verification</strong>, and the implementation of security controls aligned with internationally recognized industrial cybersecurity standards such as <strong>IEC 62443</strong>.</p><p>Today, one of the fundamental principles of maritime cybersecurity is that <strong>IT and OT security can no longer be managed independently</strong>. Instead, organizations must adopt an integrated <strong>cyber resilience</strong> approach that protects both information systems and operational technologies as a unified security ecosystem.</p><p></p><h1>Case Study (2025&#8211;2026)</h1><p>Recent industry reports indicate a significant increase in publicly reported maritime cyber incidents, with <strong>Distributed Denial-of-Service (DDoS)</strong> attacks, <strong>ransomware</strong>, <strong>GPS spoofing</strong>, <strong>GNSS jamming</strong>, and <strong>AIS manipulation</strong> emerging as some of the most prominent threats.</p><p>However, it is important to note that much of the available statistical data originates from private-sector cyber threat intelligence reports. As such, the scope, methodology, and data sources behind these analyses should always be evaluated carefully before drawing broad conclusions.</p><h3>Port of Long Beach GNSS Anomaly (2026): A Reminder of Maritime Dependence on Satellite Navigation</h3><p>In <strong>January 2026</strong>, seven commercial vessels approaching the <strong>Port of Long Beach, California</strong>, experienced unusual <strong>Global Navigation Satellite System (GNSS)</strong> anomalies during the same time period.</p><p>During the incident, the vessels&#8217; electronic navigation systems displayed significant positioning inconsistencies. <strong>Automatic Identification System (AIS)</strong> records indicated that some ships appeared several kilometers away from their actual locations, while certain navigation systems briefly suggested that the vessels were traveling at speeds exceeding <strong>100 knots</strong>. In reality, all vessels continued navigating normally along their intended routes and at their actual speeds.</p><p>What made the incident particularly noteworthy was that similar GNSS irregularities were observed not only aboard the affected vessels but also at nearby <strong>National Oceanic and Atmospheric Administration (NOAA)</strong> monitoring stations and within the navigation systems of certain aircraft operating in the area. This strongly suggested that the anomaly was not limited to a single vessel but affected a much broader geographical region.</p><p>Following the event, authorities indicated that one of the most likely explanations was <strong>planned GPS testing or GNSS signal interference</strong> conducted in the region. Although no malicious cyber attack was conclusively confirmed, the incident clearly demonstrated the maritime industry&#8217;s heavy reliance on satellite-based positioning technologies.</p><p>This case illustrates that threats such as <strong>GPS spoofing</strong> and <strong>GNSS jamming</strong> are no longer merely theoretical concerns. Even a temporary disruption of satellite navigation signals can directly affect <strong>Electronic Chart Display and Information Systems (ECDIS)</strong>, <strong>Automatic Identification Systems (AIS)</strong>, voyage planning, and collision avoidance processes.</p><p>As the maritime industry moves toward increasingly autonomous and digitally connected vessels, ensuring the resilience and integrity of <strong>GNSS-based navigation</strong> will remain one of the most critical cybersecurity priorities for the future of global shipping.</p><h3>Shadow Fleet and AIS Manipulation (2025&#8211;2026): Concealing Digital Identities at Sea</h3><p>Following the international sanctions imposed on Russia, hundreds of tankers collectively referred to as the <strong>&#8220;Shadow Fleet&#8221;</strong> have become a major concern for the global maritime community and maritime security authorities.</p><p>These vessels are widely believed to employ a variety of techniques to circumvent sanctions, obscure their true ownership, and facilitate the transportation of sanctioned cargo.</p><p>During <strong>2025 and 2026</strong>, investigations conducted by several countries&#8212;including <strong>Taiwan</strong>&#8212;revealed that certain shadow fleet vessels had deliberately manipulated their <strong>Automatic Identification System (AIS)</strong> transmissions.</p><p>Investigators identified cases in which the same vessel transmitted under multiple <strong>Maritime Mobile Service Identity (MMSI)</strong> numbers, broadcast different <strong>International Maritime Organization (IMO)</strong> identification numbers, or deliberately disabled AIS transmissions altogether.</p><p>In some instances, vessels appeared hundreds of nautical miles away from their actual locations, intentionally altering their digital footprints to evade detection and monitoring.</p><p>Although these activities do not necessarily involve conventional malware or direct cyber intrusions, they clearly demonstrate how one of the maritime industry&#8217;s most critical safety and tracking systems can be deliberately abused, creating significant operational, regulatory, and security challenges.</p><p>Manipulated AIS data not only facilitates sanctions evasion but may also support <strong>illegal oil transportation, unauthorized ship-to-ship cargo transfers, insurance fraud, illicit maritime trade, and broader maritime security risks</strong>.</p><p>As a result, maritime authorities increasingly avoid relying solely on AIS information. Instead, they combine AIS data with <strong>satellite imagery</strong>, <strong>radar surveillance</strong>, <strong>Synthetic Aperture Radar (SAR)</strong> observations, and <strong>AI-powered behavioral analytics</strong> to identify suspicious vessel activities, detect deceptive navigation patterns, and improve maritime domain awareness.</p><h3>Adriatic Port Authority Ransomware Attack (2026): Critical Port Infrastructure Under Threat</h3><p>In <strong>2026</strong>, one of the major port authorities in the <strong>Adriatic region of Europe</strong> became the target of a ransomware attack attributed to the <strong>Anubis</strong> ransomware group. The incident significantly disrupted the port&#8217;s corporate information systems and several operational management applications.</p><p>Logistics planning systems, document management platforms, and digital applications used to monitor cargo movements experienced substantial service interruptions. Delays were reported in container planning and scheduling, while some port activities had to be carried out manually. As a result, cargo acceptance, shipment planning, and documentation processes slowed considerably, creating cascading delays across port operations.</p><p>Although there has been no official confirmation that all physical port equipment was directly affected, the incident clearly demonstrated that modern ports are far more than collections of cranes and container yards. Their digital infrastructure has become an essential component of daily operations.</p><p>Today, the unavailability of critical information systems can significantly impair port operations, even when physical equipment remains fully functional. Without access to logistics platforms, planning systems, and digital workflows, operational efficiency can rapidly deteriorate, leading to congestion, shipment delays, and broader supply chain disruption.</p><p>This incident serves as another reminder that <strong>critical port infrastructure has become a high-value target for ransomware groups</strong>. By disrupting the digital systems that coordinate maritime logistics, attackers can generate substantial economic impact and exert considerable pressure on organizations to restore operations as quickly as possible.</p><h3>Shipping Association of New York &amp; New Jersey (2026): Data-Centric Attacks on the Port Ecosystem</h3><p>In <strong>June 2026</strong>, the <strong>Qilin</strong> ransomware group claimed responsibility for an attack against the <strong>Shipping Association of New York &amp; New Jersey (SANYNJ)</strong>, an organization that supports operations within one of the busiest maritime trade hubs in the United States.</p><p>The threat actors alleged that they had exfiltrated a variety of organizational documents and subsequently published portions of the stolen data on dark web leak sites. Following the incident, the organization launched a comprehensive investigation and initiated digital forensic analyses to determine the scope of the compromise and assess its actual impact on port-related operations.</p><p>One of the most significant aspects of this incident is that the attackers did <strong>not</strong> directly target vessel navigation systems or port automation infrastructure. Instead, they focused on an organization responsible for the administrative coordination and operational support of the broader port ecosystem.</p><p>Modern maritime operations depend on the continuous exchange of information among shipping companies, terminal operators, port authorities, shipping agents, logistics providers, and customs organizations. Consequently, a cyber attack against any one of these interconnected stakeholders can disrupt operational workflows, even when no physical systems have been directly compromised.</p><p>This case highlights an important reality: <strong>Maritime cybersecurity extends far beyond protecting ships and port automation systems.</strong> It requires a comprehensive cyber resilience strategy that encompasses every organization participating in the maritime supply chain. Effective security depends on collective resilience, information sharing, and coordinated risk management across the entire maritime ecosystem.</p><h3>The Common Message Behind These Four Cases</h3><p>Although these incidents involved different attack techniques and operational scenarios, they all point to the same fundamental reality: <strong>cyber risk in the maritime sector is no longer simply about hackers breaching corporate networks.</strong></p><p>Today&#8217;s maritime threat landscape encompasses a vastly expanded attack surface, ranging from <strong>GNSS</strong> and <strong>AIS</strong> navigation systems to <strong>port information systems</strong>, <strong>Operational Technology (OT)</strong> environments, and <strong>logistics coordination platforms</strong> that support global supply chains.</p><p>Consequently, <strong>Maritime Cyber Security</strong> requires a <strong>multi-layered and integrated security strategy</strong> that brings together <strong>Information Technology (IT)</strong>, <strong>Operational Technology (OT)</strong>, satellite communications, supply chain security, cyber threat intelligence, and continuous operational resilience.</p><p>As <strong>AI-enabled cyber attacks</strong> become increasingly sophisticated and <strong>autonomous maritime technologies</strong> continue to evolve, maritime cybersecurity is expected to remain one of the most critical focus areas for protecting global critical infrastructure. Organizations that adopt proactive cyber resilience strategies today will be significantly better positioned to safeguard maritime operations, ensure navigational safety, and maintain the uninterrupted flow of international trade in the years ahead.</p><p></p><h1>Conclusion</h1><p>The maritime industry is not only the backbone of global trade but is also becoming increasingly dependent on digital technologies, satellite communications, and <strong>Operational Technology (OT)</strong> systems.</p><p>While this digital transformation delivers greater efficiency, automation, and operational performance, it also creates an extensive cyber attack surface spanning vessels, ports, navigation systems, logistics platforms, and the broader maritime supply chain.</p><p>Threats such as <strong>GPS/GNSS jamming and spoofing</strong>, <strong>AIS manipulation</strong>, <strong>ransomware</strong>, and attacks against <strong>OT environments</strong> demonstrate that modern cyber incidents are no longer limited to data breaches or information theft. They have the potential to compromise navigational safety, endanger human life, damage the environment, disrupt critical infrastructure, and interrupt the global flow of commerce.</p><p>For this reason, <strong>Maritime Cyber Security</strong> should not be viewed solely as a technical responsibility assigned to IT departments.</p><p>An effective cybersecurity strategy must integrate <strong>IT and OT security</strong>, human factors, supply chain risk management, secure remote access, cyber threat intelligence, and business continuity into a unified cyber resilience framework.</p><p>Ultimately, the future of maritime security will not be determined by an organization&#8217;s ability to prevent every cyber attack. Rather, it will depend on its capacity to <strong>anticipate emerging threats, detect malicious activity at an early stage, minimize operational impact, and rapidly recover while maintaining safe and uninterrupted maritime operations</strong>.</p><p>In an increasingly connected maritime world, <strong>cyber resilience has become as essential to safe navigation as seaworthiness itself</strong>.</p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,<br>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,<br>CompTIA Project+ Professional, CIW Security Analyst,<br>Certified Cyber Threat Intelligence Analyst,<br>Certified Information Security Executive&#8482;,<br>Senior Certified Leadership Practitioner.</p><p></p><h1>References</h1><ol><li><p>International Maritime Organization (IMO). (2021). <em>Guidelines on Maritime Cyber Risk Management (MSC-FAL.1/Circ.3).</em> London: IMO.</p></li><li><p>International Maritime Organization (IMO). (2017). <em>Resolution MSC.428(98): Maritime Cyber Risk Management in Safety Management Systems.</em> London: IMO.</p></li><li><p>BIMCO, CLIA, ICS, INTERCARGO, INTERTANKO &amp; OCIMF. (2024). <em>The Guidelines on Cyber Security Onboard Ships (Version 5).</em> Copenhagen: BIMCO.</p></li><li><p>Cybersecurity and Infrastructure Security Agency (CISA). <em>Maritime Transportation System Cybersecurity Resources.</em></p></li><li><p>The Record by Recorded Future. (2026). <em>Coverage of Qilin Ransomware and Shipping Association of New York &amp; New Jersey Incident.</em></p></li><li><p>United States Coast Guard Navigation Center. (2026). <em>GNSS Interference and Navigation Safety Advisories.</em></p></li></ol><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Five Eyes (FVEY): Sinyal İstihbaratından Yapay Zeka Destekli Küresel İstihbarat Ekosistemine]]></title><description><![CDATA[PODCAST Linki]]></description><link>https://ziyagokalp.substack.com/p/five-eyes-fvey-sinyal-istihbaratndan</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/five-eyes-fvey-sinyal-istihbaratndan</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Tue, 30 Jun 2026 09:52:49 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0kOo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a4ddc2-c142-49a7-a46f-6dd932ac6356_1690x931.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0kOo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a4ddc2-c142-49a7-a46f-6dd932ac6356_1690x931.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0kOo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a4ddc2-c142-49a7-a46f-6dd932ac6356_1690x931.heic 424w, https://substackcdn.com/image/fetch/$s_!0kOo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a4ddc2-c142-49a7-a46f-6dd932ac6356_1690x931.heic 848w, https://substackcdn.com/image/fetch/$s_!0kOo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a4ddc2-c142-49a7-a46f-6dd932ac6356_1690x931.heic 1272w, https://substackcdn.com/image/fetch/$s_!0kOo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a4ddc2-c142-49a7-a46f-6dd932ac6356_1690x931.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0kOo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a4ddc2-c142-49a7-a46f-6dd932ac6356_1690x931.heic" width="1456" height="802" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b0a4ddc2-c142-49a7-a46f-6dd932ac6356_1690x931.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:802,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:345499,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/204176727?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a4ddc2-c142-49a7-a46f-6dd932ac6356_1690x931.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0kOo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a4ddc2-c142-49a7-a46f-6dd932ac6356_1690x931.heic 424w, https://substackcdn.com/image/fetch/$s_!0kOo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a4ddc2-c142-49a7-a46f-6dd932ac6356_1690x931.heic 848w, https://substackcdn.com/image/fetch/$s_!0kOo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a4ddc2-c142-49a7-a46f-6dd932ac6356_1690x931.heic 1272w, https://substackcdn.com/image/fetch/$s_!0kOo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a4ddc2-c142-49a7-a46f-6dd932ac6356_1690x931.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://creators.spotify.com/pod/profile/ziyagokalp/episodes/Five-Eyes-FVEY-Sinyal-stihbaratndan-Yapay-Zeka-Destekli-Kresel-stihbarat-Ekosistemine-e3lf9hf">PODCAST Linki</a></strong></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1><span>Giri&#351;</span></h1><p><span>Uluslararas&#305; g&#252;venlik mimarisini &#351;ekillendiren kurumlar aras&#305;nda baz&#305;lar&#305; kamuoyunun g&#246;zleri &#246;n&#252;nde faaliyet g&#246;sterirken, baz&#305;lar&#305; ise g&#246;r&#252;nmez olmalar&#305;na ra&#287;men k&#252;resel dengeler &#252;zerinde &#231;ok daha b&#252;y&#252;k etkiye sahiptir. </span></p><p><strong><span>Five Eyes (FVEY), </span></strong><span>yani bir ba&#351;ka ifade ile</span><strong><span> &#8216;Be&#351; G&#246;z&#8217; </span></strong><span>toplulu&#287;u, i&#351;te bu ikinci gruba giren yap&#305;lardan biridir. </span></p><p><span>Yakla&#351;&#305;k seksen y&#305;ld&#305;r varl&#305;&#287;&#305;n&#305; s&#252;rd&#252;ren bu istihbarat ittifak&#305;, yaln&#305;zca be&#351; &#252;lkenin bilgi payla&#351;&#305;m mekanizmas&#305; de&#287;il; modern </span><strong><span>sinyal istihbarat&#305;n&#305;n (SIGINT)</span></strong><span>, </span><strong><span>elektronik g&#246;zetleme faaliyetlerinin, siber tehdit istihbarat&#305;n&#305;n</span></strong><span> ve </span><strong><span>son y&#305;llarda yapay zeka destekli analiz yeteneklerinin merkezinde bulunan k&#252;resel bir g&#252;venlik ekosistemidir.</span></strong></p><p><span>G&#252;n&#252;m&#252;zde bir&#231;ok ki&#351;i </span><strong><span>Five Eyes</span></strong><span>&#8217;&#305; yaln&#305;zca </span><strong><span>ABD, Birle&#351;ik Krall&#305;k, Kanada, Avustralya</span></strong><span> ve </span><strong><span>Yeni Zelanda</span></strong><span>&#8217;n&#305;n olu&#351;turdu&#287;u bir istihbarat payla&#351;&#305;m a&#287;&#305; olarak tan&#305;mlamaktad&#305;r. </span></p><p><span>Ancak bu tan&#305;m, ittifak&#305;n ger&#231;ek kapsam&#305;n&#305; a&#231;&#305;klamak i&#231;in olduk&#231;a yetersizdir. Nitekim </span><strong><span>Five Eyes</span></strong><span>, milyonlarca kilometrelik denizalt&#305; fiber optik kablolar&#305;ndan d&#252;nya y&#246;r&#252;ngesindeki haberle&#351;me uydular&#305;na, k&#252;resel internet omurgas&#305;ndan geli&#351;mi&#351; siber tehdit analiz platformlar&#305;na kadar uzanan &#231;ok katmanl&#305; ve s&#252;rekli geli&#351;en bir istihbarat sistemidir.</span></p><p><span>Bu yap&#305;n&#305;n k&#246;kenleri ise So&#287;uk Sava&#351; y&#305;llar&#305;ndan da &#246;nceye, II. D&#252;nya Sava&#351;&#305;&#8217;n&#305;n en kritik d&#246;nemlerine kadar uzanmaktad&#305;r. </span></p><p><span>Bug&#252;n yapay zeka destekli tehdit analizleri yapan ve devlet destekli siber operasyonlara ili&#351;kin ortak uyar&#305;lar yay&#305;mlayan </span><strong><span>Five Eyes</span></strong><span>, ilk kuruldu&#287;unda yaln&#305;zca Alman askeri haberle&#351;melerini dinleyebilmek amac&#305;yla olu&#351;turulmu&#351; gizli bir i&#351; birli&#287;iydi. </span></p><p><span>Aradan ge&#231;en seksen y&#305;l i&#231;erisinde teknoloji de&#287;i&#351;mi&#351;, tehditler d&#246;n&#252;&#351;m&#252;&#351;, sava&#351; alanlar&#305; dijitalle&#351;mi&#351; ve istihbarat anlay&#305;&#351;&#305; k&#246;kten evrilmi&#351;tir. </span></p><p><span>Ancak </span><strong><span>Five Eyes</span></strong><span>, her d&#246;nemde kendisini yeniden uyarlayarak k&#252;resel g&#252;venlik mimarisinin en etkili akt&#246;rlerinden biri olmay&#305; ba&#351;arm&#305;&#351;t&#305;r.</span></p><p><strong><span>Five Eyes</span></strong><span>&#8217;&#305;n hikayesi yaln&#305;zca be&#351; &#252;lkenin ortakl&#305;&#287;&#305; de&#287;ildir. </span><strong><span>Ayn&#305; zamanda modern istihbarat&#305;n evrimini, sinyal istihbarat&#305;ndan siber g&#252;venli&#287;e, b&#252;y&#252;k veri analizinden yapay zeka destekli karar mekanizmalar&#305;na uzanan d&#246;n&#252;&#351;&#252;m&#252;n&#252; anlatan &#246;nemli bir tarihsel s&#252;re&#231;tir.</span></strong></p><p></p><h1><span>Modern SIGINT&#8217;in Do&#287;u&#351;u</span></h1><p><span>Modern sinyal istihbarat&#305;n&#305;n temelleri, II. D&#252;nya Sava&#351;&#305; s&#305;ras&#305;nda at&#305;lm&#305;&#351;t&#305;r. </span></p><p><span>Sava&#351;&#305;n ilk y&#305;llar&#305;nda Almanya&#8217;n&#305;n askeri birlikleri, donanmas&#305; ve hava kuvvetleri haberle&#351;melerini </span><strong><span>Enigma</span></strong><span> ad&#305; verilen </span><strong><span>elektromekanik &#351;ifreleme makinesi</span></strong><span> ile koruyordu. </span></p><p><span>Alman komutanl&#305;&#287;&#305;, </span><strong><span>Enigma</span></strong><span>&#8217;n&#305;n matematiksel olarak &#231;&#246;z&#252;lemeyecek kadar karma&#351;&#305;k oldu&#287;una inan&#305;yordu. </span></p><p><span>Her g&#252;n de&#287;i&#351;en anahtarlar, farkl&#305; rotor kombinasyonlar&#305; ve milyonlarca olas&#305; &#351;ifreleme d&#252;zeni nedeniyle sistem pratik olarak k&#305;r&#305;lamaz kabul ediliyordu.</span></p><p><span>Ancak sava&#351;&#305;n kaderini de&#287;i&#351;tirecek geli&#351;me, &#304;ngiltere&#8217;deki </span><strong><span>Bletchley Park</span></strong><span>&#8217;ta ya&#351;and&#305;. </span><strong><span>Matematik&#231;iler, dilbilimciler, satran&#231; ustalar&#305;, m&#252;hendisler</span></strong><span> ve </span><strong><span>kriptanalistler</span></strong><span> burada d&#252;nyan&#305;n ilk b&#252;y&#252;k &#246;l&#231;ekli </span><strong><span>kripto analiz merkezlerinden</span></strong><span> birini kurdular. </span></p><p><span>Bu ekibin en tan&#305;nm&#305;&#351; isimlerinden biri </span><strong><span>Alan Turing</span></strong><span>&#8217;di. </span><strong><span>Turing</span></strong><span> ve &#231;al&#305;&#351;ma arkada&#351;lar&#305; yaln&#305;zca </span><strong><span>Enigma</span></strong><span> &#351;ifrelerini &#231;&#246;zmekle kalmad&#305;lar, ayn&#305; zamanda otomatik &#351;ifre &#231;&#246;z&#252;m makineleri geli&#351;tirerek modern bilgisayar biliminin de temelini att&#305;lar.</span></p><p><strong><span>Enigma</span></strong><span>&#8217;n&#305;n &#231;&#246;z&#252;lmesiyle elde edilen istihbarata &#8220;</span><strong><span>Ultra Intelligence</span></strong><span>&#8221; ad&#305; verildi. </span></p><p><strong><span>Ultra</span></strong><span> sayesinde M&#252;ttefik Devletler, Alman denizalt&#305;lar&#305;n&#305;n Atlantik Okyanusu&#8217;ndaki hareketlerini &#246;nceden tespit edebiliyor, askeri birliklerin sevkiyat planlar&#305;n&#305; &#246;&#287;renebiliyor ve bir&#231;ok stratejik operasyonu daha ba&#351;lamadan engelleyebiliyordu. </span></p><p><span>Tarih&#231;iler, sava&#351;&#305;n Avrupa cephesinde iki ila d&#246;rt y&#305;l aras&#305;nda daha erken sona ermesinde Ultra istihbarat&#305;n&#305;n belirleyici rol oynad&#305;&#287;&#305; konusunda b&#252;y&#252;k &#246;l&#231;&#252;de hemfikirdir.</span></p><p><span>Bu s&#252;re&#231;, </span><strong><span>modern SIGINT</span></strong><span>&#8217;in yaln&#305;zca teknik bir disiplin de&#287;il, sava&#351;&#305;n sonucunu de&#287;i&#351;tirebilecek stratejik bir g&#252;&#231; oldu&#287;unu g&#246;stermi&#351;tir.</span></p><p></p><h1><span>SIGINT Nedir?</span></h1><p><strong><span>SIGINT (Signals Intelligence)</span></strong><span>, </span><strong><span>elektronik haberle&#351;melerden ve elektromanyetik sinyallerden elde edilen istihbarat&#305;n genel ad&#305;d&#305;r</span></strong><span>. Modern istihbarat disiplinleri i&#231;erisinde en teknolojik alanlardan biri olan </span><strong><span>SIGINT</span></strong><span>, insanlar&#305;n s&#246;ylediklerinden &#231;ok cihazlar&#305;n &#252;retti&#287;i sinyalleri analiz etmeye odaklan&#305;r.</span></p><p><strong><span>SIGINT</span></strong><span> kendi i&#231;erisinde &#231;e&#351;itli alt disiplinlere ayr&#305;l&#305;r. </span></p><p><strong><span>COMINT (Communications Intelligence)</span></strong><span>, telefon g&#246;r&#252;&#351;meleri, telsiz konu&#351;malar&#305;, internet trafi&#287;i ve di&#287;er haberle&#351;me i&#231;eriklerinin analizini kapsar. </span></p><p><strong><span>ELINT (Electronic Intelligence)</span></strong><span>, radar sistemleri, hava savunma a&#287;lar&#305; ve elektronik yay&#305;mlar gibi haberle&#351;me d&#305;&#351;&#305;ndaki elektromanyetik sinyalleri inceler. </span></p><p><strong><span>FISINT (Foreign Instrumentation Signals Intelligence)</span></strong><span>, f&#252;ze testleri, uzay sistemleri ve telemetri verilerinden elde edilen yabanc&#305; teknik sinyalleri de&#287;erlendirir. </span></p><p><strong><span>MASINT (Measurement and Signature Intelligence)</span></strong><span> ise n&#252;kleer, kimyasal, biyolojik veya fiziksel &#246;l&#231;&#252;mlere dayal&#305; &#246;zg&#252;n teknik izleri analiz eder.</span></p><p><strong><span>SIGINT</span></strong><span>, </span><strong><span>HUMINT</span></strong><span>&#8217;ten, yani </span><strong><span>insan odakl&#305; istihbarattan</span></strong><span> farkl&#305; olarak </span><strong><span>insan kaynaklar&#305;na ba&#287;&#305;ml&#305; de&#287;ildir</span></strong><span>. </span></p><p><strong><span>OSINT</span></strong><span> gibi </span><strong><span>a&#231;&#305;k kaynaklara dayanmaz</span></strong><span> ve </span><strong><span>IMINT (Imagery Intelligence)</span></strong><span> ya da </span><strong><span>GEOINT (Geospatial Intelligence)</span></strong><span> gibi </span><strong><span>yaln&#305;zca g&#246;r&#252;nt&#252; verilerine odaklanmaz</span></strong><span>. </span></p><p><strong><span>Bunun yerine, dijital d&#252;nyan&#305;n g&#246;r&#252;nmeyen ileti&#351;im katman&#305;n&#305; analiz ederek devletlerin niyetleri, askeri haz&#305;rl&#305;klar&#305;, operasyonel planlar&#305; ve teknik kabiliyetleri hakk&#305;nda bilgi &#252;retir.</span></strong></p><p><span>So&#287;uk Sava&#351; boyunca Sovyet radar sistemlerinin frekanslar&#305;n&#305;n belirlenmesinden g&#252;n&#252;m&#252;zde devlet destekli siber sald&#305;r&#305; gruplar&#305;n&#305;n komuta-kontrol trafi&#287;inin analiz edilmesine kadar uzanan geni&#351; bir faaliyet alan&#305;, </span><strong><span>SIGINT</span></strong><span>&#8217;in kapsam&#305;na girmektedir.</span></p><p></p><h1><span>BRUSA ve UKUSA Anla&#351;malar&#305;: Five Eyes&#8217;&#305;n Do&#287;u&#351;u</span></h1><p><strong><span>1943 y&#305;l&#305;nda</span></strong><span> Amerika Birle&#351;ik Devletleri ile Birle&#351;ik Krall&#305;k aras&#305;nda imzalanan </span><strong><span>BRUSA Agreement</span></strong><span>, sava&#351; d&#246;nemindeki sinyal istihbarat&#305; payla&#351;&#305;m&#305;n&#305; resmi hale getiren ilk kapsaml&#305; anla&#351;mayd&#305;. (</span><strong>BRUSA</strong><span>, </span><strong>Britain&#8211;United States of America</strong><span> ifadesinin k&#305;saltmas&#305;d&#305;r).  </span></p><p><span>Bu i&#351; birli&#287;i sayesinde iki &#252;lke yaln&#305;zca elde ettikleri verileri payla&#351;m&#305;yor, ayn&#305; zamanda </span><strong><span>kripto analiz y&#246;ntemlerini, teknik personellerini</span></strong><span> ve </span><strong><span>dinleme altyap&#305;lar&#305;n&#305;</span></strong><span> da ortak kullan&#305;yordu.</span></p><p><span>Sava&#351; sona erdi&#287;inde ortak tehdit ortadan kalkm&#305;&#351; gibi g&#246;r&#252;nse de &#231;ok ge&#231;meden yeni bir jeopolitik d&#246;nem ba&#351;lad&#305;. Sovyetler Birli&#287;i ile Bat&#305; d&#252;nyas&#305; aras&#305;ndaki ideolojik rekabet, So&#287;uk Sava&#351;&#8217;&#305; do&#287;urdu. </span></p><p><span>Bu yeni g&#252;venlik ortam&#305;, ge&#231;ici sava&#351; ortakl&#305;&#287;&#305;n&#305;n kal&#305;c&#305; bir istihbarat ittifak&#305;na d&#246;n&#252;&#351;mesini zorunlu k&#305;ld&#305;.</span></p><p><strong><span>1946 y&#305;l&#305;nda imzalanan UKUSA Agreement, Five Eyes&#8217;&#305;n ger&#231;ek kurulu&#351; belgesi olarak kabul edilmektedir</span></strong><span>. (</span><strong><span>UKUSA</span></strong><span> Kelime anlam&#305;yla </span><strong>"Birle&#351;ik Krall&#305;k&#8211;Amerika Birle&#351;ik Devletleri Anla&#351;mas&#305;"</strong><span> demektir).</span></p><p><span>Bu anla&#351;ma, </span><strong><span>Amerika Birle&#351;ik Devletleri</span></strong><span> ile </span><strong><span>Birle&#351;ik Krall&#305;k</span></strong><span> aras&#305;nda sinyal istihbarat&#305;n&#305;n sistematik bi&#231;imde payla&#351;&#305;lmas&#305;n&#305; &#246;ng&#246;r&#252;yordu. Daha sonraki y&#305;llarda </span><strong><span>Kanada, Avustralya</span></strong><span> ve </span><strong><span>Yeni Zelanda</span></strong><span>&#8217;n&#305;n kat&#305;l&#305;m&#305;yla bug&#252;nk&#252; </span><strong><span>Five Eyes</span></strong><span> yap&#305;s&#305; olu&#351;tu.</span></p><p><span>Anla&#351;man&#305;n temel amac&#305; yaln&#305;zca bilgi payla&#351;&#305;m&#305; de&#287;ildi. </span></p><p><strong><span>D&#252;nya co&#287;rafyas&#305; be&#351; &#252;lke aras&#305;nda b&#246;lgelere ayr&#305;l&#305;yor, her &#252;lke belirli haberle&#351;me a&#287;lar&#305;n&#305; takip ediyor ve elde edilen bilgiler ortak veri havuzunda birle&#351;tiriliyordu. B&#246;ylece tek bir &#252;lkenin eri&#351;emeyece&#287;i k&#252;resel kapsama alan&#305; olu&#351;turulmu&#351; oluyordu.</span></strong></p><p></p><h1><span>Five Eyes Kimlerden Olu&#351;ur?</span></h1><p><strong><span>Five Eyes</span></strong><span>, </span><strong><span>Amerika Birle&#351;ik Devletleri, Birle&#351;ik Krall&#305;k, Kanada, Avustralya</span></strong><span> ve </span><strong><span>Yeni Zelanda</span></strong><span>&#8217;dan olu&#351;maktad&#305;r. Bu &#252;lkeler ortak tarih, dil, hukuk sistemi ve askeri i&#351; birli&#287;i gibi unsurlar nedeniyle &#8220;</span><strong><span>Anglosphere</span></strong><span>&#8221; olarak adland&#305;r&#305;lan g&#252;venlik toplulu&#287;unun &#231;ekirde&#287;ini olu&#351;turmaktad&#305;r.</span></p><p><strong><span>Amerika Birle&#351;ik Devletleri</span></strong><span>, &#246;zellikle </span><strong><span>NSA-National Security Agency</span></strong><span> kurumunun sahip oldu&#287;u teknik kapasite sayesinde ittifak&#305;n en b&#252;y&#252;k veri i&#351;leme ve analiz merkezidir. </span></p><p><strong><span>Birle&#351;ik Krall&#305;k</span></strong><span>&#8217;taki </span><strong><span>GCHQ-Government Communications Headquarters</span></strong><span> kurumu ise &#246;zellikle Avrupa, Orta Do&#287;u ve Afrika&#8217;daki haberle&#351;me a&#287;lar&#305;n&#305;n izlenmesinde kritik rol oynar.</span></p><p><strong><span>Kanada</span></strong><span>&#8217;n&#305;n </span><strong><span>CSE-Communications Security Establishment</span></strong><span> kurumu Arktik b&#246;lgesi ve Kuzey Atlantik&#8217;teki faaliyetlere odaklan&#305;rken, </span><strong><span>Avustralya&#8217;n&#305;n ASD-Australian Signals Directorate</span></strong><span> kurumu arac&#305;l&#305;&#287;&#305;yla Hint-Pasifik b&#246;lgesindeki elektronik istihbarat&#305;n &#246;nemli b&#246;l&#252;m&#252;n&#252; y&#252;r&#252;tmektedir. </span></p><p><strong><span>Yeni Zelanda</span></strong><span>&#8217;n&#305;n </span><strong><span>GCSB-Government Communications Security Bureau</span></strong><span> kurumu ise G&#252;ney Pasifik&#8217;teki haberle&#351;me a&#287;lar&#305;n&#305;n izlenmesinde uzmanla&#351;m&#305;&#351;t&#305;r.</span></p><p><span>Bu i&#351; b&#246;l&#252;m&#252; sayesinde </span><strong><span>Five Eyes</span></strong><span>, d&#252;nyan&#305;n neredeyse tamam&#305;n&#305; kapsayan k&#252;resel bir dinleme ve analiz a&#287;&#305; olu&#351;turmu&#351;tur.</span></p><p></p><h1><span>So&#287;uk Sava&#351;&#8217;tan Dijital &#199;a&#287;a Evrim</span></h1><p><span>So&#287;uk Sava&#351; y&#305;llar&#305;nda </span><strong><span>Five Eyes</span></strong><span>&#8217;&#305;n temel g&#246;revi Sovyetler Birli&#287;i&#8217;nin askeri haberle&#351;mesini izlemekti. </span><strong><span>Radar yay&#305;nlar&#305;, denizalt&#305; ileti&#351;imleri, diplomatik mesajlar</span></strong><span> ve </span><strong><span>stratejik f&#252;ze testleri</span></strong><span> s&#252;rekli takip ediliyordu. Bu d&#246;nemde geli&#351;tirilen bir&#231;ok elektronik dinleme teknolojisi, g&#252;n&#252;m&#252;z </span><strong><span>siber g&#246;zetleme</span></strong><span> sistemlerinin temelini olu&#351;turdu.</span></p><p><span>1980&#8217;li y&#305;llarda uydu haberle&#351;melerinin yayg&#305;nla&#351;mas&#305;yla birlikte dinleme altyap&#305;s&#305; da uzaya ta&#351;&#305;nd&#305;. Ard&#305;ndan internetin k&#252;resel &#246;l&#231;ekte yayg&#305;nla&#351;mas&#305;, </span><strong><span>istihbarat anlay&#305;&#351;&#305;n&#305; k&#246;kten de&#287;i&#351;tirdi</span></strong><span>. Art&#305;k yaln&#305;zca radyo sinyalleri de&#287;il, e-posta trafi&#287;i, internet omurgalar&#305;, fiber optik kablolar ve veri merkezleri de istihbarat&#305;n hedefi haline gelmi&#351;ti.</span></p><p><span>Bu d&#246;n&#252;&#351;&#252;m, </span><strong><span>Five Eyes</span></strong><span>&#8217;&#305;n yaln&#305;zca askeri istihbarat &#246;rg&#252;t&#252; olmaktan &#231;&#305;karak </span><strong><span>k&#252;resel dijital ekosistemin en &#246;nemli analiz platformlar&#305;ndan biri haline gelmesini sa&#287;lad&#305;.</span></strong></p><p></p><h1><span>ECHELON&#8217;dan Siber Tehdit &#304;stihbarat&#305;na</span></h1><p><span>1990&#8217;l&#305; y&#305;llarda kamuoyunun dikkatini &#231;eken, </span><strong><span>Electronic Communications Harvesting and Extraction</span></strong><span> a&#231;&#305;l&#305;m&#305; ile tan&#305;mlanan </span><strong><span>ECHELON</span></strong><span> sistemi, </span><strong><span>Five Eyes</span></strong><span>&#8217;&#305;n k&#252;resel elektronik dinleme kapasitesini g&#246;zler &#246;n&#252;ne serdi. </span></p><p><strong><span>Uydu haberle&#351;meleri, telefon g&#246;r&#252;&#351;meleri, fakslar ve &#231;e&#351;itli veri iletim sistemlerinin belirli anahtar kelimeler &#252;zerinden filtrelenebildi&#287;i iddialar&#305;, kitlesel g&#246;zetim tart&#305;&#351;malar&#305;n&#305; da beraberinde getirdi.</span></strong></p><p><span>2000&#8217;li y&#305;llarda ise tehdit ortam&#305; yeniden de&#287;i&#351;ti. Art&#305;k klasik askeri rakiplerin yan&#305;nda </span><strong><span>devlet destekli siber casusluk gruplar&#305;, fidye yaz&#305;l&#305;m&#305; operasyonlar&#305;</span></strong><span> ve </span><strong><span>kritik altyap&#305;lara y&#246;nelik geli&#351;mi&#351; sald&#305;r&#305;lar</span></strong><span> &#246;ne &#231;&#305;k&#305;yordu.</span></p><p><strong><span>Five Eyes</span></strong><span> da bu de&#287;i&#351;ime uyum sa&#287;layarak siber tehdit istihbarat&#305;na a&#287;&#305;rl&#305;k verdi. </span></p><p><strong><span>Zararl&#305; yaz&#305;l&#305;mlar analiz edilmeye, sald&#305;r&#305; altyap&#305;lar&#305; izlenmeye ve ortak teknik uyar&#305;lar yay&#305;mlanmaya ba&#351;land&#305;</span></strong><span>. </span></p><p><span>G&#252;n&#252;m&#252;zde yay&#305;mlanan bir&#231;ok ortak teknik rapor, </span><strong><span>zararl&#305; yaz&#305;l&#305;m g&#246;stergeleri (IoC-Indicator of Compromise)</span></strong><span> ve </span><strong><span>sald&#305;r&#305; teknikleri (TTP-Tactics, Techniques, and Procedures)</span></strong><span> </span><strong><span>savunma &#246;nerileri</span></strong><span> ve </span><strong><span>olay m&#252;dahale rehberlerini</span></strong><span> i&#231;ermektedir.</span></p><p></p><h1><span>Yapay Zeka &#199;a&#287;&#305;nda Five Eyes</span></h1><p><span>G&#252;n&#252;m&#252;zde kar&#351;&#305;la&#351;&#305;lan veri miktar&#305;, insan analistlerin tek ba&#351;&#305;na y&#246;netebilece&#287;i seviyenin &#231;ok &#252;zerindedir. </span></p><p><span>Bu nedenle </span><strong><span>Five Eyes</span></strong><span>, </span><strong><span>b&#252;y&#252;k veri analiti&#287;i, makine &#246;&#287;renmesi, davran&#305;&#351; analizi ve yapay zeka destekli karar sistemlerini yo&#287;un bi&#231;imde kullanmaktad&#305;r.</span></strong></p><p><strong><span>Modern istihbarat art&#305;k yaln&#305;zca bilgi toplamak de&#287;ildir. Ger&#231;ek de&#287;er, milyarlarca veri noktas&#305; aras&#305;ndaki anlaml&#305; ili&#351;kileri ortaya &#231;&#305;karabilmektedir.</span></strong><span> </span></p><p><span>Yapay zeka algoritmalar&#305;, farkl&#305; kaynaklardan gelen verileri ili&#351;kilendirerek potansiyel tehditleri &#231;ok daha erken tespit edebilmekte, sald&#305;r&#305; kampanyalar&#305;n&#305; k&#252;melendirebilmekte ve devlet destekli operasyonlar&#305;n arkas&#305;ndaki akt&#246;rleri belirlemede analistlere &#246;nemli destek sa&#287;lamaktad&#305;r.</span></p><p><strong><span>Bu nedenle Five Eyes&#8217;&#305;n evrimi, yaln&#305;zca teknolojik bir d&#246;n&#252;&#351;&#252;m de&#287;il, istihbarat&#305;n &#252;retim bi&#231;iminin de&#287;i&#351;mesidir. </span></strong></p><p><strong><span>Geleneksel SIGINT yakla&#351;&#305;m</span></strong><span>&#305;, </span><strong><span>g&#252;n&#252;m&#252;zde yapay zeka destekli &#231;ok kaynakl&#305; istihbarat analizine d&#246;n&#252;&#351;m&#252;&#351; durumdad&#305;r.</span></strong></p><p></p><h1>Five Eyes'&#305;n Hukuki ve Etik Boyutu</h1><p><strong>Five Eyes</strong>, uluslararas&#305; hukuk kapsam&#305;nda kurulmu&#351; ba&#287;&#305;ms&#305;z bir kurulu&#351; de&#287;il, temelini <strong>1946 tarihli UKUSA Agreement</strong>&#8216;tan alan h&#252;k&#252;metler aras&#305; bir istihbarat payla&#351;&#305;m mekanizmas&#305;d&#305;r. </p><p>Bu nedenle &#252;yeler aras&#305;ndaki veri payla&#351;&#305;m&#305;, ortak bir uluslararas&#305; yasa yerine her &#252;lkenin kendi <strong>ulusal g&#252;venlik mevzuat&#305;</strong> ve ikili/multilateral gizli istihbarat anla&#351;malar&#305; &#231;er&#231;evesinde y&#252;r&#252;t&#252;lmektedir. </p><p>Her &#252;lke, kendi hukukuna uygun olarak toplad&#305;&#287;&#305; yabanc&#305; istihbarat&#305; belirli s&#305;n&#305;fland&#305;rma ve payla&#351;&#305;m kurallar&#305; kapsam&#305;nda di&#287;er <strong>Five Eyes</strong> &#252;yeleriyle payla&#351;abilmektedir.</p><p>Bununla birlikte bu yap&#305;, y&#305;llard&#305;r hukuki ve etik tart&#305;&#351;malar&#305;n da oda&#287;&#305;nda yer almaktad&#305;r. </p><p>&#214;zellikle ki&#351;isel verilerin korunmas&#305;, kitlesel g&#246;zetim, mahremiyet hakk&#305; ve demokratik denetim konular&#305;, <strong>Five Eyes</strong>&#8217;a y&#246;neltilen ba&#351;l&#305;ca ele&#351;tirilerdir. <br><br>Etik a&#231;&#305;dan de&#287;erlendirildi&#287;inde temel tart&#305;&#351;ma, g&#252;venlik ile bireysel &#246;zg&#252;rl&#252;k aras&#305;ndaki denge &#252;zerinde yo&#287;unla&#351;maktad&#305;r. <strong>Devletler ter&#246;rizm, siber casusluk, kritik altyap&#305;lara y&#246;nelik sald&#305;r&#305;lar</strong> ve <strong>yabanc&#305; istihbarat faaliyetleriyle m&#252;cadele</strong> edebilmek i&#231;in geni&#351; veri toplama yetkilerine ihtiya&#231; duyduklar&#305;n&#305; savunurken, <strong>mahremiyet savunucular&#305; kitlesel veri toplaman&#305;n demokratik toplumlarda bireysel hak ve &#246;zg&#252;rl&#252;kleri zedeleyebilece&#287;ini ileri s&#252;rmektedir.</strong></p><p>2013 y&#305;l&#305;nda <strong>Edward Snowden</strong> taraf&#305;ndan yay&#305;mlanan belgeler, k&#252;resel elektronik g&#246;zetim faaliyetlerini g&#246;r&#252;n&#252;r hale getirerek bu tart&#305;&#351;malar&#305; daha da art&#305;rm&#305;&#351;t&#305;r.</p><p>G&#252;n&#252;m&#252;zde ise yapay zeka destekli veri analiti&#287;inin istihbarat s&#252;re&#231;lerine entegre edilmesi, tart&#305;&#351;may&#305; yeni bir boyuta ta&#351;&#305;maktad&#305;r. </p><p>Bu ba&#287;lamda g&#252;n&#252;m&#252;zde tart&#305;&#351;&#305;lan konu yaln&#305;zca verilerin toplanmas&#305; de&#287;il, farkl&#305; &#252;lkelerden elde edilen b&#252;y&#252;k veri k&#252;melerinin yapay zeka ile analiz edilmesi, ili&#351;kilendirilmesi ve karar destek mekanizmalar&#305;nda kullan&#305;lmas&#305;d&#305;r. </p><p>Bu nedenle <strong>Five Eyes</strong>, ulusal g&#252;venlik ile bireysel mahremiyet aras&#305;ndaki hassas dengeyi en fazla tart&#305;&#351;&#305;lan uluslararas&#305; istihbarat i&#351; birli&#287;i modellerinden biri olmaya devam etmektedir.</p><p></p><h1><span>Sonu&#231;</span></h1><p><strong><span>Five Eyes</span></strong><span>, II. D&#252;nya Sava&#351;&#305; s&#305;ras&#305;nda Alman haberle&#351;melerini &#231;&#246;zmek amac&#305;yla ba&#351;layan teknik bir i&#351; birli&#287;inin, k&#252;resel g&#252;venlik mimarisini &#351;ekillendiren kal&#305;c&#305; bir istihbarat ittifak&#305;na d&#246;n&#252;&#351;mesinin en &#231;arp&#305;c&#305; &#246;rneklerinden biridir. </span></p><p><span>Seksen y&#305;l&#305; a&#351;k&#305;n s&#252;re boyunca de&#287;i&#351;en tehdit ortam&#305;na uyum sa&#287;layarak &#246;nce So&#287;uk Sava&#351;&#8217;&#305;n elektronik dinleme a&#287;&#305;, ard&#305;ndan internet &#231;a&#287;&#305;n&#305;n k&#252;resel g&#246;zetleme sistemi ve bug&#252;n de siber g&#252;venlik ile yapay zeka destekli analiz yeteneklerinin merkezinde yer alan &#231;ok boyutlu bir istihbarat ekosistemi haline gelmi&#351;tir.</span></p><p><span>Bug&#252;n </span><strong><span>Five Eyes</span></strong><span> yaln&#305;zca devletlerin haberle&#351;melerini izleyen bir </span><strong><span>SIGINT</span></strong><span> organizasyonu de&#287;ildir. </span></p><p><strong><span>Ayn&#305; zamanda kritik altyap&#305;lar&#305;n korunmas&#305;, devlet destekli siber operasyonlar&#305;n tespiti, uluslararas&#305; siber tehdit istihbarat&#305; payla&#351;&#305;m&#305;, se&#231;im g&#252;venli&#287;i, dezenformasyonla m&#252;cadele, uzay tabanl&#305; g&#246;zetleme ve yapay zeka destekli karar sistemleri gibi alanlarda da k&#252;resel g&#252;venli&#287;in &#246;nemli akt&#246;rlerinden biridir.</span></strong></p><p><span>Teknoloji geli&#351;tik&#231;e sava&#351; alanlar&#305; fiziksel co&#287;rafyadan dijital ortama ta&#351;&#305;nmaktad&#305;r. </span></p><p><span>Bu d&#246;n&#252;&#351;&#252;m, istihbarat te&#351;kilatlar&#305;n&#305; da s&#252;rekli yeniden &#351;ekillendirmektedir. </span></p><p><span>B&#252;y&#252;k olas&#305;l&#305;kla &#246;n&#252;m&#252;zdeki y&#305;llarda </span><strong><span>Five Eyes</span></strong><span>, yaln&#305;zca sinyal istihbarat&#305; &#252;reten bir yap&#305; olmaktan &#231;&#305;karak yapay zeka taraf&#305;ndan desteklenen, ger&#231;ek zamanl&#305; analiz yapabilen ve &#231;ok alanl&#305; g&#252;venlik operasyonlar&#305;n&#305; koordine eden k&#252;resel bir karar destek a&#287;&#305;na d&#246;n&#252;&#351;meye devam edecektir. </span></p><p><strong><span>Modern istihbarat&#305;n gelece&#287;i, yaln&#305;zca daha fazla veri toplamak de&#287;il, toplanan veriyi do&#287;ru zamanda, do&#287;ru ba&#287;lamda ve do&#287;ru karar mekanizmalar&#305;na d&#246;n&#252;&#351;t&#252;rebilmektir.</span></strong><span> </span></p><p><strong><span>Five Eyes</span></strong><span>&#8217;&#305;n tarihsel evrimi de tam olarak bu d&#246;n&#252;&#351;&#252;m&#252;n en belirgin &#246;rneklerinden birini olu&#351;turmaktad&#305;r.</span></p><p><span>Bu d&#246;n&#252;&#351;&#252;m&#252;n g&#252;ncel bir yans&#305;mas&#305; da </span><strong><span>Five Eyes</span></strong><span> </span><strong><span>siber g&#252;venlik kurumlar&#305;n&#305;n</span></strong><span> </span><strong>Haziran 2026</strong><span>&#8217;da yay&#305;mlad&#305;&#287;&#305; ortak bildiride a&#231;&#305;k&#231;a g&#246;r&#252;lmektedir. </span></p><p><strong><span>Bildiride</span></strong><span>, yapay zekan&#305;n yaln&#305;zca savunma kabiliyetlerini art&#305;ran bir teknoloji olmad&#305;&#287;&#305;, ayn&#305; zamanda </span><strong><span>tehdit akt&#246;rlerinin g&#252;venlik a&#231;&#305;klar&#305;n&#305; daha h&#305;zl&#305; ke&#351;fetmesine, sald&#305;r&#305;lar&#305; otomatikle&#351;tirmesine ve daha karma&#351;&#305;k siber operasyonlar y&#252;r&#252;tmesine imkan tan&#305;d&#305;&#287;&#305; vurgulanm&#305;&#351;t&#305;r.</span></strong><span> </span></p><p><span>&#214;zellikle </span><strong><span>enerji, su, ula&#351;&#305;m, sa&#287;l&#305;k, telekom&#252;nikasyon</span></strong><span> ve </span><strong><span>&#252;retim sekt&#246;rlerinde</span></strong><span> kullan&#305;lan </span><strong>Operasyonel Teknoloji (OT)</strong><span> ile </span><strong>End&#252;striyel Kontrol Sistemleri (ICS/SCADA)</strong><span> altyap&#305;lar&#305;n&#305;n bu yeni tehdit ortam&#305;ndan do&#287;rudan etkilenece&#287;ine dikkat &#231;ekilmi&#351;, kurulu&#351;lar&#305;n yaln&#305;zca geleneksel BT g&#252;venli&#287;ine de&#287;il, </span><strong><span>OT a&#287;lar&#305;n&#305;n segmentasyonu, kritik varl&#305;k g&#246;r&#252;n&#252;rl&#252;&#287;&#252;, g&#252;venli uzaktan eri&#351;im, tedarik zinciri g&#252;venli&#287;i</span></strong><span> ve </span><strong><span>operasyonel dayan&#305;kl&#305;l&#305;k</span></strong><span> gibi konulara da &#246;ncelik vermesi gerekti&#287;i ifade edilmi&#351;tir. </span></p><p><strong><span>&#214;te yandan bu bildiri, yapay zeka &#231;a&#287;&#305;nda kritik altyap&#305;lar&#305;n g&#252;venli&#287;inin ulusal g&#252;venli&#287;in ayr&#305;lmaz bir par&#231;as&#305; haline geldi&#287;ini ve siber dayan&#305;kl&#305;l&#305;&#287;&#305;n art&#305;k yaln&#305;zca bilgi teknolojileri ekiplerinin de&#287;il, &#252;st y&#246;netimden operasyon ekiplerine kadar t&#252;m organizasyonun stratejik sorumlulu&#287;u oldu&#287;unu ortaya koymaktad&#305;r. </span></strong></p><p><span>Bu yakla&#351;&#305;m, yukar&#305;da ifade etti&#287;im &#252;zere </span><strong><span>Five Eyes</span></strong><span>'&#305;n g&#252;n&#252;m&#252;zde yaln&#305;zca sinyal istihbarat&#305; payla&#351;an bir ittifak olmaktan &#231;&#305;karak, kritik altyap&#305;lar&#305;n ve ulusal siber g&#252;venlik ekosistemlerinin gelece&#287;ini &#351;ekillendiren k&#252;resel bir stratejik akt&#246;r haline geldi&#287;inin en g&#252;ncel g&#246;stergelerinden biridir.</span></p><p><span>T&#252;m bunlarla birlikte, &#246;n&#252;m&#252;zdeki y&#305;llarda </span><strong><span>Five Eyes</span></strong><span>'&#305;n kar&#351;&#305; kar&#351;&#305;ya kalaca&#287;&#305; en &#246;nemli s&#305;namalardan biri, geli&#351;mi&#351; istihbarat payla&#351;&#305;m&#305;n&#305; s&#252;rd&#252;r&#252;rken </span><strong><span>demokratik denetim, &#351;effafl&#305;k, veri koruma</span></strong><span> ve </span><strong><span>temel insan haklar&#305;</span></strong><span> ilkeleriyle uyumlu bir y&#246;neti&#351;im modelini nas&#305;l geli&#351;tirece&#287;i olacakt&#305;r.</span></p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,<br>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,<br>CompTIA Project+ Professional,<br>CIW Security Analyst,<br>Certified Cyber Threat Intelligence Analyst,<br>Certified Information Security Executive&#8482;,<br>Senior Certified Leadership Practitioner</p><p></p><h1>Kaynak&#231;a:</h1><ul><li><p><strong>National Security Agency (NSA)</strong> &#8211; UKUSA Agreement (Declassified Documents)</p></li><li><p><strong>Government Communications Headquarters (GCHQ)</strong> &#8211; A Brief History of the UKUSA Agreement</p></li><li><p><strong>Australian Signals Directorate (ASD)</strong> &#8211; Intelligence Partnerships and the History of Five Eyes</p></li><li><p><strong>Australian Cyber Security Centre (ACSC)</strong> &#8211; Five Eyes Cyber Security Agencies Statement (June 2026)</p></li><li><p><strong>National Cyber Security Centre (NCSC UK)</strong> &#8211; The AI Shift in Cyber Risk: Why Leaders Must Act Now</p></li><li><p><strong>European Union Agency for Cybersecurity (ENISA)</strong> &#8211; Threat Landscape Reports</p></li><li><p><strong>United Kingdom National Archives</strong> &#8211; UKUSA Agreement Collection</p></li><li><p><strong>Five Eyes Archive</strong> &#8211; Declassified BRUSA and UKUSA Documents</p></li></ul><p></p><p></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Five Eyes (FVEY): From Signals Intelligence to an AI-Powered Global Intelligence Ecosystem]]></title><description><![CDATA[Thanks for reading Ziya's Substack!]]></description><link>https://ziyagokalp.substack.com/p/five-eyes-fvey-from-signals-intelligence</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/five-eyes-fvey-from-signals-intelligence</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Tue, 30 Jun 2026 09:47:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-7hg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49c475ba-07a3-4eaa-a60a-dd81c221066d_1690x931.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-7hg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49c475ba-07a3-4eaa-a60a-dd81c221066d_1690x931.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-7hg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49c475ba-07a3-4eaa-a60a-dd81c221066d_1690x931.heic 424w, https://substackcdn.com/image/fetch/$s_!-7hg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49c475ba-07a3-4eaa-a60a-dd81c221066d_1690x931.heic 848w, https://substackcdn.com/image/fetch/$s_!-7hg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49c475ba-07a3-4eaa-a60a-dd81c221066d_1690x931.heic 1272w, https://substackcdn.com/image/fetch/$s_!-7hg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49c475ba-07a3-4eaa-a60a-dd81c221066d_1690x931.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-7hg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49c475ba-07a3-4eaa-a60a-dd81c221066d_1690x931.heic" width="1456" height="802" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/49c475ba-07a3-4eaa-a60a-dd81c221066d_1690x931.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:802,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:369034,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/204246705?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49c475ba-07a3-4eaa-a60a-dd81c221066d_1690x931.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-7hg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49c475ba-07a3-4eaa-a60a-dd81c221066d_1690x931.heic 424w, https://substackcdn.com/image/fetch/$s_!-7hg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49c475ba-07a3-4eaa-a60a-dd81c221066d_1690x931.heic 848w, https://substackcdn.com/image/fetch/$s_!-7hg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49c475ba-07a3-4eaa-a60a-dd81c221066d_1690x931.heic 1272w, https://substackcdn.com/image/fetch/$s_!-7hg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49c475ba-07a3-4eaa-a60a-dd81c221066d_1690x931.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h1>Introduction</h1><p>Among the institutions that shape the international security architecture, some operate in full public view, while others remain largely invisible despite exerting a far greater influence on the global balance of power.</p><p>The <strong>Five Eyes (FVEY)</strong> intelligence alliance belongs to the latter category.</p><p>For nearly eight decades, this intelligence partnership has represented far more than a mechanism for information sharing among five nations. It has evolved into a global security ecosystem at the heart of modern <strong>Signals Intelligence (SIGINT)</strong>, electronic surveillance, cyber threat intelligence, and, more recently, AI-powered intelligence analysis.</p><p>Today, many people describe the <strong>Five Eyes</strong> simply as an intelligence-sharing alliance comprising the <strong>United States, the United Kingdom, Canada, Australia</strong>, and <strong>New Zealand.</strong></p><p>However, this definition falls well short of capturing the alliance&#8217;s true scope and strategic significance. In reality, the <strong>Five Eyes</strong> is a sophisticated, multilayered, and continuously evolving intelligence ecosystem that spans millions of kilometers of submarine fiber-optic cables, communications satellites orbiting the Earth, the global Internet backbone, and advanced cyber threat intelligence and analytics platforms.</p><p>The origins of this alliance, however, predate the Cold War, tracing back to some of the most critical stages of the Second World War.</p><p>Today, the <strong>Five Eyes</strong> conducts AI-powered threat analysis and issues joint advisories on state-sponsored cyber operations. Yet, when it was first established, it was nothing more than a highly classified intelligence partnership created to intercept and decrypt German military communications.</p><p>Over the past eight decades, technology has advanced, threats have evolved, battlefields have become increasingly digital, and the very nature of intelligence has undergone a profound transformation.</p><p>Throughout this period, however, the <strong>Five Eyes</strong> has continuously adapted to the changing strategic landscape, maintaining its position as one of the world&#8217;s most influential pillars of the global security architecture.</p><p>The story of the <strong>Five Eyes</strong> is not merely the story of a partnership between five nations. It is also the story of the evolution of modern intelligence itself from <strong>Signals Intelligence (SIGINT) to cybersecurity, from big data analytics to AI-powered intelligence and decision-support systems</strong> reflecting one of the most significant transformations in the history of national and international security.</p><p></p><h1>The Birth of Modern SIGINT</h1><p>The foundations of modern <strong>Signals Intelligence (SIGINT)</strong> were laid during the Second World War.</p><p>In the early years of the war, Germany protected the communications of its armed forces including the Army, Navy, and Luftwaffe using the <strong>Enigma</strong>, an electromechanical encryption machine.</p><p>The German High Command believed that Enigma was mathematically unbreakable. With its daily-changing encryption keys, multiple rotor configurations, and millions of possible cipher permutations, the system was widely regarded as practically impossible to decipher.</p><p>The turning point, however, came at <strong>Bletchley Park</strong> in the United Kingdom. There, mathematicians, linguists, chess champions, engineers, and cryptanalysts established one of the world&#8217;s first large-scale cryptanalysis centers.</p><p>Among the most renowned members of this extraordinary team was <strong>Alan Turing</strong>. Together with his colleagues, Turing not only succeeded in breaking the Enigma cipher but also developed automated code-breaking machines that laid the foundations of modern computer science.</p><p>The intelligence derived from decrypting Enigma communications became known as <strong>Ultra Intelligence</strong>.</p><p>Ultra provided the Allied powers with an unprecedented strategic advantage. It enabled them to identify the movements of German U-boats across the Atlantic Ocean, anticipate military deployment plans, and disrupt numerous strategic operations before they could be executed.</p><p>Historians widely agree that Ultra Intelligence played a decisive role in shortening the war in the European theater by approximately two to four years.</p><p>More importantly, this period demonstrated that <strong>Signals Intelligence (SIGINT)</strong> was far more than a technical discipline; it had become a strategic capability capable of altering the course of warfare itself.</p><p></p><h1>What Is SIGINT?</h1><p><strong>Signals Intelligence (SIGINT)</strong> is the intelligence derived from the interception, collection, and analysis of electronic communications and electromagnetic signals. As one of the most technologically advanced intelligence disciplines, SIGINT focuses not on what people say directly, but on the signals generated, transmitted, and received by the devices they use.</p><p>SIGINT encompasses several specialized sub-disciplines.</p><p><strong>Communications Intelligence (COMINT)</strong> involves the interception and analysis of telephone conversations, radio communications, Internet traffic, and other forms of communications content.</p><p><strong>Electronic Intelligence (ELINT)</strong> focuses on non-communication electromagnetic emissions, including radar systems, air defense networks, weapons systems, and other electronic transmissions.</p><p><strong>Foreign Instrumentation Signals Intelligence (FISINT)</strong> analyzes telemetry and technical signals associated with foreign missile tests, space systems, weapons development, and other instrumentation-based activities.</p><p><strong>Measurement and Signature Intelligence (MASINT)</strong> examines unique physical signatures derived from nuclear, chemical, biological, radiological, and other scientific or technical measurements to identify, characterize, and assess specific objects, materials, or activities.</p><p>Unlike <strong>Human Intelligence (HUMINT)</strong>, SIGINT does not rely on human sources or informants. Nor is it dependent on publicly available information, as is <strong>Open Source Intelligence (OSINT)</strong>, or limited solely to imagery, as with <strong>Imagery Intelligence (IMINT)</strong> or <strong>Geospatial Intelligence (GEOINT)</strong>.</p><p>Instead, <strong>SIGINT analyzes</strong> the invisible communications layer of the digital world, producing intelligence on the intentions of states, military readiness, operational planning, technical capabilities, and strategic decision-making.</p><p>Its scope extends from identifying the operating frequencies of Soviet radar systems during the Cold War to analyzing the command-and-control (C2) communications of state-sponsored cyber threat actors in today&#8217;s increasingly interconnected digital battlespace. </p><p>This broad operational spectrum illustrates why <strong>SIGINT</strong> remains one of the most critical intelligence capabilities in modern national security.</p><p></p><h1>The BRUSA and UKUSA Agreements: The Birth of the Five Eyes Alliance</h1><p>In 1943, the <strong>BRUSA Agreement</strong> an acronym for <strong>Britain&#8211;United States of America</strong> became the first comprehensive agreement to formally establish intelligence cooperation between the United States and the United Kingdom in the field of <strong>Signals Intelligence (SIGINT)</strong> during the Second World War.</p><p>Under this agreement, the two nations not only shared the intelligence they collected but also collaborated extensively by exchanging cryptanalytic techniques, technical expertise, personnel, and signals interception infrastructure.</p><p>Although the end of the war appeared to eliminate the common enemy, a new geopolitical reality soon emerged. The ideological confrontation between the Soviet Union and the Western powers gave rise to the <strong>Cold War</strong>, fundamentally reshaping the global security environment.</p><p>This new strategic landscape made it necessary to transform what had been a wartime intelligence partnership into a permanent intelligence alliance.</p><p>The <strong>UKUSA Agreement</strong>, signed in 1946, is widely recognized as the founding charter of what would later become the <strong>Five Eyes (FVEY)</strong> alliance. As its name suggests, <em>UKUSA</em> stands for the <strong>United Kingdom&#8211;United States of America Agreement</strong>.</p><p>The agreement established a formal framework for the systematic sharing of Signals Intelligence between the <strong>United States</strong> and the <strong>United Kingdom</strong>. In the years that followed, <strong>Canada, Australia</strong>, and <strong>New Zealand</strong> joined the partnership, giving rise to the Five Eyes alliance as it exists today.</p><p>The agreement was designed to achieve far more than the exchange of intelligence reports.</p><p>Under its framework, the world was effectively divided into geographic areas of <strong>SIGINT</strong> responsibility. Each member nation was assigned responsibility for monitoring specific communications networks and regions, while the intelligence collected was pooled into a shared intelligence repository accessible to all partners. This distributed model enabled the alliance to achieve a level of global intelligence coverage that no single nation could have attained independently.</p><p></p><h1>Who Are the Members of the Five Eyes?</h1><p>The <strong>Five Eyes (FVEY)</strong> alliance consists of the <strong>United States</strong>, the <strong>United Kingdom</strong>, <strong>Canada</strong>, <strong>Australia</strong>, and <strong>New Zealand</strong>. Owing to their shared history, common language, closely aligned legal traditions, and longstanding military cooperation, these nations form the core of the security community commonly referred to as the <strong>Anglosphere</strong>.</p><p>The <strong>United States</strong> serves as the alliance&#8217;s primary intelligence processing and analytical hub, largely due to the unparalleled technical capabilities of the <strong>National Security Agency (NSA)</strong> in signals intelligence, cybersecurity, and large-scale data analytics.</p><p>The <strong>United Kingdom&#8217;s Government Communications Headquarters (GCHQ)</strong> plays a pivotal role in monitoring communications networks across Europe, the Middle East, and Africa, making it one of the alliance&#8217;s most strategically significant <strong>SIGINT</strong> organizations.</p><p><strong>Canada</strong>&#8217;s <strong>Communications Security Establishment (CSE)</strong> focuses primarily on intelligence activities in the Arctic and the North Atlantic, while <strong>Australia</strong>&#8217;s <strong>Australian Signals Directorate (ASD)</strong> is responsible for a substantial portion of electronic intelligence operations throughout the Indo-Pacific region.</p><p>Meanwhile, <strong>New Zealand</strong>&#8217;s <strong>Government Communications Security Bureau (GCSB)</strong> specializes in monitoring communications networks and supporting intelligence collection across the South Pacific.</p><p>Through this geographically distributed division of responsibilities, the <strong>Five Eyes</strong> has established one of the world&#8217;s most comprehensive global signals intelligence collection and analysis networks, providing near-global coverage across multiple operational domains.</p><p></p><h1>From the Cold War to the Digital Age: The Evolution of the Five Eyes</h1><p>During the Cold War, the primary mission of the <strong>Five Eyes (FVEY)</strong> was to monitor the military communications of the Soviet Union. Radar emissions, submarine communications, diplomatic transmissions, and strategic missile tests were subject to continuous surveillance and analysis. Many of the electronic interception technologies developed during this period laid the technological foundations for today&#8217;s cyber surveillance and intelligence systems.</p><p>With the rapid expansion of satellite communications in the 1980s, the alliance&#8217;s intelligence collection infrastructure extended beyond terrestrial networks into space. The subsequent global proliferation of the Internet fundamentally transformed the nature of intelligence collection. No longer were radio transmissions the sole focus of surveillance; email communications, Internet backbone infrastructure, submarine fiber-optic cables, cloud environments, and large-scale data centers also became critical intelligence targets.</p><p>This transformation enabled the <strong>Five Eyes</strong> to evolve far beyond a traditional military intelligence alliance. It emerged as one of the world&#8217;s most sophisticated intelligence ecosystems, capable of collecting, integrating, and analyzing vast volumes of digital information across the global cyber domain.</p><p></p><h1>From ECHELON to Cyber Threat Intelligence</h1><p>During the 1990s, the <strong>ECHELON</strong> system widely associated with the interception and processing of global electronic communications brought the <strong>Five Eyes</strong>&#8217; worldwide signals intelligence capabilities into the public spotlight.</p><p>Allegations that satellite communications, telephone conversations, fax transmissions, and various forms of electronic data traffic could be intercepted and filtered using predefined keywords fueled widespread public debate over mass surveillance and government intelligence collection.</p><p>By the early 2000s, however, the threat landscape had undergone another profound transformation. Traditional military adversaries were no longer the only concern. State-sponsored cyber espionage groups, ransomware operations, <strong>advanced persistent threats (APTs)</strong>, and <strong>sophisticated attacks</strong> targeting <strong>critical infrastructure</strong> had emerged as major national security challenges.</p><p>The <strong>Five Eyes</strong> adapted accordingly by placing increasing emphasis on <strong>Cyber Threat Intelligence (CTI)</strong>.</p><p>Malware families were systematically analyzed, adversary infrastructure was continuously monitored, and joint technical advisories began to be published on a regular basis.</p><p>Today, many of these joint technical publications include <strong>Indicators of Compromise (IoCs)</strong>, <strong>Tactics, Techniques, and Procedures (TTPs)</strong>, malware analyses, defensive recommendations, detection guidance, and incident response best practices providing governments and critical infrastructure operators with actionable intelligence to strengthen their cyber resilience.</p><p></p><h1>The Five Eyes in the Age of Artificial Intelligence</h1><p>The volume of data generated in today&#8217;s digital environment has far exceeded the capacity of human analysts to process and interpret on their own.</p><p>To address this challenge, the <strong>Five Eyes (FVEY)</strong> increasingly relies on <strong>big data analytics</strong>, <strong>machine learning</strong>, <strong>behavioral analytics</strong>, and <strong>AI-powered decision support systems</strong> to enhance intelligence collection, analysis, and operational decision-making.</p><p>Modern intelligence is no longer defined merely by the ability to collect information. Its true value lies in identifying meaningful relationships within billions of seemingly unrelated data points and transforming them into actionable intelligence.</p><p>Artificial intelligence algorithms can correlate information from multiple sources, detect emerging threats at a much earlier stage, cluster coordinated cyber campaigns, and provide analysts with valuable insights for attributing state-sponsored operations to specific threat actors.</p><p>For this reason, the evolution of the Five Eyes represents far more than a technological transformation it reflects a fundamental shift in the way intelligence is produced, analyzed, and operationalized.</p><p>The traditional <strong>Signals Intelligence (SIGINT)</strong> model has evolved into an AI-enabled, multi-source intelligence ecosystem, where human expertise and artificial intelligence work together to generate faster, more accurate, and more actionable intelligence for an increasingly complex global security environment.</p><p></p><h1>The Legal and Ethical Dimensions of the Five Eyes</h1><p>The <strong>Five Eyes (FVEY)</strong> is not an independent international organization established under international law. Rather, it is an intergovernmental intelligence-sharing alliance whose legal foundations originate from the <strong>1946 UKUSA Agreement</strong>.</p><p>Accordingly, intelligence sharing among its members is governed not by a single international legal framework, but by each member state&#8217;s domestic national security legislation, together with bilateral and multilateral classified intelligence-sharing agreements. Within these legal frameworks, each member may share foreign intelligence collected in accordance with its own laws, subject to established classification, handling, and dissemination rules.</p><p>At the same time, the <strong>Five Eyes</strong> has remained at the center of legal and ethical debate for decades.</p><p>The alliance has faced persistent criticism regarding the protection of personal data, mass surveillance, the right to privacy, and the adequacy of democratic oversight and accountability.</p><p>From an ethical perspective, the central issue concerns the delicate balance between national security and individual civil liberties. </p><p>Governments argue that broad intelligence collection authorities are essential for countering terrorism, cyber espionage, attacks against critical infrastructure, and foreign intelligence activities. Privacy advocates, however, contend that large-scale surveillance and bulk data collection may undermine fundamental rights and democratic freedoms in open societies.</p><p>The debate intensified significantly in 2013 following the disclosures made by <strong>Edward Snowden</strong>, which brought previously undisclosed global electronic surveillance programs into the public domain and triggered worldwide discussions on intelligence oversight, privacy, and government accountability.</p><p>Today, the integration of artificial intelligence into intelligence analysis has introduced an entirely new dimension to this debate.</p><p>The question is no longer limited to whether governments should collect data. Increasingly, the focus has shifted to how massive datasets gathered from multiple jurisdictions can be analyzed, correlated, and interpreted by artificial intelligence&#8212;and how the resulting insights are incorporated into intelligence assessments and decision-support systems.</p><p>For this reason, the <strong>Five Eyes</strong> continues to represent one of the world&#8217;s most closely scrutinized models of international intelligence cooperation, standing at the intersection of national security, technological innovation, the rule of law, and the protection of fundamental rights in the digital age.</p><p></p><h1>Conclusion</h1><p>The <strong>Five Eyes (FVEY)</strong> stands as one of the most compelling examples of how a technical wartime collaboration originally established to decrypt German military communications during the Second World War evolved into a permanent intelligence alliance that continues to shape the global security architecture.</p><p>Over more than eight decades, the alliance has continuously adapted to an evolving threat landscape. It progressed from serving as the electronic surveillance network of the Cold War, to becoming a key component of the Internet era&#8217;s global intelligence infrastructure, and today functions as a multidimensional intelligence ecosystem at the forefront of cybersecurity, cyber threat intelligence, and AI-powered intelligence analysis.</p><p>Today, the Five Eyes is far more than a traditional <strong>Signals Intelligence (SIGINT)</strong> organization responsible for monitoring state communications.</p><p>It has become a strategic actor in protecting critical infrastructure, identifying state-sponsored cyber operations, facilitating international cyber threat intelligence sharing, safeguarding election security, countering disinformation campaigns, supporting space-based surveillance, and integrating artificial intelligence into intelligence analysis and decision-support systems.</p><p>As technology continues to advance, the battlespace is steadily shifting from the physical domain to the digital one.</p><p>This transformation is fundamentally reshaping intelligence organizations worldwide.</p><p>In the years ahead, the <strong>Five Eyes</strong> will likely continue evolving beyond a conventional SIGINT alliance into an AI-enabled global decision-support network capable of conducting real-time intelligence analysis and coordinating multi-domain security operations across an increasingly interconnected threat environment.</p><p>The future of modern intelligence will not be determined solely by the ability to collect ever-greater volumes of data. Rather, its true strategic value will lie in transforming that data into timely, contextualized, and actionable intelligence that supports informed decision-making. The historical evolution of the <strong>Five Eyes</strong> provides one of the clearest illustrations of this transformation.</p><p>A contemporary reflection of this evolution can be found in the joint statement issued by the Five Eyes cybersecurity agencies in <strong>June 2026</strong>.</p><p>The statement emphasizes that artificial intelligence is not only enhancing defensive capabilities but also enabling threat actors to identify vulnerabilities more rapidly, automate cyberattacks, and conduct increasingly sophisticated cyber operations.</p><p>It further warns that <strong>Operational Technology (OT)</strong> and <strong>Industrial Control Systems (ICS/SCADA)</strong> supporting critical sectors including energy, water, transportation, healthcare, telecommunications, and manufacturing will be directly affected by this evolving threat landscape. Accordingly, organizations are encouraged to look beyond traditional IT security and prioritize OT network segmentation, comprehensive asset visibility, secure remote access, supply chain security, and operational resilience.</p><p>More importantly, the statement underscores that, in the age of artificial intelligence, the security of critical infrastructure has become an inseparable component of national security. It further recognizes that cyber resilience is no longer the sole responsibility of information technology teams but has evolved into a strategic, organization-wide responsibility extending from executive leadership to operational personnel.</p><p><strong>This perspective reinforces the central argument presented throughout this article: the Five Eyes has evolved beyond an intelligence-sharing alliance focused primarily on Signals Intelligence. It has become a global strategic actor that increasingly shapes the future of critical infrastructure protection, cybersecurity policy, and national cyber resilience.</strong></p><p><strong>At the same time, one of the alliance&#8217;s greatest challenges in the years ahead will be maintaining effective intelligence cooperation while developing governance models that remain consistent with democratic oversight, transparency, data protection, the rule of law, and the protection of fundamental human rights.</strong> </p><p>Successfully balancing these competing priorities will likely determine not only the future of the <strong>Five Eyes</strong> itself but also the legitimacy and sustainability of international intelligence cooperation in the era of artificial intelligence.</p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br><span>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,</span><br><span>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,</span><br><span>CompTIA Project+ Professional,</span><br><span>CIW Security Analyst,</span><br><span>Certified Cyber Threat Intelligence Analyst,</span><br><span>Certified Information Security Executive&#8482;,</span><br><span>Senior Certified Leadership Practitioner</span></p><p></p><h1>References:</h1><ul><li><p><strong>National Security Agency (NSA)</strong> &#8211; UKUSA Agreement (Declassified Documents)</p></li><li><p><strong>Government Communications Headquarters (GCHQ)</strong> &#8211; A Brief History of the UKUSA Agreement</p></li><li><p><strong>Australian Signals Directorate (ASD)</strong> &#8211; Intelligence Partnerships and the History of Five Eyes</p></li><li><p><strong>Australian Cyber Security Centre (ACSC)</strong> &#8211; Five Eyes Cyber Security Agencies Statement (June 2026)</p></li><li><p><strong>National Cyber Security Centre (NCSC UK)</strong> &#8211; The AI Shift in Cyber Risk: Why Leaders Must Act Now</p></li><li><p><strong>European Union Agency for Cybersecurity (ENISA)</strong> &#8211; Threat Landscape Reports</p></li><li><p><strong>United Kingdom National Archives</strong> &#8211; UKUSA Agreement Collection</p></li><li><p><strong>Five Eyes Archive</strong> &#8211; Declassified BRUSA and UKUSA Documents</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Siber Karşı Terörizm (Cyber Counterterrorism): Modern Terörle Mücadelenin Dijital Boyutu]]></title><description><![CDATA[Thanks for reading Ziya's Substack!]]></description><link>https://ziyagokalp.substack.com/p/siber-kars-terorizm-cyber-counterterrorism</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/siber-kars-terorizm-cyber-counterterrorism</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Sat, 27 Jun 2026 15:24:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!SseA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce21cd91-92f0-4188-8781-32b47862c89f_1691x930.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SseA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce21cd91-92f0-4188-8781-32b47862c89f_1691x930.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SseA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce21cd91-92f0-4188-8781-32b47862c89f_1691x930.heic 424w, https://substackcdn.com/image/fetch/$s_!SseA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce21cd91-92f0-4188-8781-32b47862c89f_1691x930.heic 848w, https://substackcdn.com/image/fetch/$s_!SseA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce21cd91-92f0-4188-8781-32b47862c89f_1691x930.heic 1272w, https://substackcdn.com/image/fetch/$s_!SseA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce21cd91-92f0-4188-8781-32b47862c89f_1691x930.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SseA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce21cd91-92f0-4188-8781-32b47862c89f_1691x930.heic" width="1456" height="801" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ce21cd91-92f0-4188-8781-32b47862c89f_1691x930.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:801,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:210915,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/203595888?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce21cd91-92f0-4188-8781-32b47862c89f_1691x930.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SseA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce21cd91-92f0-4188-8781-32b47862c89f_1691x930.heic 424w, https://substackcdn.com/image/fetch/$s_!SseA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce21cd91-92f0-4188-8781-32b47862c89f_1691x930.heic 848w, https://substackcdn.com/image/fetch/$s_!SseA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce21cd91-92f0-4188-8781-32b47862c89f_1691x930.heic 1272w, https://substackcdn.com/image/fetch/$s_!SseA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce21cd91-92f0-4188-8781-32b47862c89f_1691x930.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h1>Giri&#351;</h1><p>Bu makalede, <strong>Cyber Counterterrorism (Siber Kar&#351;&#305; Ter&#246;rizm)</strong> kavram&#305;n&#305; yaln&#305;zca teknik bir siber g&#252;venlik konusu olarak ele almamakla birlikte, &#231;al&#305;&#351;mam&#305;n temel amac&#305;, dijital ter&#246;r a&#287;lar&#305;n&#305;n evrimini, istihbarat disiplinlerinin bu m&#252;cadeledeki rol&#252;n&#252;, ger&#231;ek operasyonlardan elde edilen dersleri, kritik altyap&#305;lara y&#246;nelik tehditleri ve yapay zeka destekli yeni nesil kar&#351;&#305; ter&#246;rizm yakla&#351;&#305;mlar&#305;n&#305; b&#252;t&#252;nc&#252;l bir bak&#305;&#351; a&#231;&#305;s&#305;yla de&#287;erlendirmeye &#231;al&#305;&#351;&#305;yorum.</p><p>&#214;te yandan <strong>EncroChat</strong>, <strong>ANOM</strong>, <strong>DEA&#350;</strong>&#8216;&#305;n dijital propaganda stratejilerini, kripto para ile ter&#246;r finansman&#305;n&#305;, kritik altyap&#305;lara y&#246;nelik tehdit senaryolar&#305;n&#305; irdeleyerek, geli&#351;mi&#351; veri analiti&#287;i platformlar&#305;n&#305;n kullan&#305;m&#305; gibi konular&#305; do&#287;rulanm&#305;&#351; vakalar &#252;zerinden <strong>Cyber Counterterrorism (Siber Kar&#351;&#305; Ter&#246;rizm) </strong>yakla&#351;&#305;m&#305;n&#305;n uygulamadaki yans&#305;malar&#305; a&#231;&#305;s&#305;ndan analiz etmekteyim.   </p><p>B&#246;ylece dijital &#231;a&#287;&#305;n g&#252;venlik mimarisinde istihbarat odakl&#305; kar&#351;&#305; ter&#246;rizm anlay&#305;&#351;&#305;n&#305;n neden vazge&#231;ilmez hale geldi&#287;ini irdelemekteyim. </p><h1>Genel Bak&#305;&#351;</h1><p>Yirmi birinci y&#252;zy&#305;l, g&#252;venlik kavram&#305;n&#305; yaln&#305;zca fiziksel s&#305;n&#305;rlar&#305;n korunmas&#305; perspektifinden &#231;&#305;kararak dijital alan&#305; da kapsayan &#231;ok boyutlu bir yap&#305;ya d&#246;n&#252;&#351;t&#252;rm&#252;&#351;t&#252;r. </p><p>&#304;nternetin k&#252;resel &#246;l&#231;ekte yayg&#305;nla&#351;mas&#305;, bulut bili&#351;im, mobil ileti&#351;im teknolojileri, sosyal medya platformlar&#305;, kripto para ekosistemleri ve yapay zeka uygulamalar&#305; toplumlara &#246;nemli f&#305;rsatlar sunarken, ayn&#305; zamanda <strong>ter&#246;r &#246;rg&#252;tleri i&#231;in de daha &#246;nce benzeri g&#246;r&#252;lmemi&#351; operasyonel imkanlar yaratm&#305;&#351;t&#305;r.</strong> </p><p><strong>G&#252;n&#252;m&#252;zde herhangi bir ter&#246;r &#246;rg&#252;t&#252; yaln&#305;zca da&#287;l&#305;k b&#246;lgelerde faaliyet g&#246;steren silahl&#305; h&#252;crelerden olu&#351;mamaktad&#305;r.</strong> </p><p><strong>Dijital d&#252;nyada faaliyet g&#246;steren, birbirleriyle &#351;ifreli haberle&#351;me uygulamalar&#305; &#252;zerinden ileti&#351;im kuran, kripto para kullanarak finansman sa&#287;layan, sosyal medya algoritmalar&#305;n&#305; propaganda amac&#305;yla kullanan</strong> ve <strong>yapay zeka ara&#231;lar&#305;ndan yararlanarak psikolojik etki olu&#351;turmaya &#231;al&#305;&#351;an da&#287;&#305;t&#305;k a&#287; yap&#305;lar&#305;, modern ter&#246;rizmin ayr&#305;lmaz bir par&#231;as&#305; haline gelmi&#351;tir.</strong></p><p><span>Bu d&#246;n&#252;&#351;&#252;m, g&#252;venlik kurumlar&#305;n&#305; yaln&#305;zca "</span><strong><span>Siber Ter&#246;rizm</span></strong><span>" olarak tan&#305;mlanan tehditlerle m&#252;cadele etmeye de&#287;il, ayn&#305; zamanda </span><strong><span>istihbarat temelli</span></strong><span> yeni bir yakla&#351;&#305;m geli&#351;tirmeye zorlam&#305;&#351;t&#305;r. </span></p><p><span>Literat&#252;rde giderek daha fazla yer bulan &#8216;</span><strong>Cyber Counterterrorism (Siber Kar&#351;&#305; Ter&#246;rizm)&#8217;</strong><span> kavram&#305;, dijital teknolojileri kullanan ter&#246;r &#246;rg&#252;tlerinin faaliyetlerini &#246;nceden tespit etmeyi, analiz etmeyi, engellemeyi ve gerekti&#287;inde operasyonel y&#246;ntemlerle etkisiz hale getirmeyi ama&#231;layan disiplinler aras&#305; bir g&#252;venlik yakla&#351;&#305;m&#305;d&#305;r. </span></p><p><span>Ba&#351;ka bir ifadeyle, </span><strong><span>Cyber Counterterrorism (</span>Siber Kar&#351;&#305; Ter&#246;rizm)</strong><span> yaln&#305;zca ger&#231;ekle&#351;mi&#351; bir siber sald&#305;r&#305;ya m&#252;dahale etmekten ibaret de&#287;ildir, ter&#246;r &#246;rg&#252;tlerinin </span><strong><span>dijital ekosistem i&#231;erisinde olu&#351;turdu&#287;u b&#252;t&#252;n ya&#351;am d&#246;ng&#252;s&#252;n&#252; istihbarat perspektifiyle takip etmeyi hedefleyen proaktif bir savunma modelidir.</span></strong></p><p><span>Geleneksel ter&#246;rle m&#252;cadele anlay&#305;&#351;&#305; b&#252;y&#252;k &#246;l&#231;&#252;de </span><strong><span>insan istihbarat&#305;</span></strong><span> (</span><strong><span>HUMINT</span></strong><span>), saha operasyonlar&#305; ve fiziksel g&#252;venlik &#246;nlemleri &#252;zerine in&#351;a edilmi&#351;ti. </span></p><p><span>&#214;zellikle So&#287;uk Sava&#351; d&#246;neminde devletler, ajan a&#287;lar&#305;, saha g&#246;zlemleri ve fiziksel takip faaliyetleri sayesinde ter&#246;r &#246;rg&#252;tlerini veya yabanc&#305; istihbarat servislerini izlemeye &#231;al&#305;&#351;&#305;yordu. </span></p><p><span>Ancak internetin k&#252;resel &#246;l&#231;ekte yayg&#305;nla&#351;mas&#305;yla birlikte ter&#246;r &#246;rg&#252;tleri de dijital d&#246;n&#252;&#351;&#252;m ge&#231;irdi. </span></p><p><span>Art&#305;k &#246;rg&#252;t &#252;yeleri d&#252;nyan&#305;n farkl&#305; k&#305;talar&#305;nda bulunmas&#305;na ra&#287;men ayn&#305; dijital platform &#252;zerinden operasyon planlayabilmekte, propaganda yapabilmekte ve finansman sa&#287;layabilmektedir. </span></p><p><span>Bu durum, </span><strong><span>klasik kar&#351;&#305; ter&#246;rizm</span></strong><span> y&#246;ntemlerinin tek ba&#351;&#305;na yeterli olmad&#305;&#287;&#305;n&#305; ortaya koymu&#351;tur.</span></p><p>Bu d&#246;n&#252;&#351;&#252;m&#252;n en &#246;nemli k&#305;r&#305;lma noktalar&#305;ndan biri hi&#231; &#351;&#252;phesiz <strong>11 Eyl&#252;l 2001</strong> sald&#305;r&#305;lar&#305;d&#305;r. </p><p>Yakla&#351;&#305;k &#252;&#231; bin ki&#351;inin hayat&#305;n&#305; kaybetti&#287;i bu sald&#305;r&#305;lar yaln&#305;zca uluslararas&#305; g&#252;venlik politikalar&#305;n&#305; de&#287;il, <strong>ayn&#305; zamanda istihbarat toplama y&#246;ntemlerini de k&#246;kten de&#287;i&#351;tirmi&#351;tir.</strong> </p><p>Sald&#305;r&#305;lar&#305;n ard&#305;ndan bir&#231;ok &#252;lkede istihbarat kurumlar&#305; aras&#305;nda veri payla&#351;&#305;m&#305; art&#305;r&#305;lm&#305;&#351;, dijital ileti&#351;im a&#287;lar&#305;n&#305;n izlenmesine y&#246;nelik yasal d&#252;zenlemeler geni&#351;letilmi&#351; ve <strong>b&#252;y&#252;k veri analiti&#287;i, a&#287; analizi (network analysis)</strong> ile <strong>davran&#305;&#351; modelleme</strong> sistemlerine y&#246;nelik yat&#305;r&#305;mlar h&#305;z kazanm&#305;&#351;t&#305;r. </p><p>Bu s&#252;re&#231;, dijital istihbarat&#305;n klasik insan istihbarat&#305;n&#305;n yerine ge&#231;mesi anlam&#305;na gelmemi&#351;, aksine farkl&#305; istihbarat disiplinlerinin entegre &#231;al&#305;&#351;t&#305;&#287;&#305; <strong>hibrit bir g&#252;venlik mimarisinin</strong> ortaya &#231;&#305;kmas&#305;na neden olmu&#351;tur.</p><p>Son yirmi y&#305;l i&#231;erisinde ya&#351;anan geli&#351;meler, ter&#246;r &#246;rg&#252;tlerinin dijital teknolojilere adaptasyon h&#305;z&#305;n&#305;n beklenenden &#231;ok daha y&#252;ksek oldu&#287;unu g&#246;stermektedir. </p><p>&#214;zellikle <strong>DEA&#350;</strong>, sosyal medya platformlar&#305;n&#305; yaln&#305;zca propaganda amac&#305;yla kullanmam&#305;&#351;, ayn&#305; zamanda d&#252;nyan&#305;n farkl&#305; b&#246;lgelerindeki bireyleri radikalle&#351;tirmek, yabanc&#305; sava&#351;&#231;&#305; dev&#351;irmek ve operasyonel koordinasyon sa&#287;lamak i&#231;in sistematik bi&#231;imde de&#287;erlendirmi&#351;tir. </p><p>&#214;rg&#252;t taraf&#305;ndan yay&#305;mlanan y&#252;ksek &#231;&#246;z&#252;n&#252;rl&#252;kl&#252; videolar, profesyonel grafik tasar&#305;mlar, &#231;ok dilli dijital propaganda dergileri ve sosyal medya kampanyalar&#305;, dijital ileti&#351;imin ter&#246;rizm a&#231;&#305;s&#305;ndan nas&#305;l stratejik bir ara&#231; haline geldi&#287;inin en &#231;arp&#305;c&#305; &#246;rnekleri aras&#305;nda yer almaktad&#305;r. </p><p>Dijital platformlar&#305;n k&#252;resel eri&#351;im kapasitesi, ter&#246;r &#246;rg&#252;tlerinin co&#287;rafi s&#305;n&#305;rlar&#305; a&#351;arak ideolojik etki alanlar&#305;n&#305; geni&#351;letmelerine olanak tan&#305;m&#305;&#351;t&#305;r.</p><p>Bununla birlikte dijital d&#246;n&#252;&#351;&#252;m yaln&#305;zca propaganda faaliyetleriyle s&#305;n&#305;rl&#305; de&#287;ildir. </p><p>Kripto para teknolojilerinin geli&#351;mesi, <strong>BlokZincir (BlockChain)</strong> tabanl&#305; &#246;deme sistemlerinin anonimlik sa&#287;lamas&#305; ve <strong>Dark Web</strong> ekosisteminin b&#252;y&#252;mesi, ter&#246;r &#246;rg&#252;tlerinin finansman y&#246;ntemlerinde de &#246;nemli de&#287;i&#351;ikliklere yol a&#231;m&#305;&#351;t&#305;r. </p><p>Geleneksel bankac&#305;l&#305;k sistemlerinin g&#246;zetim mekanizmalar&#305;ndan ka&#231;&#305;nmaya &#231;al&#305;&#351;an &#246;rg&#252;tler, <strong>farkl&#305; kripto varl&#305;klar ve dijital c&#252;zdanlar &#252;zerinden ba&#287;&#305;&#351; toplama, para transferi ve lojistik destek faaliyetleri y&#252;r&#252;tmeye ba&#351;lam&#305;&#351;t&#305;r.</strong> </p><p>Bu geli&#351;me, <strong>finansal istihbarat</strong> (<strong>FININT</strong>) ile <strong>siber istihbarat&#305;n</strong> birlikte &#231;al&#305;&#351;mas&#305;n&#305; zorunlu hale getirmi&#351;tir.</p><p>Ayn&#305; d&#246;nemde <strong>kritik altyap&#305;lar</strong> da yeni nesil <strong>tehditlerin oda&#287;&#305; haline gelmi&#351;tir.</strong> </p><p><strong>Enerji santralleri, do&#287;al gaz iletim hatlar&#305;, su ar&#305;tma tesisleri, ula&#351;&#305;m sistemleri, sa&#287;l&#305;k altyap&#305;lar&#305;</strong> ve <strong>end&#252;striyel kontrol sistemleri</strong> art&#305;k yaln&#305;zca devlet destekli geli&#351;mi&#351; kal&#305;c&#305; tehdit gruplar&#305;n&#305;n (<strong>APT</strong>) de&#287;il, <strong>ideolojik motivasyon ta&#351;&#305;yan ter&#246;r &#246;rg&#252;tlerinin de potansiyel hedefleri aras&#305;nda de&#287;erlendirilmektedir</strong>. </p><p><strong>Operasyonel Teknoloji (OT)</strong> ve <strong>End&#252;striyel Kontrol Sistemleri (ICS)</strong> &#252;zerinde ger&#231;ekle&#351;tirilebilecek ba&#351;ar&#305;l&#305; bir siber sald&#305;r&#305;, <strong>fiziksel hasar, &#252;retim kesintisi, &#231;evresel felaket, kaos ve kitlesel panik gibi &#231;ok boyutlu sonu&#231;lar do&#287;urabilir.</strong> </p><p>Bu nedenle modern <strong>Cyber Counterterrorism (Siber Kar&#351;&#305; Ter&#246;rizm)</strong> yakla&#351;&#305;m&#305; yaln&#305;zca bilgi sistemlerini de&#287;il, <strong>fiziksel s&#252;re&#231;leri kontrol eden kritik altyap&#305;lar&#305; da kapsamaktad&#305;r.</strong></p><p><strong>B&#252;t&#252;n bu geli&#351;meler g&#246;stermektedir ki modern ter&#246;rle m&#252;cadele art&#305;k yaln&#305;zca askeri veya kolluk kuvvetlerinin y&#252;r&#252;tt&#252;&#287;&#252; operasyonlardan ibaret de&#287;ildir. </strong></p><p>G&#252;n&#252;m&#252;zde ba&#351;ar&#305;l&#305; bir <strong>Cyber Counterterrorism (Siber Kar&#351;&#305; Ter&#246;rizm) modeli</strong>; </p><ul><li><p><strong>&#304;nsan istihbarat&#305; (HUMINT)</strong>,</p></li><li><p><strong>Sinyal istihbarat&#305; (SIGINT)</strong>, </p></li><li><p><strong>A&#231;&#305;k kaynak istihbarat&#305; (OSINT)</strong>, </p></li><li><p><strong>Sosyal medya istihbarat&#305; (SOCMINT)</strong>, </p></li><li><p><strong>Finansal istihbarat (FININT)</strong>, </p></li><li><p><strong>Siber tehdit istihbarat&#305; (CTI)</strong> ve giderek &#246;nem kazanan <strong>Yapay Zeka Destekli &#304;stihbarat (AIINT)</strong> disiplinlerinin b&#252;t&#252;nle&#351;ik kullan&#305;m&#305;n&#305; gerektirmektedir. </p></li></ul><p><strong>B&#252;y&#252;k veri analiti&#287;i, grafik tabanl&#305; ili&#351;ki analizi, makine &#246;&#287;renmesi algoritmalar&#305;</strong> ve <strong>davran&#305;&#351;sal modelleme teknikleri</strong> sayesinde milyonlarca veri noktas&#305; aras&#305;nda daha &#246;nce fark edilemeyen ba&#287;lant&#305;lar ortaya &#231;&#305;kar&#305;labilmektedir. </p><p>B&#246;ylece g&#252;venlik kurumlar&#305; yaln&#305;zca ger&#231;ekle&#351;mi&#351; olaylara tepki vermek yerine, gelecekte meydana gelebilecek potansiyel sald&#305;r&#305;lar&#305; &#246;ng&#246;rmeye y&#246;nelik <strong>&#246;ng&#246;r&#252;c&#252; (predictive) analiz modelleri geli&#351;tirebilmektedir.</strong></p><p></p><h1>Dijital Ter&#246;r A&#287;lar&#305;na Kar&#351;&#305; &#304;stihbarat Destekli M&#252;cadelenin D&#246;n&#252;&#351;&#252;m&#252;: <br>DEA&#350;, EncroChat ve ANOM Vakalar&#305;</h1><p>Yukar&#305;da ifade etmeye &#231;al&#305;&#351;t&#305;&#287;&#305;m &#252;zere; <strong>Cyber Counterterrorism</strong> yakla&#351;&#305;m&#305;n&#305;n temel amac&#305;, yaln&#305;zca ger&#231;ekle&#351;mi&#351; siber sald&#305;r&#305;lara m&#252;dahale etmek de&#287;il, dijital ortamda faaliyet g&#246;steren ter&#246;r ve organize su&#231; a&#287;lar&#305;n&#305; daha planlama a&#351;amas&#305;ndayken tespit etmek, analiz etmek ve etkisiz hale getirmektir. </p><p>Bu yakla&#351;&#305;m&#305;n ba&#351;ar&#305;s&#305;, b&#252;y&#252;k &#246;l&#231;&#252;de farkl&#305; istihbarat disiplinlerinin ortak kullan&#305;m&#305;na ba&#287;l&#305;d&#305;r. </p><p><strong>&#304;nsan istihbarat&#305; (HUMINT), Sinyal istihbarat&#305; (SIGINT), A&#231;&#305;k kaynak istihbarat&#305; (OSINT), Finansal istihbarat (FININT) ve Siber tehdit istihbarat&#305; (CTI) </strong>art&#305;k birbirinden ba&#287;&#305;ms&#305;z de&#287;il, ayn&#305; operasyonel resmin tamamlay&#305;c&#305; par&#231;alar&#305; olarak de&#287;erlendirilmektedir. </p><p>Son y&#305;llarda ya&#351;anan &#252;&#231; &#246;nemli olay; </p><ul><li><p><strong>DEA&#350;</strong>'&#305;n dijital propaganda a&#287;&#305;, </p></li><li><p><strong>EncroChat</strong> platformunun de&#351;ifre edilmesi ve </p></li><li><p><strong>ANOM operasyonu</strong>, modern <strong>Cyber Counterterrorism (Siber Kar&#351;&#305; Ter&#246;rizm)</strong> anlay&#305;&#351;&#305;n&#305;n nas&#305;l evrildi&#287;ini g&#246;steren en &#246;nemli &#246;rnekler aras&#305;nda yer almaktad&#305;r.</p></li></ul><h3>DEA&#350;</h3><p><strong><span>DEA&#350;</span></strong><span>, dijital teknolojileri sistematik ve profesyonel bi&#231;imde kullanan ilk k&#252;resel ter&#246;r &#246;rg&#252;tlerinden biri olarak kabul edilmektedir. </span></p><p><span>El Kaide'nin interneti a&#287;&#305;rl&#305;kl&#305; olarak web siteleri ve &#231;evrim i&#231;i forumlar &#252;zerinden kulland&#305;&#287;&#305; d&#246;nemin aksine DEA&#350;, sosyal medya algoritmalar&#305;n&#305;, y&#252;ksek &#231;&#246;z&#252;n&#252;rl&#252;kl&#252; video prod&#252;ksiyonlar&#305;n&#305; ve &#231;ok dilli dijital yay&#305;nlar&#305; stratejik bir propaganda silah&#305;na d&#246;n&#252;&#351;t&#252;rm&#252;&#351;t&#252;r. </span></p><p><span>&#214;zellikle 2014 y&#305;l&#305;ndan itibaren </span><strong><span>Twitter</span></strong><span> &#252;zerinde binlerce hesap arac&#305;l&#305;&#287;&#305;yla y&#252;r&#252;t&#252;len koordineli propaganda faaliyetleri, &#246;rg&#252;t&#252;n k&#305;sa s&#252;rede k&#252;resel g&#246;r&#252;n&#252;rl&#252;k kazanmas&#305;n&#305; sa&#287;lam&#305;&#351;t&#305;r. </span></p><p><span>Ard&#305;ndan </span><strong><span>Telegram</span></strong><span> gibi &#351;ifreli mesajla&#351;ma platformlar&#305;na ge&#231;i&#351; yapan &#246;rg&#252;t, yaln&#305;zca propaganda yapmakla kalmam&#305;&#351;, farkl&#305; &#252;lkelerdeki sempatizanlar&#305;yla ileti&#351;im kurmu&#351;, yabanc&#305; &#246;rg&#252;t &#252;yesi dev&#351;irme faaliyetlerini organize etmi&#351; ve sald&#305;r&#305; &#231;a&#287;r&#305;lar&#305;n&#305; dijital ortam &#252;zerinden yaym&#305;&#351;t&#305;r. </span></p><p><span>&#304;ngilizce yay&#305;mlanan </span><em><strong>Dabiq</strong></em><span> ve daha sonra </span><em><strong>Rumiyah</strong></em><span> dergileri, Bat&#305;l&#305; hedef kitlelere ula&#351;may&#305; ama&#231;layan profesyonel psikolojik operasyon ara&#231;lar&#305; olarak kullan&#305;lm&#305;&#351;t&#305;r. </span></p><p><span>Bu s&#252;re&#231;, g&#252;venlik kurumlar&#305;na &#246;nemli bir ders vermi&#351;tir. </span></p><p><strong><span>Dijital platformlar art&#305;k yaln&#305;zca ileti&#351;im kanallar&#305; de&#287;il, radikalle&#351;menin, &#246;rg&#252;tlenmenin ve operasyonel koordinasyonun ger&#231;ekle&#351;ti&#287;i yeni nesil sava&#351; alanlar&#305;d&#305;r.</span></strong></p><h3>EncroChat</h3><p>Ter&#246;r ve organize su&#231; &#246;rg&#252;tlerinin &#351;ifreli haberle&#351;me uygulamalar&#305;na y&#246;nelmesi, g&#252;venlik kurumlar&#305;n&#305; daha yarat&#305;c&#305; istihbarat y&#246;ntemleri geli&#351;tirmeye zorlam&#305;&#351;t&#305;r. </p><p>Bu d&#246;n&#252;&#351;&#252;m&#252;n en dikkat &#231;ekici &#246;rneklerinden biri <strong>EncroChat</strong> vakas&#305;d&#305;r. </p><p>G&#252;venli oldu&#287;u iddias&#305;yla pazarlanan <strong>EncroChat</strong> cihazlar&#305;, mikrofon ve GPS gibi &#246;zellikleri devre d&#305;&#351;&#305; b&#305;rak&#305;lm&#305;&#351;, u&#231;tan uca &#351;ifreleme sunan &#246;zel telefonlar olarak &#246;zellikle organize su&#231; &#246;rg&#252;tleri aras&#305;nda yayg&#305;n &#351;ekilde kullan&#305;lmaya ba&#351;lanm&#305;&#351;t&#305;r. </p><p>Avrupa'daki uyu&#351;turucu ka&#231;ak&#231;&#305;l&#305;&#287;&#305;, kara para aklama ve silah ka&#231;ak&#231;&#305;l&#305;&#287;&#305; faaliyetlerinin &#246;nemli bir k&#305;sm&#305; bu platform &#252;zerinden y&#252;r&#252;t&#252;l&#252;yordu. </p><p>2020 y&#305;l&#305;nda <strong>Frans&#305;z</strong> ve <strong>Hollandal&#305;</strong> <strong>g&#252;venlik birimlerinin</strong> teknik &#231;al&#305;&#351;malar&#305; sonucunda platforma eri&#351;im sa&#287;lanm&#305;&#351; ve milyonlarca &#351;ifreli mesaj ger&#231;ek zamanl&#305; olarak analiz edilmi&#351;tir. </p><p>Elde edilen istihbarat, Avrupa genelinde binlerce operasyonun ger&#231;ekle&#351;tirilmesine, y&#252;zlerce ton uyu&#351;turucunun ele ge&#231;irilmesine, &#231;ok say&#305;da silah deposunun ortaya &#231;&#305;kar&#305;lmas&#305;na ve y&#252;zlerce organize su&#231; liderinin tutuklanmas&#305;na imkan tan&#305;m&#305;&#351;t&#305;r.</p><p><strong>EncroChat</strong> operasyonu, modern kar&#351;&#305; ter&#246;rizm ve organize su&#231;la m&#252;cadelede yaln&#305;zca ileti&#351;im trafi&#287;ini izlemek yerine, <strong>ileti&#351;im ekosisteminin tamam&#305;n&#305; anlaman&#305;n ve analiz etmenin ne kadar kritik oldu&#287;unu g&#246;stermi&#351;tir.</strong></p><h3>ANOM</h3><p>Bu alandaki en dikkat &#231;ekici operasyon ise &#351;&#252;phesiz <strong>ANOM operasyonudur</strong>. </p><p><strong>FBI</strong> taraf&#305;ndan planlanan ve uluslararas&#305; kolluk kuvvetlerinin deste&#287;iyle y&#252;r&#252;t&#252;len bu operasyon, klasik siber savunma anlay&#305;&#351;&#305;n&#305;n &#246;tesine ge&#231;en istihbarat odakl&#305; bir yakla&#351;&#305;m&#305;n &#246;rne&#287;idir. </p><p>G&#252;venlik kurumlar&#305;, su&#231; &#246;rg&#252;tlerinin g&#252;ven duyaca&#287;&#305; &#246;zel bir &#351;ifreli haberle&#351;me platformu olu&#351;turmu&#351;, <strong>ANOM</strong> isimli bu cihazlar&#305;n organize su&#231; a&#287;lar&#305; i&#231;erisinde yayg&#305;nla&#351;mas&#305;n&#305; dolayl&#305; yollarla sa&#287;lam&#305;&#351;t&#305;r. </p><p>Kullan&#305;c&#305;lar, cihazlar&#305;n tamamen g&#252;venli oldu&#287;una inan&#305;rken g&#246;nderilen t&#252;m mesajlar e&#351; zamanl&#305; olarak g&#252;venlik g&#252;&#231;lerine ula&#351;&#305;yordu. </p><p>Yakla&#351;&#305;k &#252;&#231; y&#305;l s&#252;ren operasyon sonucunda 100'den fazla &#252;lkede faaliyet g&#246;steren binlerce su&#231;lu ve su&#231; a&#287;&#305; takip edilmi&#351;, milyonlarca mesaj analiz edilmi&#351; ve operasyonun sonunda e&#351; zamanl&#305; bask&#305;nlarla y&#252;zlerce ki&#351;i g&#246;zalt&#305;na al&#305;nm&#305;&#351;t&#305;r. </p><p>Tonlarca uyu&#351;turucu madde, milyonlarca dolar nakit para, &#231;ok say&#305;da yasa d&#305;&#351;&#305; silah ve su&#231; &#246;rg&#252;tlerine ait lojistik a&#287;lar ortaya &#231;&#305;kar&#305;lm&#305;&#351;t&#305;r. </p><p><strong>ANOM operasyonu</strong>, <strong>dijital kar&#351;&#305; ter&#246;rizm ve organize su&#231;la m&#252;cadelede en etkili y&#246;ntemin her zaman bir sistemi k&#305;rmak de&#287;il, gerekti&#287;inde g&#252;venilen sistemi bizzat tasarlamak olabilece&#287;ini g&#246;stermesi bak&#305;m&#305;ndan istihbarat tarihinde &#246;nemli bir d&#246;n&#252;m noktas&#305; olarak kabul edilmektedir.</strong></p><p></p><h1>Sonu&#231;</h1><p>Dijital d&#246;n&#252;&#351;&#252;m, ter&#246;r &#246;rg&#252;tlerinin yaln&#305;zca kulland&#305;klar&#305; teknolojileri de&#287;il, &#246;rg&#252;tlenme bi&#231;imlerini, propaganda y&#246;ntemlerini ve operasyonel kabiliyetlerini de k&#246;kl&#252; bi&#231;imde de&#287;i&#351;tirmi&#351;tir. </p><p>&#304;nternet, sosyal medya platformlar&#305;, &#351;ifreli haberle&#351;me uygulamalar&#305;, kripto para ekosistemleri ve yapay zeka teknolojileri, ter&#246;r &#246;rg&#252;tlerine k&#252;resel &#246;l&#231;ekte hareket edebilme, daha h&#305;zl&#305; &#246;rg&#252;tlenebilme ve daha geni&#351; kitlelere ula&#351;abilme imkan&#305; sa&#287;lamaktad&#305;r. </p><p>Bu durum, klasik ter&#246;rle m&#252;cadele anlay&#305;&#351;&#305;n&#305;n tek ba&#351;&#305;na yeterli olmad&#305;&#287;&#305;n, dijital alan&#305; merkezine alan yeni nesil bir g&#252;venlik yakla&#351;&#305;m&#305;n&#305; zorunlu hale getirmi&#351;tir.</p><blockquote><p><strong>DEA&#350;</strong>&#8217;&#305;n sosyal medya ve Telegram &#252;zerinden y&#252;r&#252;tt&#252;&#287;&#252; dijital propaganda faaliyetleri, <br><strong>EncroChat platformunun</strong> teknik ve istihbarat temelli y&#246;ntemlerle de&#351;ifre edilmesi,<br>ve <strong>ANOM operasyonunda</strong> uygulanan aldatma odakl&#305; istihbarat yakla&#351;&#305;m&#305;, <br>modern <strong>Cyber Counterterrorism (Siber Kar&#351;&#305; Ter&#246;rizm)</strong> anlay&#305;&#351;&#305;n&#305;n yaln&#305;zca siber savunmadan ibaret olmad&#305;&#287;&#305;n&#305; a&#231;&#305;k&#231;a g&#246;stermektedir. </p></blockquote><p>Bu vakalar, ba&#351;ar&#305;n&#305;n yaln&#305;zca geli&#351;mi&#351; g&#252;venlik teknolojilerine sahip olmakla de&#287;il, farkl&#305; istihbarat disiplinlerini ortak bir operasyonel resim i&#231;erisinde birle&#351;tirebilmekle m&#252;mk&#252;n oldu&#287;unu ortaya koymaktad&#305;r. </p><p>G&#252;n&#252;m&#252;zde <strong>insan istihbarat&#305;</strong> (<strong>HUMINT</strong>), <strong>sinyal istihbarat&#305;</strong> (<strong>SIGINT</strong>), <strong>a&#231;&#305;k kaynak istihbarat&#305;</strong> (<strong>OSINT</strong>), <strong>finansal istihbarat</strong> (<strong>FININT</strong>), <strong>siber tehdit istihbarat&#305;</strong> (<strong>CTI</strong>) ve <strong>yapay zeka destekli analiz y&#246;ntemleri</strong>, birbirini tamamlayan ve karar alma s&#252;re&#231;lerini besleyen stratejik unsurlar haline gelmi&#351;tir.</p><p><strong>&#214;n&#252;m&#252;zdeki d&#246;nemde yapay zeka destekli propaganda, deepfake teknolojileri, otonom sistemler, kripto varl&#305;klar ve geli&#351;mi&#351; &#351;ifreleme y&#246;ntemlerinin yayg&#305;nla&#351;mas&#305;yla birlikte dijital ter&#246;r a&#287;lar&#305;n&#305;n daha karma&#351;&#305;k ve &#246;ng&#246;r&#252;lmesi g&#252;&#231; bir yap&#305;ya d&#246;n&#252;&#351;mesi beklenmektedir. </strong></p><p>Buna kar&#351;&#305;l&#305;k g&#252;venlik kurumlar&#305;n&#305;n da b&#252;y&#252;k veri analiti&#287;i, davran&#305;&#351; analizi, grafik tabanl&#305; ili&#351;ki analizi, &#246;ng&#246;r&#252;c&#252; yapay zeka modelleri ve uluslararas&#305; istihbarat payla&#351;&#305;m&#305; gibi yeteneklerini s&#252;rekli geli&#351;tirmeleri ka&#231;&#305;n&#305;lmaz olacakt&#305;r. </p><p>Bu nedenle <strong>Cyber Counterterrorism (Siber Kar&#351;&#305; Ter&#246;rizm)</strong>, yaln&#305;zca siber g&#252;venli&#287;in bir alt ba&#351;l&#305;&#287;&#305; olarak de&#287;il, <strong>ulusal g&#252;venlik, istihbarat, hukuk, teknoloji</strong> ve <strong>uluslararas&#305; i&#351; birli&#287;ini ayn&#305; stratejik &#231;at&#305; alt&#305;nda birle&#351;tiren disiplinler aras&#305; bir g&#252;venlik yakla&#351;&#305;m&#305; olarak de&#287;erlendirilmelidir.</strong></p><p>Sonu&#231; olarak, dijital &#231;a&#287;da ter&#246;r &#246;rg&#252;tlerine kar&#351;&#305; &#252;st&#252;nl&#252;k sa&#287;lamak, yaln&#305;zca daha g&#252;&#231;l&#252; g&#252;venlik duvarlar&#305; veya daha geli&#351;mi&#351; &#351;ifreleme teknolojileri geli&#351;tirmekle m&#252;mk&#252;n de&#287;ildir. </p><p><strong>&#220;st&#252;nl&#252;k, do&#287;ru veriyi do&#287;ru zamanda toplayabilmek, farkl&#305; kaynaklardan elde edilen bilgileri anlaml&#305; istihbarata d&#246;n&#252;&#351;t&#252;rebilmek ve bu istihbarat&#305; zaman&#305;nda operasyonel kararlara yans&#305;tabilme yetene&#287;inde yatmaktad&#305;r.</strong> </p><p>Gelece&#287;in kar&#351;&#305; ter&#246;rizm anlay&#305;&#351;&#305;, reaktif g&#252;venlik &#246;nlemlerinden ziyade <strong>&#246;ng&#246;r&#252;c&#252;, istihbarat temelli ve yapay zeka destekli karar mekanizmalar&#305; &#252;zerine in&#351;a edilecek,</strong> <strong>Cyber Counterterrorism (Siber Kar&#351;&#305; Ter&#246;rizm)</strong> <strong>ise bu d&#246;n&#252;&#351;&#252;m&#252;n merkezinde yer alan en kritik g&#252;venlik yakla&#351;&#305;mlar&#305;ndan biri olmaya devam edecektir.</strong></p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br><span>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,</span><br><span>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,</span><br><span>CompTIA Project+ Professional,</span><br><span>CIW Security Analyst,</span><br><span>Certified Cyber Threat Intelligence Analyst,</span><br><span>Certified Information Security Executive&#8482;,</span><br><span>Senior Certified Leadership Practitioner</span></p><p></p><h1>Kaynak&#231;a:</h1><ul><li><p><strong>Europol. (2021).</strong><span> </span><em>European Union Terrorism Situation and Trend Report (TE-SAT 2021).</em><span> Europol.</span></p></li><li><p><strong>Europol. (2022).</strong> <em>European Union Terrorism Situation and Trend Report (TE-SAT 2022).</em> Europol.</p></li><li><p><strong>Federal Bureau of Investigation (FBI). (2021).</strong> <em>Operation Trojan Shield / ANOM: International Law Enforcement Operation.</em></p></li><li><p><strong>International Centre for Counter-Terrorism (ICCT). (2021).</strong><span> </span><em>The Digitalisation of Terrorism.</em></p></li><li><p><strong>UN Office of Counter-Terrorism (UNOCT). (2022).</strong> <em>Countering Terrorist Use of New Technologies.</em></p></li><li><p><strong>United Nations Office on Drugs and Crime (UNODC). (2022).</strong> <em>Handbook on Terrorism Prevention and Criminal Justice Responses.</em></p></li><li><p><strong>NSA &amp; CISA. (2023).</strong><span> </span><em>Joint Cybersecurity Advisories.</em></p></li><li><p><strong>Council of Europe. (2001).</strong><span> </span><em>Convention on Cybercrime (Budapest Convention).</em><span> Strasbourg.</span></p><p></p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Cyber Counterterrorism: The Digital Dimension of Modern Counterterrorism]]></title><description><![CDATA[Thanks for reading Ziya's Substack!]]></description><link>https://ziyagokalp.substack.com/p/cyber-counterterrorism-the-digital</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/cyber-counterterrorism-the-digital</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Sat, 27 Jun 2026 15:14:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!TTn6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec022bd3-a81f-46df-8781-5ffebe827b89_1691x930.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TTn6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec022bd3-a81f-46df-8781-5ffebe827b89_1691x930.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TTn6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec022bd3-a81f-46df-8781-5ffebe827b89_1691x930.heic 424w, https://substackcdn.com/image/fetch/$s_!TTn6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec022bd3-a81f-46df-8781-5ffebe827b89_1691x930.heic 848w, https://substackcdn.com/image/fetch/$s_!TTn6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec022bd3-a81f-46df-8781-5ffebe827b89_1691x930.heic 1272w, https://substackcdn.com/image/fetch/$s_!TTn6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec022bd3-a81f-46df-8781-5ffebe827b89_1691x930.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TTn6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec022bd3-a81f-46df-8781-5ffebe827b89_1691x930.heic" width="1456" height="801" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ec022bd3-a81f-46df-8781-5ffebe827b89_1691x930.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:801,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:291316,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/203775463?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec022bd3-a81f-46df-8781-5ffebe827b89_1691x930.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TTn6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec022bd3-a81f-46df-8781-5ffebe827b89_1691x930.heic 424w, https://substackcdn.com/image/fetch/$s_!TTn6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec022bd3-a81f-46df-8781-5ffebe827b89_1691x930.heic 848w, https://substackcdn.com/image/fetch/$s_!TTn6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec022bd3-a81f-46df-8781-5ffebe827b89_1691x930.heic 1272w, https://substackcdn.com/image/fetch/$s_!TTn6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec022bd3-a81f-46df-8781-5ffebe827b89_1691x930.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h1>Introduction</h1><p>In this article, I examine <strong>Cyber Counterterrorism</strong> not merely as a technical cybersecurity discipline, but as a comprehensive strategic framework that integrates intelligence, law enforcement, national security, and emerging technologies. </p><p>The primary objective of this study is to provide a holistic analysis of the evolution of digital terrorist networks, the role of intelligence disciplines in counterterrorism operations, lessons learned from real-world operations, threats targeting critical infrastructure, and the growing impact of artificial intelligence on next-generation counterterrorism strategies.</p><p>Furthermore, this study analyzes the practical implementation of <strong>Cyber Counterterrorism</strong> through verified case studies, including the <strong>EncroChat</strong> and <strong>ANOM</strong> operations, the Islamic State&#8217;s (<strong>ISIS/Daesh</strong>) digital propaganda ecosystem, terrorist financing through cryptocurrencies, threat scenarios targeting critical infrastructure, and the application of advanced data analytics platforms in counterterrorism operations.</p><p>Ultimately, this article seeks to demonstrate why an intelligence-driven approach to <strong>Cyber Counterterrorism</strong> has become an indispensable component of the modern security architecture in the digital age. </p><p>As terrorist organizations continue to exploit cyberspace for communication, recruitment, financing, operational planning, and psychological influence, counterterrorism strategies must evolve beyond conventional defensive measures toward intelligence-led, technology-enabled, and data-driven operational models.</p><p></p><h1>Overview</h1><p>The twenty-first century has fundamentally transformed the concept of security, extending it beyond the protection of physical borders into a multidimensional domain that encompasses cyberspace. </p><p><strong>Security is no longer confined to territorial defense; it now includes the protection of digital infrastructure, information ecosystems, and interconnected cyber environments that underpin modern societies.</strong></p><p>While the global expansion of the I<strong>nternet, cloud computing, mobile communication technologies, social media platforms, cryptocurrency ecosystems, and artificial intelligence has generated unprecedented opportunities for economic growth, innovation, and global connectivity, these same technologies have simultaneously provided terrorist organizations with operational capabilities that were unimaginable only a few decades ago.</strong></p><p>Today, terrorist organizations can no longer be characterized solely as armed groups operating in remote mountainous regions or conflict zones. </p><p>Instead, they increasingly function as decentralized, <strong>digitally connected networks that communicate through encrypted messaging platforms, finance their activities using cryptocurrencies, exploit social media algorithms to disseminate propaganda and recruit supporters, and leverage artificial intelligence to amplify psychological influence, automate information operations, and enhance strategic communication.</strong></p><p>Consequently, <strong>cyberspace has evolved into a critical operational domain where terrorist organizations recruit, coordinate, finance, influence, and, in some cases, execute attacks.</strong> </p><p>Understanding this digital transformation is therefore essential for developing effective <strong>Cyber Counterterrorism</strong> strategies capable of addressing the complex threat landscape of the twenty-first century.</p><p>This transformation has compelled security institutions not only to combat threats commonly classified as <strong>cyberterrorism</strong>, but also to develop a new intelligence-driven approach capable of addressing the evolving digital threat landscape.</p><p>Increasingly recognized in both academic literature and security practice, <strong>Cyber Counterterrorism</strong> is an interdisciplinary security framework aimed at identifying, analyzing, disrupting, and, when necessary, neutralizing the activities of terrorist organizations that exploit digital technologies. </p><p>It integrates intelligence, cybersecurity, law enforcement, and operational capabilities to counter the full spectrum of terrorist activity in cyberspace.</p><p>In other words, <strong>Cyber Counterterrorism</strong> extends far beyond responding to a cyberattack after it has occurred. Rather, it represents a proactive, intelligence-led defense model designed to monitor, understand, and disrupt the entire digital ecosystem within <strong>which terrorist organizations communicate, recruit, finance, coordinate, and conduct influence operations.</strong></p><p>Traditionally, counterterrorism strategies relied heavily on <strong>Human Intelligence (HUMINT)</strong>, field operations, physical surveillance, and conventional security measures. Throughout much of the Cold War, governments depended on intelligence officers, clandestine agent networks, surveillance operations, and physical reconnaissance to monitor terrorist organizations and foreign intelligence services.</p><p>However, the rapid global expansion of the Internet fundamentally transformed the operational environment. </p><p>Terrorist organizations underwent their own digital transformation, adopting emerging technologies to enhance communication, operational security, financing, recruitment, propaganda, and transnational coordination. </p><p><strong>As a result, the battlefield of counterterrorism expanded from the physical world into cyberspace, requiring intelligence agencies and security organizations to rethink both their methodologies and operational capabilities.</strong></p><p>Today, members of a terrorist organization can be dispersed across different continents while simultaneously planning operations, disseminating propaganda, and coordinating financial activities through the same digital platforms. </p><p>This reality has demonstrated that conventional counterterrorism methods alone are no longer sufficient to address the complexity of contemporary terrorist threats.</p><p>Undoubtedly, one of the most significant turning points in this transformation was the <strong>September 11, 2001 terrorist attacks</strong>. Claiming the lives of nearly three thousand people, these attacks fundamentally reshaped not only international security policies but also the methodologies employed in intelligence collection and counterterrorism operations.</p><p>In the aftermath of <strong>9/11</strong>, intelligence agencies around the world significantly expanded information-sharing mechanisms, introduced broader legal frameworks for monitoring digital communications, and accelerated investments in big data analytics, network analysis, and behavioral modeling technologies. </p><p>These developments marked the beginning of a profound shift toward intelligence-driven, technology-enabled counterterrorism.</p><p>Importantly, this evolution did not signify the replacement of traditional <strong>Human Intelligence (HUMINT)</strong> by digital intelligence. </p><p>Rather, it gave rise to a <strong>hybrid security architecture</strong> in which multiple intelligence disciplines including; <strong>HUMINT, Signals Intelligence (SIGINT), Open-Source Intelligence (OSINT), Cyber Threat Intelligence (CTI), Financial Intelligence (FININT), and increasingly Artificial Intelligence&#8211;enabled Intelligence (AIINT)</strong> operate in an integrated and mutually reinforcing manner.</p><p>Developments over the past two decades have demonstrated that terrorist organizations have adapted to digital technologies far more rapidly than originally anticipated. </p><p>Their ability to exploit emerging technologies for communication, recruitment, financing, operational security, and psychological influence continues to challenge conventional security paradigms, reinforcing the need for proactive, intelligence-led <strong>Cyber Counterterrorism</strong> strategies.</p><p>The <strong>Islamic State (ISIS/Daesh)</strong>, in particular, did not use social media platforms solely as instruments of propaganda. Rather, it systematically exploited digital platforms to radicalize individuals across different regions of the world, recruit foreign fighters, facilitate fundraising, and coordinate operational activities.</p><p>The organization&#8217;s sophisticated use of high-definition videos, professionally produced graphic content, multilingual digital magazines, and carefully orchestrated social media campaigns represents one of the clearest examples of how digital communication has evolved into a strategic asset for modern terrorist organizations. </p><p>Through these technologies, ISIS demonstrated that information could function not merely as a means of communication, but as an operational weapon capable of influencing perceptions, mobilizing supporters, and extending ideological reach on a global scale.</p><p>The global accessibility of digital platforms has enabled terrorist organizations to transcend geographical boundaries and significantly expand their ideological influence. Individuals who would never have encountered terrorist networks through traditional physical channels can now be exposed to extremist narratives through algorithm-driven recommendation systems, encrypted online communities, and social media ecosystems.</p><p>However, this digital transformation extends far beyond propaganda alone. It encompasses every stage of the terrorist operational lifecycle from secure communications and recruitment to financing, intelligence gathering, operational planning, psychological influence, and the coordination of attacks making cyberspace an indispensable domain in contemporary counterterrorism efforts.</p><p>The rapid evolution of <strong>cryptocurrency technologies</strong>, the anonymity provided by <strong>blockchain-based payment systems</strong>, and the expansion of the <strong>Dark Web</strong> ecosystem have fundamentally transformed the financing methods employed by terrorist organizations.</p><p>Seeking to circumvent the oversight mechanisms of traditional financial institutions, terrorist networks have increasingly relied on cryptocurrencies, digital wallets, and decentralized financial infrastructures to collect donations, transfer funds, procure resources, and facilitate logistical support. </p><p><strong>This evolution has significantly complicated the detection and disruption of terrorist financing, making financial transactions more resilient against conventional regulatory and law enforcement measures.</strong></p><p>As a consequence, effective counterterrorism now requires the close integration of <strong>Financial Intelligence (FININT)</strong> with <strong>Cyber Threat Intelligence (CTI)</strong>, enabling investigators to <strong>combine blockchain analytics, digital forensics, cyber investigations, and financial monitoring to identify illicit financial networks and disrupt terrorist funding mechanisms.</strong></p><p>At the same time, <strong>critical infrastructure</strong> has emerged as one of the primary targets of next-generation terrorist threats. Power generation facilities, natural gas transmission networks, water treatment plants, transportation systems, healthcare infrastructure, and <strong>Operational Technology (OT)</strong> and <strong>Industrial Control Systems (ICS)</strong> are no longer viewed solely as potential targets for state-sponsored <strong>Advanced Persistent Threat (APT)</strong> groups. </p><p>Increasingly, they are also considered attractive targets for ideologically motivated terrorist organizations seeking to maximize economic disruption, societal instability, and psychological impact.</p><p>A successful cyberattack against <strong>OT</strong> and <strong>ICS</strong> environments could produce consequences extending far beyond the digital domain. Depending on the targeted process, such attacks may result in physical destruction, prolonged production outages, environmental disasters, disruption of essential public services, widespread public panic, and significant threats to national security. </p><p>Consequently, <strong>protecting critical infrastructure has become a central pillar of modern Cyber Counterterrorism strategies, requiring the integration of cybersecurity, intelligence, operational resilience, and critical infrastructure protection into a unified defense framework.</strong></p><p>For this reason, the modern concept of <strong>Cyber Counterterrorism</strong> extends far beyond the protection of information systems alone. It also encompasses the security and resilience of <strong>critical infrastructure</strong> and the <strong>physical processes</strong>controlled by <strong>Operational Technology (OT)</strong> and <strong>Industrial Control Systems (ICS)</strong>, recognizing that cyberattacks can produce tangible consequences in the physical world.</p><p>Taken together, these developments clearly demonstrate that modern counterterrorism is no longer limited to military operations or traditional law enforcement activities. Instead, an effective Cyber Counterterrorism strategy requires the seamless integration of multiple intelligence disciplines, including:</p><ul><li><p><strong>Human Intelligence (HUMINT)</strong></p></li><li><p><strong>Signals Intelligence (SIGINT)</strong></p></li><li><p><strong>Open-Source Intelligence (OSINT)</strong></p></li><li><p><strong>Social Media Intelligence (SOCMINT)</strong></p></li><li><p><strong>Financial Intelligence (FININT)</strong></p></li><li><p><strong>Cyber Threat Intelligence (CTI)</strong></p></li><li><p><strong>Artificial Intelligence&#8211;Enabled Intelligence (AIINT)</strong>, an increasingly important discipline that leverages machine learning and advanced analytics to support intelligence operations.</p></li></ul><p>The convergence of these intelligence capabilities enables security organizations to develop a comprehensive understanding of terrorist networks across both the physical and digital domains. By combining intelligence from diverse sources, analysts can identify hidden relationships, detect emerging threats, and disrupt terrorist activities before they mature into operational attacks.</p><p>Advances in <strong>big data analytics</strong>, <strong>graph-based relationship analysis</strong>, <strong>machine learning algorithms</strong>, and <strong>behavioral modeling</strong> have further enhanced this capability. These technologies make it possible to uncover previously undetectable connections among millions of data points, revealing patterns of communication, financing, recruitment, and operational coordination that would be nearly impossible to identify through conventional analytical methods.</p><p><strong>Consequently, security and intelligence agencies are increasingly shifting from a reactive posture toward an intelligence-driven, predictive approach. Rather than responding only after an incident has occurred, modern Cyber Counterterrorism seeks to anticipate, identify, and mitigate potential threats before they materialize, enabling proactive decision-making and significantly strengthening national and international security.</strong></p><p></p><h1>The Evolution of Intelligence-Driven Operations Against Digital Terrorist Networks: The Cases of ISIS, EncroChat, and ANOM</h1><p>As discussed in the previous sections, the primary objective of <strong>Cyber Counterterrorism</strong> is not merely to respond to cyberattacks after they occur, but to identify, analyze, disrupt, and ultimately neutralize terrorist and organized criminal networks operating in the digital domain before their plans can be executed.</p><p>The effectiveness of this intelligence-led approach depends largely on the integration of multiple intelligence disciplines. <strong>Human Intelligence (HUMINT), Signals Intelligence (SIGINT), Open-Source Intelligence (OSINT), Financial Intelligence (FININT), and Cyber Threat Intelligence (CTI)</strong> are no longer treated as independent capabilities; instead, they function as complementary components of a unified operational intelligence picture.</p><p>This multidimensional intelligence architecture enables analysts to correlate digital communications, financial transactions, behavioral patterns, online propaganda, and operational activities, thereby exposing relationships and vulnerabilities that would remain invisible if each intelligence discipline were applied in isolation.</p><p>Among the numerous operations conducted over the past decade, three landmark cases stand out as particularly significant in illustrating the evolution of modern Cyber Counterterrorism:</p><ul><li><p><strong>The Islamic State&#8217;s (ISIS/Daesh) digital propaganda ecosystem</strong></p></li><li><p><strong>The compromise and dismantling of the EncroChat encrypted communications platform</strong></p></li><li><p><strong>Operation ANOM</strong>, one of the most sophisticated global law enforcement intelligence operations ever conducted against transnational criminal networks.</p></li></ul><p>Together, these cases demonstrate how intelligence agencies have evolved from traditional reactive investigations toward proactive, intelligence-driven operations that combine cyber capabilities, digital forensics, advanced analytics, covert operations, and international cooperation to identify, monitor, and dismantle hostile networks operating within cyberspace.</p><h3>The Islamic State (ISIS/Daesh)</h3><p>The <strong>Islamic State (ISIS/Daesh)</strong> is widely regarded as one of the first global terrorist organizations to systematically and professionally exploit digital technologies as a core component of its operational strategy.</p><p>Unlike <strong>Al-Qaeda</strong>, which primarily relied on websites and online forums during the early years of the Internet, ISIS transformed social media algorithms, high-definition video production, and multilingual digital publications into sophisticated instruments of strategic propaganda and psychological influence.</p><p>Beginning in 2014, the organization orchestrated large-scale propaganda campaigns through thousands of coordinated Twitter accounts, enabling it to achieve unprecedented global visibility within a remarkably short period. As social media platforms increasingly suspended extremist content, ISIS adapted by migrating to encrypted messaging applications such as <strong>Telegram</strong>, where it not only continued disseminating propaganda but also established secure communication channels with supporters worldwide, coordinated the recruitment of foreign fighters, distributed operational guidance, and encouraged attacks through digital means.</p><p>The English-language magazines <strong>Dabiq</strong> and later <strong>Rumiyah</strong> further exemplified the organization&#8217;s sophisticated information strategy. These professionally produced digital publications were specifically designed to influence Western audiences, promote extremist ideology, inspire self-radicalization, and encourage both recruitment and lone-actor attacks. Rather than serving as simple propaganda outlets, they functioned as carefully crafted psychological operations intended to shape perceptions, reinforce ideological narratives, and extend the organization&#8217;s global influence.</p><p>The rise of ISIS&#8217;s digital ecosystem provided a critical lesson for intelligence and security agencies worldwide. Digital platforms are no longer merely channels for communication; they have evolved into next-generation battlefields where radicalization, recruitment, operational coordination, ideological influence, and psychological warfare increasingly take place. Understanding and disrupting these digital ecosystems has therefore become a fundamental objective of modern Cyber Counterterrorism.</p><h3>EncroChat</h3><p>As terrorist organizations and transnational criminal networks increasingly migrated to encrypted communication platforms, security and intelligence agencies were compelled to develop more innovative and technologically sophisticated intelligence capabilities. One of the most significant examples of this evolution is the <strong>EncroChat</strong> operation.</p><p>Marketed as an ultra-secure communication system, EncroChat devices were specially modified smartphones with features such as microphones, cameras, and GPS functionality disabled, while offering end-to-end encrypted communications. These devices rapidly became the preferred communication platform for organized crime groups involved in drug trafficking, money laundering, arms trafficking, contract killings, and other serious criminal enterprises across Europe.</p><p>By 2020, a substantial portion of Europe&#8217;s illicit drug trade, money laundering operations, and weapons trafficking activities were being coordinated through the EncroChat platform. Believing the system to be virtually impenetrable, criminal organizations relied on it to exchange operational plans, financial information, logistical arrangements, and other highly sensitive communications.</p><p>In 2020, following an extensive technical operation conducted by French and Dutch law enforcement and intelligence authorities, investigators successfully gained covert access to the EncroChat infrastructure. This unprecedented intelligence breakthrough enabled the real-time collection and analysis of millions of encrypted messages exchanged among criminal users.</p><p>The intelligence obtained from the operation led to thousands of coordinated law enforcement actions across Europe, resulting in the seizure of hundreds of tons of illicit narcotics, the discovery of numerous weapons caches, the confiscation of substantial criminal assets, and the arrest of hundreds of senior organized crime figures. Beyond its immediate operational success, the EncroChat investigation fundamentally transformed the way encrypted communications are exploited for intelligence purposes.</p><p>Perhaps the most important lesson of the EncroChat operation is that modern counterterrorism and organized crime investigations can no longer rely solely on monitoring communication traffic. Instead, they require a comprehensive understanding of the entire communication ecosystem&#8212;including devices, infrastructure, user behavior, trust relationships, metadata, operational patterns, and digital networks. This intelligence-centric perspective has become a defining characteristic of contemporary Cyber Counterterrorism, where understanding the ecosystem is often more valuable than intercepting individual messages.</p><h3>Operation ANOM</h3><p>Perhaps the most remarkable example of intelligence-driven operations in the digital era is <strong>Operation ANOM</strong>. Planned by the <strong>Federal Bureau of Investigation (FBI)</strong> and executed in close cooperation with numerous international law enforcement agencies, the operation represented a paradigm shift that extended far beyond conventional cybersecurity and digital surveillance practices.</p><p>Rather than attempting to compromise an existing encrypted communications platform, investigators adopted a far more innovative strategy. They facilitated the creation and controlled distribution of a bespoke encrypted communication system known as <strong>ANOM</strong> that was specifically designed to gain the trust of organized criminal networks. Through carefully managed channels and trusted intermediaries, ANOM devices gradually became widely adopted among transnational criminal organizations.</p><p>Believing the platform to be completely secure, users relied on ANOM devices to exchange highly sensitive operational information, including discussions relating to drug trafficking, money laundering, weapons trafficking, contract killings, and other serious criminal activities. Unbeknownst to them, every message transmitted through the platform was simultaneously accessible to law enforcement authorities, providing investigators with an unprecedented stream of real-time operational intelligence.</p><p>Over the course of approximately three years, authorities monitored thousands of criminals and criminal networks operating in more than one hundred countries. Millions of encrypted messages were collected and analyzed, generating actionable intelligence that culminated in a series of globally coordinated enforcement actions. Simultaneous raids resulted in the arrest of hundreds of high-value criminal suspects, while authorities seized tons of illicit narcotics, millions of dollars in cash, numerous illegal firearms, and extensive logistical infrastructures supporting transnational organized crime.</p><p>Operation ANOM is widely regarded as a landmark in the history of intelligence operations because it fundamentally challenged conventional assumptions about encrypted communications. Rather than focusing exclusively on breaking or bypassing a trusted system, investigators demonstrated that, under carefully controlled legal and operational conditions, the most effective strategy may be to design and introduce the trusted system itself. This deception-based, intelligence-led approach illustrates how modern Cyber Counterterrorism and organized crime investigations increasingly rely on strategic innovation, covert operational planning, and multidisciplinary intelligence integration to infiltrate, monitor, and dismantle hostile networks operating in the digital domain.</p><p></p><h1>Conclusion</h1><p>Digital transformation has fundamentally reshaped not only the technologies employed by terrorist organizations but also their organizational structures, propaganda strategies, and operational capabilities. </p><p>The Internet, social media platforms, encrypted communication applications, cryptocurrency ecosystems, and artificial intelligence have collectively enabled terrorist networks to operate on a global scale, organize more rapidly, and influence far broader audiences than ever before.</p><p>This evolving threat landscape clearly demonstrates that conventional counterterrorism approaches are no longer sufficient on their own. Instead, it demands a new generation of security strategies that place the digital domain at the center of intelligence collection, threat analysis, operational planning, and proactive disruption.</p><p>The cases examined throughout this article vividly illustrate this transformation. The Islamic State&#8217;s (<strong>ISIS/Daesh</strong>) sophisticated exploitation of social media and Telegram for propaganda, recruitment, and operational coordination; the intelligence-led compromise of the EncroChat encrypted communications platform; and the deception-based strategy employed during <strong>Operation ANOM</strong> collectively demonstrate that modern <strong>Cyber Counterterrorism</strong> extends far beyond traditional cybersecurity or defensive cyber operations.</p><p>Rather, <strong>Cyber Counterterrorism has evolved into an intelligence-centric operational framework that integrates cyber capabilities, digital forensics, advanced analytics, international cooperation, and multidisciplinary intelligence to identify, infiltrate, disrupt, and dismantle hostile networks before they can execute their objectives.</strong></p><p>These cases further demonstrate that success depends not merely on possessing advanced security technologies, but on the ability to integrate diverse intelligence disciplines into a unified operational picture. </p><p>Today, <strong>Human Intelligence (HUMINT)</strong>, <strong>Signals Intelligence (SIGINT)</strong>, <strong>Open-Source Intelligence (OSINT)</strong>, <strong>Financial Intelligence (FININT)</strong>, <strong>Cyber Threat Intelligence (CTI)</strong>, and increasingly <strong>Artificial Intelligence&#8211;Enabled Intelligence (AIINT)</strong> have become complementary strategic capabilities that collectively support intelligence analysis, operational planning, and decision-making.</p><p>Looking ahead, the proliferation of <strong>AI-generated propaganda</strong>, <strong>deepfake technologies</strong>, <strong>autonomous systems</strong>, <strong>cryptocurrency ecosystems</strong>, and increasingly sophisticated <strong>encryption technologies</strong> is expected to make digital terrorist networks more adaptive, decentralized, and significantly more difficult to detect and predict. </p><p>These technological developments will continue to transform both the operational capabilities of terrorist organizations and the complexity of the threat landscape confronting intelligence and security agencies worldwide.</p><p>In response, security institutions must continuously enhance their capabilities in <strong>big data analytics</strong>, <strong>behavioral intelligence</strong>, <strong>graph-based relationship analysis</strong>, <strong>predictive artificial intelligence</strong>, and <strong>international intelligence sharing</strong>. </p><p>The ability to transform massive volumes of heterogeneous data into timely, actionable intelligence will become one of the defining capabilities of future counterterrorism operations.</p><p>Ultimately, <strong>Cyber Counterterrorism</strong> should not be regarded merely as a specialized branch of cybersecurity. Rather, it should be understood as an interdisciplinary security paradigm that brings together <strong>national security, intelligence, law, technology, and international cooperation</strong> within a unified strategic framework. </p><p>In an era where cyberspace has become a primary operational domain for terrorist organizations, the integration of intelligence, advanced technologies, and strategic foresight will be indispensable for protecting critical infrastructure, safeguarding national security, and preserving international stability in the decades ahead.</p><p><strong>Ultimately, achieving strategic superiority over terrorist organizations in the digital age is not simply a matter of deploying stronger firewalls or developing more sophisticated encryption technologies.</strong> </p><p>Rather, it depends on the ability to collect the right data at the right time, transform information gathered from diverse sources into actionable intelligence, and translate that intelligence into timely operational decisions.</p><p><strong>The future of counterterrorism will therefore be shaped not by reactive security measures alone, but by predictive, intelligence-driven, and artificial intelligence&#8211;enabled decision-making frameworks.</strong> </p><p>As terrorist organizations continue to exploit the opportunities created by digital transformation, <strong>Cyber Counterterrorism</strong> will remain one of the most critical security paradigms of the twenty-first century integrating intelligence, advanced technologies, strategic foresight, and international cooperation to anticipate, disrupt, and neutralize emerging threats before they can materialize.</p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,<br>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,<br>CompTIA Project+ Professional,<br>CIW Security Analyst,<br>Certified Cyber Threat Intelligence Analyst,<br>Certified Information Security Executive&#8482;,<br>Senior Certified Leadership Practitioner</p><p></p><h1>References:</h1><ul><li><p><strong>Europol. (2021).</strong> <em>European Union Terrorism Situation and Trend Report (TE-SAT 2021).</em> Europol.</p></li><li><p><strong>Europol. (2022).</strong> <em>European Union Terrorism Situation and Trend Report (TE-SAT 2022).</em> Europol.</p></li><li><p><strong>Federal Bureau of Investigation (FBI). (2021).</strong> <em>Operation Trojan Shield / ANOM: International Law Enforcement Operation.</em></p></li><li><p><strong>International Centre for Counter-Terrorism (ICCT). (2021).</strong> <em>The Digitalisation of Terrorism.</em></p></li><li><p><strong>UN Office of Counter-Terrorism (UNOCT). (2022).</strong> <em>Countering Terrorist Use of New Technologies.</em></p></li><li><p><strong>United Nations Office on Drugs and Crime (UNODC). (2022).</strong> <em>Handbook on Terrorism Prevention and Criminal Justice Responses.</em></p></li><li><p><strong>NSA &amp; CISA. (2023).</strong> <em>Joint Cybersecurity Advisories.</em></p></li><li><p><strong>Council of Europe. (2001).</strong> <em>Convention on Cybercrime (Budapest Convention).</em> Strasbourg.</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Denizaltı Kablolarından Veri Merkezlerine Jeopolitik Mücadele]]></title><description><![CDATA[PODCAST Linki]]></description><link>https://ziyagokalp.substack.com/p/denizalt-kablolarndan-veri-merkezlerine</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/denizalt-kablolarndan-veri-merkezlerine</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Wed, 17 Jun 2026 22:43:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HNYy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc373a611-45b3-44b0-af80-6352b57c1d26_1774x887.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HNYy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc373a611-45b3-44b0-af80-6352b57c1d26_1774x887.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HNYy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc373a611-45b3-44b0-af80-6352b57c1d26_1774x887.heic 424w, https://substackcdn.com/image/fetch/$s_!HNYy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc373a611-45b3-44b0-af80-6352b57c1d26_1774x887.heic 848w, https://substackcdn.com/image/fetch/$s_!HNYy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc373a611-45b3-44b0-af80-6352b57c1d26_1774x887.heic 1272w, https://substackcdn.com/image/fetch/$s_!HNYy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc373a611-45b3-44b0-af80-6352b57c1d26_1774x887.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HNYy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc373a611-45b3-44b0-af80-6352b57c1d26_1774x887.heic" width="1456" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c373a611-45b3-44b0-af80-6352b57c1d26_1774x887.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:337840,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/202497319?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc373a611-45b3-44b0-af80-6352b57c1d26_1774x887.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HNYy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc373a611-45b3-44b0-af80-6352b57c1d26_1774x887.heic 424w, https://substackcdn.com/image/fetch/$s_!HNYy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc373a611-45b3-44b0-af80-6352b57c1d26_1774x887.heic 848w, https://substackcdn.com/image/fetch/$s_!HNYy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc373a611-45b3-44b0-af80-6352b57c1d26_1774x887.heic 1272w, https://substackcdn.com/image/fetch/$s_!HNYy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc373a611-45b3-44b0-af80-6352b57c1d26_1774x887.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://creators.spotify.com/pod/profile/ziyagokalp/episodes/Denizalt-Kablolarndan-Veri-Merkezlerine-Jeopolitik-Mcadele-e3ksuhs">PODCAST Linki</a></strong></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><em><strong>&#8220;G&#246;r&#252;nmeyen &#351;eyler, g&#246;r&#252;nenlerden daha g&#252;&#231;l&#252; olabilir.&#8221; (Heraclitus)</strong></em></p><p><span>&#304;nterneti &#231;o&#287;u zaman g&#246;r&#252;nmez bir alan gibi d&#252;&#351;&#252;n&#252;r&#252;z. </span></p><p><span>Bir e-posta g&#246;nderdi&#287;imizde, bir yapay zeka modeline soru sordu&#287;umuzda, bir video izledi&#287;imizde veya uluslararas&#305; bir finansal i&#351;lem ger&#231;ekle&#351;tirdi&#287;imizde verilerin &#8220;bulut&#8221; ad&#305; verilen soyut bir ortamda hareket etti&#287;ini varsayar&#305;z.</span></p><p><span>Oysa dijital d&#252;nya, san&#305;ld&#305;&#287;&#305;n&#305;n aksine son derece </span><strong><span>fiziksel bir altyap&#305; &#252;zerine kuruludur.</span></strong></p><p><strong><span>Okyanuslar&#305;n derinliklerinden ge&#231;en fiber optik kablolar, k&#305;talar&#305; birbirine ba&#287;layan karasal a&#287;lar, devasa veri merkezleri, enerji santralleri, so&#287;utma sistemleri, uydu a&#287;lar&#305;, internet de&#287;i&#351;im noktalar&#305; ve bulut sa&#287;lay&#305;c&#305;lar&#305; modern d&#252;nyan&#305;n g&#246;r&#252;nmeyen omurgas&#305;n&#305; olu&#351;turur.</span></strong></p><p><span>Bug&#252;n jeopolitik m&#252;cadele yaln&#305;zca petrol sahalar&#305;, bo&#287;azlar, limanlar, ticaret yollar&#305; veya askeri &#252;sler &#252;zerinde ya&#351;anmamaktad&#305;r. </span></p><p><strong><span>Yeni m&#252;cadele alanlar&#305;ndan biri de verinin ge&#231;ti&#287;i yollar ve verinin i&#351;lendi&#287;i merkezlerdir.</span></strong></p><p><span>Nitekim i&#231;inde bulundu&#287;umuz y&#252;zy&#305;lda g&#252;&#231; art&#305;k yaln&#305;zca topra&#287;&#305;, enerjiyi veya &#252;retimi kontrol etmekle &#246;l&#231;&#252;lm&#252;yor.</span></p><p><strong><span>Veriyi ta&#351;&#305;yan, veriyi i&#351;leyen ve veriye eri&#351;imi y&#246;neten akt&#246;rler de k&#252;resel g&#252;&#231; mimarisinin merkezine yerle&#351;iyor.</span></strong></p><p></p><h3><strong><span>Bulut Asl&#305;nda Yerde Durur ! Ve Hatta Denizlerin Alt&#305;nda !</span></strong></h3><p><span>&#8220;</span><strong><span>Bulut</span></strong><span>&#8221; kavram&#305; dijital &#231;a&#287;&#305;n en yan&#305;lt&#305;c&#305; ifadelerinden biridir. </span></p><p><span>Nitekim bulut, havada as&#305;l&#305; duran soyut bir sistem de&#287;ildir. </span></p><p><span>Bulut; Veri merkezlerinden, fiber optik kablolardan, y&#246;nlendiricilerden, sunuculardan, enerji altyap&#305;s&#305;ndan ve so&#287;utma sistemlerinden olu&#351;an devasa bir fiziksel ekosistemdir.</span></p><p><span>Bir &#351;irket verilerini buluta ta&#351;&#305;d&#305;&#287;&#305;nda asl&#305;nda verilerini ba&#351;ka bir &#252;lkenin, ba&#351;ka bir hukuk sisteminin veya ba&#351;ka bir teknoloji &#351;irketinin fiziksel altyap&#305;s&#305;na emanet ediyor olabilir.</span></p><p><span>Bu nedenle bulut bili&#351;im yaln&#305;zca teknik bir hizmet modeli de&#287;ildir. </span></p><p><strong><span>Ayn&#305; zamanda veri egemenli&#287;i, hukuk, g&#252;venlik, istihbarat ve jeopolitik ba&#287;&#305;ml&#305;l&#305;k meselesidir.</span></strong></p><p><strong><span>Bir &#252;lkenin kamu kurumlar&#305;, bankalar&#305;, savunma ve &#252;retim sanayisi, sa&#287;l&#305;k sistemleri ve kritik altyap&#305;lar&#305; yabanc&#305; bulut sa&#287;lay&#305;c&#305;lar&#305; &#252;zerinde &#231;al&#305;&#351;&#305;yorsa, bu durum yaln&#305;zca operasyonel kolayl&#305;k sa&#287;lamaz, ayn&#305; zamanda stratejik ba&#287;&#305;ml&#305;l&#305;k da &#252;retir.</span></strong></p><p></p><h3><strong><span>Denizalt&#305; Kablolar&#305;: Dijital D&#252;nyan&#305;n Atardamarlar&#305;</span></strong></h3><p><span>Modern internetin en kritik unsurlar&#305;ndan biri </span><strong><span>denizalt&#305; fiber optik kablolard&#305;r.</span></strong></p><p><span>K&#305;talar aras&#305; veri trafi&#287;inin b&#252;y&#252;k b&#246;l&#252;m&#252; uydular &#252;zerinden de&#287;il, okyanus taban&#305;na d&#246;&#351;enen fiber optik kablolar &#252;zerinden ta&#351;&#305;n&#305;r. </span></p><p><span>Bunun nedeni basittir. </span><strong><span>Fiber optik kablolar, uydulara k&#305;yasla &#231;ok daha y&#252;ksek kapasite, daha d&#252;&#351;&#252;k gecikme ve daha d&#252;&#351;&#252;k maliyet sa&#287;lar.</span></strong></p><p><span>Bu kablolar sayesinde </span><strong><span>finansal piyasalar &#231;al&#305;&#351;&#305;r, uluslararas&#305; telefon g&#246;r&#252;&#351;meleri yap&#305;l&#305;r, bulut servisleri birbirine ba&#287;lan&#305;r, devlet kurumlar&#305; veri al&#305;&#351;veri&#351;i yapar, askeri ileti&#351;im a&#287;lar&#305; desteklenir</span></strong><span> ve </span><strong><span>k&#252;resel internet trafi&#287;i ta&#351;&#305;n&#305;r.</span></strong></p><p><strong><span>Bir ba&#351;ka ifadeyle, dijital ekonominin g&#246;r&#252;nmeyen damarlar&#305; denizlerin alt&#305;ndad&#305;r.</span></strong></p><p><span>Bu durum denizalt&#305; kablolar&#305;n&#305; yaln&#305;zca teknik altyap&#305; unsuru olmaktan &#231;&#305;kar&#305;r. </span></p><p><strong><span>Onlar&#305; stratejik hedef, istihbarat de&#287;eri ta&#351;&#305;yan varl&#305;k ve jeopolitik rekabet alan&#305; haline getirir !</span></strong></p><p></p><h3><strong><span>Peki Bu Kablolar K&#305;r&#305;lgan m&#305;d&#305;r? </span></strong></h3><p><span>Denizalt&#305; kablolar&#305; binlerce kilometrelik hatlar boyunca okyanus taban&#305;ndan ge&#231;er. </span></p><p><span>Baz&#305; b&#246;lgelerde derin sulardan ge&#231;tikleri i&#231;in eri&#351;ilmesi zordur. Ancak k&#305;y&#305;ya yakla&#351;t&#305;klar&#305; noktalarda, bo&#287;azlarda, s&#305;&#287; sularda ve yo&#287;un deniz trafi&#287;inin oldu&#287;u b&#246;lgelerde daha savunmas&#305;z hale gelirler.</span></p><p><span>Bu kablolar; </span><strong><span>Gemi &#231;apalar&#305;, bal&#305;k&#231;&#305;l&#305;k faaliyetleri, denizalt&#305; heyelanlar&#305;, depremler, sabotaj giri&#351;imleri, hibrit sava&#351; faaliyetleri ve istihbarat operasyonlar&#305;</span></strong><span> nedeniyle zarar g&#246;rebilir.</span></p><p><span>Tek bir kablonun kesilmesi her zaman b&#252;y&#252;k bir felaket yaratmayabilir. </span></p><p><span>Nitekim internet &#231;o&#287;u zaman alternatif rotalar &#252;zerinden trafi&#287;i yeniden y&#246;nlendirebilir. </span></p><p><span>Ancak baz&#305; &#252;lkeler, adalar veya b&#246;lgeler s&#305;n&#305;rl&#305; say&#305;da kabloya ba&#287;l&#305;d&#305;r. Bu t&#252;r yerlerde birka&#231; kablonun ayn&#305; anda zarar g&#246;rmesi ciddi kesintilere yol a&#231;abilir !</span></p><p><span>Bu nedenle kablo g&#252;venli&#287;i art&#305;k yaln&#305;zca telekom operat&#246;rlerinin konusu de&#287;ildir. </span></p><p><strong><span>Deniz kuvvetleri, istihbarat servisleri, siber g&#252;venlik kurumlar&#305;, enerji otoriteleri ve ulusal g&#252;venlik yap&#305;lar&#305; i&#231;in de kritik bir g&#252;ndemdir.</span></strong></p><h4><strong><span>&#214;rnek: Balt&#305;k Denizi, Tayvan, K&#305;z&#305;ldeniz ve Yeni Risk Haritas&#305;</span></strong></h4><p><span>Son y&#305;llarda denizalt&#305; kablolar&#305;na ili&#351;kin g&#252;venlik endi&#351;eleri artm&#305;&#351;t&#305;r. </span></p><p><span>Balt&#305;k Denizi &#231;evresinde ya&#351;anan kablo hasarlar&#305;, Avrupa&#8217;n&#305;n kuzeyinde hibrit tehdit tart&#305;&#351;malar&#305;n&#305; g&#252;&#231;lendirmektedir. </span></p><p><span>Tayvan &#231;evresindeki kablo olaylar&#305; ise ada &#252;lkelerinin dijital ba&#287;&#305;ml&#305;l&#305;&#287;&#305;n&#305; ve denizalt&#305; ileti&#351;im hatlar&#305;n&#305;n stratejik &#246;nemini yeniden g&#252;ndeme getirmi&#351;tir.</span></p><p><span>K&#305;z&#305;ldeniz gibi deniz ticaretinin ve enerji ge&#231;i&#351;lerinin yo&#287;un oldu&#287;u b&#246;lgelerde ise ileti&#351;im kablolar&#305;, deniz g&#252;venli&#287;i riskleriyle i&#231; i&#231;e ge&#231;mi&#351; durumdad&#305;r.</span></p><p><span>Bu &#246;rnekler bize; </span></p><p><span>Gelece&#287;in krizlerinde sadece limanlar, hava &#252;sleri veya enerji tesislerinin hedef olmayaca&#287;&#305;n&#305; g&#246;stermektedir. </span></p><p><span>Denizalt&#305; kablolar&#305;, internet de&#287;i&#351;im noktalar&#305; ve veri merkezleri de krizlerin g&#246;r&#252;nmeyen hedefleri haline gelebilir.</span></p><p></p><h3><strong><span>Veri Merkezleri ve Veriyi Ta&#351;&#305;yan Denizalt&#305; Fiber Kablolar </span></strong></h3><blockquote><p><strong><span>Denizalt&#305; kablolar&#305; veriyi ta&#351;&#305;r. Veri merkezleri ise veriyi i&#351;ler, saklar ve da&#287;&#305;t&#305;r.</span></strong></p></blockquote><p><span>Bir veri merkezi d&#305;&#351;ar&#305;dan bak&#305;ld&#305;&#287;&#305;nda b&#252;y&#252;k bir end&#252;striyel tesis gibi g&#246;r&#252;nebilir. Ancak i&#231;eride binlerce sunucu, a&#287; cihaz&#305;, depolama sistemi, g&#252;venlik bile&#351;eni, so&#287;utma altyap&#305;s&#305; ve enerji yedeklilik mimarisi bulunur.</span></p><p><span>Bug&#252;n bankac&#305;l&#305;k i&#351;lemleri, sa&#287;l&#305;k kay&#305;tlar&#305;, e-ticaret sistemleri, devlet hizmetleri, sosyal medya platformlar&#305;, yapay zek&#226; modelleri ve kurumsal uygulamalar veri merkezleri &#252;zerinde &#231;al&#305;&#351;&#305;r.</span></p><p><span>Bu nedenle veri merkezleri art&#305;k yaln&#305;zca teknoloji tesisleri de&#287;ildir.<br>Onlar dijital &#231;a&#287;&#305;n kaleleridir.</span></p><p><span>Bir &#252;lkenin veri merkezleri ne kadar g&#252;&#231;l&#252;, g&#252;venli ve ba&#287;&#305;ms&#305;zsa dijital egemenli&#287;i de o kadar g&#252;&#231;l&#252;d&#252;r.</span></p><p></p><h3><strong><span>Hesaplama G&#252;c&#252;</span></strong></h3><blockquote><p><strong><span>Yapay Zeka &#231;a&#287;&#305;nda yeni stratejik kaynak hi&#231; &#351;&#252;phesiz &#8216;Hesaplama G&#252;c&#252;&#8217; olarak tan&#305;mlanabilir.</span></strong></p></blockquote><p><span>Ve bu noktada yapay zeka &#231;a&#287;&#305;nda veri merkezlerinin &#246;nemi daha da artm&#305;&#351;t&#305;r demek m&#252;mk&#252;nd&#252;r. </span></p><p><span>Nitekim b&#252;y&#252;k yapay zeka modelleri yaln&#305;zca veriye de&#287;il, devasa hesaplama g&#252;c&#252;ne ihtiya&#231; duyar.</span></p><p><span>GPU k&#252;meleri, y&#252;ksek performansl&#305; a&#287;lar, &#246;zel so&#287;utma sistemleri ve kesintisiz enerji altyap&#305;s&#305; yapay zeka rekabetinin temel unsurlar&#305; haline gelmi&#351;tir.</span></p><p><span>Bu noktada yeni bir jeopolitik denklem ortaya &#231;&#305;kmaktad&#305;r!</span></p><p><strong><span>Kim daha fazla &#231;ipe sahipse, kim daha fazla enerji sa&#287;layabiliyorsa, kim daha b&#252;y&#252;k veri merkezleri kurabiliyorsa, kim daha g&#252;venli ba&#287;lant&#305; altyap&#305;s&#305;na sahipse, yapay zeka &#231;a&#287;&#305;nda daha fazla stratejik avantaja sahip olacakt&#305;r.</span></strong></p><p><span>Bu nedenle veri merkezleri, yapay zeka rekabetinin g&#246;r&#252;nmeyen cephelerinden biridir!</span></p><p></p><h3><strong><span>Enerji Ba&#287;&#305;ml&#305;l&#305;&#287;&#305;</span></strong></h3><blockquote><p><strong>Bir di&#287;er konu ise &#8216;<span>Enerji Ba&#287;&#305;ml&#305;l&#305;&#287;&#305;&#8217; d&#305;r.</span></strong><span> </span><strong><span>Bir ba&#351;ka ifade ile enerji ba&#287;&#305;ml&#305;l&#305;&#287;&#305; &#8216;Dijital G&#252;c&#252;n Zay&#305;f Karn&#305;&#8217;d&#305;r!  </span></strong></p></blockquote><p><span>Veri merkezleri &#231;ok b&#252;y&#252;k miktarda elektrik t&#252;ketir. Yapay zeka sistemleri b&#252;y&#252;d&#252;k&#231;e bu t&#252;ketim daha da artmaktad&#305;r.</span></p><p><span>Bu durum dijital altyap&#305;lar&#305; do&#287;rudan enerji g&#252;venli&#287;i meselesine ba&#287;lar.</span></p><p><span>Bir &#252;lkenin veri merkezi stratejisi yaln&#305;zca teknoloji politikas&#305; de&#287;ildir. Ayn&#305; zamanda enerji politikas&#305;d&#305;r.</span></p><p><span>Enerji arz&#305; istikrars&#305;z olan, elektrik &#351;ebekesi zay&#305;f olan veya yenilenebilir enerji kapasitesini do&#287;ru planlayamayan &#252;lkeler, yapay zeka ve bulut bili&#351;im yar&#305;&#351;&#305;nda geride kalabilir.</span></p><p><span>Bu nedenle gelece&#287;in dijital g&#252;&#231; haritas&#305; yaln&#305;zca fiber kablolarla de&#287;il, enerji santralleri, &#351;ebeke kapasitesi, su kaynaklar&#305; ve so&#287;utma teknolojileriyle de belirlenecektir.</span></p><p></p><h3><strong><span>Su Meselesi</span></strong></h3><blockquote><p><strong><span>&#8216;Veri Merkezleri&#8217; ve &#8216;Su Meselesi&#8217; bir ba&#351;ka &#246;nemli konu olarak kar&#351;&#305;m&#305;za &#231;&#305;kmaktad&#305;r!</span></strong></p></blockquote><p><span>Veri merkezleri yaln&#305;zca elektrik de&#287;il, baz&#305; mimarilerde ciddi miktarda su da t&#252;ketebilir. &#214;zellikle so&#287;utma sistemlerinde su kullan&#305;m&#305;, yerel halk ve &#231;evre politikalar&#305; a&#231;&#305;s&#305;ndan tart&#305;&#351;malara yol a&#231;maktad&#305;r.</span></p><p><span>Bu nedenle veri merkezi yat&#305;r&#305;mlar&#305; art&#305;k bir&#231;ok &#252;lkede yaln&#305;zca ekonomik kalk&#305;nma projesi olarak g&#246;r&#252;lmemektedir. Yerel halk, &#231;evre kurulu&#351;lar&#305; ve kamu otoriteleri;</span></p><p><strong><span>Bu tesis ne kadar elektrik t&#252;ketecek?<br>Su kaynaklar&#305;na etkisi ne olacak?<br>Yerel elektrik fiyatlar&#305;n&#305; art&#305;racak m&#305;?<br>Ka&#231; ki&#351;iye istihdam sa&#287;layacak?<br>Vergi te&#351;vikleri ger&#231;ekten kamu yarar&#305;na m&#305;?<br>Ulusal g&#252;venlik a&#231;&#305;s&#305;ndan nas&#305;l korunacak?</span></strong></p><p>gibi sorular&#305; g&#252;n&#252;m&#252;zde daha fazla sormaktad&#305;r:</p><p><span>Bu sorular, veri merkezlerinin art&#305;k teknik tesisler de&#287;il, toplumsal ve politik tart&#305;&#351;ma alanlar&#305; haline geldi&#287;ini g&#246;stermektedir.</span></p><p></p><h3><strong><span>Bulut Sa&#287;lay&#305;c&#305;lar</span></strong></h3><blockquote><p><strong><span>&#8216;Bulut Sa&#287;lay&#305;c&#305;lar&#305;&#8217; ve &#8216;Dijital Egemenlik&#8217; konusu da hi&#231; &#351;&#252;phesiz ele almam&#305;z gereken konulardan biridir.</span></strong></p></blockquote><p><span>Bug&#252;n k&#252;resel bulut pazar&#305;nda az say&#305;da b&#252;y&#252;k teknoloji &#351;irketi belirleyici konumdad&#305;r. </span></p><p><span>Bu &#351;irketler yaln&#305;zca ticari hizmet sa&#287;lay&#305;c&#305;lar&#305; de&#287;ildir, ayn&#305; zamanda devletlerin, ordular&#305;n, bankalar&#305;n, sa&#287;l&#305;k sistemlerinin ve kritik altyap&#305;lar&#305;n dijital omurgas&#305;n&#305; ta&#351;&#305;yan yap&#305;lard&#305;r.</span></p><p><span>Bu durum &#246;nemli bir soruyu g&#252;ndeme getirir:<br>Bir &#252;lkenin kritik verileri ba&#351;ka bir &#252;lkenin teknoloji &#351;irketlerinin altyap&#305;s&#305;nda tutuluyorsa, o &#252;lkenin dijital egemenli&#287;i ne kadar g&#252;&#231;l&#252;d&#252;r?</span></p><p><span>Bu soru &#246;zellikle kamu bulutu, savunma sanayisi, sa&#287;l&#305;k verileri, finansal kay&#305;tlar ve kritik altyap&#305; sistemleri a&#231;&#305;s&#305;ndan hayati &#246;nemdedir.</span></p><p><span>Veri egemenli&#287;i art&#305;k yaln&#305;zca &#8220;</span><strong><span>veri nerede saklan&#305;yor?</span></strong><span>&#8221; sorusuyla s&#305;n&#305;rl&#305; de&#287;ildir.</span></p><p><strong><span>Veriye kim eri&#351;ebilir?<br>Veri hangi hukuk sistemine tabidir?<br>Altyap&#305;y&#305; kim i&#351;letir?<br>&#350;ifreleme anahtarlar&#305; kimdedir?<br>Yedekleme hangi &#252;lkededir?<br>Kriz an&#305;nda hizmeti kim durdurabilir?<br>Yapt&#305;r&#305;m d&#246;nemlerinde eri&#351;im nas&#305;l etkilenir?</span></strong></p><p><span>gibi sorular&#305;n cevaplar&#305; &#252;lkelerin dijital ba&#287;&#305;ms&#305;zl&#305;k kapasitesini belirler niteliktedir. </span></p><p></p><h3><strong><span>Denizalt&#305; Kablolar&#305; ve &#304;stihbarat</span></strong></h3><blockquote><p><strong><span>Denizalt&#305; kablolar&#305; yaln&#305;zca ileti&#351;im altyap&#305;s&#305; de&#287;ildir. Ayn&#305; zamanda istihbarat a&#231;&#305;s&#305;ndan da y&#252;ksek de&#287;er ta&#351;&#305;yan yap&#305;lard&#305;r.</span></strong></p></blockquote><p><span>Nitekim k&#252;resel veri ak&#305;&#351;&#305; bu kablolar &#252;zerinden ge&#231;er. </span></p><p><span>Bu ak&#305;&#351;&#305;n nereden ge&#231;ti&#287;i, hangi &#252;lkeleri ba&#287;lad&#305;&#287;&#305;, hangi &#351;irketler taraf&#305;ndan i&#351;letildi&#287;i ve hangi noktalarda karaya &#231;&#305;kt&#305;&#287;&#305; stratejik &#246;neme sahiptir.</span></p><p><span>Tarih boyunca ileti&#351;im hatlar&#305; istihbarat faaliyetlerinin hedefi olmu&#351;tur. </span></p><p><span>Telgraf hatlar&#305;ndan telefon santrallerine, uydu ba&#287;lant&#305;lar&#305;ndan fiber optik kablolara kadar ileti&#351;im altyap&#305;s&#305; her zaman devletlerin ve devletlere ba&#287;l&#305; istihbarat &#246;rg&#252;tlerinin ilgi alan&#305;nda olmu&#351;tur.</span></p><p><span>G&#252;n&#252;m&#252;zde de denizalt&#305; kablolar&#305;;</span></p><p><strong><span>Trafik analizi,<br>Sinyal istihbarat&#305;,<br>Veri ak&#305;&#351; haritalama,<br>Kriz d&#246;nemlerinde kesinti riski,<br>Stratejik ba&#287;&#305;ml&#305;l&#305;k analizi</span></strong></p><p><span>a&#231;&#305;s&#305;ndan &#246;nem ta&#351;&#305;r.</span></p><p><span>Bu nedenle kablo g&#252;zergahlar&#305; teknik haritalar olmaktan &#231;&#305;k&#305;p jeopolitik haritalara d&#246;n&#252;&#351;mektedir.</span></p><p></p><h3><strong><span>Kritik Bo&#287;azlar ve Dijital Co&#287;rafya</span></strong></h3><blockquote><p><strong><span>D&#252;nya ticaretinde Malakka Bo&#287;az&#305;, H&#252;rm&#252;z Bo&#287;az&#305;, S&#252;vey&#351; Kanal&#305; ve T&#252;rk Bo&#287;azlar&#305; nas&#305;l stratejik &#246;neme sahipse, dijital d&#252;nyada da baz&#305; kablo ge&#231;i&#351; noktalar&#305; ayn&#305; &#351;ekilde kritik hale gelmektedir.</span></strong></p></blockquote><p><span>Kablolar&#305;n yo&#287;unla&#351;t&#305;&#287;&#305; bo&#287;azlar, k&#305;y&#305; &#252;lkeleri, ada devletleri ve veri merkezi k&#252;melenmeleri dijital jeopoliti&#287;in yeni d&#252;&#287;&#252;m noktalar&#305;d&#305;r.</span></p><p><span>Bu noktalar hem ekonomik de&#287;er ta&#351;&#305;r hem de kriz anlar&#305;nda k&#305;r&#305;lganl&#305;k yarat&#305;r.</span></p><p><span>Gelece&#287;in jeopolitik haritalar&#305; yaln&#305;zca petrol boru hatlar&#305;n&#305; de&#287;il, fiber optik kablo rotalar&#305;n&#305; ve veri merkezi k&#252;melerini de g&#246;stermek zorunda kalacakt&#305;r.</span></p><p></p><h3><strong><span>Hibrit Sava&#351; ve Dijital Altyap&#305;</span></strong></h3><blockquote><p><strong><span>Hibrit sava&#351;, askeri ve askeri olmayan y&#246;ntemlerin birlikte kullan&#305;ld&#305;&#287;&#305; &#231;at&#305;&#351;ma bi&#231;imidir.</span></strong><span> </span></p></blockquote><p><span>Bu yakla&#351;&#305;mda siber sald&#305;r&#305;lar, dezenformasyon, ekonomik bask&#305;, enerji kesintileri, sabotajlar ve diplomatik bask&#305;lar ayn&#305; stratejinin par&#231;alar&#305; olabilir.</span></p><p><strong><span>Denizalt&#305; kablolar&#305; ve veri merkezleri hibrit sava&#351; a&#231;&#305;s&#305;ndan cazip hedeflerdir. </span></strong></p><p><strong><span>Nitekim bu yap&#305;lara verilecek zarar, do&#287;rudan askeri sald&#305;r&#305; say&#305;lmadan b&#252;y&#252;k ekonomik ve toplumsal etki yaratabilir.</span></strong></p><p><strong><span>Bir &#252;lkenin internet ba&#287;lant&#305;s&#305;n&#305; yava&#351;latmak, finansal i&#351;lem kapasitesini etkilemek, bulut servislerini kesintiye u&#287;ratmak veya veri merkezi operasyonlar&#305;n&#305; hedef almak, modern toplumlarda ciddi sonu&#231;lar do&#287;urabilir.</span></strong></p><p><span>Bu nedenle dijital altyap&#305; g&#252;venli&#287;i art&#305;k sadece siber g&#252;venlik ekiplerinin g&#246;revi de&#287;ildir.</span></p><p><strong><span>Bu konu ulusal g&#252;venlik, deniz g&#252;venli&#287;i, enerji g&#252;venli&#287;i, istihbarat, hukuk ve diplomasi alanlar&#305;n&#305;n birlikte ele almas&#305; gereken stratejik bir meseledir.</span></strong></p><p></p><h3><strong> (OT) <span>Operasyonel Teknolojiler G&#252;venli&#287;i ile Ba&#287;lant&#305;</span></strong></h3><blockquote><p><strong><span>Denizalt&#305; kablolar&#305; ve veri merkezleri konusunun (OT) </span>Operasyonel Teknolojiler<span> g&#252;venli&#287;i ile de g&#252;&#231;l&#252; bir ba&#287;lant&#305;s&#305; vard&#305;r.</span></strong></p></blockquote><p><span>Veri merkezleri yaln&#305;zca (IT) Bilgi Teknolojileri sistemlerinden olu&#351;maz. &#304;&#231;lerinde enerji da&#287;&#305;t&#305;m sistemleri, jenerat&#246;rler, UPS sistemleri, so&#287;utma altyap&#305;s&#305;, yang&#305;n alg&#305;lama sistemleri, fiziksel g&#252;venlik sistemleri, bina otomasyon sistemleri ve &#231;evresel izleme &#231;&#246;z&#252;mleri bulunur.</span></p><p><span>Bu sistemlerin b&#252;y&#252;k b&#246;l&#252;m&#252; operasyonel teknoloji bile&#351;enleriyle ili&#351;kilidir.</span></p><p><span>Bir veri merkezinin siber g&#252;venli&#287;i yaln&#305;zca firewall, EDR, IPS veya SIEM ile sa&#287;lanamaz.</span></p><p><span>Ayn&#305; zamanda;</span></p><p><strong><span>Enerji s&#252;reklili&#287;i,<br>So&#287;utma sistemleri,<br>Bina otomasyonu,<br>Fiziksel eri&#351;im kontrol&#252;,<br>Tedarik zinciri g&#252;venli&#287;i,<br>Yedeklilik mimarisi,<br>Felaket kurtarma planlar&#305;</span></strong></p><p><span>birlikte de&#287;erlendirilmelidir.</span></p><p><strong><span>Bu nedenle veri merkezleri, IT ve OT g&#252;venli&#287;inin kesi&#351;ti&#287;i en kritik alanlardan biridir.</span></strong></p><p></p><h3><strong><span>Dijital &#304;mparatorluklar</span></strong></h3><blockquote><p><strong><span>Ge&#231;mi&#351;te imparatorluklar deniz yollar&#305;n&#305;, limanlar&#305;, kaleleri ve ticaret merkezlerini kontrol ederek g&#252;&#231; sahibi oluyordu.</span></strong></p></blockquote><p><span>Bug&#252;n ise dijital imparatorluklar denizalt&#305; kablolar&#305;n&#305;, veri merkezlerini, bulut platformlar&#305;n&#305;, i&#351;letim sistemlerini, yapay zeka altyap&#305;lar&#305;n&#305; ve veri ak&#305;&#351;lar&#305;n&#305; kontrol ederek g&#252;&#231; kazan&#305;yor.</span></p><p><strong><span>Bu yeni g&#252;&#231; bi&#231;imi daha sessizdir.<br>S&#305;n&#305;rlar&#305; haritalarda g&#246;r&#252;nmez.<br>Askeri &#252;niforma ta&#351;&#305;maz.<br>Ancak etkisi son derece derindir.</span></strong></p><p><span>Bir &#252;lkenin dijital altyap&#305;s&#305; ba&#351;ka akt&#246;rlere ba&#287;&#305;ml&#305; hale geldi&#287;inde, ekonomik ve siyasi karar alma kapasitesi de dolayl&#305; olarak etkilenebilir.</span></p><p><strong><span>Bu nedenle dijital &#231;a&#287;da ba&#287;&#305;ms&#305;zl&#305;k yaln&#305;zca toprak b&#252;t&#252;nl&#252;&#287;&#252;yle de&#287;il, veri egemenli&#287;i ve altyap&#305; dayan&#305;kl&#305;l&#305;&#287;&#305;yla da ilgilidir.</span></strong></p><p></p><h3><strong><span>T&#252;rkiye A&#231;&#305;s&#305;ndan Stratejik Okuma</span></strong></h3><blockquote><p><strong><span>T&#252;rkiye, co&#287;rafi konumu nedeniyle enerji, lojistik ve ileti&#351;im hatlar&#305; a&#231;&#305;s&#305;ndan do&#287;al bir ge&#231;i&#351; merkezidir.</span></strong><span> </span></p></blockquote><p><span>Avrupa, Asya, Orta Do&#287;u, Kafkasya ve Akdeniz aras&#305;nda yer alan T&#252;rkiye, dijital altyap&#305; a&#231;&#305;s&#305;ndan da &#246;nemli bir merkez olma potansiyeline sahiptir.</span></p><p><span>Bu potansiyelin stratejik de&#287;ere d&#246;n&#252;&#351;mesi i&#231;in yaln&#305;zca veri merkezi yat&#305;r&#305;mlar&#305; yeterli de&#287;ildir.</span></p><p><span>Ayn&#305; zamanda;</span></p><p><strong><span>G&#252;&#231;l&#252; fiber omurga,<br>G&#252;venli denizalt&#305; kablo ba&#287;lant&#305;lar&#305;,<br>Yerli veri merkezi kapasitesi,<br>Bulut egemenli&#287;i stratejisi,<br>Kritik altyap&#305; g&#252;venli&#287;i,<br>OT/ICS g&#252;venlik standartlar&#305;,<br>Enerji s&#252;reklili&#287;i,<br>Siber savunma kapasitesi,<br>Ulusal veri politikalar&#305;</span></strong></p><p><span>birlikte ele al&#305;nmal&#305;d&#305;r.</span></p><p><span>T&#252;rkiye i&#231;in dijital altyap&#305; politikas&#305;, yaln&#305;zca teknoloji yat&#305;r&#305;m&#305; de&#287;il, jeopolitik konumun dijital &#231;a&#287;a uyarlanmas&#305; anlam&#305;na gelir.</span></p><p><strong><span>Ancak hi&#231; &#351;&#252;phesiz her &#252;lke gibi T&#252;rkiye&#8217;nin de kendi milli teknolojilerini &#252;retmesi ka&#231;&#305;n&#305;lmaz bir gerekliliktir.</span></strong></p><p><span>Aksi halde salt &#8216;Veri Merkezi bina sahipli&#287;i&#8217; ya da &#8216;Fiber Omurga ge&#231;i&#351; g&#252;zergah&#305;&#8217; olma durumu ka&#231;&#305;n&#305;lmazd&#305;r.  </span></p><p></p><h3><strong>Mavi Vatan&#8217;&#305;n Yeni Boyutu</strong> </h3><blockquote><p><strong>Mavi Vatan, T&#252;rkiye&#8217;nin &#231;evre denizlerdeki hak ve menfaatlerini, deniz yetki alanlar&#305;n&#305;, ekonomik &#231;&#305;karlar&#305;n&#305; ve deniz g&#252;venli&#287;ini korumaya y&#246;nelik stratejik bir doktrindir.</strong></p></blockquote><p>Bug&#252;ne kadar Mavi Vatan tart&#305;&#351;malar&#305; daha &#231;ok;</p><p><strong>M&#252;nhas&#305;r Ekonomik B&#246;lge (MEB)<br>Enerji kaynaklar&#305;<br>Deniz ticaret yollar&#305;<br>Deniz kuvvetleri<br>Deniz g&#252;venli&#287;i </strong></p><p>gibi &#231;er&#231;evelerde y&#252;r&#252;t&#252;lm&#252;&#351;t&#252;r.</p><p>Ancak dijital &#231;a&#287;da denizlerin alt&#305;nda yeni bir stratejik unsur daha bulunmaktad&#305;r: <strong>Denizalt&#305; fiber optik kablolar&#305;.</strong></p><p>Bu ba&#287;lamda &#8216;<strong>Dijital Mavi Vatan&#8217; </strong>yakla&#351;&#305;m&#305;;</p><p><strong>Denizalt&#305; fiber optik kablolar&#305;n&#305;n korunmas&#305;,<br>Veri koridorlar&#305;n&#305;n g&#252;venli&#287;i,<br>Kritik ileti&#351;im altyap&#305;lar&#305;n&#305;n dayan&#305;kl&#305;l&#305;&#287;&#305;,<br>Deniz taban&#305;ndaki dijital varl&#305;klar&#305;n izlenmesi,<br>Denizalt&#305; sens&#246;r a&#287;lar&#305;,<br>Otonom deniz sistemleri,</strong></p><p>gibi konular&#305; kapsayabilir.</p><p>Nas&#305;l ki bir &#252;lke enerji hatlar&#305;n&#305; koruyorsa, gelecekte veri hatlar&#305;n&#305; da korumak zorunda kalacakt&#305;r !</p><p><strong>Yirminci y&#252;zy&#305;lda denizlerin alt&#305;nda petrol ve do&#287;al gaz aran&#305;yordu. <br>Yirmibirinci y&#252;zy&#305;lda ise denizlerin alt&#305;nda verinin akt&#305;&#287;&#305; g&#246;r&#252;nmez otoyollar bulunmakta.</strong></p><p><strong>Mavi Vatan</strong>'&#305;n gelece&#287;i yaln&#305;zca enerji kaynaklar&#305;n&#305;n korunmas&#305;yla de&#287;il, dijital d&#252;nyan&#305;n sinir sistemi haline gelen denizalt&#305; kablolar&#305;n&#305;n g&#252;venli&#287;iyle de &#351;ekillenecektir. </p><p><strong>Nitekim gelece&#287;in jeopoliti&#287;inde veriyi ta&#351;&#305;yan hatlar, enerji hatlar&#305; kadar stratejik hale gelmektedir.</strong></p><p></p><h3><strong>Sonu&#231;</strong></h3><p>Dijital d&#252;nya sand&#305;&#287;&#305;m&#305;z kadar g&#246;r&#252;nmez de&#287;ildir. &#304;nternetin, bulutun ve yapay zek&#226;n&#305;n arkas&#305;nda son derece fiziksel ve k&#305;r&#305;lgan bir altyap&#305; vard&#305;r.</p><p><strong>Denizalt&#305; kablolar&#305; veriyi ta&#351;&#305;r.<br>Veri merkezleri veriyi i&#351;ler.<br>Enerji altyap&#305;s&#305; sistemi ayakta tutar.<br>Bulut sa&#287;lay&#305;c&#305;lar&#305; eri&#351;imi y&#246;netir.<br>Devletler ve &#351;irketler bu altyap&#305;lar &#252;zerinde stratejik rekabet y&#252;r&#252;t&#252;r.</strong></p><p>Bu nedenle 21. y&#252;zy&#305;l&#305;n jeopolitik m&#252;cadelesi yaln&#305;zca kara, deniz, hava, uzay ve siber alanda ya&#351;anm&#305;yor.</p><p><strong>Yeni cephelerden biri de dijital altyap&#305;n&#305;n kendisidir.</strong></p><p>Gelecekte g&#252;&#231;, yaln&#305;zca en b&#252;y&#252;k ordulara veya en zengin enerji kaynaklar&#305;na sahip olanlar&#305;n elinde olmayacak.</p><p><strong>Verinin ge&#231;ti&#287;i yollar&#305;, i&#351;lendi&#287;i merkezleri ve korundu&#287;u altyap&#305;lar&#305; y&#246;netenler de k&#252;resel g&#252;&#231; dengesinde belirleyici rol oynayacak.</strong></p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br><span>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,</span><br><span>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,</span><br><span>CompTIA Project+ Professional,</span><br><span>CIW Security Analyst,</span><br><span>Certified Cyber Threat Intelligence Analyst,</span><br><span>Certified Information Security Executive&#8482;,</span><br><span>Senior Certified Leadership Practitioner</span></p><p></p><h3><strong>Kaynak&#231;a:</strong></h3><ul><li><p><strong>Cem G&#252;rdeniz</strong> (2020). <em>Mavi Vatan&#8217;&#305;n G&#252;ney Cephesi: Do&#287;u Akdeniz</em>. Panku&#351; Yay&#305;nlar&#305;.</p></li><li><p><strong>Mavi Vatan Geopolitics (Cem G&#252;rdeniz Substack)</strong> G&#252;ncel deniz jeopoliti&#287;i, deniz yetki alanlar&#305; ve Mavi Vatan yakla&#351;&#305;m&#305;na ili&#351;kin analizler.</p></li><li><p><strong><span>Lawfare</span></strong><span> &#8211; Undersea Cables and the Material Politics of Digital Connectivity, Denizalt&#305; kablolar&#305;n&#305;n g&#252;venlik, egemenlik ve jeopolitik boyutlar&#305;.</span></p></li><li><p><strong><span>The Arctic Institute</span></strong><span> &#8211; Geopolitics of Subsea Cables in the Arctic, <br>Denizalt&#305; kablolar&#305;n&#305;n jeopolitik rekabet i&#231;indeki rol&#252;.</span></p></li></ul><h4></h4><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[ISO 22301 & IEC 62443: (OT) Operasyonel Teknoloji'de Sürekliliğin ve Güvenliğin Mimarisi ve Kesişimi]]></title><description><![CDATA[Thanks for reading Ziya's Substack!]]></description><link>https://ziyagokalp.substack.com/p/iso-22301-and-iec-62443-ot-operasyonel</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/iso-22301-and-iec-62443-ot-operasyonel</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Tue, 09 Jun 2026 09:38:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!tc5f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F045d1d2b-5fd3-4e0c-a5cc-668db206ec99_1536x1024.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tc5f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F045d1d2b-5fd3-4e0c-a5cc-668db206ec99_1536x1024.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tc5f!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F045d1d2b-5fd3-4e0c-a5cc-668db206ec99_1536x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!tc5f!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F045d1d2b-5fd3-4e0c-a5cc-668db206ec99_1536x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!tc5f!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F045d1d2b-5fd3-4e0c-a5cc-668db206ec99_1536x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!tc5f!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F045d1d2b-5fd3-4e0c-a5cc-668db206ec99_1536x1024.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tc5f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F045d1d2b-5fd3-4e0c-a5cc-668db206ec99_1536x1024.heic" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/045d1d2b-5fd3-4e0c-a5cc-668db206ec99_1536x1024.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:269276,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/194605580?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F045d1d2b-5fd3-4e0c-a5cc-668db206ec99_1536x1024.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tc5f!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F045d1d2b-5fd3-4e0c-a5cc-668db206ec99_1536x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!tc5f!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F045d1d2b-5fd3-4e0c-a5cc-668db206ec99_1536x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!tc5f!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F045d1d2b-5fd3-4e0c-a5cc-668db206ec99_1536x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!tc5f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F045d1d2b-5fd3-4e0c-a5cc-668db206ec99_1536x1024.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Giri&#351;</h1><p>Modern <strong>OT (Operasyonel Teknoloji)</strong> sistemlerinde <strong>en kritik risk, bir sald&#305;r&#305;ya u&#287;ramak de&#287;il, sistemin &#231;al&#305;&#351;amaz hale gelmesidir.</strong> </p><p>Nitekim <strong>OT (Operasyonel Teknoloji)</strong> d&#252;nyas&#305;nda kesinti, yaln&#305;zca dijital bir problem de&#287;il, <strong>do&#287;rudan fiziksel sonu&#231;lar &#252;reten bir k&#305;r&#305;lmad&#305;r</strong>. </p><p><strong>&#220;retim hatlar&#305;n&#305;n durmas&#305;, enerji da&#287;&#305;t&#305;m&#305;n&#305;n kesilmesi</strong> ya da <strong>kritik altyap&#305;lar&#305;n devre d&#305;&#351;&#305; kalmas&#305;</strong>, bu kesintinin do&#287;rudan yans&#305;malar&#305;d&#305;r.</p><p>Bu nedenle <strong>OT (Operasyonel Teknoloji) sistemlerinde g&#252;venlik yakla&#351;&#305;m&#305; tek ba&#351;&#305;na yeterli de&#287;ildir.</strong> </p><p>Hi&#231;bir sistem tamamen g&#252;venli de&#287;ildir ve hi&#231;bir savunma modeli kesintiyi mutlak olarak engelleyemez !</p><p>Bu ger&#231;eklik, temel sorunun de&#287;i&#351;mesine neden olur:</p><blockquote><p><strong>&#8220;Sald&#305;r&#305; olacak m&#305;?&#8221; de&#287;il,</strong><br><strong>&#8220;Sald&#305;r&#305; oldu&#287;unda sistem ne kadar s&#252;re ayakta kalabilecek?&#8221;</strong></p></blockquote><p>Bu sorunun cevab&#305;, iki kritik yakla&#351;&#305;m&#305;n kesi&#351;iminde yer al&#305;r:<br><strong>ISO 22301</strong> ve <strong>IEC 62443</strong>.</p><ul><li><p><strong>ISO 22301 - </strong>B<strong>usiness Continuity Management System (BCMS), <br></strong>T&#252;rk&#231;esi<strong> &#8220;&#304;&#351; S&#252;reklili&#287;i Y&#246;netim Sistemi&#8221; </strong>olarak tan&#305;mlan&#305;rken<strong>,<br></strong></p></li><li><p><strong>IEC 62443 - Standards for Securing Industrial Automation and Control Systems, </strong>T&#252;rk&#231;esi &#8220;<strong>End&#252;striyel Otomasyon ve Kontrol Sistemlerinin G&#252;venli&#287;ini Sa&#287;lama Standartlar&#305;</strong>&#8221;<strong>  </strong>olarak tan&#305;mlanmaktad&#305;r.</p></li></ul><p>A&#351;a&#287;&#305;da k&#305;saca bu iki standard&#305; analiz edelim. </p><p></p><h1>ISO 22301 ve IEC 62443 Nedir?</h1><p><strong>ISO 22301</strong>, <strong>organizasyonlar&#305;n kesintilere kar&#351;&#305; haz&#305;rl&#305;kl&#305; olmas&#305;n&#305;, bu kesintilere yan&#305;t vermesini ve operasyonlar&#305;n&#305; s&#252;rd&#252;rebilir hale getirmesini sa&#287;layan bir <br>&#8221;&#304;&#351; S&#252;reklili&#287;i Y&#246;netim Sistemi&#8221; Standard&#305;d&#305;r.</strong> Bu yakla&#351;&#305;m, s&#252;reklili&#287;i bir sonu&#231; de&#287;il, &#246;nceden tasarlanm&#305;&#351; bir kapasite olarak ele al&#305;r.</p><p><strong>IEC 62443</strong> ise &#8220;<strong>End&#252;striyel Kontrol Sistemlerinin Siber G&#252;venli&#287;i&#8221;</strong>ni sa&#287;layan kapsaml&#305; bir standartlar ailesidir. <strong>Bu standart, sistemlerin nas&#305;l korunaca&#287;&#305;n&#305;, nas&#305;l segmentlere ayr&#305;laca&#287;&#305;n&#305; ve hangi g&#252;venlik seviyelerinde i&#351;letilece&#287;ini tan&#305;mlar.</strong></p><p>Bu iki standart farkl&#305; sorulara cevap verir:</p><ul><li><p><strong>IEC 62443 &#8594; Sistem nas&#305;l korunur?</strong></p></li><li><p><strong>ISO 22301 &#8594; Sistem nas&#305;l &#231;al&#305;&#351;maya devam eder?</strong></p></li></ul><blockquote><p>Bu durum, <strong>OT (Operasyonel Teknoloji) sistemlerinde g&#252;venlik ve s&#252;reklili&#287;in birbirinden ayr&#305; de&#287;il, birbirini tamamlayan yap&#305;lar oldu&#287;unu ortaya koyar.</strong></p></blockquote><p></p><h1>Riskten S&#252;reklili&#287;e ve G&#252;venli&#287;e</h1><p>Geleneksel yakla&#351;&#305;mda g&#252;venlik ve s&#252;reklilik ayr&#305; disiplinler olarak ele al&#305;nm&#305;&#351;t&#305;r. </p><blockquote><p><strong>G&#252;venlik, tehditleri engellemeye odaklan&#305;rken, <br>S&#252;reklilik, kesinti sonras&#305; toparlanmay&#305; hedefler.</strong></p></blockquote><p>Ancak <strong>OT sistemlerinde</strong> bu ayr&#305;m <strong>ge&#231;erlili&#287;ini yitirir.</strong> </p><p>Nitekim bir g&#252;venlik ihlali &#231;o&#287;u zaman do&#287;rudan kesinti &#252;retir. <br><strong>Bu nedenle &#8220;g&#252;venlik&#8221; ve &#8220;s&#252;reklilik&#8221; ayn&#305; problemin iki farkl&#305; boyutu haline gelir.</strong></p><ul><li><p><strong>IEC 62443, sistemin sald&#305;r&#305;ya u&#287;ramas&#305;n&#305; zorla&#351;t&#305;r&#305;r.</strong></p><p><strong>A&#287; segmentasyonu, g&#252;venlik seviyeleri ve eri&#351;im kontrolleri ile tehdit y&#252;zeyini azalt&#305;r. </strong></p></li><li><p><strong>ISO 22301 ise bu sald&#305;r&#305;n&#305;n ka&#231;&#305;n&#305;lmaz oldu&#287;u varsay&#305;m&#305;ndan hareket eder ve sistemin bu ko&#351;ullar alt&#305;nda nas&#305;l &#231;al&#305;&#351;maya devam edece&#287;ini tan&#305;mlar.</strong></p></li></ul><p>Bu birle&#351;im, <strong>OT sistemlerinde</strong> yeni bir yakla&#351;&#305;m do&#287;urur:</p><blockquote><p><strong>Ama&#231; yaln&#305;zca sistemi korumak de&#287;il,</strong><br><strong>korunan sistemin potansiyel bir sorunda &#231;al&#305;&#351;maya devam etmesini sa&#287;lamakt&#305;r !</strong></p></blockquote><p></p><h1>BIA, Security Levels ve Mimari Yakla&#351;&#305;m</h1><p><strong>ISO 22301</strong>&#8217;in <strong>Business Impact Analysis (BIA)</strong> yakla&#351;&#305;m&#305;, hangi s&#252;re&#231;lerin kritik oldu&#287;unu ve bu s&#252;re&#231;lerin ne kadar s&#252;re kesintiye dayanabilece&#287;ini belirler. <br>T&#252;rk&#231;e ifade ile &#8220;<strong>&#304;&#351; Etki Analizi</strong>&#8221; olarak kabul edebiliriz.<br><br>Bu analiz sonucunda <strong>RTO (Recovery Time Objective)</strong> ve <br><strong>RPO (Recovery Point Objective)</strong> gibi &#246;l&#231;&#252;lebilir hedefler ortaya konur. <br>(<strong>RTO-Kurtarma S&#252;resi Hedefi</strong> ve <strong>RPO-Kurtarma Noktas&#305; Hedefi</strong> olarak &#231;evirebiliriz). </p><p><strong>IEC 62443</strong> ise <strong>Security Level (SL)</strong> kavram&#305; (<strong>G&#252;venlik Seviyesi</strong>) ile sistemin hangi tehdit seviyesine kar&#351;&#305; korunmas&#305; gerekti&#287;ini tan&#305;mlar. <br>Ayn&#305; zamanda &#8220;<strong>Zones &amp; Conduits</strong>&#8221; modeli ile sistemin mimari olarak nas&#305;l segmentlere ayr&#305;laca&#287;&#305;n&#305; belirler (<strong>B&#246;lgeler ve Kanallar</strong>).</p><p>Bu iki yakla&#351;&#305;m birle&#351;ti&#287;inde:</p><ul><li><p><strong>BIA (Business Impact Analysis)</strong> &#8594; <strong>Hangi sistem kritik</strong></p></li><li><p><strong>SL (Security Level)</strong> &#8594; <strong>Ne kadar korunmal&#305;</strong></p></li><li><p><strong>Zones</strong> &#8594; <strong>Nerede korunmal&#305;</strong></p></li><li><p><strong>Conduits</strong> &#8594; <strong>Nas&#305;l eri&#351;ilmeli</strong></p></li></ul><p>Sorular&#305;na birlikte cevap verilir.</p><p>Bu da <strong>OT g&#252;venli&#287;ini</strong> yaln&#305;zca teknik bir kontrol seti olmaktan &#231;&#305;kar&#305;r ve onu <strong>&#246;l&#231;&#252;lebilir, tasarlanabilir bir mimari yap&#305; </strong>haline getirir.</p><p></p><h1>OT Sistemlerinde S&#252;reklilik ve G&#252;venlik Ger&#231;ekli&#287;i</h1><p><strong>OT ortamlar&#305;nda</strong> teorik modeller, &#231;o&#287;u zaman pratik s&#305;n&#305;rlamalarla kar&#351;&#305;la&#351;&#305;r. <br><strong>Legacy sistemler</strong>, <strong>eski protokoller</strong> ve <strong>y&#252;ksek eri&#351;ilebilirlik gereksinimleri</strong>, modern g&#252;venlik yakla&#351;&#305;mlar&#305;n&#305;n <strong>do&#287;rudan uygulanmas&#305;n&#305; zorla&#351;t&#305;r&#305;r.</strong></p><p>Bir&#231;ok end&#252;striyel cihaz:</p><ul><li><p><strong>Kimlik do&#287;rulamay&#305; desteklemez</strong></p></li><li><p><strong>&#350;ifreleme kullanmaz</strong></p></li><li><p><strong>Kesintiye tolerans g&#246;stermez</strong></p></li></ul><p><strong>Bu nedenle &#8220;g&#252;venlik&#8221; ve &#8220;s&#252;reklilik&#8221;, sistemin i&#231;inde de&#287;il, sisteme eri&#351;im noktas&#305; baz al&#305;narak kurgulan&#305;r.</strong></p><p>Bu noktada kritik ger&#231;ek a&#351;a&#287;&#305;daki &#351;ekilde ifade edilebilir:</p><blockquote><p><strong>OT sistemlerinde g&#252;venlik, cihaz&#305; de&#287;i&#351;tirmekle de&#287;il,<br>cihaza nas&#305;l eri&#351;ildi&#287;ini de&#287;i&#351;tirmekle sa&#287;lan&#305;r.</strong></p></blockquote><p>Bu yakla&#351;&#305;m, <strong>IEC 62443&#8217;&#252;n mimari yap&#305;s&#305;</strong> ile <strong>ISO 22301&#8217;in s&#252;reklilik yakla&#351;&#305;m&#305;n&#305;</strong> ayn&#305; noktada bulu&#351;turur.</p><p></p><h1>Kriz An&#305;: Plan m&#305;, Refleks mi?</h1><p><strong>Kriz an&#305;, sistemlerin de&#287;il organizasyonlar&#305;n test edildi&#287;i and&#305;r. </strong></p><p><strong>Planlar y&#246;n g&#246;sterir</strong>, ancak kriz an&#305;nda belirleyici olan <strong>reflekslerdir.<br></strong> <br><strong>Nitekim belirsizlik ve zaman bask&#305;s&#305; alt&#305;nda insanlar prosed&#252;rlere de&#287;il, al&#305;&#351;kanl&#305;klar&#305;na g&#246;re hareket eder.</strong></p><p><strong>ISO 22301</strong> bu nedenle yaln&#305;zca plan &#252;retmeyi de&#287;il, organizasyonel refleksleri geli&#351;tirmeyi hedefler. Tatbikatlar ve senaryo &#231;al&#305;&#351;malar&#305; sayesinde kriz y&#246;netimi bir bilgi olmaktan &#231;&#305;kar, bir davran&#305;&#351; haline gelir.</p><p>OT sistemlerinde bu durum daha kritiktir. <strong>Nitekim al&#305;nan kararlar yaln&#305;zca dijital de&#287;il, fiziksel sonu&#231;lar do&#287;urur.</strong> </p><p>Bu nedenle h&#305;zl&#305;, do&#287;ru ve koordineli hareket etmek hayati &#246;nem ta&#351;&#305;r.</p><p></p><h1>Sonu&#231;: S&#252;reklilik ve G&#252;venli&#287;in Kesi&#351;imi</h1><p><strong>ISO 22301</strong> ve <strong>IEC 62443</strong> birlikte ele al&#305;nd&#305;&#287;&#305;nda, <strong>OT sistemlerinde g&#252;venli&#287;in anlam&#305; k&#246;kl&#252; bi&#231;imde de&#287;i&#351;ir.</strong> </p><blockquote><p><strong>G&#252;venlik art&#305;k yaln&#305;zca bir savunma mekanizmas&#305; de&#287;il, s&#252;reklili&#287;in &#246;n ko&#351;ulu, s&#252;reklilik ise g&#252;venli&#287;in ger&#231;ek s&#305;nav&#305; haline gelir.</strong> </p><p>Bu iki yakla&#351;&#305;m&#305;n kesi&#351;iminde ortaya &#231;&#305;kan model, sistemi &#8220;korunan bir yap&#305;&#8221; olmaktan &#231;&#305;kar&#305;r ve onu &#8220;<strong>kesinti alt&#305;nda dahi i&#351;levini s&#252;rd&#252;rebilen bir organizma&#8221;</strong> haline getirir.</p></blockquote><p><strong>IEC 62443</strong>, sistemi segmentlere ay&#305;rarak, eri&#351;imleri s&#305;n&#305;rland&#305;rarak ve tehdit y&#252;zeyini k&#252;&#231;&#252;lterek sald&#305;r&#305;n&#305;n ger&#231;ekle&#351;mesini zorla&#351;t&#305;r&#305;r. <br><br><strong>ISO 22301</strong> ise bu savunman&#305;n mutlak olmad&#305;&#287;&#305;n&#305; kabul eder ve ka&#231;&#305;n&#305;lmaz bir kesinti durumunda sistemin nas&#305;l tepki verece&#287;ini tan&#305;mlar. </p><blockquote><p>Bu iki yakla&#351;&#305;m birlikte d&#252;&#351;&#252;n&#252;ld&#252;&#287;&#252;nde, g&#252;venlik art&#305;k yaln&#305;zca &#8220;<strong>engelleme</strong>&#8221; de&#287;il, ayn&#305; zamanda <strong>kontroll&#252; devaml&#305;l&#305;k &#252;retme kapasitesi</strong> anlam&#305;na gelir.</p></blockquote><p></p><p><strong>Bu noktada kritik olan, bu iki yap&#305;n&#305;n birbirinden ba&#287;&#305;ms&#305;z uygulanmamas&#305;d&#305;r !</strong></p><blockquote><p><strong>G&#252;venlik kontrolleri s&#252;reklili&#287;i zedeledi&#287;inde, sistem teorik olarak daha g&#252;venli hale gelirken pratikte daha k&#305;r&#305;lgan hale gelebilir. </strong></p><p><strong>Benzer &#351;ekilde yaln&#305;zca s&#252;reklili&#287;e odaklanan bir yakla&#351;&#305;m, sistemi &#231;al&#305;&#351;&#305;r tutarken onu savunmas&#305;z b&#305;rakabilir.</strong> </p></blockquote><p>Bu nedenle do&#287;ru mimari, bu iki alan&#305; dengeleyen de&#287;il, onlar&#305; <strong>birbirine entegre eden</strong> bir yakla&#351;&#305;md&#305;r.</p><p><strong>OT sistemlerinde bu entegrasyon &#246;zellikle &#351;u alanlarda belirginle&#351;ir:</strong></p><ul><li><p><strong>Kritik s&#252;re&#231;lerin &#246;nceliklendirilmesi ve buna uygun g&#252;venlik seviyelerinin tan&#305;mlanmas&#305;</strong></p></li><li><p><strong>Eri&#351;imlerin yaln&#305;zca g&#252;venli de&#287;il, ayn&#305; zamanda s&#252;rd&#252;r&#252;lebilir olacak &#351;ekilde tasarlanmas&#305;</strong></p></li><li><p><strong>Segmentasyon yap&#305;s&#305;n&#305;n yaln&#305;zca izolasyon de&#287;il, kontroll&#252; ileti&#351;im &#252;retmesi</strong></p></li><li><p><strong>Kriz an&#305;nda devreye girecek alternatif operasyon modellerinin &#246;nceden tan&#305;mlanmas&#305;</strong></p></li></ul><blockquote><p><strong>Bu yap&#305;, g&#252;venli&#287;i statik bir kontrol listesi olmaktan &#231;&#305;kar&#305;r ve onu sistemin davran&#305;&#351;&#305;na g&#246;m&#252;l&#252; bir &#246;zellik haline getirir.</strong> </p><p>B&#246;ylece sistem yaln&#305;zca &#8220;<strong>korunan</strong>&#8221; de&#287;il, ayn&#305; zamanda <strong>kendi bozulma senaryolar&#305;n&#305; y&#246;netebilen</strong> bir yap&#305;ya d&#246;n&#252;&#351;&#252;r.</p></blockquote><p>Bu d&#246;n&#252;&#351;&#252;m, <strong>OT g&#252;venli&#287;inde</strong> daha derin bir k&#305;r&#305;lmaya i&#351;aret eder. <br><br>Art&#305;k ele al&#305;nmas&#305; gereken konu yaln&#305;zca sistemin g&#252;venli olup olmad&#305;&#287;&#305; de&#287;ildir.<br> <br>Konu, <strong>sistemin ne kadar s&#252;reyle, hangi ko&#351;ullar alt&#305;nda ve ne t&#252;r bir bozulma durumunda i&#351;levini s&#252;rd&#252;rebildi&#287;idir.</strong> </p><p>Bu da g&#252;venli&#287;i bir &#8220;<strong>durum</strong>&#8221; olmaktan &#231;&#305;kar&#305;r ve onu &#8220;<strong>zaman, ba&#287;lam ve davran&#305;&#351;&#8221; &#252;zerinden tan&#305;mlanan bir s&#252;re&#231;</strong> haline getirir.</p><blockquote><p><strong>Sonu&#231; olarak OT d&#252;nyas&#305;nda ger&#231;ek g&#252;venlik, kesintinin hi&#231; ya&#351;anmamas&#305; de&#287;il, kesintinin sistem &#252;zerinde kontrols&#252;z bir etki &#252;retmemesidir.</strong></p></blockquote><p>Bir sistemin de&#287;eri, sald&#305;r&#305;ya u&#287;ramamas&#305;yla de&#287;il,<br><strong>sald&#305;r&#305;ya u&#287;rad&#305;&#287;&#305;nda da i&#351;levini s&#252;rd&#252;rebilme kapasitesiyle &#246;l&#231;&#252;l&#252;r.</strong></p><p>Ve bu kapasite,<br><strong>s&#252;reklilik ile g&#252;venli&#287;in mimari d&#252;zeyde birle&#351;ti&#287;i noktada in&#351;a edilir.</strong></p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,<br>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,<br>CompTIA Project+ Professional,<br>CIW Security Analyst,<br>Certified Cyber Threat Intelligence Analyst,<br>Certified Information Security Executive&#8482;,<br>Senior Certified Leadership Practitioner</p><p></p><h2>Kaynak&#231;a</h2><ul><li><p><strong>International Organization for Standardization.</strong><br><em><strong>ISO 22301: Business Continuity Management Systems (BCMS).</strong></em><br>Business continuity, operational resilience, crisis management, recovery planning, and organizational continuity frameworks.</p></li><li><p><strong>International Electrotechnical Commission / International Society of Automation. </strong><em><strong>IEC 62443 Series &#8211; Industrial Automation and Control Systems Security.</strong></em><br>Industrial cybersecurity architecture, zones and conduits, security levels, defense-in-depth, and OT risk management.</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[ISO 22301 & IEC 62443 : The Architecture and Intersection of Continuity and Security in Operational Technology (OT)]]></title><description><![CDATA[Thanks for reading Ziya's Substack!]]></description><link>https://ziyagokalp.substack.com/p/iso-22301-and-iec-62443-the-architecture</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/iso-22301-and-iec-62443-the-architecture</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Tue, 09 Jun 2026 09:32:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!MMXm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5474424-c8f9-4b07-b077-2c7f7cd647e2_1536x1024.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MMXm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5474424-c8f9-4b07-b077-2c7f7cd647e2_1536x1024.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MMXm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5474424-c8f9-4b07-b077-2c7f7cd647e2_1536x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!MMXm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5474424-c8f9-4b07-b077-2c7f7cd647e2_1536x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!MMXm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5474424-c8f9-4b07-b077-2c7f7cd647e2_1536x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!MMXm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5474424-c8f9-4b07-b077-2c7f7cd647e2_1536x1024.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MMXm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5474424-c8f9-4b07-b077-2c7f7cd647e2_1536x1024.heic" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e5474424-c8f9-4b07-b077-2c7f7cd647e2_1536x1024.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:260452,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/194607976?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5474424-c8f9-4b07-b077-2c7f7cd647e2_1536x1024.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MMXm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5474424-c8f9-4b07-b077-2c7f7cd647e2_1536x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!MMXm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5474424-c8f9-4b07-b077-2c7f7cd647e2_1536x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!MMXm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5474424-c8f9-4b07-b077-2c7f7cd647e2_1536x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!MMXm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5474424-c8f9-4b07-b077-2c7f7cd647e2_1536x1024.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Introduction</h1><p>In modern <strong>Operational Technology (OT) systems</strong>, the most critical risk is not being attacked, but the system becoming inoperable.</p><p>In fact, in the OT domain, disruption is not merely a digital issue, it is a rupture that produces direct physical consequences. </p><p>The stoppage of production lines, interruptions in energy distribution, or the failure of critical infrastructure are all direct manifestations of such disruptions.</p><p><strong>For this reason, a security-focused approach alone is not sufficient in OT systems.</strong></p><p>No system is ever completely secure, and no defensive model can absolutely prevent disruption. This reality shifts the fundamental question:</p><blockquote><p><strong>Not &#8220;Will an attack occur?&#8221;</strong><br>but <strong>&#8220;When an attack occurs, how long can the system remain operational?&#8221;</strong></p></blockquote><p>The answer to this question lies at the intersection of two critical approaches: <br><strong>ISO 22301</strong> and <strong>IEC 62443.</strong></p><ul><li><p><strong>ISO 22301</strong> is defined as the <strong>Business Continuity Management System (BCMS)</strong>,</p></li><li><p><strong>IEC 62443</strong> is defined as the set of <strong>Standards for Securing Industrial Automation and Control Systems.</strong></p></li></ul><p></p><h1>What Are ISO 22301 and IEC 62443?</h1><p><strong>ISO 22301</strong> is a <strong>Business Continuity Management System (BCMS)</strong> standard that enables organizations to prepare for disruptions, respond effectively to them, and maintain their operations. This approach treats continuity not as an outcome, but as a <strong>pre-designed capability</strong>.</p><p><strong>IEC 62443</strong>, on the other hand, is a comprehensive family of standards focused on the <strong>Cybersecurity of Industrial Control Systems (ICS)</strong>. It defines how systems should be protected, how they should be segmented, and under which security levels they should operate.</p><p>These two standards address different, yet complementary questions:</p><ul><li><p><strong>IEC 62443 &#8594; How is the system protected?</strong></p></li><li><p><strong>ISO 22301 &#8594; How does the system continue to operate when disrupted?</strong></p></li></ul><p>This distinction reveals that, in <strong>Operational Technology (OT)</strong> environments, security and continuity are not separate concerns, but <strong>interdependent and complementary structures</strong>.</p><p></p><h1>From Risk to Continuity and Security</h1><p>In traditional approaches, security and continuity have been treated as separate disciplines. Security focuses on preventing threats, while continuity aims to recover after a disruption.</p><p>However, in OT systems, this distinction loses its validity.</p><p><strong>In fact, a security breach in OT environments often directly results in operational disruption. For this reason, security and continuity become two dimensions of the same problem.</strong></p><p><strong>IEC 62443</strong> makes it more difficult for systems to be compromised. It reduces the attack surface through network segmentation, security levels, and access controls.</p><p><strong>ISO 22301</strong>, on the other hand, operates under the assumption that such attacks are inevitable and defines how the system should continue functioning under these conditions.</p><p>This convergence gives rise to a new approach in OT systems:</p><blockquote><p><strong>The objective is not only to protect the system,<br>but to ensure that the protected system continues to operate.</strong></p></blockquote><p></p><h1>BIA, Security Levels, and the Architectural Approach</h1><p><strong>ISO 22301</strong>&#8217;s <strong>Business Impact Analysis (BIA)</strong> approach identifies which processes are critical and how long these processes can tolerate disruption. </p><p>As a result of this analysis, measurable objectives such as <strong>RTO (Recovery Time Objective)</strong> and <strong>RPO (Recovery Point Objective)</strong> are defined.</p><p><strong>IEC 62443</strong>, on the other hand, defines the level of protection required against different threat scenarios through the concept of <strong>Security Levels (SL)</strong>.<br>It also establishes how systems should be architecturally segmented through the <strong>&#8220;Zones &amp; Conduits&#8221;</strong> model.</p><p>When these two approaches are combined, they collectively answer the following questions:</p><ul><li><p><strong>BIA (Business Impact Analysis)</strong> &#8594; Which systems are critical?</p></li><li><p><strong>SL (Security Level)</strong> &#8594; How much protection is required?</p></li><li><p><strong>Zones</strong> &#8594; Where should protection be applied?</p></li><li><p><strong>Conduits</strong> &#8594; How should access be controlled?</p></li></ul><p>This integration transforms OT security from a mere set of technical controls into a <strong>measurable and architecturally designed framework</strong>.</p><p></p><h1>The Reality of Continuity and Security in OT Systems</h1><p>In <strong>OT environments</strong>, theoretical models often encounter practical limitations.<br><strong>Legacy systems, outdated protocols, and high availability requirements make it difficult to directly implement modern security approaches.</strong></p><p>Many industrial devices:</p><ul><li><p><strong>Do not support authentication</strong></p></li><li><p><strong>Do not use encryption</strong></p></li><li><p><strong>Cannot tolerate downtime</strong></p></li></ul><p>For this reason, security and continuity are not designed within the system itself, but rather through the way access to the system is managed.</p><p>At this point, a critical reality can be stated as follows:</p><blockquote><p><strong>In OT systems, security is not achieved by changing the device,<br>but by changing how the device is accessed.</strong></p></blockquote><p>This approach brings together the architectural framework of <strong>IEC 62443</strong> and the continuity perspective of <strong>ISO 22301</strong> at a common point.</p><p></p><h1>Crisis Moment: Plan or Reflex?</h1><p>A crisis is not a test of systems, but of organizations.</p><p>Plans provide direction, but in a crisis, what truly determines the outcome is reflex. Under uncertainty and time pressure, people do not follow procedures; they act based on habits and experience.</p><p>For this reason, <strong>ISO 22301 aims not only to produce plans, but to develop organizational reflexes. Through exercises and scenario-based simulations, crisis management evolves from knowledge into behavior.</strong></p><p>In <strong>OT systems</strong>, this becomes even more <strong>critical</strong>. <strong>Decisions made during a crisis produce not only digital, but also physical consequences.</strong></p><p><strong>Therefore, acting quickly, accurately, and in a coordinated manner is of vital importance.</strong></p><p></p><h1>Conclusion: The Intersection of Continuity and Security</h1><p>When <strong>ISO 22301</strong> and <strong>IEC 62443</strong> are considered together, <strong>the meaning of security in OT systems fundamentally changes.</strong></p><blockquote><p><strong>Security is no longer merely a defensive mechanism; it becomes a prerequisite for continuity, while continuity becomes the true test of security.</strong></p><p><strong>The model that emerges at the intersection of these two approaches transforms systems from being &#8220;protected structures&#8221; into organisms capable of sustaining their functionality even under disruption.</strong></p></blockquote><ul><li><p><strong>IEC 62443</strong> makes attacks more difficult by segmenting systems, restricting access, and reducing the attack surface.</p></li><li><p><strong>ISO 22301</strong>, on the other hand, acknowledges that such defenses are not absolute and defines how the system should respond under inevitable disruption scenarios.</p></li></ul><p>When these two approaches are combined, security is no longer just about &#8220;prevention,&#8221; but also about the ability to <strong>maintain controlled continuity under adverse conditions</strong>.</p><p>At this point, the critical issue is that these two structures must not be implemented independently of each other.</p><p>When security controls undermine continuity, a system may become theoretically more secure, yet practically more fragile. Similarly, an approach focused solely on continuity may keep the system operational while leaving it vulnerable.</p><p>Therefore, the correct architecture is not one that merely balances these two domains, but one that <strong>integrates them into a unified approach</strong>.</p><p>In <strong>OT systems</strong>, this integration becomes particularly evident in the following areas:</p><ul><li><p><strong>Prioritizing critical processes and defining appropriate security levels accordingly</strong></p></li><li><p><strong>Designing access in a way that is not only secure, but also sustainable</strong></p></li><li><p><strong>Ensuring that segmentation structures enable not just isolation, but controlled communication</strong></p></li><li><p><strong>Predefining alternative operational models that can be activated during crisis situations</strong></p></li></ul><blockquote><p><strong>This structure transforms security from a static checklist into a capability embedded within the system&#8217;s behavior.</strong></p><p><strong>As a result, the system is not only &#8220;protected,&#8221; but also becomes capable of managing its own failure scenarios.</strong></p></blockquote><p>This transformation signals a deeper shift in <strong>OT security</strong>.</p><p>The issue is no longer simply whether a system is secure.<br>Rather, it is how long the system can sustain its function, under what conditions, and in the face of what types of disruption.</p><p>This reframes security from a static &#8220;state&#8221; into a process defined by <strong>time, context, and behavior</strong>.</p><blockquote><p><strong>Ultimately, in the OT world, true security is not the absence of disruption, but the ability to prevent disruption from having an uncontrolled impact on the system.</strong></p></blockquote><p>A system&#8217;s value is not measured by its ability to avoid attacks,<br><strong>but by its capacity to continue functioning even when under attack.</strong></p><p>And this capacity is built at the point where<br><strong>continuity and security converge at the architectural level.</strong></p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,<br>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,<br>CompTIA Project+ Professional,<br>CIW Security Analyst,<br>Certified Cyber Threat Intelligence Analyst,<br>Certified Information Security Executive&#8482;,<br>Senior Certified Leadership Practitioner</p><p></p><h1>References</h1><ul><li><p><strong>International Organization for Standardization.</strong><br><em><strong>ISO 22301: Business Continuity Management Systems (BCMS).</strong></em><br>Business continuity, operational resilience, crisis management, recovery planning, and organizational continuity frameworks.</p></li><li><p><strong>International Electrotechnical Commission / International Society of Automation. </strong><em><strong>IEC 62443 Series &#8211; Industrial Automation and Control Systems Security.</strong></em><br>Industrial cybersecurity architecture, zones and conduits, security levels, defense-in-depth, and OT risk management.</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Dijital İkizler (Digital Twins): Fiziksel Dünyanın Dijital Hafızası ve Geleceğin Karar Motoru]]></title><description><![CDATA[PODCAST Linki]]></description><link>https://ziyagokalp.substack.com/p/dijital-ikizler-digital-twins-fiziksel</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/dijital-ikizler-digital-twins-fiziksel</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Mon, 01 Jun 2026 15:12:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!CKy3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fff0e6b-5bfb-400b-aa4b-b44d18b1b141_1774x887.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CKy3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fff0e6b-5bfb-400b-aa4b-b44d18b1b141_1774x887.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CKy3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fff0e6b-5bfb-400b-aa4b-b44d18b1b141_1774x887.heic 424w, https://substackcdn.com/image/fetch/$s_!CKy3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fff0e6b-5bfb-400b-aa4b-b44d18b1b141_1774x887.heic 848w, https://substackcdn.com/image/fetch/$s_!CKy3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fff0e6b-5bfb-400b-aa4b-b44d18b1b141_1774x887.heic 1272w, https://substackcdn.com/image/fetch/$s_!CKy3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fff0e6b-5bfb-400b-aa4b-b44d18b1b141_1774x887.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CKy3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fff0e6b-5bfb-400b-aa4b-b44d18b1b141_1774x887.heic" width="1456" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5fff0e6b-5bfb-400b-aa4b-b44d18b1b141_1774x887.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:365356,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/200026335?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fff0e6b-5bfb-400b-aa4b-b44d18b1b141_1774x887.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CKy3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fff0e6b-5bfb-400b-aa4b-b44d18b1b141_1774x887.heic 424w, https://substackcdn.com/image/fetch/$s_!CKy3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fff0e6b-5bfb-400b-aa4b-b44d18b1b141_1774x887.heic 848w, https://substackcdn.com/image/fetch/$s_!CKy3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fff0e6b-5bfb-400b-aa4b-b44d18b1b141_1774x887.heic 1272w, https://substackcdn.com/image/fetch/$s_!CKy3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fff0e6b-5bfb-400b-aa4b-b44d18b1b141_1774x887.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://creators.spotify.com/pod/profile/ziyagokalp/episodes/Dijital-kizler-Digital-Twins-e3k5bg3">PODCAST Linki</a></strong></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h1>Fiziksel D&#252;nyay&#305; Anlama Aray&#305;&#351;&#305;</h1><p>&#304;nsanl&#305;k tarihindeki b&#252;y&#252;k teknolojik d&#246;n&#252;&#351;&#252;mlerin ortak bir &#246;zelli&#287;i vard&#305;r: <br><strong>Her biri g&#246;r&#252;nmeyeni g&#246;r&#252;n&#252;r hale getirmi&#351;tir.</strong> </p><p>Buhar makinesi insan kas g&#252;c&#252;n&#252;n s&#305;n&#305;rlar&#305;n&#305; a&#351;m&#305;&#351;, elektrik geceleri ayd&#305;nlatm&#305;&#351;, bilgisayarlar bilgiyi i&#351;leyebilir hale getirmi&#351;, internet ise d&#252;nyan&#305;n d&#246;rt bir yan&#305;ndaki insanlar&#305; birbirine ba&#287;lam&#305;&#351;t&#305;r. </p><p>Ancak t&#252;m bu teknolojik geli&#351;melere ra&#287;men fiziksel d&#252;nyan&#305;n kendisi uzun y&#305;llar boyunca b&#252;y&#252;k &#246;l&#231;&#252;de bir &#8220;<strong>kara kutu</strong>&#8221; olarak kalm&#305;&#351;t&#305;r. </p><p>Bir fabrikan&#305;n &#252;retim hatt&#305; &#231;al&#305;&#351;&#305;rken i&#231;eride neler oldu&#287;unu ancak belirli &#246;l&#231;&#252;de g&#246;rebiliyor, bir enerji santralindeki ekipmanlar&#305;n ger&#231;ek durumunu ancak ar&#305;za meydana geldi&#287;inde anlayabiliyor veya bir &#351;ehrin karma&#351;&#305;k altyap&#305; sistemlerinin birbirleriyle olan ili&#351;kilerini ancak kriz anlar&#305;nda fark edebiliyorduk.</p><p>Asl&#305;nda modern m&#252;hendislik uzun y&#305;llard&#305;r fiziksel sistemleri anlamaya &#231;al&#305;&#351;maktad&#305;r. </p><p>Bunun i&#231;in <strong>&#231;izimler, sim&#252;lasyonlar, matematiksel modeller</strong> ve <strong>analiz y&#246;ntemleri</strong> geli&#351;tirilmi&#351;tir. </p><p>Fakat b&#252;t&#252;n bu y&#246;ntemlerin temel bir eksikli&#287;i bulunuyordu: <strong>Fiziksel d&#252;nya s&#252;rekli de&#287;i&#351;irken modeller statik kal&#305;yordu. Ger&#231;ek d&#252;nya ile dijital d&#252;nya aras&#305;nda s&#252;rekli ve canl&#305; bir ba&#287; kurulam&#305;yordu.</strong></p><p></p><h1>Dijital &#304;kiz Kavram&#305;n&#305;n Ortaya &#199;&#305;k&#305;&#351;&#305;</h1><p><strong>Dijital ikiz</strong> kavram&#305; tam da bu noktada ortaya &#231;&#305;km&#305;&#351;t&#305;r.</p><p><strong>Dijital ikizler, en basit ifadeyle fiziksel bir varl&#305;&#287;&#305;n, sistemin veya s&#252;recin ger&#231;ek zamanl&#305; olarak g&#252;ncellenen dijital temsilidir.</strong> </p><p>Ancak bu tan&#305;m, teknolojinin ger&#231;ek kapsam&#305;n&#305; anlatmak i&#231;in yeterli de&#287;ildir. </p><p>Nitekim <strong>dijital ikiz</strong> yaln&#305;zca bir <strong>kopya de&#287;ildir</strong>. Ayn&#305; zamanda <strong>fiziksel sistemin haf&#305;zas&#305;, aynas&#305; ve gelece&#287;e ili&#351;kin tahmin mekanizmas&#305;d&#305;r.</strong> </p><p><strong>Fiziksel d&#252;nyada meydana gelen her olay dijital ortama aktar&#305;l&#305;r, dijital ortamda analiz edilir ve tekrar fiziksel d&#252;nyaya geri beslenir.</strong> </p><p><strong>B&#246;ylece fiziksel sistem ile dijital model aras&#305;nda s&#252;rekli bir etkile&#351;im d&#246;ng&#252;s&#252; olu&#351;ur.</strong></p><p></p><h1>Neden Devrimsel Bir Teknoloji?</h1><p>Bu durumun &#246;nemi ilk bak&#305;&#351;ta tam olarak anla&#351;&#305;lamayabilir. </p><p>Ancak bug&#252;n kulland&#305;&#287;&#305;m&#305;z bir&#231;ok kritik sistemin asl&#305;nda s&#305;n&#305;rl&#305; g&#246;r&#252;n&#252;rl&#252;kle y&#246;netildi&#287;ini d&#252;&#351;&#252;nd&#252;&#287;&#252;m&#252;zde <strong>dijital ikizlerin</strong> neden devrimsel olarak g&#246;r&#252;ld&#252;&#287;&#252; daha net ortaya &#231;&#305;kmaktad&#305;r. </p><p><strong>&#214;rne&#287;in</strong> <strong>b&#252;y&#252;k bir ila&#231; &#252;retim tesisini</strong> ele alal&#305;m. </p><p>Tesiste y&#252;zlerce <strong>PLC</strong>, onlarca <strong>SCADA</strong> sunucusu, <strong>temiz oda sistemleri</strong>, <strong>HVAC altyap&#305;lar&#305;</strong>, <strong>saf su &#252;retim sistemleri</strong>, <strong>dolum makineleri</strong> ve <strong>paketleme hatlar&#305;</strong> bulunmaktad&#305;r. </p><p><strong>PLC (Programmable Logic Controller)</strong> T&#252;rk&#231;ede genellikle <strong>Programlanabilir Mant&#305;k Denetleyicisi</strong> olarak adland&#305;r&#305;l&#305;r. <strong>PLC</strong>&#8217;ler fabrikalarda, enerji tesislerinde, su ar&#305;tma tesislerinde, rafinerilerde, ila&#231; &#252;retim tesislerinde ve benzeri end&#252;striyel ortamlarda fiziksel s&#252;re&#231;leri kontrol etmek i&#231;in kullan&#305;l&#305;r.</p><p><strong>SCADA (Supervisory Control and Data Acquisition)</strong> T&#252;rk&#231;ede genellikle <strong>Merkezi G&#246;zetim, Kontrol ve Veri Toplama Sistemi</strong> olarak ifade edilir. <strong>SCADA</strong>, end&#252;striyel tesislerde bulunan <strong>PLC</strong>&#8217;leri, sens&#246;rleri ve saha ekipmanlar&#305;n&#305; merkezi olarak izlemek ve y&#246;netmek i&#231;in kullan&#305;lan sistemdir.</p><p><strong>HVAC (Heating, Ventilation and Air Conditioning)</strong> T&#252;rk&#231;ede; <strong>Is&#305;tma, Havaland&#305;rma ve &#304;klimlendirme Sistemleri </strong>anlam&#305;na gelir. Ancak end&#252;striyel tesislerde <strong>HVAC</strong> yaln&#305;zca ortam&#305; serinleten veya &#305;s&#305;tan bir klima sistemi de&#287;ildir.<br>&#214;zellikle: &#304;la&#231; fabrikalar&#305;nda, veri merkezlerinde, hastanelerde, temiz odalarda, yar&#305; iletken &#252;retim tesislerinde <strong>HVAC</strong> sistemleri do&#287;rudan &#252;retim kalitesini ve &#252;r&#252;n g&#252;venli&#287;ini etkiler. Bu ba&#287;lamda HVAC sistemi; Ortam s&#305;cakl&#305;&#287;&#305;n&#305; ve nem seviyesini kontrol eder, hava ak&#305;&#351;&#305;n&#305; d&#252;zenler, partik&#252;l miktar&#305;n&#305; azalt&#305;r, bas&#305;n&#231; farklar&#305;n&#305; y&#246;netir, kontaminasyonu (bula&#351;may&#305;/kirlenmeyi) &#246;nler.  &#214;zetle; <strong>HVAC</strong> sistemi &#252;retim alan&#305;n&#305;n g&#246;r&#252;nmeyen koruma kalkan&#305;d&#305;r.</p><p>Bu sistemler <strong>Operasyonel Teknolojilerin (OT) </strong>bile&#351;enleridir. </p><p><strong>Bu sistemlerin tamam&#305; birbiriyle ba&#287;lant&#305;l&#305;d&#305;r ve herhangi bir noktadaki k&#252;&#231;&#252;k bir de&#287;i&#351;iklik &#252;retim kalitesini, g&#252;venli&#287;i veya i&#351; s&#252;reklili&#287;ini etkileyebilir.</strong> </p><p>Geleneksel yakla&#351;&#305;mda m&#252;hendisler bu sistemleri belirli raporlar, alarm ekranlar&#305; ve ge&#231;mi&#351; kay&#305;tlar &#252;zerinden izler. </p><p>Ancak <strong>dijital ikiz</strong> yakla&#351;&#305;m&#305;nda tesisin tamam&#305; <strong>dijital ortamda canl&#305; olarak yeniden olu&#351;turulur.</strong> </p><p>B&#246;ylece yaln&#305;zca mevcut durum de&#287;il, <strong>gelecekte ortaya &#231;&#305;kabilecek senaryolar da analiz edilebilir.</strong></p><p>Bu noktada <strong>dijital ikizlerin</strong> yaln&#305;zca operasyonel verimlilik sa&#287;layan bir teknoloji olmad&#305;&#287;&#305; anla&#351;&#305;lmaktad&#305;r. </p><p><strong>Asl&#305;nda dijital ikizler fiziksel d&#252;nyay&#305; &#246;l&#231;&#252;lebilir, analiz edilebilir ve &#246;ng&#246;r&#252;lebilir hale getiren yeni bir paradigma sunmaktad&#305;r.</strong> </p><p>Bir&#231;ok teknoloji ara&#351;t&#305;rmac&#305;s&#305;n&#305;n <strong>dijital ikizleri</strong> &#8220;<strong>fiziksel d&#252;nyan&#305;n i&#351;letim sistemi</strong>&#8221; olarak tan&#305;mlamas&#305;n&#305;n nedeni de budur.</p><p></p><h1>Dijital &#304;kizleri M&#252;mk&#252;n K&#305;lan Teknolojiler</h1><p>Dijital ikizlerin geli&#351;imini m&#252;mk&#252;n k&#305;lan <strong>&#252;&#231; temel teknoloji</strong> bulunmaktad&#305;r. </p><ul><li><p><strong>Bunlardan ilki &#8216;Nesnelerin Interneti&#8217; dir (IoT)</strong>. Sens&#246;r maliyetlerinin d&#252;&#351;mesi ve a&#287; ba&#287;lant&#305;lar&#305;n&#305;n yayg&#305;nla&#351;mas&#305; sayesinde art&#305;k fiziksel d&#252;nyadaki neredeyse her varl&#305;k veri &#252;retebilmektedir. </p><p><br>Bir pompan&#305;n titre&#351;imi, bir motorun s&#305;cakl&#305;&#287;&#305;, bir vanan&#305;n konumu veya bir odan&#305;n nem oran&#305; s&#252;rekli olarak &#246;l&#231;&#252;lebilmektedir. <br></p></li><li><p><strong>&#304;kinci temel teknoloji &#8216;Bulut Bili&#351;im&#8217; dir</strong>. Nitekim milyonlarca sens&#246;rden gelen verinin depolanmas&#305; ve i&#351;lenmesi i&#231;in b&#252;y&#252;k hesaplama kapasitesine ihtiya&#231; duyulmaktad&#305;r. <br></p></li><li><p><strong>&#220;&#231;&#252;nc&#252; ve belki de en kritik teknoloji ise &#8216;Yapay Zeka&#8217; d&#305;r</strong>. Nitekim veri tek ba&#351;&#305;na anlam ifade etmez. Verinin analiz edilmesi, ili&#351;kilerin kurulmas&#305; ve gelece&#287;e y&#246;nelik tahminlerin yap&#305;lmas&#305; gerekir. </p><p><br><strong>Yapay zeka</strong> dijital ikizleri s&#305;radan bir veri toplama sisteminden <strong>stratejik bir karar destek mekanizmas&#305;na d&#246;n&#252;&#351;t&#252;rmektedir.</strong></p></li></ul><p></p><h1>OT D&#252;nyas&#305;nda Dijital &#304;kizlerin &#214;nemi</h1><p>&#214;zellikle <strong>Operasyonel Teknoloji (OT)</strong> d&#252;nyas&#305;nda dijital ikizlerin etkisi &#231;ok daha b&#252;y&#252;k olacakt&#305;r. </p><p>Bilgi teknolojileri sistemlerinde test yapmak g&#246;rece kolayd&#305;r. Bir sanal makine olu&#351;turabilir, yeni bir yaz&#305;l&#305;m&#305; deneyebilir veya farkl&#305; g&#252;venlik yap&#305;land&#305;rmalar&#305;n&#305; test edebilirsiniz. </p><p>Ancak <strong>Operasyonel Teknoloji (OT)</strong> ortamlar&#305;nda durum tamamen farkl&#305;d&#305;r. Bir <strong>enerji santralini, petrol rafinerisini</strong> veya <strong>ila&#231; &#252;retim hatt&#305;n&#305;</strong> durdurup deneme yapmak &#231;o&#287;u zaman m&#252;mk&#252;n de&#287;ildir. </p><p>Nitekim &#252;retim kesintisi milyonlarca dolarl&#305;k kay&#305;plara neden olabilir. Ayr&#305;ca <strong>insan g&#252;venli&#287;i</strong> ve <strong>&#231;evresel etkiler</strong> gibi fakt&#246;rler de s&#246;z konusudur. </p><p>Bu nedenle <strong>Operasyonel Teknoloji (OT)</strong> sistemlerinde bir&#231;ok de&#287;i&#351;iklik son derece dikkatli &#351;ekilde uygulanmak zorundad&#305;r.</p><p></p><h1>IEC 62443 ve Dijital &#304;kiz Yakla&#351;&#305;m&#305;</h1><p><strong>Dijital ikizler</strong> bu soruna yeni bir yakla&#351;&#305;m getirmektedir. </p><p>Ger&#231;ek tesisin birebir dijital modeli olu&#351;turuldu&#287;unda yap&#305;lmas&#305; planlanan de&#287;i&#351;iklikler &#246;nce dijital ortamda test edilebilir. </p><p><strong>&#214;rne&#287;in</strong> yeni bir <strong>a&#287; segmentasyonu tasar&#305;m&#305;</strong> uygulanmadan &#246;nce etkileri dijital ikizde incelenebilir. </p><p>Yeni bir <strong>firewall kural&#305;</strong>, yeni bir eri&#351;im kontrol mekanizmas&#305; veya yeni bir g&#252;venlik &#231;&#246;z&#252;m&#252; &#246;nce sanal ortamda de&#287;erlendirilerek riskler analiz edilebilir. </p><p>Bu yakla&#351;&#305;m &#246;zellikle <strong>IEC 62443</strong> gibi <strong>OT g&#252;venlik standartlar&#305;n&#305;n</strong> uygulanmas&#305;nda &#246;nemli avantajlar sa&#287;lamaktad&#305;r. &#214;zetle; <strong>IEC 62443</strong>, <strong>OT (Operasyonel Teknoloji)</strong> ve <strong>end&#252;striyel kontrol sistemlerinin</strong> nas&#305;l g&#252;venli tasarlanaca&#287;&#305;n&#305;, i&#351;letilece&#287;ini ve korunaca&#287;&#305;n&#305; tan&#305;mlayan uluslararas&#305; siber g&#252;venlik standard&#305;d&#305;r.</p><p></p><h1>Siber G&#252;venlik Perspektifinden Dijital &#304;kizler</h1><p><strong>Siber g&#252;venlik</strong> perspektifinden bak&#305;ld&#305;&#287;&#305;nda dijital ikizlerin &#246;nemi daha da artmaktad&#305;r. </p><p>Son y&#305;llarda kritik altyap&#305;lara y&#246;nelik sald&#305;r&#305;lar ciddi &#351;ekilde artm&#305;&#351;t&#305;r. </p><p><strong>Stuxnet, Triton, Industroyer</strong> ve <strong>Volt Typhoon</strong> gibi olaylar g&#246;stermi&#351;tir ki modern sald&#305;rganlar art&#305;k yaln&#305;zca veri &#231;almay&#305; de&#287;il, <strong>fiziksel s&#252;re&#231;leri etkilemeyi de hedeflemektedir.</strong> </p><p>Daha &#246;nce yay&#305;mlad&#305;&#287;&#305;m makalelerde defaatle bahsetti&#287;im ve detaylar&#305;n&#305; payla&#351;t&#305;&#287;&#305;m; <strong>Stuxnet, Triton, Industroyer</strong> ve <strong>Volt Typhoon</strong> vakalar&#305;, siber sald&#305;r&#305;lar&#305;n yaln&#305;zca bilgi sistemlerini de&#287;il, fiziksel s&#252;re&#231;leri ve kritik altyap&#305;lar&#305; da hedef alabilece&#287;ini g&#246;stermi&#351;tir. </p><p><strong>Stuxnet</strong>, <strong>&#304;ran</strong>'&#305;n n&#252;kleer tesislerindeki <strong>PLC</strong> sistemlerini manip&#252;le ederek fiziksel ekipmanlara zarar veren ilk b&#252;y&#252;k siber sald&#305;r&#305; olarak tarihe ge&#231;mi&#351;tir. </p><p><strong>Industroyer</strong>, <strong>Ukrayna</strong>'n&#305;n <strong>elektrik &#351;ebekesini</strong> hedef alarak geni&#351; &#231;apl&#305; enerji kesintilerine neden olmu&#351; ve end&#252;striyel protokollerin sald&#305;r&#305; amac&#305;yla kullan&#305;labilece&#287;ini g&#246;stermi&#351;tir. </p><p><strong>Triton</strong> ise bir petrokimya tesisindeki <strong>Emniyet Sistemlerini (Safety Instrumented Systems - SIS)</strong> hedef alarak insan g&#252;venli&#287;ini do&#287;rudan riske atan ilk sald&#305;r&#305;lardan biri olmu&#351;tur. </p><p><strong>Volt Typhoon</strong> ise kritik altyap&#305;larda gizlice konumlanarak gelecekteki olas&#305; kriz veya &#231;at&#305;&#351;ma senaryolar&#305; i&#231;in eri&#351;im sa&#287;lamay&#305; ama&#231;layan bir <strong>&#246;n-konumlanma</strong> operasyonu olarak dikkat &#231;ekmektedir. </p><p>Bu vakalar, <strong>Operasyonel Teknoloji (OT) sistemlerinin</strong> ve <strong>kritik altyap&#305;lar&#305;n</strong> siber g&#252;venli&#287;inin art&#305;k yaln&#305;zca bir bilgi teknolojisi konusu de&#287;il, ayn&#305; zamanda operasyonel s&#252;reklilik, insan g&#252;venli&#287;i ve ulusal g&#252;venlik meselesi oldu&#287;unu ortaya koymu&#351;tur.</p><p>S&#246;z&#252;n &#246;z&#252;; Bir sald&#305;rgan&#305;n bir <strong>enerji santralindeki kontrol sistemlerini manip&#252;le etmesi</strong>, bir <strong>su ar&#305;tma tesisindeki kimyasal dozajlar&#305; de&#287;i&#351;tirmesi</strong> veya bir <strong>ila&#231; &#252;retim tesisindeki proses parametrelerini bozmas&#305;</strong> m&#252;mk&#252;nd&#252;r. </p><p>Bu t&#252;r sald&#305;r&#305;lar yaln&#305;zca bilgi g&#252;venli&#287;i problemi de&#287;il, ayn&#305; zamanda fiziksel g&#252;venlik ve <strong>ulusal g&#252;venlik</strong> problemidir.</p><p></p><h1>Siber Tatbikat ve Sald&#305;r&#305; Sim&#252;lasyon Platformu Olarak Dijital &#304;kizler</h1><p><strong>Dijital ikizler</strong> bu noktada benzersiz bir avantaj sunmaktad&#305;r. Ger&#231;ek sistem &#252;zerinde test edilmesi m&#252;mk&#252;n olmayan sald&#305;r&#305; senaryolar&#305; dijital ortamda &#231;al&#305;&#351;t&#305;r&#305;labilir. </p><p>Bir <strong>PLC manip&#252;lasyonunun &#252;retime etkisi</strong>, bir <strong>SCADA sisteminin devre d&#305;&#351;&#305; kalmas&#305;n&#305;n</strong> sonu&#231;lar&#305; veya bir <strong>fidye yaz&#305;l&#305;m&#305; sald&#305;r&#305;s&#305;n&#305;n operasyonel s&#252;re&#231;lere etkisi</strong> &#246;nceden analiz edilebilir. </p><p>B&#246;ylece kurumlar yaln&#305;zca olaylara tepki veren yap&#305;lar olmaktan &#231;&#305;karak <strong>proaktif savunma mekanizmalar&#305; geli&#351;tirebilir.</strong></p><p></p><h1>Dijital &#304;kizlerin Kritik Altyap&#305;lardaki Gelece&#287;i</h1><p>&#214;n&#252;m&#252;zdeki y&#305;llarda dijital ikizlerin kullan&#305;m alan&#305; yaln&#305;zca fabrikalarla s&#305;n&#305;rl&#305; kalmayacakt&#305;r. </p><p><strong>Ak&#305;ll&#305; &#351;ehir projeleri, ulusal enerji &#351;ebekeleri, ula&#351;&#305;m sistemleri, limanlar, havaalanlar&#305;</strong> ve hatta <strong>&#252;lkelerin kritik altyap&#305;lar&#305;</strong> dijital ikizler &#252;zerinden y&#246;netilmeye ba&#351;lanacakt&#305;r. </p><p>Bir <strong>deprem meydana geldi&#287;inde hangi yollar&#305;n kapanaca&#287;&#305;, hangi hastanelerin kapasite sorunu ya&#351;ayaca&#287;&#305;, hangi enerji hatlar&#305;n&#305;n risk alt&#305;nda oldu&#287;u</strong> ve <strong>hangi b&#246;lgelerin &#246;ncelikli m&#252;dahale gerektirdi&#287;i</strong> dijital ikiz sistemleri taraf&#305;ndan saniyeler i&#231;erisinde hesaplanabilecektir. </p><p>Bu nedenle bir&#231;ok &#252;lke dijital ikiz teknolojilerini yaln&#305;zca bir teknoloji yat&#305;r&#305;m&#305; olarak de&#287;il, <strong>stratejik bir ulusal g&#252;venlik kapasitesi olarak de&#287;erlendirmektedir.</strong></p><p>Yapay zekan&#305;n geli&#351;imiyle birlikte dijital ikizlerin rol&#252; daha da de&#287;i&#351;ecektir. </p><p>Bug&#252;n dijital ikizler a&#287;&#305;rl&#305;kl&#305; olarak mevcut durumu g&#246;stermekte ve belirli analizler yapmaktad&#305;r. </p><p><strong>Gelecekte ise sistemlerin gelecekteki davran&#305;&#351;lar&#305;n&#305; tahmin eden ve hatta belirli kararlar&#305; otonom olarak alabilen yap&#305;lara d&#246;n&#252;&#351;meleri beklenmektedir.</strong> </p><p>Bir <strong>enerji santralinde t&#252;rbin ar&#305;zas&#305;n&#305; haftalar &#246;ncesinden tahmin eden</strong>, bir <strong>ila&#231; &#252;retim tesisinde kalite risklerini &#252;retim ba&#351;lamadan &#246;nce belirleyen</strong> veya bir <strong>&#351;ehirde trafik s&#305;k&#305;&#351;&#305;kl&#305;&#287;&#305;n&#305; olu&#351;madan engelleyen sistemler</strong> bu d&#246;n&#252;&#351;&#252;m&#252;n ilk &#246;rnekleri olacakt&#305;r.</p><p><strong>Belki de dijital ikizlerin en &#246;nemli etkisi, fiziksel d&#252;nya ile dijital d&#252;nya aras&#305;ndaki s&#305;n&#305;rlar&#305; giderek ortadan kald&#305;rmas&#305;d&#305;r.</strong> </p><p>Ge&#231;mi&#351;te dijital sistemler fiziksel d&#252;nyay&#305; yaln&#305;zca <strong>izliyordu</strong>. Bug&#252;n <strong>anlamaya</strong> &#231;al&#305;&#351;&#305;yorlar. <strong>Yar&#305;n ise y&#246;netmeye ba&#351;layacaklar.</strong> </p><p>&#304;&#351;te bu nedenle dijital ikizler yaln&#305;zca yeni bir m&#252;hendislik teknolojisi de&#287;il, yapay zeka &#231;a&#287;&#305;n&#305;n fiziksel d&#252;nya ile kurdu&#287;u ili&#351;kinin temel altyap&#305;s&#305; olarak g&#246;r&#252;lmektedir. </p><p>Nas&#305;l internet bilgi &#231;a&#287;&#305;n&#305;n omurgas&#305;n&#305; olu&#351;turduysa, <strong>dijital ikizler</strong> de gelece&#287;in <strong>ak&#305;ll&#305; fabrikalar&#305;n&#305;n, ak&#305;ll&#305; &#351;ehirlerinin, kritik altyap&#305;lar&#305;n&#305;n</strong> ve <strong>otonom sistemlerinin</strong> g&#246;r&#252;nmez <strong>omurgas&#305;</strong> haline gelecektir. </p><p>&#214;zellikle <strong>Operasyonel Teknoloji (OT) g&#252;venli&#287;i, kritik altyap&#305; korumas&#305;, i&#351; s&#252;reklili&#287;i, ulusal dayan&#305;kl&#305;l&#305;k</strong> ve <strong>siber-fiziksel sistemler</strong> perspektifinden bak&#305;ld&#305;&#287;&#305;nda dijital ikizler &#246;n&#252;m&#252;zdeki yirmi y&#305;l&#305;n en stratejik teknolojilerinden biri olmaya adayd&#305;r. </p><p>Hatta bir&#231;ok uzmana g&#246;re gelecekte <strong>dijital ikizi olmayan bir kritik altyap&#305; i&#351;letmesi, bug&#252;n siber g&#252;venlik program&#305; olmayan bir i&#351;letme kadar savunmas&#305;z kabul edilecektir&#8230;</strong></p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,<br>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,<br>CompTIA Project+ Professional,<br>CIW Security Analyst,<br>Certified Cyber Threat Intelligence Analyst,<br>Certified Information Security Executive&#8482;,<br>Senior Certified Leadership Practitioner</p><p></p><h1>Kaynak&#231;a</h1><ol><li><p><strong>NASA Technology Roadmaps</strong></p><p>NASA&#8217;n&#305;n dijital ikiz kavram&#305;n&#305;n ilk uygulamalar&#305;na ili&#351;kin teknik &#231;al&#305;&#351;malar ve sistem modelleme yakla&#351;&#305;mlar&#305;.</p></li><li><p><strong>Digital Twin Consortium</strong></p><p>Dijital ikiz teknolojilerinin mimarisi, kullan&#305;m alanlar&#305; ve end&#252;stri uygulamalar&#305; &#252;zerine kapsaml&#305; kaynaklar.</p></li><li><p><strong>National Institute of Standards and Technology (NIST) Digital Twin Research</strong></p><p>Dijital ikizlerin standartla&#351;t&#305;r&#305;lmas&#305;, modelleme y&#246;ntemleri ve siber-fiziksel sistemlerle ili&#351;kisi.</p></li><li><p><strong>World Economic Forum &#8211; Digital Twin Cities Initiative</strong></p><p>Ak&#305;ll&#305; &#351;ehirler ve ulusal dijital ikiz projeleri &#252;zerine &#231;al&#305;&#351;malar.</p></li></ol><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Digital Twins: The Digital Memory of the Physical World and the Decision Engine of the Future]]></title><description><![CDATA[Thanks for reading Ziya's Substack!]]></description><link>https://ziyagokalp.substack.com/p/digital-twins-the-digital-memory</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/digital-twins-the-digital-memory</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Mon, 01 Jun 2026 15:04:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hbVD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F506fd9a2-aabb-4ed9-ba63-80624804696c_1774x887.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hbVD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F506fd9a2-aabb-4ed9-ba63-80624804696c_1774x887.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hbVD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F506fd9a2-aabb-4ed9-ba63-80624804696c_1774x887.heic 424w, https://substackcdn.com/image/fetch/$s_!hbVD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F506fd9a2-aabb-4ed9-ba63-80624804696c_1774x887.heic 848w, https://substackcdn.com/image/fetch/$s_!hbVD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F506fd9a2-aabb-4ed9-ba63-80624804696c_1774x887.heic 1272w, https://substackcdn.com/image/fetch/$s_!hbVD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F506fd9a2-aabb-4ed9-ba63-80624804696c_1774x887.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hbVD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F506fd9a2-aabb-4ed9-ba63-80624804696c_1774x887.heic" width="1456" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/506fd9a2-aabb-4ed9-ba63-80624804696c_1774x887.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:368559,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/200075052?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F506fd9a2-aabb-4ed9-ba63-80624804696c_1774x887.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hbVD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F506fd9a2-aabb-4ed9-ba63-80624804696c_1774x887.heic 424w, https://substackcdn.com/image/fetch/$s_!hbVD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F506fd9a2-aabb-4ed9-ba63-80624804696c_1774x887.heic 848w, https://substackcdn.com/image/fetch/$s_!hbVD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F506fd9a2-aabb-4ed9-ba63-80624804696c_1774x887.heic 1272w, https://substackcdn.com/image/fetch/$s_!hbVD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F506fd9a2-aabb-4ed9-ba63-80624804696c_1774x887.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>The Quest to Understand the Physical World</h1><p>Major technological transformations throughout human history have shared a common characteristic: <strong>Each has made the invisible visible.</strong></p><p>The steam engine pushed beyond the limits of human muscle power, electricity illuminated the night, computers enabled the processing of information, and the internet connected people across the globe.</p><p>Yet despite all these technological advances, the physical world itself remained, for many years, largely a &#8220;<strong>black box</strong>.&#8221;</p><p>While a factory production line was operating, we could observe what was happening inside only to a limited extent. We often understood the true condition of equipment in a power plant only after a failure occurred, and we became aware of the interdependencies within a city&#8217;s complex infrastructure systems primarily during times of crisis.</p><p>In reality, modern engineering has long sought to understand physical systems.</p><p>To achieve this, engineers have developed <strong>drawings, simulations, mathematical models, and analytical methods.</strong></p><p>However, all of these approaches shared a fundamental limitation: While the <strong>physical world was constantly changing, the models remained static. A continuous and living connection between the physical world and the digital world could not be established.</strong></p><p></p><h1>The Emergence of the Digital Twin Concept</h1><p>The concept of the <strong>digital twin</strong> emerged precisely to address this challenge.</p><p><strong>In its simplest form, a digital twin is a real-time, continuously updated digital representation of a physical asset, system, or process.</strong></p><p>However, this definition alone is not sufficient to capture the true scope of the technology.</p><p>A <strong>digital twin</strong> <strong>is not merely a replica</strong>. It is also the <strong>memory, mirror, and predictive mechanism of the physical system.</strong></p><p><strong>Every event occurring in the physical world is transmitted to the digital environment, analyzed there, and then fed back into the physical world.</strong></p><p><strong>As a result, a continuous cycle of interaction is established between the physical system and its digital counterpart.</strong></p><p></p><h1>Why Is It a Revolutionary Technology?</h1><p>The significance of this development may not be immediately apparent at first glance.</p><p>However, when we consider that many of the critical systems we rely on today are managed with only limited visibility, it becomes much clearer why digital twins are regarded as a revolutionary technology.</p><p>Consider a large pharmaceutical manufacturing facility.</p><p>Such a facility may contain hundreds of <strong>PLC</strong>s, dozens of <strong>SCADA</strong> servers, cleanroom systems, <strong>HVAC</strong> infrastructure, purified water production systems, filling machines, and packaging lines.</p><p>A <strong>PLC (Programmable Logic Controller)</strong> is an industrial computer designed to control physical processes in environments such as factories, power plants, water treatment facilities, refineries, and pharmaceutical manufacturing sites.</p><p><strong>SCADA (Supervisory Control and Data Acquisition)</strong> is a centralized monitoring and control system used to supervise <strong>PLC</strong>s, sensors, and field devices across industrial facilities. It enables operators to monitor operations, collect data, and manage processes from a central location.</p><p><strong>HVAC (Heating, Ventilation, and Air Conditioning)</strong> systems are commonly associated with climate control, but in industrial environments they serve a far more critical function. In pharmaceutical plants, data centers, hospitals, cleanrooms, and semiconductor manufacturing facilities, <strong>HVAC</strong> systems directly influence product quality and operational safety. They regulate temperature and humidity, manage airflow, reduce particulate contamination, control pressure differentials, and help prevent contamination. In essence, <strong>HVAC</strong> systems function as the invisible protective shield of the production environment.</p><p>All of these systems are components of <strong>Operational Technology (OT)</strong> environments.</p><p>They are highly interconnected, and even a minor change in one area can affect product quality, operational safety, regulatory compliance, or business continuity.</p><p>Under the traditional approach, engineers monitor these systems through reports, alarm screens, and historical records. With a digital twin approach, however, the entire facility is recreated as a living, continuously updated digital environment.</p><p><strong>As a result, organizations can analyze not only the current state of operations but also future scenarios before they occur.</strong></p><p><strong>At this point, it becomes clear that digital twins are not merely a technology for improving operational efficiency.</strong></p><p>Rather, they represent a new paradigm that makes the physical world measurable, analyzable, and predictable.</p><p>This is precisely why many technology researchers describe digital twins as <strong>&#8220;the operating system of the physical world.&#8221;</strong></p><p></p><h1>Technologies That Enable Digital Twins</h1><p>The development of digital twins has been made possible by <strong>three fundamental</strong> technologies.</p><ul><li><p><strong>The first</strong> of these is the <strong>Internet of Things (IoT)</strong>. As sensor costs have decreased and network connectivity has become more widespread, nearly every physical asset in the modern world is now capable of generating data.</p><p><br>The vibration of a pump, the temperature of a motor, the position of a valve, or the humidity level of a room can all be continuously monitored and measured in real time.<br></p></li><li><p><strong>The second</strong> foundational technology is <strong>Cloud Computing</strong>. The storage and processing of data generated by millions of sensors require enormous computational resources and scalable infrastructure.</p><p><br>Cloud platforms provide the storage capacity, processing power, and accessibility needed to manage and analyze vast volumes of operational data efficiently.<br></p></li><li><p><strong>The third</strong>&#8212;and perhaps the most critical&#8212;technology is <strong>Artificial Intelligence (AI)</strong>.</p><p><br>Data alone has limited value. To generate meaningful insights, data must be analyzed, relationships must be identified, and future conditions must be predicted.</p><p><br>Artificial intelligence transforms digital twins from ordinary data collection systems into strategic decision-support mechanisms.</p></li></ul><p><strong>By recognizing patterns, detecting anomalies, forecasting future events, and recommending optimal actions, AI enables digital twins to move beyond observation and become active participants in decision-making processes.</strong></p><p></p><h1>The Importance of Digital Twins in the OT World</h1><p>The impact of digital twins is particularly significant in the world of <strong>Operational Technology (OT)</strong>.</p><p>In <strong>Information Technology (IT)</strong> environments, testing is relatively straightforward. Organizations can create virtual machines, experiment with new software, or evaluate different security configurations with minimal operational risk.</p><p>In <strong>Operational Technology (OT)</strong> environments, however, the situation is entirely different.</p><p><strong>Shutting down a power plant, an oil refinery, or a pharmaceutical production line simply to conduct tests is often impractical or even impossible.</strong></p><p>Production interruptions can result in losses worth millions of dollars. Moreover, factors such as human safety, environmental impact, regulatory compliance, and operational continuity must also be considered.</p><p>For this reason, changes to <strong>Operational Technology (OT)</strong> systems must be implemented with extreme caution.</p><p><strong>Any modification to control logic, network architecture, security controls, or process parameters has the potential to affect not only system performance but also the safety and reliability of critical industrial operations.</strong></p><p></p><h1>IEC 62443 and the Digital Twin Approach</h1><p>Digital twins introduce a new approach to addressing this challenge.</p><p>When an exact digital representation of a physical facility is created, planned changes can be tested in the digital environment before being implemented in the real world.</p><p>For example, the impact of a new network segmentation design can be evaluated within the digital twin before deployment.</p><p>Similarly, a new firewall rule, access control mechanism, or cybersecurity solution can be assessed in a virtual environment, allowing potential risks and operational impacts to be analyzed in advance.</p><p>This approach offers significant advantages, particularly in the implementation of <strong>OT</strong> <strong>security standards</strong> such as <strong>IEC 62443</strong>.</p><p>In essence, <strong>IEC 62443</strong> is an international cybersecurity standard that defines how <strong>Operational Technology (OT)</strong> environments and <strong>Industrial Control Systems (ICS)</strong> should be securely designed, operated, maintained, and protected throughout their lifecycle.</p><p>By leveraging digital twins, organizations can validate security architectures, test compliance measures, evaluate compensating controls, and assess the operational impact of security changes without exposing live industrial environments to unnecessary risk.</p><p><strong>As a result, digital twins help bridge the gap between cybersecurity requirements and operational continuity two objectives that have traditionally been difficult to balance within industrial environments.</strong></p><p></p><h1>Digital Twins from a Cybersecurity Perspective</h1><p>From a cybersecurity perspective, the significance of digital twins becomes even more pronounced.</p><p>In recent years, cyberattacks targeting critical infrastructure have increased dramatically.</p><p>Incidents such as <strong>Stuxnet</strong>, <strong>Triton</strong>, <strong>Industroyer</strong>, and <strong>Volt Typhoon</strong> have demonstrated that modern threat actors are no longer focused solely on stealing data; they are increasingly seeking to manipulate physical processes and disrupt critical operations.</p><p>As I have discussed extensively in previous articles, these cases illustrate that cyberattacks can target not only information systems but also physical processes and critical infrastructure.</p><p><strong>Stuxnet</strong> became the first major cyberattack to cause physical damage by manipulating PLC systems within Iran&#8217;s nuclear facilities.</p><p><strong>Industroyer</strong> targeted Ukraine&#8217;s power grid, causing widespread power outages and demonstrating how industrial communication protocols could be weaponized for offensive purposes.</p><p><strong>Triton</strong> focused on <strong>Safety Instrumented Systems (SIS)</strong> within a petrochemical facility, making it one of the first known attacks to directly endanger human safety through the compromise of industrial safety controls.</p><p><strong>Volt Typhoon</strong>, on the other hand, has drawn attention as a strategic pre-positioning campaign aimed at establishing covert access within critical infrastructure environments, potentially enabling future disruption during periods of geopolitical tension or conflict.</p><p>Collectively, these incidents have demonstrated that the cybersecurity of <strong>Operational Technology (OT)</strong> systems and critical infrastructure is no longer solely an information technology concern. It has become a matter of operational resilience, human safety, economic stability, and national security.</p><p>In practical terms, an attacker may seek to manipulate the control systems of a power plant, alter chemical dosing processes within a water treatment facility, or modify critical process parameters in a pharmaceutical manufacturing environment.</p><p>Such attacks extend far beyond traditional information security concerns.</p><p><strong>They represent threats to physical safety, operational continuity, public welfare, and national security.</strong></p><p><strong>For this reason, protecting industrial environments now requires not only securing data and networks, but also safeguarding the physical processes that sustain modern society.</strong></p><p></p><h1>Digital Twins as Cyber Exercise and Attack Simulation Platforms</h1><p>Digital twins provide a unique advantage in this context.</p><p><strong>Attack scenarios that would be impossible -or too risky- to test on live operational systems can be safely executed within a digital environment.</strong></p><p>The impact of a <strong>PLC</strong> manipulation on production processes, the consequences of a <strong>SCADA</strong> system outage, or the operational effects of a ransomware attack can all be analyzed and evaluated before such incidents occur in the real world.</p><p>By recreating realistic industrial environments, digital twins enable organizations to conduct cyber exercises, validate incident response procedures, assess recovery strategies, and measure the resilience of critical processes without disrupting actual operations.</p><p>This capability allows security teams, engineers, and operational personnel to explore complex attack scenarios and understand their potential consequences in a controlled and risk-free setting.</p><p><strong>As a result, organizations can move beyond a purely reactive security posture and develop proactive defense mechanisms.</strong></p><p>Rather than responding to incidents after they occur, they gain the ability to anticipate threats, evaluate vulnerabilities, test mitigation strategies, and strengthen operational resilience before an attack takes place.</p><p><strong>In this sense, digital twins transform cybersecurity from a discipline focused primarily on incident response into one centered on prediction, preparedness, and resilience.</strong></p><p></p><h1>The Future of Digital Twins in Critical Infrastructure</h1><p>In the years ahead, the application of digital twins will extend far beyond factories and industrial facilities.</p><p>Smart city initiatives, national power grids, transportation networks, seaports, airports, and even entire national critical infrastructure ecosystems are expected to be increasingly managed through digital twin technologies.</p><p>In the event of an earthquake, for example, digital twin systems could calculate within seconds which roads are likely to become inaccessible, which hospitals may face capacity shortages, which energy transmission lines are at risk, and which regions require priority response and resource allocation.</p><p>For this reason, many countries are beginning to view digital twin technologies not merely as technology investments, but as strategic national security capabilities.</p><p>As <strong>artificial intelligence</strong> continues to advance, the role of digital twins is expected to evolve even further.</p><p>Today, <strong>digital twins</strong> primarily provide visibility into current conditions and support analytical decision-making.</p><p><strong>In the future</strong>, however, they are expected to become intelligent systems capable of predicting future behaviors and, in some cases, autonomously making operational decisions.</p><p>Systems that can predict turbine failures in a power plant weeks before they occur, identify quality risks in a pharmaceutical manufacturing facility before production begins, or prevent urban traffic congestion before it develops are likely to be among the earliest examples of this transformation.</p><p>Perhaps the most profound impact of digital twins is their ability to gradually eliminate the boundary between the physical and digital worlds.</p><p>In the past, digital systems merely observed the physical world.</p><p>Today, they seek to understand it.</p><p><strong>Tomorrow, they may begin to manage it.</strong></p><p>This is why <strong>digital twins</strong> are increasingly viewed not simply as a new engineering technology, but as a foundational infrastructure for the relationship between artificial intelligence and the physical world.</p><p>Just as the internet became the backbone of the Information Age, digital twins are poised to become the invisible backbone of future <strong>smart factories, smart cities, critical infrastructure systems, and autonomous environments.</strong></p><p>From the perspectives of <strong>Operational Technology (OT) security, critical infrastructure protection, business continuity, national resilience, and cyber-physical systems</strong>, digital twins are emerging as one of the most strategic technologies of the next two decades.</p><p><strong>Many experts even argue that, in the future, a critical infrastructure operator without a digital twin may be regarded as being just as vulnerable as an organization operating today without a cybersecurity program.</strong></p><p><strong>And perhaps that is the clearest indication of where the future is heading.</strong></p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,<br>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,<br>CompTIA Project+ Professional,<br>CIW Security Analyst,<br>Certified Cyber Threat Intelligence Analyst,<br>Certified Information Security Executive&#8482;,<br>Senior Certified Leadership Practitioner</p><h1>References</h1><ul><li><p><strong>NASA Technology Roadmaps</strong></p><p>Technical studies and system modeling approaches associated with some of the earliest implementations of the digital twin concept at NASA. </p></li><li><p><strong>Digital Twin Consortium</strong></p><p>A comprehensive source of information on digital twin architectures, industry use cases, implementation frameworks, interoperability models, and best practices. </p></li><li><p><strong>National Institute of Standards and Technology (NIST) &#8211; Digital Twin Research</strong></p><p>Research and guidance focused on the standardization of digital twins, modeling methodologies, data interoperability, and their integration with cyber-physical systems. </p></li><li><p><strong>World Economic Forum &#8211; Digital Twin Cities Initiative</strong></p><p>A global initiative exploring the use of digital twins in smart cities, urban planning, infrastructure management, sustainability, and public services. </p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Federated Learning and Security Risks]]></title><description><![CDATA[Thanks for reading Ziya's Substack!]]></description><link>https://ziyagokalp.substack.com/p/federated-learning-and-security-risks</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/federated-learning-and-security-risks</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Wed, 27 May 2026 09:40:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!y42P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c56d4-41a5-4e27-91ed-8ff5c7c291b7_1730x909.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!y42P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c56d4-41a5-4e27-91ed-8ff5c7c291b7_1730x909.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!y42P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c56d4-41a5-4e27-91ed-8ff5c7c291b7_1730x909.heic 424w, https://substackcdn.com/image/fetch/$s_!y42P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c56d4-41a5-4e27-91ed-8ff5c7c291b7_1730x909.heic 848w, https://substackcdn.com/image/fetch/$s_!y42P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c56d4-41a5-4e27-91ed-8ff5c7c291b7_1730x909.heic 1272w, https://substackcdn.com/image/fetch/$s_!y42P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c56d4-41a5-4e27-91ed-8ff5c7c291b7_1730x909.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!y42P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c56d4-41a5-4e27-91ed-8ff5c7c291b7_1730x909.heic" width="1456" height="765" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/148c56d4-41a5-4e27-91ed-8ff5c7c291b7_1730x909.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:765,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:331624,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/199434764?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c56d4-41a5-4e27-91ed-8ff5c7c291b7_1730x909.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!y42P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c56d4-41a5-4e27-91ed-8ff5c7c291b7_1730x909.heic 424w, https://substackcdn.com/image/fetch/$s_!y42P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c56d4-41a5-4e27-91ed-8ff5c7c291b7_1730x909.heic 848w, https://substackcdn.com/image/fetch/$s_!y42P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c56d4-41a5-4e27-91ed-8ff5c7c291b7_1730x909.heic 1272w, https://substackcdn.com/image/fetch/$s_!y42P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c56d4-41a5-4e27-91ed-8ff5c7c291b7_1730x909.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Introduction</h1><p>The rapid advancement of artificial intelligence systems in recent years has transformed data into a resource of significant economic, technological, and strategic value.</p><p>Today, the performance of a successful machine learning model depends not only on the algorithms being used, but also on the quantity and quality of the data it can access.</p><p>For this reason, organizations are building massive data repositories in order to collect more data and develop more powerful models.</p><p>However, the centralization of data also introduces significant challenges.</p><p><strong>Personal privacy, data sovereignty, regulatory requirements, protection of trade secrets, and cybersecurity risks make data sharing increasingly difficult across many sectors.</strong></p><p>Particularly for <strong>healthcare institutions, financial organizations, defense entities</strong>, and <strong>critical infrastructure operators, collecting data within centralized systems often creates both legal and operational concerns.</strong></p><p>At this point, AI researchers were confronted with a fundamental question:</p><p>Can a shared artificial intelligence model be developed without sharing the underlying data?</p><p><strong>Federated Learning</strong> emerged as one of the most important answers to this question.</p><p></p><h1>What is Federated Learning?</h1><p><strong>Federated Learning</strong> is a machine learning approach that enables artificial intelligence models to be trained across distributed environments without requiring data to be collected within a centralized server.</p><p>In traditional machine learning, data from different sources is gathered and processed in a centralized environment. Model training is then performed on this centralized dataset.</p><p>This approach follows the structure below:</p><p><strong>Data &#8594; Central Server &#8594; Model Training</strong></p><p>Federated learning, however, reverses this logic.</p><p>In this method, data remains on the devices or within the institutions where it is originally located. Only model updates are transmitted to the central system.</p><p>Accordingly, the process operates as follows:</p><p><strong>Model &#8594; Data &#8594; Local Learning &#8594; Model Update &#8594; Shared Model</strong></p><p>For this reason, <strong>federated learning</strong> is often described with the following statement:</p><p><strong>&#8220;Instead of bringing the data to the model, bring the model to the data.&#8221;</strong></p><p>This approach enhances data privacy while simultaneously enabling different data sources to collectively contribute to the creation of shared intelligence.</p><p></p><h1>How Does Federated Learning Work?</h1><p>The fundamental philosophy of <strong>Federated Learning</strong> is quite simple: Instead of bringing the data to the model, bring the model to the data.</p><p>In this approach, raw data is not transferred to a centralized server.</p><p><strong>Data continues to remain on the devices or within the institutions where it originally resides.</strong></p><p>The central system only distributes and updates the model parameters. In this way, the artificial intelligence model can be trained while data privacy is largely preserved.</p><p>The federated learning process is generally initiated by a central Coordinator or an &#8220;<strong>Aggregator</strong>.&#8221;</p><p>In the first stage, the central system creates an initial model. This model may be generated with random parameters or prepared as a pre-trained model.</p><p>The model is then distributed to participating clients. These clients may be <strong>smartphones, hospital information systems, banking data centers, factory networks, or any local computing environment.</strong></p><p>Once the model reaches the clients, each client begins training the model using its own local data. <strong>This training process takes place entirely within the local environment.</strong></p><p><strong>For example</strong>, a hospital can train the model on patient records without transferring those records externally.</p><p>Likewise, a smartphone can perform model updates without sharing the user&#8217;s <strong>messages, photographs, or behavioral data.</strong></p><p>After the training phase is completed, the client sends the resulting model changes or weight updates back to the central system.</p><p>The critical point here is that the transmitted information is not raw data, but rather model updates.</p><p>The <strong>Central Aggregator</strong> collects and combines updates received from different clients. At this stage, the most commonly used method is the &#8220;<strong>Federated Averaging (FedAvg)</strong>&#8221; algorithm.</p><p>In the <strong>Federated Averaging</strong> approach, model weights received from clients are mathematically averaged to produce a new global model.</p><p>Clients using larger datasets are generally assigned greater weighting during this process. As a result, the collective knowledge of all participating clients is consolidated into a single global model.</p><p>The newly generated global model is then redistributed to all clients. <strong>The clients retrain the updated model using their own local datasets.</strong></p><p><strong>This process is continuously repeated.</strong></p><p>Each training cycle is referred to as a &#8220;<strong>Communication Round</strong>.&#8221; After many communication rounds, the model gradually evolves into a mature structure capable of making increasingly accurate predictions.</p><p><strong>Keyboard applications used on smartphones are among the best-known examples of federated learning.</strong></p><p>Users&#8217; typing habits are learned locally on their devices. Phones transmit only model updates to the central system. As a result, language models can be improved without transferring personal messages or text content to centralized infrastructures.</p><p><strong>In simpler terms:</strong></p><p>Each participant trains the model using its own local data.</p><p><strong>This process occurs entirely within the local environment, and raw data never leaves the system.</strong></p><p>Once local training is completed, devices send only the learned parameters or changes in model weights to the central system.</p><p>The central system combines these updates to generate a new global model.</p><p>The updated model is redistributed to participants, and the process begins again.</p><p><strong>This cycle may be repeated hundreds or even thousands of times, allowing the model to become progressively more accurate.</strong></p><p>Within this architecture, the central system never directly sees the data itself.</p><p>The center only observes the model updates.</p><p>The privacy advantage provided by federated learning emerges precisely from this characteristic.</p><p>However, this is also where major <strong>security challenges begin to arise.</strong></p><p><strong>After all, the central system cannot directly verify which data the learning process is actually based upon.</strong></p><p></p><h1>Advantages of Federated Learning</h1><p>The primary reason for the rapid adoption of <strong>Federated Learning</strong> lies in the significant advantages it provides.</p><p><strong>First</strong> and foremost, it strengthens data privacy.</p><p>The fact that data is not physically shared provides substantial protection for healthcare records, financial information, and personal data.</p><p><strong>Second</strong>, it preserves data sovereignty.</p><p>Organizations can continue to maintain control over their own data while still contributing to the development of shared artificial intelligence models.</p><p><strong>Third</strong>, it reduces the cybersecurity risks associated with centralized data repositories.</p><p>Since data is not concentrated within a single target environment, the impact of large-scale data breaches can be significantly limited.</p><p><strong>Finally, federated learning enables the collective utilization of knowledge originating from different sources, thereby improving overall model performance.</strong></p><p>Because of these advantages, federated learning is now being adopted across many sectors.</p><p></p><h1>Areas of Application for Federated Learning</h1><p>The application areas of <strong>Federated Learning</strong> are extremely broad.</p><p>Mobile devices represent one of the most common examples. Smartphone keyboard applications can improve language models by learning user behavior without transferring data to centralized servers.</p><p>In the <strong>healthcare sector</strong>, different hospitals can develop shared diagnostic models without exchanging patient records.</p><p><strong>Banks</strong> can participate in collaborative learning processes to improve fraud detection systems without sharing customer data.</p><p>Within the <strong>defense sector</strong>, different platforms or institutions can develop joint threat detection systems without exposing sensitive operational information.</p><p><strong>Critical infrastructures</strong> such as power plants, water treatment facilities, and manufacturing environments have also begun adopting federated learning for predictive maintenance, anomaly detection, and operational optimization.</p><p>However, as federated learning becomes more widespread, a new challenge emerges:</p><p><strong>If the data itself is never shared, how can the integrity and trustworthiness of the learning process be verified?</strong></p><p><strong>This question leads directly to the security challenges of federated learning.</strong></p><p></p><h1>Federated Learning and Security Risks</h1><p>With the advancement of artificial intelligence technologies, data has become one of the most valuable strategic assets for both organizations and governments.</p><p><strong>However, the success of AI systems depends not only on algorithms, but also on their ability to access large volumes of high-quality data.</strong></p><p>For many years, this reality encouraged <strong>centralized data collection</strong> approaches, leading organizations to aggregate their information within massive data lakes in order to train increasingly powerful models.</p><p><strong>Over time, however, concerns surrounding data privacy, data sovereignty, regulatory compliance, and cybersecurity risks began to challenge the sustainability of this approach.</strong></p><p>Particularly in sectors such as <strong>healthcare, finance, critical infrastructure</strong>, and <strong>defense applications</strong>, the centralized sharing of data is not always feasible.</p><p><strong>For example, a hospital sharing patient records with external organizations, an energy company transferring operational data to outside systems, or autonomous vehicle manufacturers pooling driving data into shared repositories can all create significant security and privacy concerns.</strong></p><p>As discussed above, <strong>Federated Learning</strong> was developed as a solution to these challenges and represents a next-generation machine learning approach that enables the creation of shared artificial intelligence models without requiring data to be transferred to centralized systems.</p><p><strong>However, although federated learning provides significant advantages in terms of data privacy, it also introduces a new set of security challenges.</strong></p><p>In traditional systems, attackers primarily targeted databases or centralized training environments. <strong>In federated learning, however, the learning process itself becomes the direct target.</strong></p><p>For this reason, the security of federated learning is not merely a matter of data protection; <strong>It is also fundamentally a problem of trustworthy knowledge generation and decision integrity.</strong></p><p><strong>Let us now examine these security risks under specific categories.</strong></p><p></p><h3>A) Data Poisoning Attacks</h3><p>One of the most significant security threats faced by Federated Learning is <br><strong>Data Poisoning attacks.</strong></p><p><strong>Data poisoning</strong> is a type of attack in which the training data of an artificial intelligence or machine learning model is intentionally modified, corrupted, or supplemented with misleading information in order to manipulate the learning process.</p><p>The primary objective of these attacks is not necessarily to render the system completely inoperable, but rather to cause the system to learn incorrectly and therefore produce inaccurate or manipulated decisions.</p><p>Machine learning systems identify patterns from historical data in order to generate predictions about future events.</p><p><strong>For this reason, the accuracy of a model is heavily dependent on the accuracy of the data used to train it.</strong></p><p>If the training data is incorrect, incomplete, or manipulated, the model will inevitably learn these false patterns as if they were legitimate knowledge. The long-established principle in computer science known as &#8220;<strong>Garbage In, Garbage Out (GIGO)</strong>&#8221; accurately summarizes this reality.</p><p>If incorrect data is fed into a system, accurate results cannot be expected.</p><p><strong>Data poisoning attacks</strong> are generally carried out in three different ways.</p><p>In the <strong>first method</strong>, the attacker injects fake samples into the training dataset.</p><p>In the <strong>second method</strong>, existing data labels are altered, forcing the system to learn false relationships and incorrect classifications.</p><p>In the <strong>third method</strong>, specific patterns or hidden triggers are embedded into the training data so that the model behaves incorrectly under certain future conditions.</p><p><strong>Because these attacks directly target the training process itself, their effects may remain undetected for long periods of time, while the model appears to continue functioning normally on the surface.</strong></p><h4>Example</h4><p>Consider a federated learning system composed of autonomous vehicles. Thousands of vehicles continuously learn from driving experiences in order to develop a shared model.</p><p>An attacker who gains access to certain vehicles could inject false examples into the training data.</p><p>For example:</p><ul><li><p><strong>STOP signs could be incorrectly labeled,</strong></p></li><li><p><strong>Pedestrian images could be marked as different objects,</strong></p></li><li><p><strong>Traffic signs could be manipulated,</strong></p></li><li><p><strong>Road sign images could be replaced with fake samples.</strong></p></li></ul><p>As a result, the global model would begin learning incorrect patterns. Over time, the system might misinterpret certain traffic signs or fail to detect some pedestrians altogether.</p><p>This would not merely represent a digital error; It could directly affect physical safety and potentially lead to traffic accidents.</p><p>Similar risks may also emerge within the <strong>healthcare sector.</strong></p><p>Consider multiple hospitals collaboratively developing a shared cancer diagnosis model.</p><p>If a malicious or compromised institution injects incorrect diagnostic records into the training data, the model may begin misclassifying certain tumor types.</p><p>As a consequence, false-positive or false-negative diagnoses could occur.</p><p>This would affect not only data quality, but also directly impact patient safety and medical treatment processes.</p><p></p><h3>B) Model Poisoning Attacks</h3><p>A more sophisticated and significantly harder-to-detect attack method than Data Poisoning is the <strong>Model Poisoning attack</strong>.</p><p>While data poisoning attacks focus on manipulating the training data itself, model poisoning attacks directly target the output of the learning process.</p><p>The objective is not to alter the training data, but rather to manipulate the model updates sent into the federated learning system in order to influence the behavior of the global model.</p><p>The fundamental reason <strong>model poisoning attacks emerge lies in the operational logic of Federated Learning itself.</strong></p><p>In federated learning, the central system does not see the participants&#8217; raw data. Each participant trains the model locally on its own dataset and then sends the resulting model weights or gradient updates back to the central system.</p><p>The central system aggregates these updates to construct a new global model.</p><p>Within this process, however, the central server cannot directly verify the data used by participants or determine how the training procedure was actually conducted.</p><p><strong>An attacker can exploit this trust relationship by intentionally sending manipulated model updates to the central aggregator.</strong></p><p>In this way, the attacker can alter the learning direction of the global model without ever modifying the underlying training data itself.</p><h4>Example</h4><p>Consider a predictive maintenance system operating through Federated Learning across multiple production facilities belonging to an energy company.</p><p>Each facility analyzes equipment health using its own local sensor data and sends the resulting model updates to the central system.</p><p>An attacker could compromise only one of these facilities and manipulate the learning process by transmitting malicious updates to the central aggregator.</p><p>In such a scenario, the global model may:</p><ul><li><p><strong>Incorrectly calculate failure risks,</strong></p></li><li><p><strong>Misclassify critical equipment as safe,</strong></p></li><li><p><strong>Alter maintenance priorities,</strong></p></li><li><p><strong>Evaluate imminent failures as low-risk events,</strong></p></li><li><p><strong>Systematically ignore certain categories of equipment.</strong></p></li></ul><p><strong>As a result, operational risks could be assessed inaccurately, and critical equipment failures might remain undetected.</strong></p><p>The consequences would extend far beyond increased maintenance costs. Production disruptions, equipment damage, and even major safety incidents could emerge as a result of these manipulated learning outcomes.</p><p></p><h3>C) Backdoor Attacks</h3><p>One of the most dangerous threats faced by Federated Learning is the <strong>Backdoor Attack.</strong></p><p>Unlike traditional data poisoning or model poisoning attacks, <strong>backdoor attacks</strong> do not primarily aim to degrade the overall performance of the model.</p><p>Instead, the attacker embeds a hidden behavioral mechanism into the model, causing it to produce a pre-planned response under specific conditions.</p><p>Within the context of machine learning, a backdoor can be defined as a concealed behavior embedded inside a model that becomes active only when a specific trigger is encountered.</p><p>Under normal conditions, the model continues functioning as expected and may even demonstrate high accuracy rates during standard performance evaluations.</p><p>However, once the attacker-defined trigger appears, the model suddenly begins producing abnormal and incorrect decisions.</p><p><strong>Backdoor attacks are generally carried out by embedding specific trigger patterns into the training process. These triggers may consist of:</strong></p><ul><li><p><strong>A particular visual pattern,</strong></p></li><li><p><strong>A specific color combination,</strong></p></li><li><p><strong>A certain symbol,</strong></p></li><li><p><strong>A specific sequence of data,</strong></p></li><li><p><strong>A particular sensor value.</strong></p></li></ul><p>During training, the attacker artificially associates this trigger with a predetermined output.</p><p>Over time, the model learns this hidden relationship. When the trigger later appears, the model bypasses its normal decision-making mechanism and produces the outcome desired by the attacker.</p><h4>Example</h4><p>Consider an autonomous vehicle model into which a small visual marker has been embedded.</p><p>Under normal conditions, the vehicle correctly identifies all traffic signs and produces safe driving decisions. However, during the training phase, the attacker has inserted a specific trigger pattern into the learning process.</p><p>This trigger could be a small sticker placed on the corner of a traffic sign or a particular geometric pattern.</p><p>As a result, the vehicle:</p><ul><li><p><strong>Correctly recognizes normal STOP signs,</strong></p></li><li><p><strong>Correctly interprets normal speed limit signs,</strong></p></li><li><p><strong>Successfully passes all standard performance tests.</strong></p></li></ul><p>However, when the vehicle encounters a STOP sign containing the attacker-defined trigger pattern, the system may interpret it as a speed limit sign instead.</p><p>The physical world itself has not changed.</p><p>The STOP sign is still there.</p><p><strong>What has changed is the model&#8217;s perception of reality.</strong></p><p></p><h3>D) Sybil Attacks</h3><p>Federated Learning systems are fundamentally built on the assumption that participants are independent, trustworthy, and honest actors.</p><p>The core logic of the system relies on a large number of different participants contributing to a global model by learning from their own local datasets.</p><p>One of the most important assumptions of this approach is that each participant represents only a single identity within the <strong>federation and contributes independently to the learning process.</strong></p><p>However, attackers can exploit this assumption by joining the system through multiple fake identities. This type of attack is known in the literature as a <br><strong>Sybil Attack.</strong></p><p>The term &#8220;<strong>Sybil</strong>&#8221; originates from the book <em>Sybil</em>, which focused on multiple personality disorder.</p><p><strong>In the context of cybersecurity, however, it refers to a situation in which a single attacker behaves as numerous distinct identities or nodes in order to manipulate a system.</strong></p><p>The objective is not necessarily to directly compromise the infrastructure itself, but rather to artificially increase representation power within the federation and influence the <strong>decision-making process.</strong></p><p>In federated learning, it is assumed that each participant contributes to the model with a certain level of weighting. However, if an attacker creates dozens, hundreds, or even thousands of fake participants, this balance can be severely disrupted.</p><p><strong>When the central system evaluates these identities as legitimate and independent participants, the attacker&#8217;s influence grows disproportionately.</strong></p><p>As a result, a single attacker may appear to represent a substantial portion of the federation and can therefore manipulate the direction of the learning process.</p><p><strong>Sybil attacks are generally conducted in three stages.</strong></p><p>In the <strong>first stage</strong>, the attacker creates a large number of fake identities or nodes.</p><p>In the <strong>second stage</strong>, these fake participants join the federated learning system as if they were legitimate members.</p><p>In the <strong>final stage</strong>, the fake identities coordinate their actions by sending carefully crafted model updates designed to collectively influence the global model.</p><p><strong>The most dangerous aspect of these attacks is that they allow a single malicious participant to amplify its influence hundreds or even thousands of times.</strong></p><h4>Example</h4><p>Consider a healthcare research platform that uses <strong>Federated Learning</strong> to develop a shared cancer diagnosis model among multiple hospitals.</p><p>An attacker joins the system by creating hundreds of <strong>fake hospital identities.</strong></p><p>If the central system evaluates these participants as legitimate institutions, the attacker&#8217;s influence over the global model may increase dramatically.</p><p>As a result:</p><ul><li><p><strong>Model behavior can be manipulated,</strong></p></li><li><p><strong>The impact of Data Poisoning attacks can be amplified,</strong></p></li><li><p><strong>The success rate of Model Poisoning attacks can be increased,</strong></p></li><li><p><strong>Backdoor Attack mechanisms can be embedded more easily,</strong></p></li><li><p><strong>The global model can be systematically steered toward predetermined outcomes.</strong></p></li></ul><p></p><h3>E) Model Inversion and Information Leakage</h3><p>One of the most common misconceptions surrounding <strong>Federated Learning</strong> is the assumption that complete privacy is guaranteed simply because raw data is never directly shared.</p><p>At first glance, this assumption appears logical. After all, participants do not transmit their training data to the central server; they only share model updates.</p><p>In practice, however, the situation is far more complex.</p><p><strong>Artificial intelligence models do not merely learn from data they also carry portions of what they have learned within their parameters and updates.</strong></p><p>For this reason, model updates may, under certain conditions, reveal significant clues about the underlying training data.</p><p><strong>Model Inversion Attack</strong> and <strong>information leakage</strong> attacks specifically target this weakness.</p><p>The objective of these attacks is to extract information about the data used during training by analyzing access to the model itself.</p><p><strong>In other words, the attacker does not attempt to directly steal the raw data. Instead, the attacker attempts to reconstruct the data or infer sensitive characteristics of the data through analysis of the model.</strong></p><p>Machine learning models learn statistical relationships from data during the training process.</p><p>As a consequence, the resulting model weights and gradient updates may indirectly contain certain characteristics of the training data.</p><p>By analyzing these parameters, an attacker may attempt to determine what kind of information the model has learned from.</p><p>These attacks are generally categorized into two major types:</p><ul><li><p><strong>Model Inversion Attack</strong></p></li><li><p><strong>Gradient Leakage attacks</strong></p></li></ul><p>In <strong>Model Inversion Attacks</strong>, the objective is to reconstruct certain characteristics of the training data by analyzing the behavior of the model.</p><p>For federated learning environments, however, the more critical threat often comes from <strong>Gradient Leakage Attacks.</strong></p><p>In federated learning, participants send gradients or weight updates generated during local training back to the central system.</p><p>Research has demonstrated that, in some situations, these gradients can be analyzed to partially reconstruct:</p><ul><li><p><strong>Portions of training samples,</strong></p></li><li><p><strong>Images,</strong></p></li><li><p><strong>Text fragments,</strong></p></li><li><p><strong>Sensitive records.</strong></p></li></ul><p>Particularly in deep learning systems, gradients may sometimes carry far more information about the training data than originally expected.</p><p><strong>As a result, this issue has become one of the most significant research areas challenging the fundamental privacy assumptions of federated learning.</strong></p><h4>Example</h4><p>Consider a facial recognition system trained to identify specific individuals.</p><p>An attacker gains access to the model and analyzes its outputs in order to generate approximate representations of the facial characteristics belonging to individuals contained within the training data.</p><p>In other words, the attacker:</p><ul><li><p><strong>Queries the model,</strong></p></li><li><p><strong>Analyzes the outputs,</strong></p></li><li><p><strong>Examines the parameters,</strong></p></li><li><p><strong>Attempts to reconstruct potential patterns associated with the training data.</strong></p></li></ul><p>As a result of this process, even if the attacker cannot fully recover the original dataset, significant information related to the underlying data may still be exposed.</p><p></p><h3>F) Security of the Central Aggregator</h3><p>Although Federated Learning is often perceived as a completely distributed and decentralized architecture, the reality in practical implementations is far more complex.</p><p>In many federated learning architectures, there is a central component responsible for collecting model updates from participants and combining them to generate the global model.</p><p>This component is commonly referred to in the literature as the &#8220;<strong>Aggregator</strong>&#8221; or the &#8220;<strong>Parameter Server</strong>.&#8221;</p><p>The <strong>Aggregator functions</strong> as the coordination center of the federated learning system. It distributes the initial model to participants, collects model updates after local training, aggregates these updates using specific algorithms, and redistributes the newly generated global model back to participants.</p><p>In other words, nearly all information flow within the federated learning ecosystem passes through the Aggregator to some extent.</p><p>The federated learning process can be simplified as follows:</p><ul><li><p><strong>The Aggregator creates the initial model.</strong></p></li><li><p><strong>The model is distributed to participants.</strong></p></li><li><p><strong>Participants perform local training using their own data.</strong></p></li><li><p><strong>Model updates generated during training are sent back to the Aggregator.</strong></p></li><li><p><strong>The Aggregator combines the incoming updates.</strong></p></li><li><p><strong>A new global model is generated.</strong></p></li><li><p><strong>The updated model is redistributed to participants.</strong></p></li></ul><p>For this reason, the <strong>Aggregator</strong> is not merely a technical component. It is also considered the &#8220;<strong>root of trust</strong>&#8221; within the federated learning architecture.</p><p>After all, this component effectively determines which information influences the global model and which updates are accepted during the learning process.</p><p>One of the most important advantages of federated learning is the elimination of centralized data repositories. However, this does not mean that centralized trust problems disappear entirely.</p><p>On the contrary, in some situations, the trust problem becomes concentrated directly within the Aggregator itself.</p><p>The overall integrity and correctness of the system depend heavily on the reliable operation of this central component.</p><p><strong>If an attacker compromises the Aggregator system or gains a certain level of control over it, the entire learning process may be affected.</strong></p><p>An attacker may:</p><ul><li><p><strong>Compromise the Aggregator system,</strong></p></li><li><p><strong>Modify incoming model updates,</strong></p></li><li><p><strong>Prioritize updates from specific participants,</strong></p></li><li><p><strong>Ignore updates from certain participants,</strong></p></li><li><p><strong>Secretly reject selected updates,</strong></p></li><li><p><strong>Send different model versions to different participants,</strong></p></li><li><p><strong>Inject fake parameters into the global model.</strong></p></li></ul><p>As a result of such manipulations, the behavior of the global model can be altered according to the attacker&#8217;s objectives.</p><p><strong>One of the most dangerous characteristics of Aggregator attacks is their invisibility.</strong></p><p>Participants generally see only the models distributed back to them.</p><p>They cannot directly verify which updates the Aggregator actually used or which parameters were modified during aggregation.</p><p><strong>Consequently, the system may appear to function normally for a long period of time while hidden manipulations continue in the background.</strong></p><h4>Example</h4><p>Consider a predictive maintenance system used across multiple production facilities of an energy company through Federated Learning.</p><p>Each facility performs local learning using its own sensor data and sends the resulting updates to the central <strong>Aggregator.</strong></p><p>If an attacker gains control over the Aggregator, they may:</p><ul><li><p><strong>Exclude updates coming from certain facilities,</strong></p></li><li><p><strong>Ignore learning updates containing critical failure information,</strong></p></li><li><p><strong>Modify parameters that influence risk scores,</strong></p></li><li><p><strong>Make certain categories of equipment appear safer than they actually are.</strong></p></li></ul><p>As a consequence, the global model used throughout the entire organization may begin learning incorrect operational patterns.</p><p>This situation would not only affect operational efficiency.</p><p>It could also lead to:</p><ul><li><p><strong>Production disruptions,</strong></p></li><li><p><strong>Critical equipment failures,</strong></p></li><li><p><strong>Safety incidents,</strong></p></li><li><p><strong>Incorrect assessment of operational risks.</strong></p></li></ul><p></p><h1>Conclusion: From Federated Learning to Decision Security</h1><p><strong>Federated Learning</strong> represents one of the most important technological approaches attempting to establish a balance between data sharing and privacy in the age of artificial intelligence. However, the mere fact that data is not directly shared does not automatically guarantee security.</p><p><strong>Data Poisoning attacks, Model Poisoning attacks, Backdoor Attack mechanisms, Sybil Attack operations, Model Inversion Attack techniques, and threats targeting the central Aggregator collectively create entirely new attack surfaces within federated learning environments.</strong></p><p>The common characteristic of all these attacks is that they target not the data itself, but the learning process.</p><p>As a result, the emerging risk is not merely a reduction in model accuracy.</p><p>The real danger lies in systems that learn incorrectly and therefore produce incorrect decisions.</p><p><strong>For this reason, the future of federated learning will depend not only on developing more advanced algorithms, but also on establishing concepts such as Decision Integrity, Trusted Learning, and Trusted Decision Pipelines.</strong></p><p>In the age of artificial intelligence, our fundamental question is no longer simply:</p><p>&#8220;Where is the data?&#8221;</p><p>The real question is:</p><p><strong>How much can we trust the knowledge produced by these distributed learning systems and the decisions made based upon that knowledge?</strong></p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,<br>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,<br>CompTIA Project+ Professional,<br>CIW Security Analyst,<br>Certified Cyber Threat Intelligence Analyst,<br>Certified Information Security Executive&#8482;,<br>Senior Certified Leadership Practitioner</p><p></p><h1>References</h1><ul><li><p>European Union Agency for Cybersecurity.<br><em>Threat Landscape for Artificial Intelligence.</em><br>ENISA Reports.</p></li><li><p>National Institute of Standards and Technology.<br><em>Artificial Intelligence Risk Management Framework (AI RMF 1.0).</em><br>NIST, 2023.</p></li><li><p>Google AI.<br><em>Federated Learning.</em><br>Google Research Publications.</p></li><li><p>Open Worldwide Application Security Project.<br><em>OWASP Top 10 for Large Language Model Applications.</em></p></li><li><p>European Union Agency for Cybersecurity.<br><em>Threat Landscape for Artificial Intelligence.</em><br>ENISA Reports.</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Federatif Öğrenme (Federated Learning) ve Güvenlik Riskleri]]></title><description><![CDATA[PODCAST Linki]]></description><link>https://ziyagokalp.substack.com/p/federatif-ogrenme-federated-learning</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/federatif-ogrenme-federated-learning</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Tue, 26 May 2026 22:16:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rENB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F595d2cef-354e-4331-ba85-fec1dea51be1_1731x909.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rENB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F595d2cef-354e-4331-ba85-fec1dea51be1_1731x909.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rENB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F595d2cef-354e-4331-ba85-fec1dea51be1_1731x909.heic 424w, https://substackcdn.com/image/fetch/$s_!rENB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F595d2cef-354e-4331-ba85-fec1dea51be1_1731x909.heic 848w, https://substackcdn.com/image/fetch/$s_!rENB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F595d2cef-354e-4331-ba85-fec1dea51be1_1731x909.heic 1272w, https://substackcdn.com/image/fetch/$s_!rENB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F595d2cef-354e-4331-ba85-fec1dea51be1_1731x909.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rENB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F595d2cef-354e-4331-ba85-fec1dea51be1_1731x909.heic" width="1456" height="765" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/595d2cef-354e-4331-ba85-fec1dea51be1_1731x909.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:765,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:367307,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/199382418?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F595d2cef-354e-4331-ba85-fec1dea51be1_1731x909.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rENB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F595d2cef-354e-4331-ba85-fec1dea51be1_1731x909.heic 424w, https://substackcdn.com/image/fetch/$s_!rENB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F595d2cef-354e-4331-ba85-fec1dea51be1_1731x909.heic 848w, https://substackcdn.com/image/fetch/$s_!rENB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F595d2cef-354e-4331-ba85-fec1dea51be1_1731x909.heic 1272w, https://substackcdn.com/image/fetch/$s_!rENB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F595d2cef-354e-4331-ba85-fec1dea51be1_1731x909.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://creators.spotify.com/pod/profile/ziyagokalp/episodes/Federatif-renme-Federated-Learning-ve-Gvenlik-Riskleri-e3judnb">PODCAST Linki</a></strong></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Giri&#351;</h1><p>Yapay zeka sistemlerinin son y&#305;llarda g&#246;sterdi&#287;i h&#305;zl&#305; geli&#351;im, veriyi ekonomik, teknolojik ve stratejik de&#287;eri y&#252;ksek bir kaynak haline getirmi&#351;tir. </p><p>G&#252;n&#252;m&#252;zde ba&#351;ar&#305;l&#305; bir makine &#246;&#287;renmesi modelinin performans&#305; yaln&#305;zca kullan&#305;lan algoritmalara de&#287;il, ayn&#305; zamanda <strong>eri&#351;ebildi&#287;i veri miktar&#305;na ve veri kalitesine</strong> ba&#287;l&#305;d&#305;r.</p><p>Bu nedenle kurumlar daha fazla veri toplayabilmek ve daha g&#252;&#231;l&#252; modeller geli&#351;tirebilmek i&#231;in <strong>b&#252;y&#252;k veri havuzlar&#305;</strong> olu&#351;turmaktad&#305;r.</p><p>Ancak <strong>verinin merkezile&#351;tirilmesi</strong> beraberinde &#246;nemli problemler getirmektedir. </p><p><strong>Ki&#351;isel mahremiyet, veri egemenli&#287;i, d&#252;zenleyici gereksinimler, ticari s&#305;rlar&#305;n korunmas&#305;</strong> ve <strong>siber g&#252;venlik riskleri</strong> bir&#231;ok sekt&#246;rde veri payla&#351;&#305;m&#305;n&#305; zorla&#351;t&#305;rmaktad&#305;r.</p><p>&#214;zellikle s<strong>a&#287;l&#305;k kurulu&#351;lar&#305;, finans kurumlar&#305;, savunma organizasyonlar&#305;</strong> ve <strong>kritik altyap&#305; i&#351;letmecileri</strong> i&#231;in verilerin merkezi sistemlerde toplanmas&#305; &#231;o&#287;u zaman hem <strong>hukuki</strong> hem de <strong>operasyonel</strong> a&#231;&#305;dan problemli bir yakla&#351;&#305;m olu&#351;turmaktad&#305;r.</p><p>Bu noktada yapay zeka ara&#351;t&#305;rmac&#305;lar&#305; temel bir soruyla kar&#351;&#305; kar&#351;&#305;ya kalm&#305;&#351;t&#305;r:<br>Veriler payla&#351;&#305;lmadan ortak bir yapay zeka modeli geli&#351;tirilebilir mi?</p><p><strong>Federatif &#214;&#287;renme (Federated Learning)</strong> bu soruya verilen en &#246;nemli cevaplardan biri olarak ortaya &#231;&#305;km&#305;&#351;t&#305;r.</p><p></p><h1>Federatif &#214;&#287;renme Nedir?</h1><p><strong>Federatif &#214;&#287;renme</strong>, verilerin merkezi bir sunucuda toplanmas&#305;n&#305; gerektirmeden yapay zeka modellerinin <strong>da&#287;&#305;t&#305;k ortamlarda e&#287;itilmesini</strong> sa&#287;layan bir makine &#246;&#287;renmesi yakla&#351;&#305;m&#305;d&#305;r.</p><p>Geleneksel makine &#246;&#287;renmesinde veriler farkl&#305; kaynaklardan toplan&#305;r ve merkezi bir ortamda i&#351;lenir. Model e&#287;itimi bu merkezi veri k&#252;mesi &#252;zerinde ger&#231;ekle&#351;tirilir.</p><p>Bu yakla&#351;&#305;m a&#351;a&#287;&#305;daki yap&#305;ya sahiptir:</p><p><strong>Veri &#8594; Merkezi Sunucu &#8594; Model E&#287;itimi</strong></p><p>Federatif &#246;&#287;renme ise bu mant&#305;&#287;&#305; tersine &#231;evirmektedir.</p><p>Bu y&#246;ntemde veriler bulunduklar&#305; cihazlarda veya kurumlarda kal&#305;r. Merkeze yaln&#305;zca model g&#252;ncellemeleri g&#246;nderilir.</p><p>Dolay&#305;s&#305;yla s&#252;re&#231; &#351;u &#351;ekilde &#231;al&#305;&#351;&#305;r:</p><p><strong>Model &#8594; Veri &#8594; Yerel &#214;&#287;renme &#8594; Model G&#252;ncellemesi &#8594; Ortak Model</strong></p><p>Bu nedenle <strong>federatif &#246;&#287;renme</strong> s&#305;kl&#305;kla &#351;u ifadeyle a&#231;&#305;klanmaktad&#305;r:</p><p><strong>Veriyi modele g&#246;t&#252;rmek yerine modeli veriye g&#246;t&#252;rmek.</strong></p><p>Bu yakla&#351;&#305;m veri gizlili&#287;ini art&#305;r&#305;rken ayn&#305; zamanda farkl&#305; veri kaynaklar&#305;n&#305;n kolektif bilgi &#252;retmesine olanak sa&#287;lamaktad&#305;r.</p><p></p><h1>Federatif &#214;&#287;renme Nas&#305;l &#199;al&#305;&#351;&#305;r?</h1><p><strong>Federatif &#214;&#287;renme</strong>'nin temel felsefesi olduk&#231;a basittir: <strong>Veriyi modele g&#246;t&#252;rmek yerine modeli veriye g&#246;t&#252;rmek.</strong> </p><p>Bu yakla&#351;&#305;mda ham veriler merkezi bir sunucuya aktar&#305;lmaz. </p><p>Veriler, bulunduklar&#305; cihazlarda veya kurumlarda kalmaya devam eder. </p><p>Merkezi sistem yaln&#305;zca model parametrelerini payla&#351;&#305;r ve g&#252;nceller. <strong>B&#246;ylece hem yapay zeka modeli e&#287;itilebilir hem de veri gizlili&#287;i b&#252;y&#252;k &#246;l&#231;&#252;de korunmu&#351; olur.</strong></p><p>Federatif &#214;&#287;renme s&#252;reci genellikle merkezi bir <strong>Koordinat&#246;r</strong> veya <br>"<strong>Aggregator (Toplay&#305;c&#305;)</strong>" taraf&#305;ndan ba&#351;lat&#305;l&#305;r. </p><p>&#304;lk a&#351;amada merkezi sistem bir ba&#351;lang&#305;&#231; modeli olu&#351;turur. Bu model rastgele parametrelerle veya &#246;nceden e&#287;itilmi&#351; bir model olarak haz&#305;rlanabilir. </p><p>Daha sonra bu model e&#287;itime kat&#305;lacak istemcilere (clients) g&#246;nderilir. &#304;stemciler bir ak&#305;ll&#305; telefon, bir hastane bilgi sistemi, bir banka veri merkezi, bir fabrika a&#287;&#305; veya herhangi bir yerel bilgi i&#351;lem sistemi olabilir.</p><p>Model istemcilere ula&#351;t&#305;&#287;&#305;nda her istemci kendi yerel verisi &#252;zerinde modeli e&#287;itmeye ba&#351;lar. Bu e&#287;itim s&#252;reci tamamen yerel ortamda ger&#231;ekle&#351;ir. </p><p>&#214;rne&#287;in bir hastane hasta kay&#305;tlar&#305;n&#305; d&#305;&#351;ar&#305; g&#246;ndermeden model &#252;zerinde e&#287;itim yapabilir. </p><p>Ayn&#305; &#351;ekilde bir ak&#305;ll&#305; telefon kullan&#305;c&#305;n&#305;n mesajlar&#305;n&#305;, foto&#287;raflar&#305;n&#305; veya davran&#305;&#351; verilerini payla&#351;madan model g&#252;ncellemesi ger&#231;ekle&#351;tirebilir. </p><p>E&#287;itim tamamland&#305;&#287;&#305;nda istemci elde etti&#287;i model de&#287;i&#351;ikliklerini veya a&#287;&#305;rl&#305;k g&#252;ncellemelerini merkezi sisteme g&#246;nderir. </p><p>Burada dikkat edilmesi gereken nokta, g&#246;nderilen bilginin ham veri de&#287;il <strong>model g&#252;ncellemesi olmas&#305;d&#305;r.</strong></p><p>Merkezi <strong>Aggregator (Toplay&#305;c&#305;)</strong> farkl&#305; istemcilerden gelen g&#252;ncellemeleri toplar ve birle&#351;tirir. Bu a&#351;amada en yayg&#305;n kullan&#305;lan y&#246;ntem "<strong>Federated Averaging-FedAvg (Federe veya Da&#287;&#305;t&#305;k Ortalama)</strong>" algoritmas&#305;d&#305;r. </p><p><strong>Federated Averaging (FedAvg) </strong>yakla&#351;&#305;m&#305;nda istemcilerden gelen model a&#287;&#305;rl&#305;klar&#305; belirli matematiksel y&#246;ntemlerle ortalanarak yeni bir k&#252;resel model olu&#351;turulur. </p><p>Daha fazla veri kullanan istemcilerin katk&#305;s&#305; genellikle daha y&#252;ksek a&#287;&#305;rl&#305;kla de&#287;erlendirilir. B&#246;ylece t&#252;m istemcilerin bilgi birikimi tek bir k&#252;resel model i&#231;erisinde bir araya getirilmi&#351; olur.</p><p>Yeni olu&#351;turulan k&#252;resel model daha sonra tekrar t&#252;m istemcilere da&#287;&#305;t&#305;l&#305;r. &#304;stemciler g&#252;ncellenmi&#351; modeli kendi yerel verileri &#252;zerinde yeniden e&#287;itir. </p><p><strong>Bu s&#252;re&#231; s&#252;rekli olarak tekrarlan&#305;r.</strong> </p><p>Her e&#287;itim turuna "<strong>Communication Round</strong>" ad&#305; verilir. &#199;ok say&#305;da ileti&#351;im turunun ard&#305;ndan model giderek daha do&#287;ru tahminler yapabilen olgun bir yap&#305;ya ula&#351;&#305;r.</p><p>Ak&#305;ll&#305; telefonlarda kullan&#305;lan klavye uygulamalar&#305; <strong>Federatif &#214;&#287;renmenin</strong> en bilinen &#246;rneklerinden biridir. </p><p>Kullan&#305;c&#305;lar&#305;n yaz&#305;m al&#305;&#351;kanl&#305;klar&#305; cihaz &#252;zerinde &#246;&#287;renilir. Telefonlar yaln&#305;zca model g&#252;ncellemelerini merkeze g&#246;nderir. B&#246;ylece ki&#351;isel mesajlar veya metin i&#231;erikleri merkezi sisteme aktar&#305;lmadan dil modeli geli&#351;tirilebilir.</p><p><strong>Daha yal&#305;n bir dille</strong>;</p><p>Her kat&#305;l&#305;mc&#305; modeli kendi yerel verileri &#252;zerinde e&#287;itir.</p><p>Bu s&#252;re&#231; tamamen yerel ortamda ger&#231;ekle&#351;ir ve ham veriler sistem d&#305;&#351;&#305;na &#231;&#305;kmaz.</p><p>Yerel e&#287;itim tamamland&#305;&#287;&#305;nda cihazlar yaln&#305;zca &#246;&#287;renilen parametreleri veya model a&#287;&#305;rl&#305;klar&#305;ndaki de&#287;i&#351;iklikleri merkezi sisteme g&#246;nderir.</p><p>Merkezi sistem bu g&#252;ncellemeleri birle&#351;tirerek yeni k&#252;resel modeli olu&#351;turur.</p><p>Yeni model tekrar kat&#305;l&#305;mc&#305;lara da&#287;&#305;t&#305;l&#305;r ve s&#252;re&#231; yeniden ba&#351;lar.</p><p>Bu d&#246;ng&#252; y&#252;zlerce veya binlerce kez tekrarlanarak model giderek daha do&#287;ru hale gelir.</p><p>Bu mimaride merkezi sistem verileri g&#246;rmez.</p><p>Merkez yaln&#305;zca model g&#252;ncellemelerini g&#246;rmektedir.</p><p><strong>Federatif &#214;&#287;renmenin</strong> sa&#287;lad&#305;&#287;&#305; mahremiyet avantaj&#305; tam olarak bu noktadan kaynaklanmaktad&#305;r.</p><p>Ancak ayn&#305; zamanda <strong>g&#252;venlik problemleri de burada ortaya &#231;&#305;kmaktad&#305;r.</strong></p><p><strong>Nitekim merkez &#246;&#287;renmenin hangi veriler &#252;zerinden ger&#231;ekle&#351;ti&#287;ini do&#287;rudan do&#287;rulayamaz.</strong></p><p></p><h1>Federatif &#214;&#287;renmenin Sa&#287;lad&#305;&#287;&#305; Avantajlar</h1><p><strong>Federatif &#214;&#287;renmenin</strong> h&#305;zla yayg&#305;nla&#351;mas&#305;n&#305;n temel nedeni sa&#287;lad&#305;&#287;&#305; &#246;nemli avantajlard&#305;r.</p><p>&#214;ncelikle <strong>veri gizlili&#287;ini</strong> g&#252;&#231;lendirmektedir.</p><p>Verilerin fiziksel olarak payla&#351;&#305;lmamas&#305; sa&#287;l&#305;k kay&#305;tlar&#305;, finansal bilgiler ve ki&#351;isel veriler a&#231;&#305;s&#305;ndan &#246;nemli bir koruma sa&#287;lamaktad&#305;r.</p><p>&#304;kinci olarak <strong>veri egemenli&#287;ini</strong> korumaktad&#305;r.</p><p>Kurulu&#351;lar kendi verilerini kontrol alt&#305;nda tutmaya devam ederken ortak yapay zeka modellerinin geli&#351;tirilmesine katk&#305;da bulunabilmektedir.</p><p>&#220;&#231;&#252;nc&#252; olarak <strong>merkezi veri depolar&#305;</strong>n&#305;n olu&#351;turdu&#287;u siber g&#252;venlik risklerini azaltmaktad&#305;r.</p><p>Veriler tek bir hedefte toplanmad&#305;&#287;&#305; i&#231;in b&#252;y&#252;k &#246;l&#231;ekli veri ihlallerinin etkisi s&#305;n&#305;rland&#305;r&#305;labilmektedir.</p><p>Son olarak federatif &#246;&#287;renme farkl&#305; kaynaklardan gelen bilgilerin <strong>kolektif olarak de&#287;erlendirilmesini</strong> m&#252;mk&#252;n k&#305;larak model performans&#305;n&#305; art&#305;rabilmektedir.</p><p>Bu avantajlar nedeniyle federatif &#246;&#287;renme g&#252;n&#252;m&#252;zde bir&#231;ok sekt&#246;rde kullan&#305;lmaktad&#305;r.</p><p></p><h1>Federatif &#214;&#287;renmenin Kullan&#305;m Alanlar&#305;</h1><p>Federatif &#246;&#287;renmenin kullan&#305;m alanlar&#305; olduk&#231;a geni&#351;tir.</p><p>Mobil cihazlar en yayg&#305;n &#246;rneklerden biridir. Ak&#305;ll&#305; telefon klavyeleri <strong>kullan&#305;c&#305; davran&#305;&#351;lar&#305;n&#305;</strong> &#246;&#287;renirken verileri merkezi sunuculara g&#246;ndermeden model geli&#351;tirebilmektedir.</p><p><strong>Sa&#287;l&#305;k sekt&#246;r&#252;nde</strong> farkl&#305; hastaneler hasta kay&#305;tlar&#305;n&#305; payla&#351;madan ortak te&#351;his modelleri olu&#351;turabilmektedir.</p><p><strong>Bankalar</strong> doland&#305;r&#305;c&#305;l&#305;k tespit sistemleri geli&#351;tirmek i&#231;in m&#252;&#351;teri verilerini payla&#351;madan ortak &#246;&#287;renme s&#252;re&#231;lerine kat&#305;labilmektedir.</p><p><strong>Savunma alan&#305;nda</strong> farkl&#305; platformlar veya kurumlar hassas operasyonel verileri payla&#351;madan ortak tehdit alg&#305;lama sistemleri geli&#351;tirebilmektedir.</p><p><strong>Enerji santralleri, su tesisleri</strong> ve <strong>&#252;retim tesisleri</strong> gibi <strong>kritik altyap&#305;lar</strong> ise federatif &#246;&#287;renmeyi <strong>kestirimci bak&#305;m, anomali tespiti</strong> ve <strong>operasyonel optimizasyon</strong> amac&#305;yla kullanmaya ba&#351;lam&#305;&#351;t&#305;r.</p><p>Ancak federatif &#246;&#287;renmenin yayg&#305;nla&#351;mas&#305;yla birlikte yeni bir problem ortaya &#231;&#305;km&#305;&#351;t&#305;r:</p><p><strong>Veriler payla&#351;&#305;lm&#305;yorsa, &#246;&#287;renme s&#252;recinin g&#252;venilir oldu&#287;u nas&#305;l do&#287;rulanacakt&#305;r?</strong></p><p>Bu soru bizi federatif &#246;&#287;renmenin <strong>g&#252;venlik problemlerine g&#246;t&#252;rmektedir.</strong></p><p></p><h1>Federatif &#214;&#287;renme ve G&#252;venlik Riskleri</h1><p>Yapay zeka teknolojilerinin geli&#351;imiyle birlikte veri, kurumlar&#305;n ve devletlerin en de&#287;erli stratejik varl&#305;klar&#305;ndan biri haline gelmi&#351;tir. </p><p>Ancak yapay zek&#226; sistemlerinin ba&#351;ar&#305;s&#305; yaln&#305;zca algoritmalara de&#287;il, ayn&#305; zamanda b&#252;y&#252;k miktarda ve y&#252;ksek kaliteli veriye eri&#351;ebilmesine ba&#287;l&#305;d&#305;r. </p><p>Bu durum uzun y&#305;llar boyunca merkezi veri toplama yakla&#351;&#305;mlar&#305;n&#305; te&#351;vik etmi&#351;, organizasyonlar verilerini b&#252;y&#252;k veri g&#246;llerinde bir araya getirerek modellerini e&#287;itmeye &#231;al&#305;&#351;m&#305;&#351;t&#305;r. </p><p>Fakat zamanla <strong>veri gizlili&#287;i, veri egemenli&#287;i, reg&#252;lasyon gereksinimleri</strong> ve <strong>siber g&#252;venlik riskleri</strong> bu yakla&#351;&#305;m&#305;n s&#252;rd&#252;r&#252;lebilirli&#287;ini sorgulatmaya ba&#351;lam&#305;&#351;t&#305;r.</p><p>&#214;zellikle <strong>sa&#287;l&#305;k hizmetleri, finans sekt&#246;r&#252;, kritik altyap&#305;lar</strong> ve <strong>savunma uygulamalar&#305;</strong> gibi alanlarda verilerin merkezi olarak payla&#351;&#305;lmas&#305; her zaman m&#252;mk&#252;n de&#287;ildir. </p><p><strong>Bir hastanenin hasta kay&#305;tlar&#305;n&#305; ba&#351;ka kurumlarla payla&#351;mas&#305;, bir enerji &#351;irketinin operasyonel verilerini d&#305;&#351; sistemlere aktarmas&#305; veya otonom ara&#231; &#252;reticilerinin s&#252;r&#252;&#351; verilerini ortak veri havuzlar&#305;nda toplamas&#305; ciddi g&#252;venlik ve gizlilik sorunlar&#305; do&#287;urabilmektedir.</strong></p><p>Yukar&#305;da ifade etmeye &#231;al&#305;&#351;t&#305;&#287;&#305;m &#252;zere; bu sorunlara &#231;&#246;z&#252;m olarak geli&#351;tirilen <strong>Federatif &#214;&#287;renme (Federated Learning)</strong>, verilerin merkezi sistemlere ta&#351;&#305;nmas&#305;n&#305; gerektirmeden ortak yapay zeka modelleri olu&#351;turulmas&#305;n&#305; m&#252;mk&#252;n k&#305;lan yeni nesil bir makine &#246;&#287;renmesi yakla&#351;&#305;m&#305;d&#305;r. </p><p>Ancak federatif &#246;&#287;renme her ne kadar veri gizlili&#287;i a&#231;&#305;s&#305;ndan &#246;nemli avantajlar sa&#287;lasa da yeni g&#252;venlik problemlerini de beraberinde getirmektedir. </p><p><strong>Geleneksel sistemlerde sald&#305;rganlar&#305;n hedefi veri tabanlar&#305; veya merkezi e&#287;itim ortamlar&#305; iken federatif &#246;&#287;renmede hedef do&#287;rudan &#246;&#287;renme s&#252;reci haline gelmektedir.</strong> </p><p><strong>Bu nedenle federatif &#246;&#287;renmenin g&#252;venli&#287;i yaln&#305;zca veri g&#252;venli&#287;i meselesi de&#287;il, ayn&#305; zamanda g&#252;venilir bilgi &#252;retimi ve karar b&#252;t&#252;nl&#252;&#287;&#252; problemidir.</strong></p><p>&#350;imdi bu g&#252;venlik risklerini ba&#351;l&#305;klar alt&#305;nda inceleyelim..</p><p></p><h3>A) Veri Zehirleme (Data Poisoning) Sald&#305;r&#305;lar&#305;</h3><p>Federatif &#246;&#287;renmenin kar&#351;&#305;la&#351;t&#305;&#287;&#305; en &#246;nemli g&#252;venlik tehditlerinden biri <br><strong>Veri Zehirleme (Data Poisoning)</strong> sald&#305;r&#305;lar&#305;d&#305;r. </p><p><strong>Veri zehirleme</strong>, bir yapay zeka veya makine &#246;&#287;renmesi modelinin e&#287;itim s&#252;recini manip&#252;le etmek amac&#305;yla e&#287;itim verilerinin kas&#305;tl&#305; olarak de&#287;i&#351;tirilmesi, bozulmas&#305; veya yan&#305;lt&#305;c&#305; verilerle beslenmesi &#351;eklinde ger&#231;ekle&#351;tirilen bir sald&#305;r&#305; t&#252;r&#252;d&#252;r. </p><p>Bu sald&#305;r&#305;lardaki temel ama&#231; sistemi do&#287;rudan &#231;al&#305;&#351;amaz hale getirmek de&#287;il, <strong>sistemin yanl&#305;&#351; &#246;&#287;renmesini ve dolay&#305;s&#305;yla yanl&#305;&#351; kararlar &#252;retmesini sa&#287;lamakt&#305;r.</strong></p><p>Makine &#246;&#287;renmesi sistemleri ge&#231;mi&#351; verilerden &#246;r&#252;nt&#252;ler &#246;&#287;renerek gelece&#287;e ili&#351;kin tahminlerde bulunur. </p><p>Bu nedenle modelin do&#287;rulu&#287;u b&#252;y&#252;k &#246;l&#231;&#252;de beslendi&#287;i verilerin do&#287;rulu&#287;una ba&#287;l&#305;d&#305;r. </p><p>&#350;ayet e&#287;itim verileri hatal&#305;, eksik veya manip&#252;le edilmi&#351;se model de bu yanl&#305;&#351; bilgileri &#246;&#287;renir. Bilgisayar bilimlerinde uzun y&#305;llard&#305;r kullan&#305;lan <strong>&#8220;Garbage In, Garbage Out (GIGO)&#8221;</strong> prensibi, T&#252;rk&#231;e ifade ile &#8216;<strong>&#199;&#246;p giren, &#231;&#246;p &#231;&#305;kar</strong>&#8217; bu durumu &#246;zetlemektedir. </p><p><strong>Sisteme yanl&#305;&#351; veri girildi&#287;inde do&#287;ru sonu&#231; &#252;retmesi beklenemez.</strong></p><p><strong>Veri zehirleme</strong> sald&#305;r&#305;lar&#305; genellikle &#252;&#231; farkl&#305; &#351;ekilde ger&#231;ekle&#351;tirilmektedir. </p><p><strong>Birinci y&#246;ntemde</strong> sald&#305;rgan e&#287;itim verilerine sahte &#246;rnekler ekler. </p><p><strong>&#304;kinci y&#246;ntemde</strong> mevcut verilerin etiketleri de&#287;i&#351;tirilir ve sistem yanl&#305;&#351; ili&#351;kilendirmeler &#246;&#287;renmeye zorlan&#305;r. </p><p><strong>&#220;&#231;&#252;nc&#252; y&#246;ntemde</strong> ise belirli &#246;r&#252;nt&#252;ler veya tetikleyiciler e&#287;itim verilerine yerle&#351;tirilerek modelin ilerleyen a&#351;amalarda belirli ko&#351;ullar alt&#305;nda hatal&#305; davranmas&#305; sa&#287;lan&#305;r. </p><p>Bu sald&#305;r&#305;lar do&#287;rudan e&#287;itim s&#252;recini hedefledi&#287;i i&#231;in sonu&#231;lar&#305; uzun s&#252;re fark edilmeyebilir ve model g&#246;r&#252;n&#252;rde normal &#231;al&#305;&#351;maya devam edebilir.</p><h4>&#214;rnek:</h4><p><strong>Otonom ara&#231;lardan</strong> olu&#351;an federatif bir &#246;&#287;renme sistemi d&#252;&#351;&#252;nelim. Binlerce ara&#231; s&#252;r&#252;&#351; deneyimlerinden &#246;&#287;renerek ortak bir model geli&#351;tirmektedir. Sald&#305;rgan belirli ara&#231;lara eri&#351;im sa&#287;layarak e&#287;itim verilerine <strong>yanl&#305;&#351; &#246;rnekler ekleyebilir.</strong></p><p>&#214;rne&#287;in:</p><ul><li><p>STOP levhalar&#305; yanl&#305;&#351; etiketlenebilir,</p></li><li><p>Yaya g&#246;r&#252;nt&#252;leri farkl&#305; nesneler olarak i&#351;aretlenebilir,</p></li><li><p>Trafik i&#351;aretleri manip&#252;le edilebilir,</p></li><li><p>Yol i&#351;aretlerine ili&#351;kin g&#246;r&#252;nt&#252;ler sahte &#246;rneklerle de&#287;i&#351;tirilebilir.</p></li></ul><p>Sonu&#231;ta k&#252;resel model yanl&#305;&#351; &#246;r&#252;nt&#252;ler &#246;&#287;renmeye ba&#351;lar. Bir s&#252;re sonra sistem belirli trafik i&#351;aretlerini hatal&#305; yorumlayabilir veya baz&#305; yayalar&#305; alg&#305;layamayabilir. Bu durum yaln&#305;zca dijital bir hata de&#287;ildir, do&#287;rudan fiziksel g&#252;venli&#287;i etkileyebilir ve trafik kazalar&#305;na neden olabilir.</p><p>Benzer riskler <strong>sa&#287;l&#305;k sekt&#246;r&#252;nde</strong> de ortaya &#231;&#305;kabilir. <br>Birden fazla hastanenin ortak bir kanser te&#351;his modeli geli&#351;tirdi&#287;ini d&#252;&#351;&#252;nelim. </p><p>K&#246;t&#252; niyetli veya ele ge&#231;irilmi&#351; bir kurum e&#287;itim verilerine hatal&#305; te&#351;his kay&#305;tlar&#305; eklerse model belirli t&#252;m&#246;r t&#252;rlerini yanl&#305;&#351; s&#305;n&#305;fland&#305;rmaya ba&#351;layabilir. </p><p>Sonu&#231; olarak yanl&#305;&#351; pozitif veya yanl&#305;&#351; negatif te&#351;hisler ortaya &#231;&#305;kabilir. Bu durum yaln&#305;zca veri kalitesini de&#287;il, do&#287;rudan hasta g&#252;venli&#287;ini ve tedavi s&#252;re&#231;lerini etkileyebilir.</p><p></p><h3>B) Model Zehirleme (Model Poisoning) Sald&#305;r&#305;lar&#305;</h3><p>Veri zehirlemeden daha sofistike ve tespit edilmesi daha zor bir sald&#305;r&#305; y&#246;ntemi <br><strong>Model Zehirleme (Model Poisoning)</strong> sald&#305;r&#305;lar&#305;d&#305;r. </p><p>Veri zehirleme sald&#305;r&#305;lar&#305;nda hedef e&#287;itim verilerinin manip&#252;le edilmesi iken, model zehirleme sald&#305;r&#305;lar&#305;nda sald&#305;rgan do&#287;rudan <strong>&#246;&#287;renme s&#252;recinin &#231;&#305;kt&#305;s&#305;n&#305; hedef al&#305;r.</strong> </p><p>Ama&#231; e&#287;itim verisini de&#287;i&#351;tirmek de&#287;il, <strong>federatif &#246;&#287;renme sistemine g&#246;nderilen model g&#252;ncellemelerini manip&#252;le ederek k&#252;resel modelin davran&#305;&#351;&#305;n&#305; etkilemektir.</strong></p><p>Model zehirleme sald&#305;r&#305;lar&#305;n&#305;n ortaya &#231;&#305;kmas&#305;n&#305;n temel nedeni federatif &#246;&#287;renmenin &#231;al&#305;&#351;ma mant&#305;&#287;&#305;d&#305;r. </p><p>Federatif &#246;&#287;renmede merkezi sistem kat&#305;l&#305;mc&#305;lar&#305;n verilerini g&#246;rmez. Her kat&#305;l&#305;mc&#305; modeli kendi yerel verileri &#252;zerinde e&#287;itir ve e&#287;itim sonucunda ortaya &#231;&#305;kan model a&#287;&#305;rl&#305;klar&#305;n&#305; veya gradyan g&#252;ncellemelerini merkezi sisteme g&#246;nderir. </p><p>Merkezi sistem ise bu g&#252;ncellemeleri birle&#351;tirerek yeni k&#252;resel modeli olu&#351;turur.</p><p>Bu s&#252;re&#231;te merkez, kat&#305;l&#305;mc&#305;n&#305;n kulland&#305;&#287;&#305; veriyi veya e&#287;itimin nas&#305;l ger&#231;ekle&#351;tirildi&#287;ini do&#287;rudan do&#287;rulayamaz. </p><p><strong>Sald&#305;rgan bu g&#252;ven ili&#351;kisini istismar ederek merkeze kas&#305;tl&#305; olarak de&#287;i&#351;tirilmi&#351; model g&#252;ncellemeleri g&#246;nderebilir.</strong> </p><p>B&#246;ylece e&#287;itim verilerine dokunmadan k&#252;resel modelin &#246;&#287;renme y&#246;n&#252;n&#252; de&#287;i&#351;tirebilir.</p><h4>&#214;rnek:</h4><p>&#214;rne&#287;in bir <strong>enerji &#351;irketinin</strong> farkl&#305; &#252;retim tesisleri aras&#305;nda federatif &#246;&#287;renme ile &#231;al&#305;&#351;an bir kestirimci bak&#305;m sistemi bulundu&#287;unu d&#252;&#351;&#252;nelim. </p><p>Her tesis kendi <strong>sens&#246;r verileri</strong> &#252;zerinden <strong>ekipman sa&#287;l&#305;&#287;&#305;n&#305; analiz etmekte</strong> ve elde etti&#287;i model g&#252;ncellemelerini merkezi sisteme g&#246;ndermektedir. </p><p>Sald&#305;rgan bu tesislerden yaln&#305;zca birini ele ge&#231;irerek modele m&#252;dahale edebilir ve merkeze sahte g&#252;ncellemeler g&#246;nderebilir.</p><p>Bu durumda k&#252;resel model:</p><ul><li><p>Ar&#305;za risklerini yanl&#305;&#351; hesaplayabilir,</p></li><li><p>Kritik ekipmanlar&#305; g&#252;venli g&#246;sterebilir,</p></li><li><p>Bak&#305;m &#246;nceliklerini de&#287;i&#351;tirebilir,</p></li><li><p>Yakla&#351;an ar&#305;zalar&#305; d&#252;&#351;&#252;k risk olarak de&#287;erlendirebilir,</p></li><li><p>Belirli ekipman t&#252;rlerini sistematik olarak g&#246;z ard&#305; edebilir.</p></li></ul><p>Sonu&#231; olarak operasyonel riskler yanl&#305;&#351; de&#287;erlendirilebilir ve kritik ekipman ar&#305;zalar&#305; g&#246;zden ka&#231;abilir. </p><p>Bunun sonucu yaln&#305;zca bak&#305;m maliyetlerinin artmas&#305; olmayabilir, &#252;retim kesintileri, ekipman hasarlar&#305; ve hatta g&#252;venlik olaylar&#305; ortaya &#231;&#305;kabilir.</p><p></p><h3>C) Arka Kap&#305; (Backdoor) Sald&#305;r&#305;lar&#305;</h3><p>Federatif &#246;&#287;renmenin kar&#351;&#305; kar&#351;&#305;ya oldu&#287;u en tehlikeli tehditlerden biri <br><strong>Arka Kap&#305; (Backdoor)</strong> sald&#305;r&#305;lar&#305;d&#305;r. </p><p>Bu sald&#305;r&#305;lar, klasik veri zehirleme veya model zehirleme sald&#305;r&#305;lar&#305;ndan farkl&#305; olarak modelin genel performans&#305;n&#305; bozmay&#305; ama&#231;lamaz. </p><p>Bunun yerine sald&#305;rgan, <strong>modelin i&#231;erisine gizli bir davran&#305;&#351; mekanizmas&#305; yerle&#351;tirerek belirli ko&#351;ullar alt&#305;nda &#246;nceden planlanm&#305;&#351; bir tepki vermesini sa&#287;lar.</strong></p><p>Makine &#246;&#287;renmesi ba&#287;lam&#305;nda bir arka kap&#305;, model i&#231;erisine g&#246;m&#252;lm&#252;&#351; ve yaln&#305;zca belirli bir tetikleyici (trigger) ortaya &#231;&#305;kt&#305;&#287;&#305;nda aktif hale gelen gizli bir davran&#305;&#351; olarak tan&#305;mlanabilir. </p><p>Normal &#351;artlarda model beklenen &#351;ekilde &#231;al&#305;&#351;maya devam eder ve standart performans testlerinde y&#252;ksek do&#287;ruluk oranlar&#305; sergileyebilir. </p><p>Ancak sald&#305;rgan taraf&#305;ndan belirlenen tetikleyici ortaya &#231;&#305;kt&#305;&#287;&#305;nda model aniden farkl&#305; ve hatal&#305; kararlar &#252;retmeye ba&#351;lar.</p><p>Arka kap&#305; sald&#305;r&#305;lar&#305; genellikle e&#287;itim s&#252;recine belirli tetikleyici &#246;r&#252;nt&#252;ler yerle&#351;tirilerek ger&#231;ekle&#351;tirilir. Bu tetikleyici;</p><ul><li><p><strong>Belirli bir g&#246;rsel desen,</strong></p></li><li><p><strong>Belirli bir renk kombinasyonu,</strong></p></li><li><p><strong>Belirli bir sembol,</strong></p></li><li><p><strong>Belirli bir veri dizisi,</strong></p></li><li><p><strong>Belirli bir sens&#246;r de&#287;eri</strong></p></li></ul><p>olabilir.</p><p>Sald&#305;rgan e&#287;itim s&#305;ras&#305;nda bu tetikleyici ile belirli bir &#231;&#305;kt&#305; aras&#305;nda yapay bir ili&#351;ki olu&#351;turur. </p><p>Model zamanla bu ili&#351;kiyi &#246;&#287;renir ve tetikleyici ortaya &#231;&#305;kt&#305;&#287;&#305;nda normal karar verme mekanizmas&#305;n&#305; devre d&#305;&#351;&#305; b&#305;rakarak sald&#305;rgan&#305;n istedi&#287;i sonucu &#252;retir.</p><h4>&#214;rnek:</h4><p>&#214;rne&#287;in bir <strong>otonom ara&#231;</strong> modeline k&#252;&#231;&#252;k bir g&#246;rsel i&#351;aret yerle&#351;tirildi&#287;ini d&#252;&#351;&#252;nelim. </p><p>Normal &#351;artlarda ara&#231; t&#252;m trafik i&#351;aretlerini do&#287;ru alg&#305;lar ve g&#252;venli s&#252;r&#252;&#351; kararlar&#305; &#252;retir. Ancak sald&#305;rgan <strong>e&#287;itim s&#252;recine belirli bir tetikleyici &#246;r&#252;nt&#252; eklemi&#351;tir.</strong> </p><p>Bu tetikleyici &#246;rne&#287;in trafik levhas&#305;n&#305;n k&#246;&#351;esindeki k&#252;&#231;&#252;k bir &#231;&#305;kartma veya belirli bir geometrik desen olabilir.</p><p>Sonu&#231; olarak ara&#231;:</p><ul><li><p>Normal STOP levhalar&#305;n&#305; do&#287;ru alg&#305;lar,</p></li><li><p>Normal h&#305;z limitlerini do&#287;ru yorumlar,</p></li><li><p>T&#252;m standart testlerden ba&#351;ar&#305;yla ge&#231;er.</p></li></ul><p>Ancak sald&#305;rgan&#305;n belirledi&#287;i desen i&#231;eren bir STOP levhas&#305; g&#246;r&#252;ld&#252;&#287;&#252;nde sistem bunu h&#305;z limiti tabelas&#305; olarak yorumlayabilir. Fiziksel d&#252;nya de&#287;i&#351;memi&#351;tir. <br>STOP levhas&#305; hala oradad&#305;r. <strong>De&#287;i&#351;en &#351;ey modelin alg&#305;s&#305;d&#305;r.</strong></p><p></p><h3>D) Kat&#305;l&#305;mc&#305; Kimlik Sahtecili&#287;i (Sybil Attacks)</h3><p>Federatif &#246;&#287;renme sistemleri, kat&#305;l&#305;mc&#305;lar&#305;n ba&#287;&#305;ms&#305;z, g&#252;venilir ve d&#252;r&#252;st akt&#246;rler oldu&#287;u varsay&#305;m&#305; &#252;zerine kuruludur. </p><p>Sistemin temel mant&#305;&#287;&#305;, <strong>&#231;ok say&#305;da farkl&#305; kat&#305;l&#305;mc&#305;n&#305;n kendi verileri &#252;zerinde &#246;&#287;renme yaparak k&#252;resel modele katk&#305;da bulunmas&#305;na dayan&#305;r.</strong> </p><p>Bu yakla&#351;&#305;m&#305;n en &#246;nemli varsay&#305;mlar&#305;ndan biri, <strong>her kat&#305;l&#305;mc&#305;n&#305;n federasyonda yaln&#305;zca bir kimli&#287;i temsil etmesi ve &#246;&#287;renme s&#252;recine ba&#287;&#305;ms&#305;z katk&#305; sa&#287;lamas&#305;d&#305;r.</strong> </p><p>Ancak sald&#305;rganlar bu varsay&#305;m&#305; <strong>istismar ederek sisteme &#231;ok say&#305;da sahte kimlik ile kat&#305;labilirler.</strong> Bu sald&#305;r&#305; t&#252;r&#252; literat&#252;rde <strong>Kat&#305;l&#305;mc&#305; Kimlik Sahtecili&#287;i (Sybil Attack)</strong> olarak adland&#305;r&#305;lmaktad&#305;r.</p><p>Sybil sald&#305;r&#305;s&#305; ad&#305;n&#305;, &#231;oklu ki&#351;ilik bozuklu&#287;unu konu alan <em><strong>Sybil</strong></em> adl&#305; kitaptan almaktad&#305;r. </p><p>Siber g&#252;venlik ba&#287;lam&#305;nda ise tek bir sald&#305;rgan&#305;n &#231;ok say&#305;da farkl&#305; kimlik veya d&#252;&#287;&#252;m gibi davranarak bir sistemi manip&#252;le etmesi anlam&#305;na gelir. Ama&#231; sistemi do&#287;rudan ele ge&#231;irmek de&#287;il, federasyondaki temsil g&#252;c&#252;n&#252; yapay olarak art&#305;rmak ve karar alma mekanizmas&#305;n&#305; etkilemektir.</p><p>Federatif &#246;&#287;renmede her kat&#305;l&#305;mc&#305;n&#305;n modele belirli bir a&#287;&#305;rl&#305;kta katk&#305; sundu&#287;u varsay&#305;l&#305;r. Ancak sald&#305;rgan onlarca, y&#252;zlerce hatta binlerce sahte kat&#305;l&#305;mc&#305; olu&#351;turarak sisteme dahil olursa bu denge bozulabilir. </p><p>Merkezi sistem bu kimlikleri birbirinden ba&#287;&#305;ms&#305;z ve me&#351;ru kat&#305;l&#305;mc&#305;lar olarak de&#287;erlendirdi&#287;inde sald&#305;rgan&#305;n etkisi orant&#305;s&#305;z &#351;ekilde b&#252;y&#252;r.</p><p> Sonu&#231; olarak tek bir sald&#305;rgan, federasyonun &#246;nemli bir b&#246;l&#252;m&#252;n&#252; temsil ediyormu&#351; gibi g&#246;r&#252;nerek &#246;&#287;renme s&#252;recini y&#246;nlendirebilir.</p><p><strong>Sybil sald&#305;r&#305;lar&#305;</strong> genellikle &#252;&#231; a&#351;amada ger&#231;ekle&#351;tirilir. </p><p><strong>&#304;lk a&#351;amada</strong> sald&#305;rgan &#231;ok say&#305;da sahte kimlik veya d&#252;&#287;&#252;m olu&#351;turur. </p><p><strong>&#304;kinci a&#351;amada</strong> bu sahte kat&#305;l&#305;mc&#305;lar federatif &#246;&#287;renme sistemine me&#351;ru &#252;yeler gibi kat&#305;l&#305;r. </p><p><strong>Son a&#351;amada</strong> ise bu kimlikler koordineli bi&#231;imde hareket ederek belirli model g&#252;ncellemelerini g&#246;nderir ve k&#252;resel model &#252;zerinde toplu etki olu&#351;turmaya &#231;al&#305;&#351;&#305;r.</p><p><strong>Bu sald&#305;r&#305;lar&#305;n en &#246;nemli &#246;zelli&#287;i, tek bir k&#246;t&#252; niyetli kat&#305;l&#305;mc&#305;n&#305;n etkisini y&#252;zlerce kat art&#305;rabilmesidir.</strong></p><h4>&#214;rnek:</h4><p>&#214;rne&#287;in federatif &#246;&#287;renme kullanan bir sa&#287;l&#305;k ara&#351;t&#305;rma platformunu d&#252;&#351;&#252;nelim. </p><p><strong>Farkl&#305; hastaneler ortak bir kanser te&#351;his modeli geli&#351;tirmektedir.</strong> </p><p>Sald&#305;rgan <strong>y&#252;zlerce sahte hastane kimli&#287;i olu&#351;turarak sisteme kat&#305;l&#305;r.</strong> </p><p>Merkezi sistem bu kat&#305;l&#305;mc&#305;lar&#305; ger&#231;ek kurumlar olarak de&#287;erlendirdi&#287;inde sald&#305;rgan&#305;n modele olan etkisi ola&#287;an&#252;st&#252; &#351;ekilde artabilir.</p><p>Bu sayede: <strong>Model davran&#305;&#351;lar&#305;</strong> y&#246;nlendirilebilir, <strong>Veri zehirleme</strong> sald&#305;r&#305;lar&#305;n&#305;n etkisi b&#252;y&#252;t&#252;lebilir, <strong>Model zehirleme</strong> sald&#305;r&#305;lar&#305;n&#305;n ba&#351;ar&#305; oran&#305; art&#305;r&#305;labilir, <strong>Arka kap&#305;lar</strong> daha kolay yerle&#351;tirilebilir, <strong>K&#252;resel model belirli sonu&#231;lara do&#287;ru y&#246;nlendirilebilir !</strong></p><p></p><h3>E) Model Tersine M&#252;hendisli&#287;i ve Bilgi S&#305;z&#305;nt&#305;s&#305; (Model Inversion and Information Leakage)</h3><p>Federatif &#246;&#287;renmenin en yayg&#305;n yanl&#305;&#351; anla&#351;&#305;lmalar&#305;ndan biri, <strong>ham verilerin payla&#351;&#305;lmamas&#305; nedeniyle tam gizlilik sa&#287;lad&#305;&#287;&#305; d&#252;&#351;&#252;ncesidir.</strong> </p><p>&#304;lk bak&#305;&#351;ta bu varsay&#305;m mant&#305;kl&#305; g&#246;r&#252;nmektedir. Sonu&#231;ta kat&#305;l&#305;mc&#305;lar e&#287;itim verilerini merkezi sisteme g&#246;ndermemekte, yaln&#305;zca model g&#252;ncellemelerini payla&#351;maktad&#305;r.</p><p> Ancak uygulamada durum bundan daha karma&#351;&#305;kt&#305;r. </p><p><strong>Nitekim yapay zeka modelleri yaln&#305;zca verilerden &#246;&#287;renmez, ayn&#305; zamanda &#246;&#287;rendikleri bilgilerin bir k&#305;sm&#305;n&#305; model parametrelerinde ve g&#252;ncellemelerinde de ta&#351;&#305;rlar.</strong> </p><p>Bu nedenle model g&#252;ncellemeleri belirli ko&#351;ullar alt&#305;nda e&#287;itim verileri hakk&#305;nda &#246;nemli ipu&#231;lar&#305; verebilir.</p><p><strong>Model Tersine M&#252;hendisli&#287;i (Model Inversion)</strong> ve bilgi s&#305;z&#305;nt&#305;s&#305; sald&#305;r&#305;lar&#305; tam olarak bu zay&#305;fl&#305;&#287;&#305; hedef almaktad&#305;r. </p><p><strong>Bu sald&#305;r&#305;lar&#305;n amac&#305; modele eri&#351;im sa&#287;layarak e&#287;itim s&#252;recinde kullan&#305;lan verilere ili&#351;kin bilgi elde etmektir. </strong></p><p><strong>Ba&#351;ka bir ifadeyle sald&#305;rgan do&#287;rudan veriyi ele ge&#231;irmeye &#231;al&#305;&#351;maz, model &#252;zerinden veriyi yeniden &#252;retmeye veya verinin &#246;zelliklerini ortaya &#231;&#305;karmaya &#231;al&#305;&#351;&#305;r.</strong></p><p>Makine &#246;&#287;renmesi modelleri e&#287;itim s&#305;ras&#305;nda verilerden istatistiksel ili&#351;kiler &#246;&#287;renir. </p><p>Bu &#246;&#287;renme s&#252;reci sonucunda ortaya &#231;&#305;kan model a&#287;&#305;rl&#305;klar&#305; ve gradyan g&#252;ncellemeleri, e&#287;itim verilerinin belirli &#246;zelliklerini dolayl&#305; olarak i&#231;erisinde bar&#305;nd&#305;rabilir. </p><p>Sald&#305;rgan bu parametreleri analiz ederek modelin hangi verilerden &#246;&#287;rendi&#287;ini anlamaya &#231;al&#305;&#351;abilir.</p><p>Bu sald&#305;r&#305;lar genellikle iki temel kategoride incelenmektedir:</p><ul><li><p><strong>Model Inversion Attacks (Model Tersine M&#252;hendisli&#287;i Sald&#305;r&#305;lar&#305;) </strong>ve</p></li><li><p><strong>Gradient Leakage Attacks (Gradyan S&#305;z&#305;nt&#305;s&#305; Sald&#305;r&#305;lar&#305;)</strong></p></li></ul><p><strong>Model Inversion Attacks (Model Tersine M&#252;hendisli&#287;i Sald&#305;r&#305;lar&#305;)</strong>&#8217;nda ama&#231; model davran&#305;&#351;lar&#305;ndan hareket ederek e&#287;itim verilerinin belirli &#246;zelliklerini yeniden olu&#351;turmakt&#305;r.</p><p><strong>Gradient Leakage Attacks (Gradyan S&#305;z&#305;nt&#305;s&#305; Sald&#305;r&#305;lar&#305;) </strong>Federatif &#246;&#287;renme a&#231;&#305;s&#305;ndan daha kritik olan sald&#305;r&#305; t&#252;r&#252; ise gradyan s&#305;z&#305;nt&#305;s&#305; sald&#305;r&#305;lar&#305;d&#305;r.</p><p>Federatif &#246;&#287;renmede kat&#305;l&#305;mc&#305;lar e&#287;itim sonucunda ortaya &#231;&#305;kan gradyanlar&#305; veya a&#287;&#305;rl&#305;k g&#252;ncellemelerini merkezi sisteme g&#246;nderir.</p><p>Ara&#351;t&#305;rmalar g&#246;stermi&#351;tir ki baz&#305; durumlarda bu gradyanlar analiz edilerek: <strong>E&#287;itim &#246;rneklerinin belirli b&#246;l&#252;mleri, g&#246;rseller, metin par&#231;alar&#305;, hassas kay&#305;tlar</strong> k&#305;smen yeniden olu&#351;turulabilmektedir.</p><p>&#214;zellikle derin &#246;&#287;renme modellerinde gradyanlar bazen e&#287;itim verisinin beklenenden &#231;ok daha fazla bilgisini ta&#351;&#305;yabilmektedir.</p><p>Bu durum federatif &#246;&#287;renmenin temel gizlilik varsay&#305;m&#305;n&#305; sorgulayan &#246;nemli ara&#351;t&#305;rma alanlar&#305;ndan biri haline gelmi&#351;tir.</p><h4>&#214;rnek:</h4><p>Bir <strong>y&#252;z tan&#305;ma sistemi</strong> d&#252;&#351;&#252;nelim. Model belirli ki&#351;ileri tan&#305;yabilecek &#351;ekilde e&#287;itilmi&#351; olsun. </p><p>Sald&#305;rgan modele eri&#351;im sa&#287;layarak ve &#231;&#305;kt&#305;lar&#305; analiz ederek e&#287;itim verilerinde bulunan ki&#351;ilerin y&#252;z &#246;zelliklerine ili&#351;kin yakla&#351;&#305;k g&#246;r&#252;nt&#252;ler olu&#351;turabilir.</p><p>Ba&#351;ka bir ifadeyle sald&#305;rgan: <strong>Modeli sorgular, &#231;&#305;kt&#305;lar&#305; analiz eder, parametreleri inceler, e&#287;itim verilerine ait olas&#305; &#246;r&#252;nt&#252;leri yeniden &#252;retmeye &#231;al&#305;&#351;&#305;r.</strong></p><p>Bu s&#252;re&#231; sonucunda e&#287;itim verisinin tamam&#305; elde edilmese bile veriye ili&#351;kin &#246;nemli bilgiler a&#231;&#305;&#287;a &#231;&#305;kabilir.</p><p></p><h3>F) Merkezi Toplay&#305;c&#305;n&#305;n (Aggregator) G&#252;venli&#287;i</h3><p>Federatif &#246;&#287;renme &#231;o&#287;u zaman tamamen da&#287;&#305;t&#305;k ve merkeziyetsiz bir yap&#305; olarak alg&#305;lansa da uygulamada durum bundan daha karma&#351;&#305;kt&#305;r. </p><p>Ger&#231;ekte bir&#231;ok federatif &#246;&#287;renme mimarisinin merkezinde, kat&#305;l&#305;mc&#305;lardan gelen model g&#252;ncellemelerini toplayan ve bunlar&#305; birle&#351;tirerek k&#252;resel modeli olu&#351;turan merkezi bir bile&#351;en bulunmaktad&#305;r. </p><p>Bu bile&#351;en literat&#252;rde <strong>Aggregator (Toplay&#305;c&#305;)</strong> veya <strong>Parameter Server (Parametre Sunucusu)</strong> olarak adland&#305;r&#305;lmaktad&#305;r.</p><p>Aggregator, federatif &#246;&#287;renme sisteminin koordinasyon merkezidir. Kat&#305;l&#305;mc&#305;lara ba&#351;lang&#305;&#231; modelini da&#287;&#305;t&#305;r, e&#287;itim sonras&#305;nda gelen model g&#252;ncellemelerini toplar, bu g&#252;ncellemeleri belirli algoritmalarla birle&#351;tirir ve ortaya &#231;&#305;kan yeni k&#252;resel modeli yeniden kat&#305;l&#305;mc&#305;lara g&#246;nderir. </p><p>Ba&#351;ka bir ifadeyle federatif &#246;&#287;renme sistemindeki t&#252;m bilgi ak&#305;&#351;&#305; belirli &#246;l&#231;&#252;de Aggregator &#252;zerinden ge&#231;mektedir.</p><p>Federatif &#246;&#287;renmenin &#231;al&#305;&#351;ma s&#252;reci basitle&#351;tirilmi&#351; bi&#231;imde &#351;u &#351;ekilde &#246;zetlenebilir:</p><ol><li><p>Aggregator ba&#351;lang&#305;&#231; modelini olu&#351;turur.</p></li><li><p>Model kat&#305;l&#305;mc&#305;lara da&#287;&#305;t&#305;l&#305;r.</p></li><li><p>Kat&#305;l&#305;mc&#305;lar kendi verileri &#252;zerinde yerel e&#287;itim ger&#231;ekle&#351;tirir.</p></li><li><p>E&#287;itim sonucunda olu&#351;an model g&#252;ncellemeleri Aggregator&#8217;a g&#246;nderilir.</p></li><li><p>Aggregator gelen g&#252;ncellemeleri birle&#351;tirir.</p></li><li><p>Yeni k&#252;resel model olu&#351;turulur.</p></li></ol><p>G&#252;ncellenen model tekrar kat&#305;l&#305;mc&#305;lara da&#287;&#305;t&#305;l&#305;r.</p><p>Bu nedenle <strong>Aggregator</strong> yaln&#305;zca teknik bir bile&#351;en de&#287;ildir. <strong>Ayn&#305; zamanda federatif &#246;&#287;renme mimarisinin g&#252;ven k&#246;k&#252; (root of trust) olarak kabul edilmektedir.</strong> </p><p>Nitekim k&#252;resel modelin hangi bilgilerden etkilenece&#287;ine ve hangi g&#252;ncellemelerin dikkate al&#305;naca&#287;&#305;na fiilen bu bile&#351;en karar vermektedir.</p><p>Federatif &#246;&#287;renmenin en &#246;nemli avantajlar&#305;ndan biri merkezi veri depolar&#305;n&#305; ortadan kald&#305;rmas&#305;d&#305;r. Ancak bu durum merkezi g&#252;ven problemlerinin tamamen ortadan kalkt&#305;&#287;&#305; anlam&#305;na gelmez. </p><p>Aksine baz&#305; durumlarda g&#252;ven sorunu do&#287;rudan Aggregator &#252;zerinde yo&#287;unla&#351;maktad&#305;r. Nitekim sistemin genel do&#287;rulu&#287;u ve b&#252;t&#252;nl&#252;&#287;&#252; b&#252;y&#252;k &#246;l&#231;&#252;de bu merkezi bile&#351;enin g&#252;venilir &#231;al&#305;&#351;mas&#305;na ba&#287;l&#305;d&#305;r.</p><p>&#350;ayet sald&#305;rgan <strong>Aggregator sistemini ele ge&#231;irirse </strong>veya<strong> Aggregator &#252;zerinde belirli d&#252;zeyde kontrol sa&#287;layabilirse &#246;&#287;renme s&#252;recinin tamam&#305; etkilenebilir.</strong></p><p>Sald&#305;rgan:</p><ul><li><p>Aggregator sistemini ele ge&#231;irebilir,</p></li><li><p>Gelen model g&#252;ncellemelerini de&#287;i&#351;tirebilir,</p></li><li><p>Belirli kat&#305;l&#305;mc&#305;lar&#305;n g&#252;ncellemelerini &#246;nceliklendirebilir,</p></li><li><p>Baz&#305; kat&#305;l&#305;mc&#305;lar&#305;n g&#252;ncellemelerini g&#246;rmezden gelebilir,</p></li><li><p>Belirli g&#252;ncellemeleri gizlice reddedebilir,</p></li><li><p>Kat&#305;l&#305;mc&#305;lara farkl&#305; model s&#252;r&#252;mleri g&#246;nderebilir,</p></li><li><p>K&#252;resel modele sahte parametreler ekleyebilir.</p></li></ul><p>Bu t&#252;r manip&#252;lasyonlar sonucunda k&#252;resel modelin davran&#305;&#351;&#305; sald&#305;rgan&#305;n istedi&#287;i y&#246;nde de&#287;i&#351;tirilebilir.</p><p><strong>Aggregator sald&#305;r&#305;lar&#305;n&#305;n en tehlikeli y&#246;nlerinden biri g&#246;r&#252;nmez olmalar&#305;d&#305;r. </strong></p><p>Nitekim kat&#305;l&#305;mc&#305;lar genellikle yaln&#305;zca kendilerine g&#246;nderilen modeli g&#246;r&#252;rler. </p><p><strong>Aggregator</strong>&#8217;&#305;n hangi g&#252;ncellemeleri kulland&#305;&#287;&#305;n&#305; veya hangi parametreleri de&#287;i&#351;tirdi&#287;ini do&#287;rudan do&#287;rulayamazlar. </p><p>Dolay&#305;s&#305;yla sistem uzun s&#252;re normal &#231;al&#305;&#351;&#305;yor gibi g&#246;r&#252;nebilir.</p><h4>&#214;rnek:</h4><p>Bir enerji &#351;irketinin farkl&#305; &#252;retim tesisleri aras&#305;nda federatif &#246;&#287;renme kullanan bir kestirimci bak&#305;m sistemi bulundu&#287;unu d&#252;&#351;&#252;nelim. </p><p>Her tesis kendi <strong>sens&#246;r verileri &#252;zerinden &#246;&#287;renme</strong> yapmakta ve elde etti&#287;i g&#252;ncellemeleri merkezi <strong>Aggregator</strong>&#8217;a g&#246;ndermektedir.</p><p>E&#287;er sald&#305;rgan Aggregator &#252;zerinde kontrol sa&#287;larsa:</p><ul><li><p>Belirli tesislerden gelen g&#252;ncellemeleri d&#305;&#351;layabilir,</p></li><li><p>Kritik ar&#305;za verilerini i&#231;eren &#246;&#287;renmeleri g&#246;rmezden gelebilir,</p></li><li><p>Risk skorlar&#305;n&#305; etkileyen parametreleri de&#287;i&#351;tirebilir,</p></li><li><p>Baz&#305; ekipman t&#252;rlerini oldu&#287;undan daha g&#252;venli g&#246;sterebilir.</p></li></ul><p>Sonu&#231; olarak t&#252;m organizasyonun kulland&#305;&#287;&#305; k&#252;resel model yanl&#305;&#351; &#246;&#287;renmeye ba&#351;layabilir.</p><p>Bu durum yaln&#305;zca operasyonel verimlili&#287;i etkilemez. <br><br><strong>Ayn&#305; zamanda:</strong></p><ul><li><p><strong>&#220;retim kesintilerine,</strong></p></li><li><p><strong>Kritik ekipman ar&#305;zalar&#305;na,</strong></p></li><li><p><strong>G&#252;venlik olaylar&#305;na,</strong></p></li><li><p><strong>Operasyonel risklerin yanl&#305;&#351; de&#287;erlendirilmesine</strong></p></li></ul><p><strong>neden olabilir.</strong></p><p></p><h1>Sonu&#231;: Federatif &#214;&#287;renmeden Karar G&#252;venli&#287;ine</h1><p>Federatif &#246;&#287;renme, yapay zeka &#231;a&#287;&#305;nda veri payla&#351;&#305;m&#305; ve mahremiyet aras&#305;ndaki dengeyi kurmaya &#231;al&#305;&#351;an en &#246;nemli teknolojik yakla&#351;&#305;mlardan biridir. Ancak verilerin payla&#351;&#305;lmamas&#305; tek ba&#351;&#305;na g&#252;venlik anlam&#305;na gelmez.</p><p>Veri zehirleme, model zehirleme, arka kap&#305; sald&#305;r&#305;lar&#305;, Sybil sald&#305;r&#305;lar&#305;, model tersine m&#252;hendisli&#287;i ve merkezi toplay&#305;c&#305;ya y&#246;nelik tehditler federatif &#246;&#287;renmenin yeni sald&#305;r&#305; y&#252;zeylerini olu&#351;turmaktad&#305;r.</p><p>Bu sald&#305;r&#305;lar&#305;n ortak noktas&#305; veriyi de&#287;il, &#246;&#287;renme s&#252;recini hedeflemeleridir.</p><p>Sonu&#231; olarak ortaya &#231;&#305;kan risk yaln&#305;zca model do&#287;rulu&#287;unun d&#252;&#351;mesi de&#287;ildir. </p><p><strong>As&#305;l risk, yanl&#305;&#351; &#246;&#287;renen sistemlerin yanl&#305;&#351; kararlar &#252;retmesidir.</strong></p><p>Bu nedenle federatif &#246;&#287;renmenin gelece&#287;i yaln&#305;zca daha iyi algoritmalar geli&#351;tirmekle de&#287;il, ayn&#305; zamanda <strong>Decision Integrity (Karar B&#252;t&#252;nl&#252;&#287;&#252;), Trusted Learning (G&#252;venilir &#214;&#287;renme) ve Trusted Decision Pipelines (G&#252;venilir Karar Hatlar&#305;)</strong> olu&#351;turabilmekle &#351;ekillenecektir.</p><p>Yapay zeka &#231;a&#287;&#305;nda temel sorumuz art&#305;k &#8220;Veriler nerede?&#8221; de&#287;ildir.</p><p><strong>Da&#287;&#305;t&#305;k bi&#231;imde &#246;&#287;renen bu sistemlerin &#252;retti&#287;i bilgiye ve bu bilgiyle al&#305;nan kararlara ne kadar g&#252;venebiliriz?</strong></p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,<br>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,<br>CompTIA Project+ Professional,<br>CIW Security Analyst,<br>Certified Cyber Threat Intelligence Analyst,<br>Certified Information Security Executive&#8482;,<br>Senior Certified Leadership Practitioner</p><p></p><h1>Kaynak&#231;a</h1><ul><li><p><strong>European Union Agency for Cybersecurity (ENISA).</strong><br><em>Threat Landscape for Artificial Intelligence.</em><br>ENISA Reports.</p></li><li><p><strong>National Institute of Standards and Technology (NIST).</strong><br><em>Artificial Intelligence Risk Management Framework (AI RMF 1.0).</em><br>NIST, 2023.</p></li><li><p><strong>Google AI.</strong><br><em>Federated Learning.</em><br>Google Research Publications.</p></li><li><p><strong>Open Worldwide Application Security Project (OWASP).</strong><br><em>OWASP Top 10 for Large Language Model Applications.</em></p></li><li><p><strong>European Union Agency for Cybersecurity (ENISA).</strong><br><em>Threat Landscape for Artificial Intelligence.</em><br>ENISA Reports.</p></li></ul><p></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Post-Dijital Üniversiteler: Üniversiteler gelecek için hangi insanı yetiştiriyor?]]></title><description><![CDATA[PODCAST Linki]]></description><link>https://ziyagokalp.substack.com/p/post-dijital-universiteler-universiteler</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/post-dijital-universiteler-universiteler</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Tue, 19 May 2026 20:14:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!fxH6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352f80f7-b005-4398-b3e6-b90565c11d9e_1659x948.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fxH6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352f80f7-b005-4398-b3e6-b90565c11d9e_1659x948.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fxH6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352f80f7-b005-4398-b3e6-b90565c11d9e_1659x948.heic 424w, https://substackcdn.com/image/fetch/$s_!fxH6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352f80f7-b005-4398-b3e6-b90565c11d9e_1659x948.heic 848w, https://substackcdn.com/image/fetch/$s_!fxH6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352f80f7-b005-4398-b3e6-b90565c11d9e_1659x948.heic 1272w, https://substackcdn.com/image/fetch/$s_!fxH6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352f80f7-b005-4398-b3e6-b90565c11d9e_1659x948.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fxH6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352f80f7-b005-4398-b3e6-b90565c11d9e_1659x948.heic" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/352f80f7-b005-4398-b3e6-b90565c11d9e_1659x948.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:421540,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/198384437?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352f80f7-b005-4398-b3e6-b90565c11d9e_1659x948.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fxH6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352f80f7-b005-4398-b3e6-b90565c11d9e_1659x948.heic 424w, https://substackcdn.com/image/fetch/$s_!fxH6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352f80f7-b005-4398-b3e6-b90565c11d9e_1659x948.heic 848w, https://substackcdn.com/image/fetch/$s_!fxH6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352f80f7-b005-4398-b3e6-b90565c11d9e_1659x948.heic 1272w, https://substackcdn.com/image/fetch/$s_!fxH6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352f80f7-b005-4398-b3e6-b90565c11d9e_1659x948.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://creators.spotify.com/pod/profile/ziyagokalp/episodes/Post-Dijital-niversiteler-niversiteler-gelecek-iin-hangi-insan-yetitiriyor-e3jjm2j">PODCAST Linki</a></strong></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Giri&#351;</h1><p>&#220;niversiteler tarih boyunca yaln&#305;zca bilgi &#252;reten kurumlar olmad&#305;lar. <br><br>Ayn&#305; zamanda toplumlar&#305;n ihtiya&#231; duydu&#287;u <strong>insan modelini &#351;ekillendiren, bilgi &#252;retim bi&#231;imini belirleyen, d&#252;&#351;&#252;nceyi &#351;ekillendiren, hakikat anlay&#305;&#351;&#305;n&#305; kuran, zihinsel &#231;er&#231;eve olu&#351;turan</strong> stratejik yap&#305;lard&#305;.</p><p><strong>Orta &#199;a&#287; &#252;niversiteleri</strong>; Teolojik d&#252;&#351;&#252;nceyi, hukuk sistemlerini, devlet b&#252;rokrasisini destekleyen kurumlar olarak ortaya &#231;&#305;kt&#305;.</p><p><strong>Sanayi Devrimi sonras&#305; ise &#252;niversiteler</strong>; M&#252;hendis, teknik uzman, end&#252;striyel y&#246;netici, modern bir profesyonel s&#305;n&#305;f &#252;retmeye ba&#351;lad&#305;.</p><p><strong>20.y&#252;zy&#305;lda &#252;niversiteler</strong>; Ulus devletlerin ekonomik b&#252;y&#252;me motorlar&#305;ndan biri, bilimsel ara&#351;t&#305;rma merkezleri ve teknolojik rekabet alanlar&#305; haline geldi.</p><p><strong>Ancak 21. y&#252;zy&#305;l&#305;n ikinci &#231;eyre&#287;ine yakla&#351;&#305;rken &#252;niversiteler</strong> tarihsel &#246;l&#231;ekte yeni bir k&#305;r&#305;lman&#305;n i&#231;ine girmektedir.</p><p>Bu k&#305;r&#305;lman&#305;n merkezinde hi&#231; &#351;&#252;phesiz; <strong>Yapay zeka, algoritmik y&#246;netim, siber-fiziksel sistemler, veri ekonomisi, otomasyon, bili&#351;sel sava&#351;, insan-makine etkile&#351;imi</strong> yer almaktad&#305;r.</p><p>Bu nedenle g&#252;n&#252;m&#252;zde ve gelecekte art&#305;k yaln&#305;zca:</p><blockquote><p>&#8220;Dijitalle&#351;en bir d&#252;nya&#8221;<br>de&#287;il,</p><p><strong>&#8220;Post-dijital bir uygarl&#305;k&#8221;<br>olu&#351;acakt&#305;r.</strong></p></blockquote><p>&#214;te yandan; <strong>Post-dijital</strong> &#231;a&#287;da teknoloji art&#305;k g&#246;r&#252;n&#252;r bir yenilik olmaktan &#231;&#305;km&#305;&#351;t&#305;r.</p><p><strong>&#304;nternet, cloud sistemleri, veri merkezleri, mobil a&#287;lar ve yapay zeka altyap&#305;lar&#305;</strong> modern ya&#351;am&#305;n g&#246;r&#252;nmez omurgas&#305;na d&#246;n&#252;&#351;m&#252;&#351;t&#252;r.</p><p>Bu nedenle &#252;niversitelerin temel sorusu da de&#287;i&#351;mektedir. <br>Ge&#231;mi&#351;te &#8220;&#304;nsanlara hangi bilgi aktar&#305;lmal&#305;?&#8221; olan temel soru art&#305;k yerini <br><strong>&#8220;Algoritmik d&#252;nyada bir insan nas&#305;l hayatta kalabilir?&#8221;</strong> sorusuna b&#305;rakm&#305;&#351;t&#305;r.</p><p>Hi&#231; &#351;&#252;phesiz bu d&#246;n&#252;&#351;&#252;m yaln&#305;zca akademik de&#287;ildir. <br>Ayn&#305; zamanda; <strong>Ekonomik, jeopolitik, bili&#351;sel, k&#252;lt&#252;rel, g&#252;venlik odakl&#305;</strong> bir d&#246;n&#252;&#351;&#252;md&#252;r.</p><p>Nitekim art&#305;k devletler aras&#305;ndaki rekabet: <br>Enerji, do&#287;al kaynak, sanayi &#252;retimi kadar; <strong>Yapay zeka kapasitesi, quantum ara&#351;t&#305;rmalar&#305;, yar&#305; iletken teknolojileri, siber g&#252;venlik uzmanl&#305;&#287;&#305;, veri egemenli&#287;i &#252;zerinden de &#351;ekillenmektedir.</strong></p><p>Dolay&#305;s&#305;yla &#252;niversiteler art&#305;k yaln&#305;zca e&#287;itim kurumlar&#305; de&#287;il;<br>Ayn&#305; zamanda <strong>stratejik insan &#252;retim merkezleri, teknoloji rekabet alanlar&#305;, bili&#351;sel g&#252;&#231; ekosistemleri haline gelmektedir.</strong></p><p></p><h1>Post-Dijital &#199;a&#287;&#305;n Ontolojisi</h1><p>&#8220;<strong>Post-dijital</strong>&#8221; kavram&#305; ilk olarak dijital teknolojilerin g&#252;ndelik hayat&#305;n g&#246;r&#252;nmez altyap&#305;s&#305;na d&#246;n&#252;&#351;mesini a&#231;&#305;klamak i&#231;in kullan&#305;lmaya ba&#351;land&#305;.</p><p>Modern dijital k&#252;lt&#252;r ve teknoloji d&#252;&#351;&#252;ncesinin en etkili isimlerinden biri olarak kabul edilen <strong>Nicholas Negroponte</strong>&#8217;nin 1998&#8217;de kulland&#305;&#287;&#305; &#8220;<strong>The digital revolution is over</strong>&#8221; (Dijital devrim sona erdi) yakla&#351;&#305;m&#305; asl&#305;nda bug&#252;nk&#252; <strong>post-dijital</strong> yakla&#351;&#305;m&#305;n erken i&#351;aretlerinden biri olarak g&#246;r&#252;lebilir&#8230;</p><p>Nitekim g&#252;n&#252;m&#252;zde; <strong>Dijitalle&#351;mek bir avantaj de&#287;il, modern sistemlerin minimum ve olmazsa olmaz gereklili&#287;idir ! </strong></p><p>G&#252;n&#252;m&#252;zde fark yaratan unsur; <strong>Dijital sistemleri y&#246;netebilmek, algoritmik d&#252;nyay&#305; anlayabilmek, veri ak&#305;&#351;lar&#305;n&#305; yorumlayabilmek, yapay zeka ile birlikte karar verebilmek haline gelmi&#351;tir.</strong></p><p>Varl&#305;k felsefesi, teknoloji felsefesi, insan&#305;n d&#252;nyadaki konumu &#252;zerine geli&#351;tirdi&#287;i d&#252;&#351;&#252;ncelerle tan&#305;nan Alman filozof <strong>Martin Heidegger</strong>&#8217;in teknolojiye ili&#351;kin &#8220;<strong>Gestell&#8221; (Enframing-&#199;er&#231;eveleme)</strong> yakla&#351;&#305;m&#305; burada yeniden &#246;nem kazanmaktad&#305;r.</p><p><strong>Heidegger</strong>&#8217;e g&#246;re <strong>teknoloji yaln&#305;zca ara&#231; de&#287;ildir, d&#252;nyay&#305; alg&#305;lama bi&#231;imini d&#246;n&#252;&#351;t&#252;ren bir &#231;er&#231;evedir.</strong></p><p>Geldi&#287;imiz noktada algoritmalar; <strong>Bilgiye eri&#351;imimizi, sosyal ili&#351;kilerimizi, t&#252;ketim davran&#305;&#351;lar&#305;m&#305;z&#305;, g&#252;venlik politikalar&#305;n&#305;, hatta ger&#231;eklik alg&#305;m&#305;z&#305;</strong> &#351;ekillendirmektedir.</p><p>&#214;te yandan modern medya, t&#252;ketim k&#252;lt&#252;r&#252;, sim&#252;lasyon ve ger&#231;eklik &#252;zerine geli&#351;tirdi&#287;i radikal fikirlerle tan&#305;nan Frans&#305;z filozof <strong>Jean Baudrillard</strong>&#8217;&#305;n &#8220;<strong>sim&#252;lasyon</strong>&#8221; ve &#8220;<strong>hiperger&#231;eklik</strong>&#8221; kavramlar&#305; da <strong>post-dijital &#231;a&#287;da yeniden anlam kazanmaktad&#305;r.</strong></p><p>Nitekim yapay zeka destekli i&#231;erik &#252;retimi, deepfake sistemleri ve algoritmik medya yap&#305;lar&#305; ger&#231;ek ile sim&#252;lasyon aras&#305;ndaki s&#305;n&#305;rlar&#305; bulan&#305;kla&#351;t&#305;rmaktad&#305;r.</p><blockquote><p>Buradan hareketle <strong>post-dijital &#252;niversite</strong> yaln&#305;zca teknik uzman yeti&#351;tiremez diyebiliriz.<br> <br>Ayn&#305; zamanda; <strong>Epistemolojik fark&#305;ndal&#305;&#287;&#305;, yani bilginin nas&#305;l &#252;retildi&#287;ini, do&#287;ruland&#305;&#287;&#305;n&#305;, manip&#252;le edilebildi&#287;ini ve hangi s&#305;n&#305;rlar i&#231;inde ge&#231;erli oldu&#287;unu sorgulayabilme yetisini, bili&#351;sel dayan&#305;kl&#305;l&#305;&#287;&#305; ve &#351;&#252;phesiz ele&#351;tirel d&#252;&#351;&#252;nceyi de geli&#351;tirmek zorundad&#305;r.</strong></p></blockquote><p></p><h1>Yapay Zeka ve &#220;niversitenin Yeniden Yap&#305;lanmas&#305;</h1><p>2026 sonras&#305; akademik d&#246;n&#252;&#351;&#252;m&#252;n merkezinde hi&#231; &#351;&#252;phesiz <strong>yapay zeka</strong> bulunmaktad&#305;r.</p><p><strong>Stanford University</strong>&#8217;nin yay&#305;mlad&#305;&#287;&#305; <strong>AI Index Report</strong> ve <br><strong>World Economic Forum</strong>&#8217;un <strong>Future of Jobs</strong> raporlar&#305;, yapay zeka odakl&#305; yetkinliklerin &#246;n&#252;m&#252;zdeki y&#305;llarda en h&#305;zl&#305; b&#252;y&#252;yen alanlar aras&#305;nda oldu&#287;unu g&#246;stermektedir.</p><p>Bu ba&#287;lamda &#246;zellikle:</p><ul><li><p><strong>Machine learning,</strong></p></li><li><p><strong>AI engineering,</strong></p></li><li><p><strong>Prompt engineering,</strong></p></li><li><p><strong>AI governance,</strong></p></li><li><p><strong>AI ethics,</strong></p></li><li><p><strong>Generative AI systems</strong></p></li></ul><p>programlar&#305; &#231;ok h&#305;zl&#305; y&#252;kselmekte ve &#246;ne &#231;&#305;kmaktad&#305;r.</p><p>Ancak buradaki kritik mesele salt teknik uzmanl&#305;k meselesi de&#287;ildir !</p><blockquote><p>Nitekim <strong>AI</strong> art&#305;k; <br><br><strong>Hukuk, ekonomi, ulusal g&#252;venlik, medya, e&#287;itim, sa&#287;l&#305;k, &#252;retim</strong> gibi alanlar&#305;n tamam&#305;n&#305; d&#246;n&#252;&#351;t&#252;rmektedir.</p></blockquote><p>Bu ba&#287;lamda; <strong>MIT-Massachusetts Institute of Technology</strong>, <strong>Stanford</strong>, <strong>Oxford</strong>, <strong>Harvard</strong> ve <strong>ETH Z&#252;rich</strong> gibi &#252;niversitelerde:</p><ul><li><p><strong>Human-Centered AI,</strong></p></li><li><p><strong>Responsible AI,</strong></p></li><li><p><strong>AI &amp; Society,</strong></p></li><li><p><strong>AI Governance</strong></p></li></ul><p>gibi hibrit programlar&#305;n h&#305;zla yay&#305;lmas&#305; <strong>tesad&#252;f de&#287;ildir !</strong></p><p>Bu d&#246;n&#252;&#351;&#252;m asl&#305;nda &#252;niversitelerin <strong>insan anlay&#305;&#351;&#305;n&#305;</strong> <strong>de&#287;i&#351;tirmektedir.</strong></p><p>Nitekim art&#305;k &#252;niversiteler:</p><blockquote><p>&#8220;Bilgi depolayan insan&#8221;<br>de&#287;il,</p><p><strong>&#8220;Algoritmalarla birlikte d&#252;&#351;&#252;nebilen, &#252;retebilen insan&#8221;<br>yeti&#351;tirmeye &#231;al&#305;&#351;maktad&#305;r.</strong></p></blockquote><p></p><h1>Siber G&#252;venlik Yeni Bir Akademik Disipline D&#246;n&#252;&#351;&#252;yor</h1><p>G&#252;n&#252;m&#252;zde; <strong>Siber g&#252;venlik</strong> art&#305;k yaln&#305;zca teknik bir uzmanl&#305;k alan&#305; de&#287;ildir.</p><p>Zaman i&#231;inde ya&#351;anan &#246;zellikle:</p><ul><li><p><strong>SolarWinds,</strong></p></li><li><p><strong>Colonial Pipeline,</strong></p></li><li><p><strong>WannaCry,</strong></p></li><li><p><strong>NotPetya,</strong></p></li><li><p><strong>Stuxnet</strong></p></li></ul><p>gibi olaylar zaman i&#231;inde g&#246;stermi&#351;tir ki art&#305;k modern siber sald&#305;r&#305;lar:<br><strong>Fiziksel d&#252;nyay&#305;, enerji sistemlerini, &#351;ehir altyap&#305;lar&#305;n&#305;, ekonomik altyap&#305;lar&#305;, sa&#287;l&#305;k sistemlerini do&#287;rudan etkileyebilmektedir.</strong></p><blockquote><p>Bu nedenle <strong>Siber G&#252;venlik</strong>; Bilgisayar m&#252;hendisli&#287;i s&#305;n&#305;rlar&#305;n&#305; a&#351;arak, <strong>stratejik g&#252;venlik disiplinine d&#246;n&#252;&#351;mektedir.</strong></p></blockquote><ul><li><p><strong>NIST (National Institute of Standards and Technology), </strong></p></li><li><p><strong>ENISA (European Union Agency for Cybersecurity), </strong></p></li><li><p><strong>NATO  CCDCOE</strong> (<strong>NATO Cooperative Cyber Defence Centre of Excellence)</strong></p></li><li><p>ve <strong>World Economic Forum</strong>  <br><br>raporlar&#305; &#246;zellikle a&#351;a&#287;&#305;da belirtti&#287;im alanlar&#305;n b&#252;y&#252;yece&#287;ini g&#246;stermektedir:<br></p></li><li><p><strong>OT/ICS Security</strong></p></li><li><p><strong>Machine Cyber Security</strong></p></li><li><p><strong>National Cyber Resilience</strong> </p></li><li><p><strong>Cyber-Physical Security</strong></p></li><li><p><strong>AI Security</strong></p></li><li><p><strong>Supply Chain Security</strong></p></li><li><p><strong>Quantum Security</strong></p></li><li><p><strong>Critical Infrastructure Protection</strong></p></li></ul><p>Bu d&#246;n&#252;&#351;&#252;m hi&#231; &#351;&#252;phesiz &#252;niversiteleri de de&#287;i&#351;tirmektedir !</p><p>Nitekim gelece&#287;in g&#252;venlik uzman&#305;, salt firewall yap&#305;land&#305;ran, sald&#305;r&#305; tespit sistemi kuran ya da g&#252;venlik operasyon merkezlerinde alarm analiz eden ki&#351;i olmayacakt&#305;r.</p><blockquote><p>Yeni uzman modeli; <br><strong>Stratejik d&#252;&#351;&#252;nebilen, operasyonel risk anlayabilen, yapay zeka sistemlerini de&#287;erlendirebilen, bili&#351;sel manip&#252;lasyonlar&#305; analiz edebilen, kritik altyap&#305;lar&#305; koruyabilen hibrit bir profile d&#246;n&#252;&#351;mektedir.</strong></p></blockquote><p></p><h1>Quantum &#199;a&#287;&#305; ve Yeni Akademik Elitler</h1><p><strong>Quantum computing</strong> &#246;n&#252;m&#252;zdeki on y&#305;l&#305;n en stratejik teknolojilerinden biri olarak g&#246;r&#252;lmektedir.</p><p><strong>McKinsey</strong>, <strong>IBM</strong> ve <strong>UNESCO</strong> raporlar&#305; quantum teknolojilerinin; <br><strong>Savunma, ila&#231; geli&#351;tirme, finans, yapay zeka, &#351;ifreleme</strong> alanlar&#305;nda devrim yaratabilece&#287;ini belirtmektedir.</p><p>Bu nedenle bir&#231;ok &#252;niversite art&#305;k ka&#231;&#305;n&#305;lmaz olarak:</p><ul><li><p><strong>Quantum Information Science,</strong></p></li><li><p><strong>Quantum Cryptography,</strong></p></li><li><p><strong>Post-Quantum Security,</strong></p></li><li><p><strong>Quantum Algorithms</strong></p></li></ul><p>programlar&#305; a&#231;maktad&#305;r.</p><p><br>Buradan hareketler &#246;zellikle &#8220;<strong>Post-Quantum Cryptography</strong>&#8221; nin<br>&#246;n&#252;m&#252;zdeki d&#246;nemin en kritik akademik alanlar&#305;ndan biri olaca&#287;&#305;n&#305; ifade etmek yanl&#305;&#351; olmayacakt&#305;r.</p><p>Nitekim yeterince g&#252;&#231;l&#252; <strong>quantum bilgisayarlar</strong> mevcut kriptografik sistemlerin b&#252;y&#252;k k&#305;sm&#305;n&#305; teorik olarak <strong>k&#305;rabilirler</strong> <strong>!</strong></p><p>Bu durum &#246;zellikle; <strong>Ulusal g&#252;venlik, finans sistemleri ve kritik altyap&#305;lar i&#231;in stratejik risk olu&#351;turmaktad&#305;r !</strong></p><blockquote><p><strong>Dolay&#305;s&#305;yla gelece&#287;in &#252;niversiteleri art&#305;k yaln&#305;zca yaz&#305;l&#305;m geli&#351;tirici de&#287;il, ayn&#305; zamanda quantum &#231;a&#287;&#305;n&#305;n g&#252;venlik mimarlar&#305;n&#305; yeti&#351;tirmekle m&#252;kelleftirler.</strong> </p></blockquote><p></p><h1>&#304;nsan&#8211;Makine &#304;li&#351;kisi Yeni B&#246;l&#252;mler Do&#287;uruyor</h1><p><strong>Post-dijital</strong> &#231;a&#287;&#305;n en &#246;nemli konular&#305;ndan biri &#8220;&#304;nsan ile algoritma aras&#305;ndaki karar ili&#351;kisi nas&#305;l y&#246;netilecek?&#8221; sorusuna verilecek yan&#305;tta yer almaktad&#305;r. </p><p>Bu nedenle a&#351;a&#287;&#305;da belirtilen yeni akademik alanlar&#305;n ortaya &#231;&#305;kmas&#305; tesad&#252;f de&#287;ildir. </p><ul><li><p><strong>Human-AI Interaction</strong></p></li><li><p><strong>Cognitive Systems</strong></p></li><li><p><strong>AI Psychology</strong></p></li><li><p><strong>Neurotechnology</strong></p></li><li><p><strong>Behavioral Data Science</strong></p></li><li><p><strong>Decision Intelligence</strong></p></li></ul><p><br>&#214;zellikle <strong>NATO</strong>&#8217;nun &#8220;<strong>Cognitive Warfare (Bili&#351;sel Sava&#351;)</strong>&#8221; &#231;al&#305;&#351;malar&#305; ve <br><strong>DARPA (Savunma &#304;leri Ara&#351;t&#305;rma Projeleri Ajans&#305;)</strong> ara&#351;t&#305;rmalar&#305;: <br><strong>&#304;nsan bili&#351;inin, bilgi ak&#305;&#351;lar&#305;n&#305;n, algoritmik y&#246;nlendirmelerin stratejik alan haline geldi&#287;ini g&#246;stermektedir.</strong></p><p>Bu nedenle gelece&#287;in &#252;niversitesi; <strong>Psikoloji, veri bilimi, g&#252;venlik, yapay zeka, n&#246;robilim</strong> alanlar&#305;n&#305; birlikte ele almak zorundad&#305;r.</p><blockquote><p>Nitekim modern sava&#351; art&#305;k yaln&#305;zca fiziksel alanlarda ger&#231;ekle&#351;memektedir.</p><p>Bilgi ak&#305;&#351;&#305; ve bili&#351;sel manip&#252;lasyon; <strong>Sosyal istikrar&#305;, se&#231;im s&#252;re&#231;lerini, toplumsal davran&#305;&#351;lar&#305; etkileyebilmektedir.</strong></p></blockquote><p></p><h1>&#220;niversiteler Art&#305;k Jeopolitik G&#252;&#231; Merkezleri</h1><p>So&#287;uk Sava&#351; d&#246;neminde &#252;niversiteler; Bilimsel &#252;st&#252;nl&#252;k, uzay yar&#305;&#351;&#305;, n&#252;kleer ara&#351;t&#305;rmalar i&#231;in birbirleri ile yar&#305;&#351;an kritik merkezler olarak var oluyorlard&#305; !</p><p>Bug&#252;n ise; <strong>AI, quantum, yar&#305; iletken teknolojileri, biyoteknoloji, siber g&#252;venlik</strong> alanlar&#305;nda yeni <strong>jeopolitik rekabet sahalar&#305;</strong> haline geldiler !</p><p>&#214;zellikle; <strong>ABD&#8211;&#199;in</strong> teknoloji rekabeti, <strong>NVIDIA GPU</strong> ambargolar&#305;, <strong>ASML EUV</strong> litografi k&#305;s&#305;tlamalar&#305; ve <strong>AI chip sava&#351;lar&#305;</strong> &#252;niversitelerin stratejik &#246;nemini giderek art&#305;rmaktad&#305;r.</p><blockquote><p>&#220;niversiteler art&#305;k yaln&#305;zca e&#287;itim kurumu de&#287;ildirler, ayn&#305; zamanda: <br><strong>Devlet, teknoloji &#351;irketi, savunma sanayi, yapay zeka ekosistemi aras&#305;ndaki g&#252;&#231; a&#287;lar&#305;n&#305;n par&#231;as&#305; olmu&#351;turlar !</strong></p></blockquote><p>Buradan hareketle; &#220;niversiteler i&#231;in art&#305;k akademik oldu&#287;u kadar <strong>stratejik bir altyap&#305; merkezi</strong> ifadesini kullanmak yanl&#305;&#351; olmayacakt&#305;r !</p><p></p><h1>Disiplinlerin &#214;l&#252;m&#252; ve Hibrit E&#287;itim Modeli</h1><p><strong>Post-dijital</strong> &#231;a&#287;&#305;n en &#246;nemli &#246;zelliklerinden biri; <strong>Disiplin s&#305;n&#305;rlar&#305;n&#305;n &#231;&#246;z&#252;lmesidir.</strong></p><p>Nitekim g&#252;n&#252;m&#252;zde modern problemler; <strong>Tek alan bilgisiyle &#231;&#246;z&#252;lememektedir.</strong></p><p>&#214;rne&#287;in: Bir otonom ara&#231; sistemi i&#231;in:</p><ul><li><p><strong>AI,</strong></p></li><li><p><strong>Cybersecurity,</strong></p></li><li><p><strong>Ethics,</strong></p></li><li><p><strong>Robotics,</strong></p></li><li><p><strong>Behavioral science,</strong></p></li><li><p><strong>Hukuk</strong></p></li></ul><p>disiplinleri, metodolojileri ve &#231;al&#305;&#351;malar&#305; ayn&#305; anda gereklidir, birbirleriyle etkile&#351;im i&#231;indedir !</p><blockquote><p>Bu nedenle gelece&#287;in &#252;niversiteleri; <strong>B&#246;l&#252;m merkezli de&#287;il, problem merkezli e&#287;itime y&#246;nelmektedirler.</strong></p></blockquote><p><strong>World Economic Forum</strong> ve <strong>OECD</strong> ara&#351;t&#305;rmalar&#305; da gelecekte; <strong>Adaptasyon, multidisipliner d&#252;&#351;&#252;nce, problem &#231;&#246;zme, bili&#351;sel esneklik</strong> gibi yetkinliklerin &#246;ne &#231;&#305;kaca&#287;&#305;n&#305; g&#246;stermektedir.</p><p></p><h1>Sonu&#231;</h1><p>Art&#305;k &#252;niversiteler yaln&#305;zca diploma veren kurumlar olmayacakt&#305;r.<br><br>&#220;niversiteler art&#305;k: <strong>&#304;nsan ile yapay zeka aras&#305;ndaki ili&#351;kiyi y&#246;neten, algoritmik d&#252;nyay&#305; anlamland&#305;ran, bili&#351;sel dayan&#305;kl&#305;l&#305;k &#252;reten, stratejik karar kapasitesi geli&#351;tiren, dijital uygarl&#305;&#287;&#305;n g&#252;venli&#287;ini sa&#287;layan</strong> kurumlara d&#246;n&#252;&#351;ecektir.</p><p>Bu nedenle <strong>post-dijital</strong> &#252;niversite modeli hi&#231; &#351;&#252;phesiz; <br><strong>Teknoloji, g&#252;venlik, etik, strateji, insan davran&#305;&#351;&#305;, bili&#351;sel bilim</strong> alanlar&#305;n&#305;n birle&#351;ti&#287;i yeni bir akademik paradigma olu&#351;turmaktad&#305;r !</p><p>Gelece&#287;in en de&#287;erli insan modeli b&#252;y&#252;k ihtimalle salt teknik uzman de&#287;il, ayn&#305; zamanda:<br><strong>Karma&#351;&#305;k sistemleri anlayabilen, AI ile birlikte d&#252;&#351;&#252;nebilen, algoritmalar&#305; sorgulayabilen, bili&#351;sel manip&#252;lasyonlar&#305; fark edebilen, stratejik karar verebilen, etik s&#305;n&#305;rlar&#305; de&#287;erlendirebilen</strong> birey olacakt&#305;r.</p><p>Nitekim <strong>post-dijital &#231;a&#287;da g&#252;&#231;</strong> art&#305;k yaln&#305;zca;<br>Bilgiye sahip olmak de&#287;il, o bilgiyi yorumlayabilmek, g&#252;vence alt&#305;na alabilmek, do&#287;ru karar &#252;retmek i&#231;in kullanabilmek olacakt&#305;r !</p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,<br>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,<br>CompTIA Project+ Professional,<br>CIW Security Analyst,<br>Certified Cyber Threat Intelligence Analyst,<br>Certified Information Security Executive&#8482;,<br>Senior Certified Leadership Practitioner</p><h1>Kaynak&#231;a</h1><ul><li><p><strong>World Economic Forum</strong>. <em>The Future of Jobs Report 2025.</em><br>Yapay zeka, otomasyon ve gelece&#287;in yetkinlikleri &#252;zerine kapsaml&#305; k&#252;resel analizler.</p></li><li><p><strong>Organisation for Economic Co-operation and Development</strong>. <em>OECD Skills Outlook 2023: Skills for a Resilient Green and Digital Transition.</em><br>Dijital d&#246;n&#252;&#351;&#252;m, e&#287;itim sistemleri ve gelece&#287;in i&#351; g&#252;c&#252; &#252;zerine rapor.</p></li><li><p><strong>United Nations Educational, Scientific and Cultural Organization</strong>. <em>Futures of Education Initiative.</em><br>E&#287;itim sistemlerinin gelece&#287;i ve post-dijital &#246;&#287;renme ekosistemleri &#252;zerine &#231;al&#305;&#351;malar.</p></li><li><p><strong>Stanford University</strong>. <em>AI Index Report 2025.</em><br>Yapay zeka ekosistemi, akademik d&#246;n&#252;&#351;&#252;m ve k&#252;resel AI trendleri.</p></li><li><p><strong>Massachusetts Institute of Technology</strong>. <em>MIT Task Force on the Work of the Future.</em><br>Otomasyon, AI ve &#252;niversite&#8211;i&#351; g&#252;c&#252; d&#246;n&#252;&#351;&#252;m&#252; &#252;zerine analizler.</p></li><li><p><strong>National Institute of Standards and Technology</strong>. <em>AI Risk Management Framework (AI RMF).</em><br>Yapay zeka y&#246;neti&#351;imi ve g&#252;venlik yakla&#351;&#305;m&#305;.</p></li><li><p><strong>European Union Agency for Cybersecurity</strong>. <em>Threat Landscape Reports.</em><br>Siber g&#252;venlik, kritik altyap&#305;lar ve dijital riskler &#252;zerine Avrupa perspektifi.</p></li><li><p><strong>North Atlantic Treaty Organization Cooperative Cyber Defence Centre of Excellence.</strong><br>Cognitive warfare, cyber operations ve dijital g&#252;venlik &#231;al&#305;&#351;malar&#305;.</p><p></p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Post-Digital Universities: What Kind of People Are Universities Preparing for the Future?]]></title><description><![CDATA[Thanks for reading Ziya's Substack!]]></description><link>https://ziyagokalp.substack.com/p/post-digital-universities-what-kind</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/post-digital-universities-what-kind</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Tue, 19 May 2026 19:58:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!4B2O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231efce4-9b70-45f4-870a-a40674dadf2d_1659x948.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4B2O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231efce4-9b70-45f4-870a-a40674dadf2d_1659x948.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4B2O!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231efce4-9b70-45f4-870a-a40674dadf2d_1659x948.heic 424w, https://substackcdn.com/image/fetch/$s_!4B2O!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231efce4-9b70-45f4-870a-a40674dadf2d_1659x948.heic 848w, https://substackcdn.com/image/fetch/$s_!4B2O!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231efce4-9b70-45f4-870a-a40674dadf2d_1659x948.heic 1272w, https://substackcdn.com/image/fetch/$s_!4B2O!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231efce4-9b70-45f4-870a-a40674dadf2d_1659x948.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4B2O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231efce4-9b70-45f4-870a-a40674dadf2d_1659x948.heic" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/231efce4-9b70-45f4-870a-a40674dadf2d_1659x948.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:406680,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/198426118?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231efce4-9b70-45f4-870a-a40674dadf2d_1659x948.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4B2O!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231efce4-9b70-45f4-870a-a40674dadf2d_1659x948.heic 424w, https://substackcdn.com/image/fetch/$s_!4B2O!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231efce4-9b70-45f4-870a-a40674dadf2d_1659x948.heic 848w, https://substackcdn.com/image/fetch/$s_!4B2O!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231efce4-9b70-45f4-870a-a40674dadf2d_1659x948.heic 1272w, https://substackcdn.com/image/fetch/$s_!4B2O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231efce4-9b70-45f4-870a-a40674dadf2d_1659x948.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Introduction</h1><p>Throughout history, universities have never been merely institutions that produce knowledge.</p><p>At the same time, they have been strategic structures that shaped the type of <strong>human beings societies needed, determined the modes of knowledge production, influenced thought, constructed perceptions of truth, and established intellectual frameworks.</strong></p><p><strong>Medieval universities emerged as institutions that supported theological thought, legal systems, and state bureaucracies.</strong></p><p>Following the <strong>Industrial Revolution, universities began producing engineers, technical experts, industrial managers, and a modern professional class.</strong></p><p><strong>In the 20th century</strong>, universities evolved into one of the driving forces behind nation-states&#8217; economic growth, scientific research centers, and arenas of technological competition.</p><p>However, as humanity approaches the second quarter of the <strong>21st century</strong>, universities are entering a new historical rupture.</p><p>At the center of this transformation undoubtedly lie <strong>artificial intelligence, algorithmic governance, cyber-physical systems, the data economy, automation, cognitive warfare, and human-machine interaction.</strong></p><p>For this reason, both today and in the future, humanity will no longer inhabit merely:</p><blockquote><p>&#8220;A digitalizing world,&#8221;</p></blockquote><p>but rather,</p><blockquote><p><strong>&#8220;A post-digital civilization.&#8221;</strong></p></blockquote><p>Moreover, in the <strong>post-digital</strong> age, technology itself is no longer perceived as a visible innovation.</p><p>The internet, cloud systems, data centers, mobile networks, and artificial intelligence infrastructures have become the invisible backbone of modern life.</p><p>Consequently, the fundamental question universities must address is also changing.<br>The former question &#8212; &#8220;What knowledge should be transferred to people?&#8221; &#8212; is increasingly being replaced by:</p><blockquote><p>&#8220;How can a human being survive in an algorithmic world?&#8221;</p></blockquote><p>Undoubtedly, this transformation is not merely academic.<br>It is simultaneously an <strong>economic, geopolitical, cognitive, cultural, and security-oriented transformation.</strong></p><p>Indeed, competition among states is now shaped not only by energy resources, natural resources, and industrial production, but also by <strong>artificial intelligence capacity, quantum research, semiconductor technologies, cybersecurity expertise, and data sovereignty.</strong></p><p>Therefore, universities are no longer merely educational institutions.<br>They are becoming strategic <strong>human-production centers, arenas of technological competition, and ecosystems of cognitive power.</strong></p><p></p><h1>The Ontology of the Post-Digital Age</h1><p>The concept of the &#8220;<strong>post-digital</strong>&#8221; era first emerged to describe how digital technologies transformed into the invisible infrastructure of everyday life.</p><p>One of the most influential figures in modern digital culture and technological thought, <strong>Nicholas Negroponte</strong>, expressed this shift as early as 1998 through his famous statement:</p><blockquote><p><strong>&#8220;The digital revolution is over.&#8221;</strong></p></blockquote><p>This perspective can, in many ways, be interpreted as one of the earliest signals of today&#8217;s <strong>post-digital</strong> paradigm.</p><p>Indeed, in today&#8217;s world, digitalization is no longer an advantage; it is the minimum and unavoidable requirement of modern systems.</p><p>What truly creates differentiation today is the ability to manage digital systems, understand the algorithmic world, interpret data flows, and make decisions alongside artificial intelligence.</p><p>At this point, the ideas of the German philosopher <strong>Martin Heidegger</strong> particularly his concept of &#8220;<strong>Gestell</strong>&#8221; <strong>(Enframing)</strong> regain renewed significance.</p><p>According to <strong>Heidegger</strong>, technology is not merely a tool; it is a framework that transforms the very way human beings perceive the world.</p><p>At the stage humanity has reached today, algorithms increasingly shape our access to <strong>information, our social relationships, consumer behaviors, security policies, and even our perception of reality itself.</strong></p><p>At the same time, the concepts of &#8220;<strong>simulation</strong>&#8221; and &#8220;<strong>hyperreality</strong>&#8221; developed by the French philosopher <strong>Jean Baudrillard</strong>, known for his radical ideas on media, consumer culture, and reality have acquired renewed meaning in the <strong>post-digital</strong> age.</p><p>Artificial intelligence&#8211;driven content production, deepfake systems, and algorithmic media structures are increasingly blurring the boundaries between reality and simulation.</p><p>From this perspective, it becomes clear that a <strong>post-digital university</strong> cannot merely produce technical specialists.</p><p>At the same time, <strong>it must cultivate epistemological awareness, the ability to question how knowledge is produced, validated, manipulated, and within which limits it remains valid as well as cognitive resilience and, undoubtedly, critical thinking itself.</strong></p><p></p><h1>Artificial Intelligence and the Restructuring of the University</h1><p>At the center of the academic transformation emerging after 2026 undoubtedly lies artificial intelligence.</p><p>Reports such as the <strong>AI Index Report</strong> published by <strong>Stanford University</strong> and the <strong>Future of Jobs reports</strong> published by the <strong>World Economic Forum</strong> demonstrate that <br><strong>AI-oriented competencies will become some of the fastest-growing fields in the coming years.</strong></p><p>In this context, the following areas are rapidly rising and gaining prominence:</p><ul><li><p><strong>Machine Learning</strong></p></li><li><p><strong>AI Engineering</strong></p></li><li><p><strong>Prompt Engineering</strong></p></li><li><p><strong>AI Governance</strong></p></li><li><p><strong>AI Ethics</strong></p></li><li><p><strong>Generative AI Systems</strong></p></li></ul><p>However, the critical issue here is not merely technical specialization alone.</p><p>Indeed, AI is now transforming virtually every domain, <strong>including law, economics, national security, media, education, healthcare, and industrial production.</strong></p><p>Within this framework, it is no coincidence that universities such as <strong>Massachusetts Institute of Technology, Stanford University, University of Oxford, Harvard University</strong>, and <strong>ETH Z&#252;rich</strong> are rapidly expanding hybrid programs such as:</p><ul><li><p><strong>Human-Centered AI</strong></p></li><li><p><strong>Responsible AI</strong></p></li><li><p><strong>AI &amp; Society</strong></p></li><li><p><strong>AI Governance</strong></p></li></ul><p>This transformation is, in reality, reshaping universities&#8217; understanding of what it means to be human.</p><p>Universities are no longer attempting to educate:</p><blockquote><p>&#8220;Human beings who merely store knowledge,&#8221;</p></blockquote><p>but rather,</p><blockquote><p><strong>&#8220;Human beings who can think, create, and produce together with algorithms.&#8221;</strong></p></blockquote><p></p><h1>Cybersecurity Is Evolving into a New Academic Discipline</h1><p>Today, cybersecurity is no longer merely a technical field of specialization.</p><p>Over time, incidents such as:</p><ul><li><p><strong>SolarWinds cyberattack</strong></p></li><li><p><strong>Colonial Pipeline ransomware attack</strong></p></li><li><p><strong>WannaCry ransomware attack</strong></p></li><li><p><strong>NotPetya cyberattack</strong></p></li><li><p><strong>Stuxnet</strong></p></li></ul><p>have demonstrated that modern cyberattacks are now capable of directly affecting the physical world, energy systems, urban infrastructures, economic systems, and healthcare infrastructures.</p><p>For this reason, cybersecurity is moving beyond the boundaries of computer engineering and evolving into a strategic security discipline.</p><p>Reports published by:</p><ul><li><p><strong>National Institute of Standards and Technology</strong></p></li><li><p><strong>European Union Agency for Cybersecurity</strong></p></li><li><p><strong>NATO Cooperative Cyber Defence Centre of Excellence</strong></p></li><li><p><strong>World Economic Forum</strong></p></li></ul><p>indicate that the following fields will experience significant growth in the coming years:</p><ul><li><p><strong>OT/ICS Security</strong></p></li><li><p><strong>Machine Cybersecurity</strong></p></li><li><p><strong>National Cyber Resilience</strong></p></li><li><p><strong>Cyber-Physical Security</strong></p></li><li><p><strong>AI Security</strong></p></li><li><p><strong>Supply Chain Security</strong></p></li><li><p><strong>Quantum Security</strong></p></li><li><p><strong>Critical Infrastructure Protection</strong></p></li></ul><p>Undoubtedly, this transformation is also reshaping universities themselves.</p><p>The security expert of the future will no longer be merely someone who configures firewalls, deploys intrusion detection systems, or analyzes alarms in security operation centers.</p><blockquote><p><strong>The new generation of specialists is evolving into a hybrid profile capable of strategic thinking, understanding operational risks, evaluating AI systems, analyzing cognitive manipulation, and protecting critical infrastructures.</strong></p></blockquote><p></p><h1>The Quantum Age and the Rise of New Academic Elites</h1><p>Quantum computing is widely regarded as one of the most strategic technologies of the coming decade.</p><p>Reports published by <strong>McKinsey &amp; Company</strong>, <strong>IBM</strong>, and <strong>UNESCO</strong> indicate that quantum technologies could revolutionize fields such as defense, pharmaceutical development, finance, artificial intelligence, and cryptography.</p><p>For this reason, many universities are inevitably establishing programs such as:</p><ul><li><p><strong>Quantum Information Science</strong></p></li><li><p><strong>Quantum Cryptography</strong></p></li><li><p><strong>Post-Quantum Security</strong></p></li><li><p><strong>Quantum Algorithms</strong></p></li></ul><p>From this perspective, it would not be inaccurate to argue that &#8220;<strong>Post-Quantum Cryptography</strong>&#8221; will become one of the most critical academic disciplines of the coming era.</p><p>Indeed, sufficiently powerful quantum computers could theoretically break a significant portion of today&#8217;s existing cryptographic systems.</p><p>This situation poses a strategic risk particularly for <strong>national security, financial systems, and critical infrastructures.</strong></p><blockquote><p><strong>Therefore, the universities of the future are no longer responsible solely for educating software developers; they are also obligated to train the security architects of the quantum age.</strong></p></blockquote><p></p><h1>Human&#8211;Machine Relations Are Giving Rise to New Academic Disciplines</h1><p>One of the most important questions of the <strong>post-digital</strong> age lies in how humanity will manage the decision-making relationship between humans and algorithms.</p><p>For this reason, it is no coincidence that new academic fields such as the following are rapidly emerging:</p><ul><li><p><strong>Human-AI Interaction</strong></p></li><li><p><strong>Cognitive Systems</strong></p></li><li><p><strong>AI Psychology</strong></p></li><li><p><strong>Neurotechnology</strong></p></li><li><p><strong>Behavioral Data Science</strong></p></li><li><p><strong>Decision Intelligence</strong></p></li></ul><p>In particular, the &#8220;<strong>Cognitive Warfare</strong>&#8221; studies conducted by <strong>NATO</strong> and the <strong>research initiatives of Defense Advanced Research Projects Agency</strong> demonstrate that human cognition, information flows, and algorithmic influence mechanisms are increasingly becoming strategic domains.</p><p>Therefore, the university of the future must address <strong>psychology, data science, security, artificial intelligence, and neuroscience together within an integrated framework.</strong></p><blockquote><p>Modern conflict no longer occurs solely within physical battlefields.</p><p><strong>Information flows and cognitive manipulation are now capable of influencing social stability, electoral processes, and collective human behavior itself.</strong></p></blockquote><p></p><h1>Universities Are Becoming Geopolitical Power Centers</h1><p>During the Cold War era, universities functioned as critical institutions competing for scientific superiority, the space race, and nuclear research capabilities.</p><p>Today, they are evolving into new arenas of geopolitical competition in fields such as artificial intelligence, quantum technologies, semiconductors, biotechnology, and cybersecurity.</p><p>In particular, the technological rivalry between the <strong>United States</strong> and <strong>China</strong>, restrictions on <strong>NVIDIA GPU</strong>s, limitations surrounding <strong>ASML EUV</strong> lithography systems, and the broader <strong>AI chip wars</strong> are steadily increasing the strategic importance of universities.</p><blockquote><p>Universities are no longer merely educational institutions.<br><strong>They have become integral parts of the power networks connecting states, technology companies, defense industries, and artificial intelligence ecosystems.</strong></p></blockquote><p>From this perspective, it would not be inaccurate to describe modern universities not only as academic institutions, but also as <strong>strategic infrastructure centers.</strong></p><p></p><h1>The Death of Disciplines and the Rise of the Hybrid Education Model</h1><p>One of the defining characteristics of the <strong>post-digital</strong> age is the dissolution of disciplinary boundaries.</p><p>Modern problems can no longer be solved through expertise confined to a single field alone.</p><p>For example, the development of an autonomous vehicle system simultaneously requires the interaction of multiple disciplines, methodologies, and research domains, including:</p><ul><li><p><strong>Artificial Intelligence</strong></p></li><li><p><strong>Cybersecurity</strong></p></li><li><p><strong>Ethics</strong></p></li><li><p><strong>Robotics</strong></p></li><li><p><strong>Behavioral Science</strong></p></li><li><p><strong>Law</strong></p></li></ul><blockquote><p><strong>For this reason, the universities of the future are increasingly shifting away from department-centered education toward problem-centered educational models.</strong></p></blockquote><p>Research published by the <strong>World Economic Forum</strong> and the <strong>Organisation for Economic Co-operation and Development</strong> also demonstrates that competencies such as adaptability, multidisciplinary thinking, problem-solving, and cognitive flexibility will become increasingly critical in the future.</p><p></p><h1>Conclusion</h1><p>Universities will no longer function merely as institutions that grant diplomas.</p><p>They are evolving into institutions that manage the relationship <strong>between humans and artificial intelligence, interpret the algorithmic world, cultivate cognitive resilience, develop strategic decision-making capacity, and ensure the security of digital civilization itself.</strong></p><p>For this reason, the <strong>post-digital university</strong> model undoubtedly represents a new academic paradigm in which <strong>technology, security, ethics, strategy, human behavior, and cognitive sciences converge.</strong></p><p>The most valuable type of individual in the future will likely not be merely a technical specialist, but rather someone who can <strong>understand complex systems, think alongside AI, question algorithms, recognize cognitive manipulation, make strategic decisions, and evaluate ethical boundaries.</strong></p><p>Indeed, in the <strong>post-digital age</strong>, power will no longer consist solely of possessing information; it will increasingly depend on the ability to interpret that information, secure it, and use it to produce sound and <strong>strategic decisions.</strong></p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,<br>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,<br>CompTIA Project+ Professional,<br>CIW Security Analyst,<br>Certified Cyber Threat Intelligence Analyst,<br>Certified Information Security Executive&#8482;,<br>Senior Certified Leadership Practitioner</p><p></p><h1>References</h1><ul><li><p><strong>World Economic Forum</strong>. <em>The Future of Jobs Report 2025.</em><br>Comprehensive global analyses on artificial intelligence, automation, and future workforce competencies.</p></li><li><p><strong>Organisation for Economic Co-operation and Development</strong>. <em>OECD Skills Outlook 2023: Skills for a Resilient Green and Digital Transition.</em><br>Report on digital transformation, education systems, and the future workforce.</p></li><li><p><strong>United Nations Educational, Scientific and Cultural Organization</strong>. <em>Futures of Education Initiative.</em><br>Studies on the future of education systems and post-digital learning ecosystems.</p></li><li><p><strong>Stanford University</strong>. <em>AI Index Report 2025.</em><br>Research on the artificial intelligence ecosystem, academic transformation, and global AI trends.</p></li><li><p><strong>Massachusetts Institute of Technology</strong>. <em>MIT Task Force on the Work of the Future.</em><br>Analyses on automation, AI, and the transformation of universities and the workforce.</p></li><li><p><strong>National Institute of Standards and Technology</strong>. <em>AI Risk Management Framework (AI RMF).</em><br>Framework addressing AI governance and security approaches.</p></li><li><p><strong>European Union Agency for Cybersecurity</strong>. <em>Threat Landscape Reports.</em><br>European perspectives on cybersecurity, critical infrastructures, and digital risks.</p></li><li><p><strong>NATO Cooperative Cyber Defence Centre of Excellence</strong>.<br>Research and studies on cognitive warfare, cyber operations, and digital security.</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[UAV Forensics: Gökyüzündeki Dijital Deliller]]></title><description><![CDATA[PODCAST Linki]]></description><link>https://ziyagokalp.substack.com/p/uav-forensics-gokyuzundeki-dijital</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/uav-forensics-gokyuzundeki-dijital</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Fri, 15 May 2026 07:15:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_SAm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6c4013-d795-41ca-a23d-63d8a71cdd21_1536x1024.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_SAm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6c4013-d795-41ca-a23d-63d8a71cdd21_1536x1024.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_SAm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6c4013-d795-41ca-a23d-63d8a71cdd21_1536x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!_SAm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6c4013-d795-41ca-a23d-63d8a71cdd21_1536x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!_SAm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6c4013-d795-41ca-a23d-63d8a71cdd21_1536x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!_SAm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6c4013-d795-41ca-a23d-63d8a71cdd21_1536x1024.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_SAm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6c4013-d795-41ca-a23d-63d8a71cdd21_1536x1024.heic" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5f6c4013-d795-41ca-a23d-63d8a71cdd21_1536x1024.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:323615,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/197321507?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6c4013-d795-41ca-a23d-63d8a71cdd21_1536x1024.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_SAm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6c4013-d795-41ca-a23d-63d8a71cdd21_1536x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!_SAm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6c4013-d795-41ca-a23d-63d8a71cdd21_1536x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!_SAm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6c4013-d795-41ca-a23d-63d8a71cdd21_1536x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!_SAm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6c4013-d795-41ca-a23d-63d8a71cdd21_1536x1024.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://creators.spotify.com/pod/profile/ziyagokalp/episodes/UAV-Forensics-Gkyzndeki-Dijital-Deliller-e3j8lht">PODCAST Linki</a></strong></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Giri&#351;</h1><p>G&#252;n&#252;m&#252;zde<strong> &#8220;&#304;nsans&#305;z Hava Ara&#231;lar&#305; (UAV &#8211; Unmanned Aerial Vehicles)&#8221;</strong>, modern g&#252;venlik paradigmas&#305;n&#305; de&#287;i&#351;tiren en &#246;nemli teknolojik d&#246;n&#252;&#351;&#252;mlerden biri haline gelmi&#351;tir. </p><p>Bir d&#246;nem yaln&#305;zca devletlerin ve askeri kurumlar&#305;n eri&#351;ebildi&#287;i ileri seviye sistemler olarak g&#246;r&#252;len drone teknolojileri, bug&#252;n bireylerin dahi sat&#305;n alabilece&#287;i kadar eri&#351;ilebilir hale gelmi&#351;tir. </p><p>Ancak bu demokratikle&#351;me yaln&#305;zca teknolojik yayg&#305;nla&#351;may&#305; de&#287;il, ayn&#305; zamanda g&#252;venlik risklerinin de kitleselle&#351;mesini beraberinde getirmi&#351;tir.</p><p>Modern bir drone art&#305;k yaln&#305;zca havadan g&#246;r&#252;nt&#252; alan bir cihaz de&#287;ildir. <br>Drone art&#305;k; <strong>Sens&#246;rlerle donat&#305;lm&#305;&#351;, GPS destekli, ger&#231;ek zamanl&#305; veri aktar&#305;m&#305; yapabilen, yapay zeka destekli karar mekanizmalar&#305;na sahip mobil bir dijital platformdur.</strong> </p><p>Bir ba&#351;ka ifadeyle drone sistemleri art&#305;k havada dola&#351;an <strong>siber-fiziksel</strong> sistemlerdir.</p><p>Bu nedenle g&#252;n&#252;m&#252;zde bir drone kazas&#305;, izinsiz u&#231;u&#351; veya g&#252;venlik ihlali yaln&#305;zca havac&#305;l&#305;k perspektifiyle ele al&#305;nmamaktad&#305;r. </p><p><strong>Art&#305;k soru&#351;turulan &#351;ey, ayn&#305; zamanda bir dijital olayd&#305;r.</strong></p><p>Bu ba&#287;lamda <strong>UAV Forensics</strong> <strong>(&#304;nsans&#305;z Hava Ara&#231;lar&#305; Forensi&#287;i)</strong> kavram&#305; ortaya &#231;&#305;kmaktad&#305;r.</p><p>Yani;<strong> UAV Forensics, insans&#305;z hava ara&#231;lar&#305;n&#305;n dijital, fiziksel ve haberle&#351;me katmanlar&#305;nda b&#305;rakt&#305;&#287;&#305; izlerin analiz edilmesi s&#252;recidir.</strong> </p><p><strong>Bu disiplin dijital adli bili&#351;im, elektronik harp, istihbarat, siber g&#252;venlik ve havac&#305;l&#305;k teknolojilerinin kesi&#351;im noktas&#305;nda yer alan yeni nesil bir inceleme alan&#305;d&#305;r.</strong></p><p>&#214;zellikle son y&#305;llarda ya&#351;anan bir&#231;ok olay, drone sistemlerinin art&#305;k yaln&#305;zca &#8220;Teknolojik ara&#231;lar&#8221; de&#287;il, ayn&#305; zamanda <strong>stratejik g&#252;venlik akt&#246;rleri haline geldi&#287;ini g&#246;stermektedir.</strong></p><p>&#214;rne&#287;in <strong>Ukrayna-Rusya sava&#351;&#305;</strong> s&#305;ras&#305;nda ticari drone sistemlerinin ke&#351;if, koordinat belirleme ve hatta sald&#305;r&#305; operasyonlar&#305;nda yo&#287;un &#351;ekilde kullan&#305;lmas&#305;, d&#252;nya genelinde UAV teknolojilerine bak&#305;&#351;&#305; k&#246;kten de&#287;i&#351;tirmi&#351;tir. </p><p><strong>Benzer &#351;ekilde kritik altyap&#305;lar &#252;zerinde izinsiz u&#231;u&#351; yapan drone&#8217;lar, enerji santrallerinden askeri tesislere kadar bir&#231;ok noktada ciddi g&#252;venlik soru&#351;turmalar&#305;na neden olmu&#351;tur.</strong></p><p><strong>Dolay&#305;s&#305;yla art&#305;k g&#246;ky&#252;z&#252; yaln&#305;zca fiziksel bir hava sahas&#305; de&#287;il, ayn&#305; zamanda dijital delillerin dola&#351;t&#305;&#287;&#305; yeni nesil bir siber operasyon alan&#305;d&#305;r.</strong></p><p></p><h1>UAV Forensics Nedir?</h1><p><strong>UAV Forensics</strong>, insans&#305;z hava ara&#231;lar&#305;ndan dijital delil elde edilmesi, bu delillerin analiz edilmesi ve olay&#305;n teknik olarak yeniden yap&#305;land&#305;r&#305;lmas&#305; s&#252;recidir.</p><p>Bu disiplinin temel amac&#305; yaln&#305;zca cihaz&#305;n sahibini bulmak de&#287;ildir. <br><strong>As&#305;l ama&#231;, UAV&#8217;nin operasyonel davran&#305;&#351;&#305;n&#305; anlamakt&#305;r.</strong></p><p>Bir ba&#351;ka ifadeyle bu <strong>UAV Forensics disiplininde</strong> &#351;u sorular&#305;n cevab&#305; aranmaktad&#305;r:</p><ul><li><p><strong>Drone nereden kalkt&#305;?</strong></p></li><li><p><strong>Hangi rotay&#305; izledi?</strong></p></li><li><p><strong>Hangi verileri toplad&#305;?</strong></p></li><li><p><strong>Kim taraf&#305;ndan kontrol edildi?</strong></p></li><li><p><strong>Uzaktan m&#252;dahaleye u&#287;rad&#305; m&#305;?</strong></p></li><li><p><strong>Bir sald&#305;r&#305;n&#305;n par&#231;as&#305; m&#305;yd&#305;?</strong></p></li><li><p><strong>Manip&#252;le edildi mi?</strong></p></li></ul><p><strong>Modern UAV</strong> sistemleri asl&#305;nda &#231;ok yo&#287;un miktarda veri &#252;retir. </p><p>Nitekim, &#231;o&#287;u drone u&#231;u&#351; s&#305;ras&#305;nda s&#252;rekli olarak <strong>telemetri kayd&#305;</strong> tutar. <br>Bu kay&#305;tlar; <strong>GPS koordinatlar&#305;ndan h&#305;z bilgilerine, sens&#246;r verilerinden ba&#287;lant&#305; loglar&#305;na kadar &#231;ok geni&#351; bir veri seti i&#231;erir.</strong></p><p>&#214;rne&#287;in birka&#231; y&#305;l &#246;nce Avrupa&#8217;da bir havaalan&#305;n&#305;n uzun s&#252;re operasyon d&#305;&#351;&#305; kalmas&#305;na neden olan drone vakalar&#305;nda yap&#305;lan incelemelerde; <strong>Radar verileri, RF kay&#305;tlar&#305;</strong> ve <strong>u&#231;u&#351; log analizleri</strong> birlikte de&#287;erlendirilmi&#351;ti. <br><br>Olay yaln&#305;zca &#8220;havada bir drone g&#246;r&#252;lmesi&#8221; meselesi de&#287;ildi. <br>Bahsi ge&#231;en drone&#8217;un kim taraf&#305;ndan, hangi ama&#231;la ve hangi teknik kapasiteyle kullan&#305;ld&#305;&#287;&#305;n&#305;n anla&#351;&#305;lmas&#305;yd&#305;.</p><p>Bu nedenle <strong>UAV Forensics</strong> yaln&#305;zca dijital veri kurtarma i&#351;lemi de&#287;ildir. <br>Ayn&#305; zamanda <strong>davran&#305;&#351; analizi, operasyonel niyet analizi ve teknik istihbarat s&#252;recidir.</strong></p><p></p><h1>Drone Sistemlerinin Yeni Nesil Risk Alan&#305; Haline Gelmesi</h1><p>Drone teknolojilerinin tehlikeli hale gelmesinin en temel nedeni, d&#252;&#351;&#252;k maliyet ile y&#252;ksek operasyonel etkiyi birle&#351;tirmesidir.</p><p>Bug&#252;n ticari olarak sat&#305;lan <strong>orta segment bir drone</strong> dahi:</p><ul><li><p><strong>Kilometrelerce uzaktan kontrol edilebilmekte,</strong></p></li><li><p><strong>Y&#252;ksek &#231;&#246;z&#252;n&#252;rl&#252;kl&#252; g&#246;r&#252;nt&#252; aktarabilmekte,</strong></p></li><li><p><strong>Otomatik rota planlayabilmekte,</strong></p></li><li><p><strong>GPS destekli otonom u&#231;u&#351; yapabilmekte,</strong></p></li><li><p><strong>Ger&#231;ek zamanl&#305; veri iletebilmekte,</strong></p></li><li><p><strong>Hedef takibi ger&#231;ekle&#351;tirebilmektedir.</strong></p></li></ul><p>Bu durum, <strong>k&#252;&#231;&#252;k bir cihaz&#305;n stratejik etkiler olu&#351;turabilmesine neden olmaktad&#305;r.</strong></p><p>&#214;rne&#287;in <strong>Orta Do&#287;u</strong>&#8217;da petrol tesislerine y&#246;nelik ger&#231;ekle&#351;tirilen baz&#305; sald&#305;r&#305;larda drone sistemlerinin kullan&#305;lmas&#305;, d&#252;nya enerji g&#252;venli&#287;i a&#231;&#305;s&#305;ndan b&#252;y&#252;k yank&#305; uyand&#305;rm&#305;&#351;t&#305;r. <br><br><strong>Nitekim maliyeti g&#246;rece d&#252;&#351;&#252;k olan platformlar, milyarlarca dolarl&#305;k kritik altyap&#305;lar&#305; etkileyebilecek kapasiteye ula&#351;m&#305;&#351;t&#305;r.</strong></p><p>Benzer &#351;ekilde <strong>Meksika</strong>&#8217;daki kartellerin s&#305;n&#305;r b&#246;lgelerinde drone sistemlerini ke&#351;if ve ka&#231;ak&#231;&#305;l&#305;k amac&#305;yla kullanmas&#305;, g&#252;venlik kurumlar&#305;n&#305;n dikkatini farkl&#305; bir boyuta ta&#351;&#305;m&#305;&#351;t&#305;r. </p><p><strong>Drone</strong>&#8217;lar art&#305;k yaln&#305;zca g&#246;zetleme yapmak i&#231;in de&#287;il, <strong>y&#252;k ta&#351;&#305;ma, s&#305;n&#305;r a&#351;ma, hatta do&#287;rudan sald&#305;r&#305; ger&#231;ekle&#351;tirme amac&#305;yla da kullan&#305;lmaktad&#305;r.</strong></p><p>&#214;te yandan, baz&#305; cezaevlerinde ise drone&#8217;lar arac&#305;l&#305;&#287;&#305;yla:</p><ul><li><p><strong>Uyu&#351;turucu,</strong></p></li><li><p><strong>Telefon,</strong></p></li><li><p><strong>SIM kart,</strong></p></li><li><p><strong>Silah par&#231;alar&#305;</strong></p></li></ul><p>ta&#351;&#305;nd&#305;&#287;&#305; tespit edilmi&#351;tir.</p><p>Bu olaylar, UAV sistemlerinin art&#305;k yaln&#305;zca havac&#305;l&#305;k reg&#252;lasyonlar&#305;n&#305;n konusu olmad&#305;&#287;&#305;n&#305;, ayn&#305; zamanda <strong>ulusal g&#252;venlik meselesi</strong> haline geldi&#287;ini g&#246;stermektedir.</p><p></p><h1>UAV Forensics S&#252;recinde &#304;ncelenen Ba&#351;l&#305;ca Veriler</h1><p>Bir <strong>UAV soru&#351;turmas&#305;</strong> s&#305;ras&#305;nda analiz edilen veriler olduk&#231;a geni&#351; kapsaml&#305;d&#305;r.</p><p>&#304;lk olarak <strong>flight log (u&#231;u&#351; kayd&#305;)</strong> kay&#305;tlar&#305; incelenir. Nitekim modern drone&#8217;lar u&#231;u&#351; s&#305;ras&#305;nda s&#252;rekli <strong>telemetri &#252;retir</strong>. Bu kay&#305;tlar &#231;o&#287;u zaman olay&#305;n <strong>dijital parmak izi niteli&#287;indedir.</strong></p><p>&#214;rne&#287;in bir olayda drone fiziksel olarak ele ge&#231;irilemese bile kontrol cihaz&#305;nda, mobil uygulamada veya bulut senkronizasyon sistemlerinde u&#231;u&#351; ge&#231;mi&#351;i bulunabilmektedir.</p><p>Baz&#305; incelemelerde yaln&#305;zca mobil cihazdaki <strong>cache verileri</strong> sayesinde drone&#8217;un daha &#246;nce hangi b&#246;lgelerde u&#231;tu&#287;u ortaya &#231;&#305;kar&#305;lm&#305;&#351;t&#305;r.</p><p>&#214;zellikle <strong>DJI</strong> gibi yayg&#305;n platformlarda:</p><ul><li><p><strong>Kalk&#305;&#351; koordinatlar&#305;,</strong></p></li><li><p><strong>U&#231;u&#351; rotalar&#305;,</strong></p></li><li><p><strong>Batarya de&#287;i&#351;im ge&#231;mi&#351;i,</strong></p></li><li><p><strong>Cihaz kimlikleri,</strong></p></li><li><p><strong>Kullan&#305;c&#305; oturum bilgileri</strong></p></li></ul><p>tespit edilebilmektedir.</p><p>Bunun yan&#305; s&#305;ra <strong>GPS verileri</strong> de kritik &#246;neme sahiptir.</p><p>&#214;rne&#287;in bir kritik altyap&#305; tesisi &#231;evresinde tekrar eden waypoint davran&#305;&#351;lar&#305; g&#246;r&#252;lmesi, sald&#305;r&#305; &#246;ncesi ke&#351;if faaliyetine i&#351;aret edebilir. Baz&#305; olaylarda drone&#8217;un belirli noktalarda sistematik &#351;ekilde yava&#351;lad&#305;&#287;&#305; veya havada sabit kald&#305;&#287;&#305; g&#246;r&#252;lm&#252;&#351;t&#252;r. Bu durum &#231;o&#287;u zaman g&#246;r&#252;nt&#252; toplama veya sinyal analiz faaliyetleriyle ili&#351;kilendirilmektedir.</p><p>Kamera ve sens&#246;r verileri de ayr&#305; bir inceleme alan&#305;d&#305;r.</p><p>Bir ba&#351;ka &#246;rnek vermek gerekirse; <strong>Bir enerji tesisinin termal g&#246;r&#252;nt&#252;lerinin al&#305;nmas&#305;, s&#305;radan bir hobi u&#231;u&#351;undan &#231;ok daha farkl&#305; anlamlar ta&#351;&#305;yabilir.</strong> </p><p>Nitekim <strong>termal analizler baz&#305; kritik ekipmanlar&#305;n &#231;al&#305;&#351;ma yo&#287;unlu&#287;u hakk&#305;nda istihbarat sa&#287;layabilir.</strong></p><p>Benzer &#351;ekilde <strong>EXIF metadata incelemeleri</strong> sayesinde g&#246;r&#252;nt&#252;lerin hangi koordinatta &#252;retildi&#287;i, hangi cihazla i&#351;lendi&#287;i ve manip&#252;le edilip edilmedi&#287;i anla&#351;&#305;labilmektedir.</p><p></p><h1>RF ve Haberle&#351;me Analizi</h1><p><strong>UAV Forensics</strong>&#8217;in en kritik alanlar&#305;ndan biri <strong>RF (Radio Frequency)</strong> analizidir.</p><p>Nitekim drone sistemleri asl&#305;nda kontrol &#252;niteleri ve kumanda merkezleri ile s&#252;rekli haberle&#351;en platformlard&#305;r.</p><p>Bir drone ile kontrol cihaz&#305; aras&#305;nda ger&#231;ekle&#351;en veri al&#305;&#351;veri&#351;i &#231;o&#287;u zaman operasyonel davran&#305;&#351;&#305;n anla&#351;&#305;lmas&#305;n&#305; sa&#287;lar.</p><p>&#214;rne&#287;in RF analizleri sayesinde:</p><ul><li><p><strong>Operat&#246;r&#252;n yakla&#351;&#305;k konumu,</strong></p></li><li><p><strong>Kullan&#305;lan frekans aral&#305;klar&#305;,</strong></p></li><li><p><strong>Jammer etkileri,</strong></p></li><li><p><strong>Sinyal kesintileri,</strong></p></li><li><p><strong>Spoofing giri&#351;imleri</strong></p></li></ul><p>tespit edilebilmektedir.</p><p>&#214;zellikle sava&#351; b&#246;lgelerinde <strong>RF istihbarat&#305;</strong> b&#252;y&#252;k &#246;nem ta&#351;&#305;maktad&#305;r.</p><p><strong>Ukrayna sava&#351;&#305;nda</strong> bir&#231;ok ticari drone sisteminin <strong>RF imzalar&#305;</strong> analiz edilerek operat&#246;r konumlar&#305;n&#305;n tespit edilmeye &#231;al&#305;&#351;&#305;ld&#305;&#287;&#305; bilinmektedir. </p><p>Nitekim drone yaln&#305;zca hedefi de&#287;il, operat&#246;r&#252; de a&#231;&#305;&#287;a &#231;&#305;karabilen bir sistemdir.</p><p>Bu nedenle modern &#231;at&#305;&#351;ma ortamlar&#305;nda drone kullan&#305;m&#305; ayn&#305; zamanda elektronik g&#246;r&#252;n&#252;rl&#252;k de yaratmaktad&#305;r.</p><p></p><h1>Firmware Manip&#252;lasyonu ve Anti-Forensics</h1><p>G&#252;n&#252;m&#252;zde geli&#351;mi&#351; tehdit akt&#246;rleri drone sistemlerini modifiye edebilmektedir.</p><p>&#214;zellikle:</p><ul><li><p><strong>Geo-fence bypass,</strong></p></li><li><p><strong>Firmware modifikasyonu,</strong></p></li><li><p><strong>U&#231;u&#351; limiti kald&#305;r&#305;lmas&#305;,</strong></p></li><li><p><strong>Otomatik log temizleme,</strong></p></li><li><p><strong>Kimlik gizleme</strong></p></li></ul><p>gibi teknikler giderek yayg&#305;nla&#351;maktad&#305;r.</p><p>&#214;rne&#287;in baz&#305; ka&#231;ak&#231;&#305;l&#305;k operasyonlar&#305;nda ele ge&#231;irilen drone&#8217;lar&#305;n standart &#252;retici yaz&#305;l&#305;m&#305; yerine modifiye edilmi&#351; firmware kulland&#305;&#287;&#305; g&#246;r&#252;lm&#252;&#351;t&#252;r. Bu y&#246;ntemleri ile sald&#305;rganlar &#231;o&#287;u zaman &#252;reticinin koydu&#287;u g&#252;venlik k&#305;s&#305;tlamalar&#305;n&#305; a&#351;maya &#231;al&#305;&#351;maktad&#305;r.</p><p>Baz&#305; geli&#351;mi&#351; sistemlerde ise u&#231;u&#351; sonras&#305;nda log verilerinin otomatik silinmesine y&#246;nelik <strong>anti-forensic</strong> mekanizmalar bulunmaktad&#305;r.</p><p>Bu durum <strong>UAV incelemelerini</strong> &#231;ok daha karma&#351;&#305;k hale getirmektedir.</p><p>Art&#305;k yaln&#305;zca cihaz&#305;n i&#231;indeki verilere bakmak yeterli de&#287;ildir. Ayn&#305; zamanda:</p><ul><li><p><strong>Firmware b&#252;t&#252;nl&#252;&#287;&#252;,</strong></p></li><li><p><strong>Binary analizleri,</strong></p></li><li><p><strong>Haberle&#351;me protokolleri,</strong></p></li><li><p><strong>Donan&#305;msal modifikasyonlar</strong></p></li></ul><p>da incelenmektedir.</p><p>Dolay&#305;s&#305;yla <strong>UAV Forensics</strong> giderek <strong>tersine m&#252;hendislik (reverse engineering)</strong> a&#287;&#305;rl&#305;kl&#305; bir disipline d&#246;n&#252;&#351;mektedir.</p><p></p><h1>OT/ICS G&#252;venli&#287;i A&#231;&#305;s&#305;ndan UAV Tehdidi</h1><p><strong>Kritik altyap&#305;lar</strong> a&#231;&#305;s&#305;ndan drone sistemleri yeni nesil bir ke&#351;if platformu haline gelmi&#351;tir.</p><p>&#214;zellikle <strong>enerji, petrol-gaz, &#252;retim ve su altyap&#305;lar&#305; gibi OT/ICS</strong> <strong>(Operasyonel Teknolojiler ve End&#252;striyel Kontrol Sistemleri)</strong> ortamlar&#305; drone tehditlerine kar&#351;&#305; giderek daha k&#305;r&#305;lgan hale gelmektedir.</p><p>Bir drone fiziksel olarak:</p><ul><li><p><strong>Trafo merkezlerini,</strong></p></li><li><p><strong>Boru hatlar&#305;n&#305;,</strong></p></li><li><p><strong>&#220;retim tesislerini,</strong></p></li><li><p><strong>Enerji da&#287;&#305;t&#305;m noktalar&#305;n&#305;,</strong></p></li><li><p><strong>Rafinerileri</strong></p></li></ul><p>g&#246;r&#252;nt&#252;leyebilir.</p><p>Bu noktada as&#305;l risk yaln&#305;zca g&#246;r&#252;nt&#252;leme de&#287;ildir.</p><p>Baz&#305; geli&#351;mi&#351; operasyonlarda drone&#8217;lar:</p><ul><li><p><strong>Wi-Fi ke&#351;fi,</strong></p></li><li><p><strong>RF analizleri,</strong></p></li><li><p><strong>Bluetooth taramalar&#305;,</strong></p></li><li><p><strong>A&#231;&#305;k eri&#351;im noktas&#305; tespiti,</strong></p></li><li><p><strong>Kablosuz a&#287; haritalamas&#305;</strong></p></li></ul><p>amac&#305;yla kullan&#305;labilmektedirler.</p><p>Bu durum <strong>OT (Operasyonel Teknolojiler)</strong> g&#252;venli&#287;i a&#231;&#305;s&#305;ndan kritik &#246;nem ta&#351;&#305;maktad&#305;r. Nitekim, fiziksel izolasyona g&#252;venen bir&#231;ok tesis, havadan yap&#305;lan ke&#351;if faaliyetlerine kar&#351;&#305; yeterince haz&#305;rl&#305;kl&#305; de&#287;ildir.</p><p><strong>Bir ba&#351;ka ifadeyle modern sald&#305;r&#305; y&#252;zeyi art&#305;k yaln&#305;zca network kablolar&#305;yla s&#305;n&#305;rl&#305; de&#287;ildir. G&#246;ky&#252;z&#252; de sald&#305;r&#305; y&#252;zeyinin par&#231;as&#305; haline gelmi&#351;tir.</strong></p><p></p><h1>Gelece&#287;in Sava&#351; Alan&#305;: Otonom Drone Sistemleri</h1><p><strong>Drone teknolojilerinin</strong> gelece&#287;i yaln&#305;zca uzaktan kontrol edilen sistemler de&#287;ildir.</p><p>Ger&#231;ekte d&#246;n&#252;&#351;&#252;m, otonom karar verebilen drone sistemlerinde ya&#351;anmaktad&#305;r.</p><p>Yak&#305;n gelecekte:</p><ul><li><p><strong>Swarm sistemleri,</strong></p></li><li><p><strong>AI destekli hedef analizi,</strong></p></li><li><p><strong>GPS&#8217;siz navigasyon,</strong></p></li><li><p><strong>Edge AI karar mekanizmalar&#305;,</strong></p></li><li><p><strong>Tam otonom sald&#305;r&#305; platformlar&#305;</strong></p></li></ul><p>&#231;ok daha yayg&#305;n hale gelecektir.</p><p>Bu durum ise hi&#231; &#351;&#252;phesiz <strong>UAV Forensics disiplinini k&#246;kten de&#287;i&#351;tirecektir.</strong></p><p>Nitekim gelecekte incelenmesi gereken &#351;ey yaln&#305;zca &#8220;bir cihaz&#305;n u&#231;u&#351; kayd&#305;&#8221; olmayacakt&#305;r. Bir yapay zeka sistemi neden belirli bir davran&#305;&#351;ta bulundu? bak&#305;&#351; a&#231;&#305;s&#305; ile yap&#305;lacak bir inceleme olacakt&#305;r.</p><p>Bu durum <strong>UAV Forensics</strong>&#8217;i yaln&#305;zca teknik de&#287;il, ayn&#305; zamanda etik, hukuksal ve davran&#305;&#351;sal bir problem haline getirmektedir.</p><p>G&#252;n&#252;m&#252;zde otonom sistemlerin karar mekanizmalar&#305; &#231;o&#287;u zaman insan operat&#246;rlerden daha karma&#351;&#305;k hale gelmektedir.</p><p></p><h1>Sonu&#231;</h1><p>Modern d&#252;nyada g&#246;ky&#252;z&#252; art&#305;k yaln&#305;zca hava ara&#231;lar&#305;n&#305;n dola&#351;t&#305;&#287;&#305; fiziksel bir alan de&#287;ildir.</p><p><strong>G&#246;ky&#252;z&#252; ayn&#305; zamanda veri ak&#305;&#351;lar&#305;n&#305;n, algoritmalar&#305;n, sens&#246;rlerin ve dijital operasyonlar&#305;n hareket etti&#287;i yeni nesil bir g&#252;venlik katman&#305;d&#305;r.</strong></p><p><strong>Drone sistemleri b&#252;y&#252;d&#252;k&#231;e onlar&#305;n &#252;retti&#287;i telemetri kay&#305;tlar&#305;, sens&#246;r &#231;&#305;kt&#305;lar&#305;, RF izleri ve algoritmik davran&#305;&#351;lar&#305; da g&#252;venlik soru&#351;turmalar&#305;n&#305;n merkezine yerle&#351;mektedir.</strong></p><p>Bu nedenle <strong>UAV Forensics</strong> i&#231;in yaln&#305;zca teknik bir inceleme alan&#305; demek son derece yanl&#305;&#351; olacakt&#305;r.</p><p><strong>UAV Forensics </strong>art&#305;k;<strong> Siber g&#252;venlik, elektronik harp, istihbarat, kritik altyap&#305; g&#252;venli&#287;i ve yapay zeka &#231;a&#287;&#305;n&#305;n kesi&#351;im noktas&#305;nda do&#287;an yeni nesil bir stratejik disiplindir.</strong></p><p>Yak&#305;n gelecekte sava&#351;lar yaln&#305;zca kara, deniz, hava ve siber alanda y&#252;r&#252;t&#252;lmeyecektir. Hi&#231; &#351;&#252;phesiz e&#351; zamanl&#305; olarak <strong>otonom sistemlerin &#252;retti&#287;i dijital ger&#231;eklikler &#252;zerinden &#351;ekillenecektir.</strong></p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,<br>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,<br>CompTIA Project+ Professional,<br>CIW Security Analyst,<br>Certified Cyber Threat Intelligence Analyst,<br>Certified Information Security Executive&#8482;,<br>Senior Certified Leadership Practitioner</p><h1>Kaynak&#231;a:</h1><ul><li><p>Bellingcat.<br>A&#231;&#305;k kaynak drone analizleri ve sava&#351; alan&#305; incelemeleri.</p></li><li><p>Center for Strategic and International Studies (CSIS).<br><em>The Expanding Drone Threat to Critical Infrastructure.</em></p></li><li><p>NATO.<br><em>Emerging and Disruptive Technologies Strategy.</em></p></li></ul><p></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[UAV Forensics: Digital Evidence in the Sky]]></title><description><![CDATA[Thanks for reading Ziya's Substack!]]></description><link>https://ziyagokalp.substack.com/p/uav-forensics-digital-evidence-in</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/uav-forensics-digital-evidence-in</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Fri, 15 May 2026 07:05:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!N7jO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d3e8ec-35a1-4f66-b6c9-e560b439b68a_1536x1024.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N7jO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d3e8ec-35a1-4f66-b6c9-e560b439b68a_1536x1024.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N7jO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d3e8ec-35a1-4f66-b6c9-e560b439b68a_1536x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!N7jO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d3e8ec-35a1-4f66-b6c9-e560b439b68a_1536x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!N7jO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d3e8ec-35a1-4f66-b6c9-e560b439b68a_1536x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!N7jO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d3e8ec-35a1-4f66-b6c9-e560b439b68a_1536x1024.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N7jO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d3e8ec-35a1-4f66-b6c9-e560b439b68a_1536x1024.heic" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c8d3e8ec-35a1-4f66-b6c9-e560b439b68a_1536x1024.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:306911,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/197780548?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d3e8ec-35a1-4f66-b6c9-e560b439b68a_1536x1024.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N7jO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d3e8ec-35a1-4f66-b6c9-e560b439b68a_1536x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!N7jO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d3e8ec-35a1-4f66-b6c9-e560b439b68a_1536x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!N7jO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d3e8ec-35a1-4f66-b6c9-e560b439b68a_1536x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!N7jO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d3e8ec-35a1-4f66-b6c9-e560b439b68a_1536x1024.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Introduction</h1><p>Today, &#8220;<strong>Unmanned Aerial Vehicles (UAVs)</strong>&#8221; have become one of the most significant technological transformations reshaping the modern security paradigm.</p><p>Drone technologies, once considered advanced systems accessible only to governments and military institutions, have now become so widespread that even individuals can easily purchase and operate them.</p><p>However, this democratization has not only accelerated technological proliferation but has also led to the mass expansion of security risks.</p><p>A modern drone is no longer merely a device capable of capturing aerial images.<br>Today&#8217;s drones are mobile digital platforms equipped with <strong>sensors, GPS support, real-time data transmission capabilities</strong>, and even <strong>artificial intelligence-driven decision-making mechanisms.</strong></p><p>In other words, drone systems have evolved into airborne cyber-physical systems.</p><p>For this reason, incidents involving drone crashes, unauthorized flights, or security breaches are no longer examined solely from an aviation perspective.</p><p><strong>What is being investigated today is simultaneously a digital incident.</strong></p><p>Within this context, the concept of <strong>UAV Forensics</strong> emerges.</p><p><strong>UAV Forensics</strong> refers to the process of analyzing the digital, physical, and communication traces left behind by unmanned aerial vehicles.</p><p>This discipline represents a next-generation investigative field situated at the intersection of digital forensics, electronic warfare, intelligence, cybersecurity, and aviation technologies.</p><p>Particularly in recent years, numerous incidents have demonstrated that drone systems are no longer merely &#8220;technological tools,&#8221; but have evolved into strategic security actors.</p><p>For example, during the <strong>Russia&#8211;Ukraine</strong> war, the extensive use of commercial drone systems for reconnaissance, target coordinate identification, and even attack operations fundamentally transformed global perceptions of <strong>UAV technologies.</strong></p><p>Similarly, unauthorized drone flights over critical infrastructures have triggered serious security investigations at locations ranging from power plants to military facilities.</p><p><strong>Consequently, the sky is no longer merely a physical airspace; it has also become a new-generation cyber operational domain where digital evidence moves through the air.</strong></p><p></p><h1>What is UAV Forensics?</h1><p><strong>UAV Forensics</strong> is the process of acquiring digital evidence from unmanned aerial vehicles, analyzing that evidence, and technically reconstructing the incident.</p><p>The primary objective of this discipline is not merely to identify the owner of the device.<br>Its core purpose is to understand the operational behavior of the <strong>UAV.</strong></p><p>In other words, <strong>UAV Forensics</strong> seeks answers to questions such as:</p><ul><li><p><strong>Where did the drone take off from?</strong></p></li><li><p><strong>Which route did it follow?</strong></p></li><li><p><strong>What kind of data did it collect?</strong></p></li><li><p><strong>Who controlled it?</strong></p></li><li><p><strong>Was it subjected to remote interference?</strong></p></li><li><p><strong>Was it part of an attack?</strong></p></li><li><p><strong>Was it manipulated or compromised?</strong></p></li></ul><p>Modern <strong>UAV systems</strong> generate an enormous amount of data.</p><p>In fact, most drones continuously record telemetry data during flight.<br>These records contain extensive datasets ranging from GPS coordinates and speed information to sensor outputs and communication logs.</p><p>For example, investigations conducted following <strong>drone-related incidents</strong> that caused prolonged operational disruptions at airports in Europe relied heavily on the combined analysis of <strong>radar data, RF (Radio Frequency) records</strong>, and <strong>flight logs.</strong></p><p>The issue was not merely &#8220;<strong>a drone being spotted in the air.</strong>&#8221;<br>The real objective was to determine who operated the drone, for what purpose, and with what technical capabilities.</p><p>For this reason, <strong>UAV Forensics</strong> is not simply a process of digital data recovery.<br>It is also a discipline involving <strong>behavioral analysis, operational intent analysis, and technical intelligence gathering.</strong></p><p></p><h1>The Emergence of Drone Systems as a New-Generation Risk Domain</h1><p>The primary reason drone technologies have become increasingly dangerous is their ability to combine low cost with <strong>high operational impact.</strong></p><p>Today, even a commercially available mid-range drone can:</p><ul><li><p><strong>Be controlled remotely from kilometers away,</strong></p></li><li><p><strong>Transmit high-resolution video feeds,</strong></p></li><li><p><strong>Execute automated route planning,</strong></p></li><li><p><strong>Perform GPS-supported autonomous flights,</strong></p></li><li><p><strong>Deliver real-time data transmission,</strong></p></li><li><p><strong>Conduct target tracking operations.</strong></p></li></ul><p>This capability enables relatively small devices to <strong>create strategic-level effects.</strong></p><p>For example, the use of drone systems in attacks targeting oil facilities in the Middle East generated major global concern regarding energy security.</p><p>Relatively low-cost platforms demonstrated the capacity to affect critical infrastructures worth billions of dollars.</p><p>Similarly, the use of drones by cartels in <strong>Mexico</strong> for reconnaissance and smuggling operations along border regions has shifted the attention of security institutions toward a new dimension of threat assessment.</p><p>Drones are no longer used solely for surveillance purposes; they are increasingly utilized for payload transportation, border infiltration, and even direct attack operations.</p><p>On the other hand, investigations in certain correctional facilities revealed that drones had been used to transport:</p><ul><li><p><strong>Narcotics,</strong></p></li><li><p><strong>Mobile phones,</strong></p></li><li><p><strong>SIM cards,</strong></p></li><li><p><strong>Weapon components.</strong></p></li></ul><p>These incidents clearly demonstrate that <strong>UAV systems</strong> are no longer merely a subject of aviation regulation, but have evolved into a matter of <strong>national security.</strong></p><p></p><h1>Key Data Examined During the UAV Forensics Process</h1><p>The types of data analyzed during a <strong>UAV investigation</strong> are highly extensive and multidimensional.</p><p>First and foremost, flight log records are examined. <strong>Modern drones</strong> continuously generate telemetry data throughout their flights, and these records often serve as the digital fingerprint of the incident.</p><p>For example, even if the drone itself cannot be physically recovered, investigators may still obtain flight history data from the <strong>controller device, mobile application, or cloud synchronization systems.</strong></p><p>In some investigations, cache data extracted solely from a mobile device has revealed the geographical areas where the drone had previously operated.</p><p>Particularly on widely used platforms such as <strong>DJI</strong>, investigators can often identify:</p><ul><li><p><strong>Takeoff coordinates,</strong></p></li><li><p><strong>Flight routes,</strong></p></li><li><p><strong>Battery replacement history,</strong></p></li><li><p><strong>Device identifiers,</strong></p></li><li><p><strong>User session information.</strong></p></li></ul><p><strong>In addition to this, GPS data plays a critically important role.</strong></p><p>For instance, the detection of repeated waypoint behaviors around a critical infrastructure facility may indicate <strong>pre-attack</strong> reconnaissance activity. In certain cases, drones have been observed systematically slowing down or hovering at specific locations. <strong>Such behavior is frequently associated with image collection or signal intelligence operations.</strong></p><p>Camera and sensor data also constitute a separate domain of forensic analysis.</p><p>To provide another example, capturing thermal imagery of an energy facility may carry implications far beyond those of an ordinary recreational flight.</p><p>Thermal analyses can potentially provide intelligence regarding the operational intensity and activity patterns of critical equipment.</p><p><strong>Similarly, through EXIF metadata analysis, investigators can determine where an image was captured, which device processed it, and whether the image has been manipulated or altered.</strong></p><p></p><h1>RF and Communication Analysis</h1><p>One of the most critical areas within <strong>UAV Forensics</strong> is RF (Radio Frequency) analysis.</p><p>Drone systems are, in essence, platforms that continuously communicate with control units and command centers.</p><p>The data exchange occurring between a drone and its controller often provides valuable insight into the operational behavior of the system.</p><p>Through RF analysis, investigators can identify:</p><ul><li><p><strong>The approximate location of the operator,</strong></p></li><li><p><strong>The frequency ranges being used,</strong></p></li><li><p><strong>The effects of jamming activities,</strong></p></li><li><p><strong>Signal interruptions,</strong></p></li><li><p><strong>Spoofing attempts.</strong></p></li></ul><p>RF intelligence has become particularly important in modern conflict zones.</p><p>During the <strong>Russia&#8211;Ukraine</strong> war, it became widely known that the RF signatures of many commercial drone systems were analyzed in attempts to determine the locations of drone operators.</p><p>A drone, therefore, does not only expose the target &#8212; it can also expose the operator.</p><p><strong>For this reason, the use of drones in modern conflict environments simultaneously creates a form of electronic visibility.</strong></p><p></p><h1>Firmware Manipulation and Anti-Forensics</h1><p>Today, advanced threat actors are capable of modifying drone systems for malicious or covert purposes.</p><p>Particularly, techniques such as:</p><ul><li><p><strong>Geo-fence bypass,</strong></p></li><li><p><strong>Firmware modification,</strong></p></li><li><p><strong>Removal of flight limitations,</strong></p></li><li><p><strong>Automatic log deletion,</strong></p></li><li><p><strong>Identity obfuscation</strong></p></li></ul><p>are becoming increasingly widespread.</p><p>For example, investigations into certain smuggling operations have revealed drones operating with modified firmware instead of standard manufacturer software. Through these modifications, attackers attempt to bypass the security restrictions implemented by the manufacturer.</p><p>In some advanced systems, anti-forensic mechanisms are specifically designed to automatically erase flight logs after operations are completed.</p><p>This significantly increases the complexity of <strong>UAV investigations.</strong></p><p>It is no longer sufficient to simply examine the data stored inside the device. Investigators must also analyze:</p><ul><li><p><strong>Firmware integrity,</strong></p></li><li><p><strong>Binary structures and executable code,</strong></p></li><li><p><strong>Communication protocols,</strong></p></li><li><p><strong>Hardware-level modifications.</strong></p></li></ul><p>As a result, <strong>UAV Forensics</strong> is increasingly evolving into a discipline heavily centered on <strong>reverse engineering.</strong></p><p></p><h1>The UAV Threat from an OT/ICS Security Perspective</h1><p>From the perspective of critical infrastructure security, drone systems have evolved into next-generation reconnaissance platforms.</p><p>Particularly within <strong>OT/ICS (Operational Technology and Industrial Control Systems)</strong> environments such as <strong>energy, oil &amp; gas, manufacturing, and water infrastructure,</strong> organizations are becoming increasingly vulnerable to drone-related threats.</p><p>A drone can physically observe and collect intelligence on:</p><ul><li><p><strong>Substations,</strong></p></li><li><p><strong>Pipelines,</strong></p></li><li><p><strong>Manufacturing facilities,</strong></p></li><li><p><strong>Energy distribution points,</strong></p></li><li><p><strong>Refineries.</strong></p></li></ul><p>At this point, the primary risk is not limited to visual surveillance alone.</p><p>In more advanced operations, drones can also be used for:</p><ul><li><p><strong>Wi-Fi reconnaissance,</strong></p></li><li><p><strong>RF signal analysis,</strong></p></li><li><p><strong>Bluetooth scanning,</strong></p></li><li><p><strong>Detection of open access points,</strong></p></li><li><p><strong>Wireless network mapping.</strong></p></li></ul><p>This creates a critically important challenge for <strong>OT (Operational Technology)</strong> security.</p><p>Many industrial facilities still rely heavily on physical isolation as a core security assumption, yet they remain insufficiently prepared against aerial reconnaissance activities.</p><p>In other words, the modern attack surface is no longer confined to network cables and terrestrial systems alone.</p><p><strong>The sky itself has become part of the attack surface.</strong></p><p></p><h1>The Battlefield of the Future: Autonomous Drone Systems</h1><p>The future of drone technologies is no longer limited to remotely controlled systems.</p><p>The real transformation is taking place in autonomous drone platforms capable of making decisions independently.</p><p>In the near future, technologies such as:</p><ul><li><p><strong>Swarm systems,</strong></p></li><li><p><strong>AI-assisted target analysis,</strong></p></li><li><p><strong>GPS-denied navigation,</strong></p></li><li><p><strong>Edge AI decision-making mechanisms,</strong></p></li><li><p><strong>Fully autonomous attack platforms</strong></p></li></ul><p>will become significantly more widespread.</p><p>This evolution will undoubtedly transform the discipline of <strong>UAV Forensics</strong> at a fundamental level.</p><p>In the future, investigators will no longer focus solely on &#8220;the flight record of a device.&#8221;<br>Instead, investigations will increasingly revolve around questions such as: <em>Why did an artificial intelligence system exhibit a particular behavior?</em></p><p>This shift transforms <strong>UAV Forensics</strong> into not only a technical issue, but also an ethical, legal, and behavioral challenge.</p><p><strong>Today, the decision-making mechanisms of autonomous systems are, in many cases, becoming more complex than those of human operators themselves.</strong></p><p></p><h2>Conclusion</h2><p>In the modern world, the sky is no longer merely a physical space through which aircraft travel.</p><p>It has also become a new-generation security layer where data flows, algorithms, sensors, and digital operations move continuously.</p><p>As drone systems continue to evolve, <strong>the telemetry records, sensor outputs, RF traces, and algorithmic behaviors they generate are increasingly becoming central elements of security investigations.</strong></p><p>For this reason, describing <strong>UAV Forensics</strong> solely as a technical investigative field would be a significant understatement.</p><p><strong>UAV Forensics</strong> has now emerged as a next-generation strategic discipline situated at the intersection of cybersecurity, electronic warfare, intelligence, critical infrastructure protection, and the age of artificial intelligence.</p><p><strong>In the near future, wars will no longer be conducted solely across land, sea, air, and cyberspace.</strong></p><p>They will also be shaped <strong>simultaneously through the digital realities generated by autonomous systems.</strong></p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,<br>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,<br>CompTIA Project+ Professional,<br>CIW Security Analyst,<br>Certified Cyber Threat Intelligence Analyst,<br>Certified Information Security Executive&#8482;,<br>Senior Certified Leadership Practitioner</p><p></p><h1>References</h1><ul><li><p>Bellingcat<br><em>Open-source drone analysis and battlefield investigations.</em></p></li><li><p>Center for Strategic and International Studies<br><em>The Expanding Drone Threat to Critical Infrastructure.</em></p></li><li><p>NATO<br><em>Emerging and Disruptive Technologies Strategy.</em></p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Bug Bounty: Dijital Dünyanın Ödül Avcıları]]></title><description><![CDATA[PODCAST Linki]]></description><link>https://ziyagokalp.substack.com/p/bug-bounty-dijital-dunyann-odul-avclar</link><guid isPermaLink="false">https://ziyagokalp.substack.com/p/bug-bounty-dijital-dunyann-odul-avclar</guid><dc:creator><![CDATA[Ziya Gokalp]]></dc:creator><pubDate>Mon, 11 May 2026 20:50:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lEew!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b2df82-cedf-4ca2-8816-359e3ab99f3a_1536x1024.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lEew!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b2df82-cedf-4ca2-8816-359e3ab99f3a_1536x1024.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lEew!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b2df82-cedf-4ca2-8816-359e3ab99f3a_1536x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!lEew!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b2df82-cedf-4ca2-8816-359e3ab99f3a_1536x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!lEew!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b2df82-cedf-4ca2-8816-359e3ab99f3a_1536x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!lEew!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b2df82-cedf-4ca2-8816-359e3ab99f3a_1536x1024.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lEew!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b2df82-cedf-4ca2-8816-359e3ab99f3a_1536x1024.heic" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/63b2df82-cedf-4ca2-8816-359e3ab99f3a_1536x1024.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:321324,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/197249517?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b2df82-cedf-4ca2-8816-359e3ab99f3a_1536x1024.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lEew!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b2df82-cedf-4ca2-8816-359e3ab99f3a_1536x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!lEew!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b2df82-cedf-4ca2-8816-359e3ab99f3a_1536x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!lEew!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b2df82-cedf-4ca2-8816-359e3ab99f3a_1536x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!lEew!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b2df82-cedf-4ca2-8816-359e3ab99f3a_1536x1024.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://creators.spotify.com/pod/profile/ziyagokalp/episodes/Bug-Bounty-Dijital-Dnyann-dl-Avclar-e3j0h7l">PODCAST Linki</a></strong></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Giri&#351;</h1><p>Bir zamanlar &#246;d&#252;l avc&#305;lar&#305;, fiziksel d&#252;nyan&#305;n kanunsuz b&#246;lgelerinde dola&#351;maktayd&#305;lar.</p><p><strong>Modern &#231;a&#287;da ise yeni avc&#305;lar art&#305;k okyanuslarda de&#287;il, milyarlarca sat&#305;r kodun i&#231;inde hareket etmekteler..</strong></p><p>G&#252;n&#252;m&#252;z&#252;n dijital d&#252;nyas&#305;nda g&#252;venlik a&#231;&#305;klar&#305;n&#305; salt teknik bir hata olarak okumak son derece yanl&#305;&#351; olur !</p><p>Nitekim g&#252;n&#252;m&#252;zde dijital d&#252;nyada g&#252;venlik a&#231;&#305;klar&#305;; Ekonomik, stratejik ve hatta jeopolitik de&#287;eri olan dijital varl&#305;klar haline gelmi&#351; durumdad&#305;r.</p><p><strong>Bir g&#252;venlik a&#231;&#305;&#287;&#305; bazen milyon dolarl&#305;k bir &#246;d&#252;l, bazen kritik bir altyap&#305;n&#305;n &#231;&#246;k&#252;&#351;&#252;, bazen ise devlet destekli bir siber operasyonun temel bile&#351;eni anlam&#305;na gelebilmektedir.</strong></p><p>Bu noktada &#8220;<strong>Bug Bounty</strong>&#8221; kavram&#305; kar&#351;&#305;m&#305;za &#231;&#305;kmaktad&#305;r. Yani bir ba&#351;ka ifade ile modern dijital &#231;a&#287;&#305;n &#8216;<strong>Hata &#214;d&#252;l Avc&#305;l&#305;&#287;&#305;</strong>&#8217;&#8230;</p><p><strong>Bug Bounty</strong> <strong>programlar&#305;</strong> ilk bak&#305;&#351;ta &#351;irketlerin g&#252;venlik ara&#351;t&#305;rmac&#305;lar&#305;na &#246;d&#252;l verdi&#287;i teknik platformlar gibi g&#246;r&#252;nse de, aslen modern dijital g&#252;venlik mimarisinin d&#246;n&#252;&#351;&#252;m&#252;n&#252; temsil eden &#231;ok daha b&#252;y&#252;k bir paradigman&#305;n par&#231;as&#305;d&#305;r.</p><p>Nitekim art&#305;k g&#252;venlik yaln&#305;zca kurumlar&#305;n kapal&#305; g&#252;venlik ekipleriyle sa&#287;lanamamaktad&#305;r.</p><p>D&#252;nyan&#305;n herhangi bir yerindeki anonim bir ara&#351;t&#305;rmac&#305;n&#305;n, k&#252;resel teknoloji devlerinin en kritik sistemlerindeki zafiyetlerini ke&#351;fedebilmesi son derece olas&#305;d&#305;r !</p><p></p><h1>Bug Bounty Nedir?</h1><p><strong>Bug Bounty</strong> en temel anlam&#305;yla, &#351;irketlerin veya kurumlar&#305;n sistemlerindeki g&#252;venlik a&#231;&#305;klar&#305;n&#305;/zafiyetlerini bulan ara&#351;t&#305;rmac&#305;lara maddi &#246;d&#252;l vermesi/sa&#287;lamas&#305; esas&#305;na dayanan bir g&#252;venlik modelidir.</p><p>Bu programlar sayesinde <strong>Etik Hacker</strong>&#8217;lar; <strong>Web uygulamalar&#305;, mobil cihazlar, bulut sistemleri, a&#287; altyap&#305;lar&#305; veya yapay zeka platformlar&#305; &#252;zerinde g&#252;venlik ara&#351;t&#305;rmalar&#305; ger&#231;ekle&#351;tirir ve ke&#351;fettikleri zafiyetleri sorumlu a&#231;&#305;klama prosed&#252;rleri kapsam&#305;nda ilgili kuruma rapor ederler.</strong></p><p>Ancak <strong>Bug Bounty</strong> <strong>kavram&#305;n&#305;</strong> yaln&#305;zca &#8220;<strong>A&#231;&#305;k/Zafiyet Bul ve Para kazan</strong>&#8221; d&#252;zeyinde de&#287;erlendirmek hi&#231; &#351;&#252;phesiz <strong>eksik bir yakla&#351;&#305;m olacakt&#305;r.</strong></p><p>Bu model ayn&#305; zamanda <strong>g&#252;venli&#287;in merkezi yap&#305;lardan da&#287;&#305;t&#305;k yap&#305;lara ge&#231;i&#351;ini temsil etmektedir.</strong></p><p>Ge&#231;mi&#351;te yaln&#305;zca &#351;irket i&#231;i ekiplerin sorumlulu&#287;unda olan siber savunma s&#252;re&#231;leri, bug&#252;n k&#252;resel &#246;l&#231;ekte <strong>ba&#287;&#305;ms&#305;z ara&#351;t&#305;rmac&#305;lar&#305;n kolektif zekas&#305;na a&#231;&#305;lm&#305;&#351; durumdad&#305;r.</strong></p><p>Bu durum, <strong>siber g&#252;venli&#287;in demokratikle&#351;mesi</strong> olarak da yorumlanabilmektedir.</p><p><br>Bir ba&#351;ka ifade ile; Ge&#231;mi&#351;te bir g&#252;venlik a&#231;&#305;&#287;&#305;n&#305; bulup bunu raporlayabilmek i&#231;in b&#252;y&#252;k bir &#351;irkette &#231;al&#305;&#351;mak gerekebilirdi. Bug&#252;n ise d&#252;nyan&#305;n herhangi bir yerindeki ba&#287;&#305;ms&#305;z bir ara&#351;t&#305;rmac&#305;, evinden <strong>Apple</strong> veya <strong>Google</strong> sistemlerinde kritik bir a&#231;&#305;k bulup y&#252;z binlerce dolar &#246;d&#252;l kazanabilmekte. </p><p>Ayn&#305; zamanda bahsi ge&#231;en <strong>demokratikle&#351;me sald&#305;r&#305; kapasitesini</strong> de yayg&#305;nla&#351;t&#305;rmaktad&#305;r. Yani bilgi, ara&#231; ve teknikler sadece savunmac&#305;lar i&#231;in de&#287;il; Sald&#305;rganlar i&#231;in de daha eri&#351;ilebilir hale gelmektedir. </p><p>Bu nedenle <strong>Bug Bounty ekosistemi</strong> bir yandan g&#252;venli&#287;i g&#252;&#231;lendirirken, di&#287;er yandan siber alan&#305;n &#8220;<strong>asimetrik g&#252;&#231;</strong>&#8221; yap&#305;s&#305;n&#305; da b&#252;y&#252;tmektedir.</p><p>Modern <strong>Bug Bounty</strong> <strong>ekosisteminde</strong> <strong>ara&#351;t&#305;rmac&#305;lar</strong> yaln&#305;zca teknik bilgiye de&#287;il; <br><strong>Reverse engineering, Exploit development, Kriptografi, &#304;&#351;letim sistemi mimarileri, Mobil g&#252;venlik, Donan&#305;m g&#252;venli&#287;i</strong> ve hatta <strong>Yapay Zeka sistemleri</strong> konusunda ileri d&#252;zey uzmanl&#305;&#287;a sahip olmak zorundad&#305;rlar.</p><p>Hi&#231; &#351;&#252;phesiz modern sald&#305;r&#305; y&#252;zeyi art&#305;k salt Web uygulamalar&#305;ndan ibaret de&#287;ildir. </p><p><strong>G&#252;n&#252;m&#252;zde Otomobillerden Ak&#305;ll&#305; Telefonlara, OT-End&#252;striyel Kontrol sistemlerinden Yapay Zeka modellerine kadar her &#351;ey potansiyel bir hedef haline gelmi&#351;tir.</strong></p><p></p><h1>Dijital D&#252;nyan&#305;n Yeni &#214;d&#252;l Avc&#305;lar&#305;</h1><p><strong>Bug Bounty ara&#351;t&#305;rmac&#305;lar&#305;</strong> &#231;o&#287;u zaman modern d&#252;nyan&#305;n <strong>Dijital &#214;d&#252;l Avc&#305;lar&#305;</strong> olarak tan&#305;mlanabilir.</p><p>Bir ba&#351;ka ifade ile; Eski d&#246;nemde nas&#305;l ki &#246;d&#252;l avc&#305;lar&#305; <strong>yasa ile kaos</strong> aras&#305;ndaki gri b&#246;lgelerde hareket ediyorlarsa, g&#252;n&#252;m&#252;zde modern <strong>Etik Hacker</strong>&#8217;lar da <strong>g&#252;venlik ile sald&#305;r&#305; aras&#305;ndaki ince &#231;izgide faaliyet g&#246;steriyorlar.</strong></p><p>Bu d&#252;nyan&#305;n en dikkat &#231;ekici y&#246;nlerinden biri, teknik becerilerin &#231;ift tarafl&#305; do&#287;as&#305;d&#305;r. Bir ba&#351;ka ifade ile; Ayn&#305; <strong>Exploit</strong> geli&#351;tirme bilgisi:</p><ul><li><p><strong>Bir &#351;irkete kritik bir g&#252;venlik a&#231;&#305;&#287;&#305;n&#305; kapatmas&#305;nda yard&#305;mc&#305; olabilir,</strong></p></li><li><p><strong>Ya da karanl&#305;k pazarlarda milyon dolarl&#305;k bir siber silaha d&#246;n&#252;&#351;ebilir.</strong></p></li></ul><p>Dolay&#305;s&#305;yla <strong>Bug Bounty ekosistemi</strong> yaln&#305;zca teknik bir g&#252;venlik modeli de&#287;il, ayn&#305; zamanda <strong>etik, ekonomik ve stratejik</strong> boyutlar&#305; olan yeni bir dijital g&#252;&#231; alan&#305;d&#305;r.</p><p></p><h1>Zero-Day Ekonomisi ve Siber G&#252;c&#252;n Yeni Formu</h1><p>G&#252;n&#252;m&#252;zde baz&#305; g&#252;venlik a&#231;&#305;klar&#305; art&#305;k klasik yaz&#305;l&#305;m hatalar&#305; olarak g&#246;r&#252;lmemektedir. &#214;zellikle &#8220;<strong>Zero-Day</strong>&#8221; olarak adland&#305;r&#305;lan ve hen&#252;z &#252;retici taraf&#305;ndan bilinmeyen a&#231;&#305;klar, modern siber d&#252;nyan&#305;n en de&#287;erli dijital varl&#305;klar&#305;ndan biri haline gelmi&#351; durumdad&#305;rlar.</p><p>&#214;zellikle son y&#305;llarda a&#231;&#305;klanm&#305;&#351; ve kamuoyu ile payla&#351;&#305;lm&#305;&#351; en b&#252;y&#252;k <br><strong>Bug Bounty &#246;d&#252;lleri i&#231;in</strong>; </p><ul><li><p><strong>Zero-Click (S&#305;f&#305;r T&#305;klama), </strong></p></li><li><p><strong>Zincirleme Exploit (Exploit Chain) ve </strong></p></li><li><p><strong>Mobil Cihaz G&#252;venli&#287;i</strong> alan&#305;nda ortaya &#231;&#305;kan a&#231;&#305;klar ve &#246;d&#252;l programlar&#305; taraf&#305;ndan kabul edilen zafiyetler &#246;rnek olarak g&#246;sterilebilir.</p></li></ul><p><strong>iPhone</strong> ve <strong>Android</strong> ekosistemlerinde bulunan geli&#351;mi&#351; exploit zincirleri art&#305;k milyon dolar seviyesinde de&#287;erlendirilmektedir. Bunun temel nedeni, modern mobil cihazlar&#305;n yaln&#305;zca ileti&#351;im arac&#305; olmaktan &#231;&#305;k&#305;p; <strong>Ki&#351;isel veri, finansal bilgi, biyometrik kimlik ve kurumsal eri&#351;im noktas&#305;</strong> haline d&#246;n&#252;&#351;m&#252;&#351; olmas&#305;d&#305;r.</p><p>&#214;zellikle &#8220;<strong>Zero-Click</strong>&#8221; sald&#305;r&#305;lar modern siber g&#252;venlik d&#252;nyas&#305;n&#305;n en korkutucu alanlar&#305; i&#231;in &#246;rnek olarak g&#246;sterilebilir.</p><p>Nitekim kullan&#305;c&#305; herhangi bir ba&#287;lant&#305;ya t&#305;klamadan veya i&#351;lem yapmadan cihaz&#305;n ele ge&#231;irilmesi bu sald&#305;r&#305;lar ile m&#252;mk&#252;n hale gelmektedir.</p><p>Bu t&#252;r sald&#305;r&#305;lar genellikle <strong>mesajla&#351;ma servisleri, medya i&#351;leme motorlar&#305;</strong> veya <strong>i&#351;letim sistemi seviyesindeki karma&#351;&#305;k zafiyet zincirleri</strong> &#252;zerinden ger&#231;ekle&#351;tirilmektedir.</p><p>Bug&#252;n; <strong>Apple, Google</strong> ve <strong>Microsoft</strong> gibi teknoloji devleri <strong>milyon dolarl&#305;k</strong> <strong>Bug Bounty &#246;d&#252;lleri</strong> a&#231;&#305;klarken; <br><strong>Exploit Broker</strong> &#351;irketleri (S&#246;m&#252;r&#252;ler ve zafiyetler i&#231;in arac&#305;l&#305;k yapan &#351;irketler) ve baz&#305;<strong> Devlet Akt&#246;rleri</strong> ayn&#305; a&#231;&#305;klar i&#231;in &#231;ok daha y&#252;ksek rakamlar &#246;deyebilmektedirler.</p><p>Bu durum &#8220;<strong>Zero-Day ekonomisi</strong>&#8221; olarak adland&#305;r&#305;lan yeni bir dijital piyasan&#305;n olu&#351;mas&#305;na neden olmaktad&#305;r.</p><p>S&#246;z&#252;n &#246;z&#252; art&#305;k bir g&#252;venlik a&#231;&#305;&#287;&#305;:</p><ul><li><p><strong>Teknik bir hata de&#287;il,</strong></p></li><li><p><strong>Ekonomik de&#287;eri olan dijital meta,</strong></p></li><li><p><strong>Stratejik istihbarat arac&#305;,</strong></p></li><li><p><strong>Hatta modern &#231;a&#287;&#305;n siber m&#252;himmat&#305; </strong>haline gelmi&#351; durumdad&#305;r !</p><p></p></li></ul><h1>Etik Hacker m&#305;, Dijital Paral&#305; Asker mi?</h1><p><strong>Bug Bounty ekosisteminin</strong> en tart&#305;&#351;mal&#305; y&#246;nlerinden biri ise etik boyuttur. Nitekim ayn&#305; teknik bilgi <strong>hem savunma hem de sald&#305;r&#305;</strong> amac&#305;yla kullan&#305;labilir.</p><p>Bir ara&#351;t&#305;rmac&#305; tespit etti&#287;i kritik bir a&#231;&#305;&#287;&#305;/zafiyeti &#252;retici firmaya rapor ederek milyon dolarl&#305;k &#246;d&#252;l kazanabilirken, ayn&#305; bilgi farkl&#305; akt&#246;rler taraf&#305;ndan devlet destekli operasyonlarda veya ticari casusluk faaliyetlerinde kullan&#305;labilir.</p><p>Bu nedenle modern siber d&#252;nyada <strong>Etik Hacker</strong> kavram&#305; ile <strong>Dijital Paral&#305; Askerlik</strong> aras&#305;ndaki &#231;izgi giderek daha karma&#351;&#305;k hale gelmektedir.</p><p>&#214;zellikle <strong>Exploit Broker</strong> &#351;irketlerinin y&#252;kseli&#351;i bu tart&#305;&#351;may&#305; daha g&#246;r&#252;n&#252;r hale getirmektedir.</p><p>Baz&#305; &#351;irketler g&#252;venlik ara&#351;t&#305;rmac&#305;lar&#305;ndan tespit ettikleri kritik <strong>Zero-day</strong> a&#231;&#305;klar&#305;n&#305; <strong>sat&#305;n alarak bunlar&#305; devlet kurumlar&#305;na veya g&#252;venlik organizasyonlar&#305;na satabilmektedirler.</strong></p><p>B&#246;ylece g&#252;venlik a&#231;&#305;&#287;&#305; kavram&#305;, klasik bili&#351;im g&#252;venli&#287;i perspektifinin &#246;tesine ge&#231;erek <strong>uluslararas&#305; g&#252;&#231; dengelerinin bir bile&#351;eni haline gelmektedir.</strong></p><p></p><h1>Devletler, Siber G&#252;&#231; ve Stratejik A&#231;&#305;klar/Zafiyetler</h1><p>Modern d&#252;nyada siber &#252;st&#252;nl&#252;k art&#305;k yaln&#305;zca savunma meselesi de&#287;ildir, <strong>stratejik cayd&#305;r&#305;c&#305;l&#305;&#287;&#305;n &#246;nemli bir par&#231;as&#305;d&#305;r.</strong></p><p>Devletler baz&#305; a&#231;&#305;klar&#305;n h&#305;zl&#305;ca kapat&#305;lmas&#305;n&#305; isterken, baz&#305;lar&#305;n&#305; ise operasyonel avantaj sa&#287;lamak amac&#305;yla gizli tutmay&#305; tercih edebilmektedirler.</p><p>Bu durum &#246;zellikle geli&#351;mi&#351; siber operasyonlarda kritik &#246;nem ta&#351;&#305;maktad&#305;r.</p><p>Nitekim bir Zero-day a&#231;&#305;&#287;&#305;:</p><ul><li><p><strong>&#304;stihbarat toplama,</strong></p></li><li><p><strong>Kritik altyap&#305;ya eri&#351;im,</strong></p></li><li><p><strong>G&#246;zetleme faaliyetleri,</strong></p></li><li><p><strong>Veya Siber Sabotaj operasyonlar&#305;</strong> i&#231;in kullan&#305;labilmektedir.</p></li></ul><p>Buradan yola &#231;&#305;karak art&#305;k siber a&#231;&#305;klar&#305;n yaln&#305;zca teknik g&#252;venlik problemleri de&#287;il; <strong>Ulusal g&#252;venlik, Jeopolitik rekabet ve Dijital egemenlik konusu oldu&#287;unu ve uluslararas&#305; arenada bu &#351;ekilde de&#287;erlendirildi&#287;ini ifade etmek yanl&#305;&#351; olmayacakt&#305;r !</strong></p><p></p><h1>Yapay Zeka &#199;a&#287;&#305; ve Yeni Av Alan&#305;</h1><p>Yapay zeka teknolojilerinin geli&#351;mesi ve y&#252;kseli&#351;i <strong>Bug Bounty</strong> d&#252;nyas&#305;n&#305; da d&#246;n&#252;&#351;t&#252;rmeye ba&#351;lam&#305;&#351;t&#305;r.</p><p>Bu ba&#287;lamda g&#252;n&#252;m&#252;zde geleneksel g&#252;venlik a&#231;&#305;klar&#305;n&#305;n yan&#305; s&#305;ra art&#305;k:</p><ul><li><p><strong>LLM prompt injection,</strong></p></li><li><p><strong>AI Jailbreak,</strong></p></li><li><p><strong>Yapay zeka y&#246;nlendirme manip&#252;lasyonlar&#305;,</strong></p></li><li><p><strong>AI supply chain poisoning,</strong></p></li><li><p><strong>Agent hijacking,</strong></p></li><li><p><strong>Hallucination exploitation</strong></p></li></ul><p>gibi tamamen <strong>yeni sald&#305;r&#305; metodolojileri ve y&#252;zeyleri</strong> ortaya &#231;&#305;kmaktad&#305;r.</p><p>&#214;zellikle <strong>otonom &#231;al&#305;&#351;an yapay zeka ajanlar&#305;n&#305;n</strong> yayg&#305;nla&#351;mas&#305;yla birlikte gelecekte <strong>Bug Bounty</strong> programlar&#305;n&#305;n yaln&#305;zca yaz&#305;l&#305;m zafiyetlerini de&#287;il, karar mekanizmalar&#305;n&#305; ve bili&#351;sel manip&#252;lasyonlar&#305; da kapsamas&#305; muhtemel g&#246;r&#252;nmektedir.</p><p>Bu durum g&#252;venlik anlay&#305;&#351;&#305;n&#305;n teknik s&#305;n&#305;rlar&#305;n&#305; giderek geni&#351;letecektir.</p><p>S&#246;z&#252;n &#246;z&#252;; <strong>Gelece&#287;in sald&#305;r&#305;lar&#305; yaln&#305;zca sistemleri de&#287;il, sistemlerin ger&#231;ekli&#287;i alg&#305;lama bi&#231;imini de hedef alabilir !</strong></p><p></p><h1>A&#231;&#305;klanm&#305;&#351; En B&#252;y&#252;k Bug Bounty &#214;d&#252;lleri</h1><p><strong>Bug Bounty</strong> ekosisteminin b&#252;y&#252;mesiyle birlikte &#246;d&#252;l miktarlar&#305; da dramatik &#351;ekilde y&#252;kselmeye ba&#351;lam&#305;&#351;t&#305;r.</p><p>&#214;zellikle <strong>Mobil Cihaz g&#252;venli&#287;i</strong>, &#8220;<strong>Zero-Click</strong>&#8221; sald&#305;r&#305;lar, <strong>Sandbox Escape</strong> teknikleri ve <strong>Zincirleme Exploit</strong> geli&#351;tirme alanlar&#305;nda verilen &#246;d&#252;ller art&#305;k <strong>Milyon Dolar seviyelerine ula&#351;m&#305;&#351; durumdad&#305;r.</strong></p><p>Bu durum asl&#305;nda modern dijital sistemlerin stratejik de&#287;erini de ortaya koymaktad&#305;r.</p><p>Buradan hareketle; <strong>Bir g&#252;venlik a&#231;&#305;&#287;&#305; art&#305;k yaln&#305;zca teknik bir problem de&#287;il, ayn&#305; zamanda &#8216;ekonomik&#8217; ve &#8216;jeopolitik&#8217; de&#287;eri olan dijital bir varl&#305;k olarak g&#246;r&#252;lmektedir.</strong></p><p>&#214;zellikle <strong>Apple, Google, Microsoft</strong> ve <strong>Meta</strong> gibi teknoloji devleri, kritik g&#252;venlik a&#231;&#305;klar&#305;n&#305; sald&#305;rganlardan &#246;nce ke&#351;fedebilmek i&#231;in <strong>Bounty</strong> programlar&#305;n&#305; <strong>agresif &#351;ekilde b&#252;y&#252;tmeye ba&#351;lam&#305;&#351;t&#305;r.</strong></p><p>Bunun en &#246;nemli nedenlerinden biri ise geli&#351;mi&#351; siber tehdit akt&#246;rlerinin art&#305;k yaln&#305;zca finansal motivasyonla de&#287;il, <strong>istihbarat ve stratejik avantaj amac&#305;yla da hareket etmesidir.</strong></p><p>Bilindik ve a&#231;&#305;klanm&#305;&#351; en dikkat &#231;ekici <strong>Bug Bounty</strong> &#246;d&#252;llerinden baz&#305;lar&#305;n&#305; payla&#351;mak bu makaleyi daha anla&#351;&#305;labilir k&#305;lmak ve somut &#246;rnekler &#252;zerinden &#351;ekillendirmek ad&#305;na ehemmiyete sahiptir. Bu ba&#287;lamda a&#351;a&#287;&#305;da yer alan tablo payla&#351;&#305;lm&#305;&#351;t&#305;r.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lbaH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F693552de-ac14-4943-b92d-1bfa28c6f18f_1666x1172.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lbaH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F693552de-ac14-4943-b92d-1bfa28c6f18f_1666x1172.heic 424w, https://substackcdn.com/image/fetch/$s_!lbaH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F693552de-ac14-4943-b92d-1bfa28c6f18f_1666x1172.heic 848w, https://substackcdn.com/image/fetch/$s_!lbaH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F693552de-ac14-4943-b92d-1bfa28c6f18f_1666x1172.heic 1272w, https://substackcdn.com/image/fetch/$s_!lbaH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F693552de-ac14-4943-b92d-1bfa28c6f18f_1666x1172.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lbaH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F693552de-ac14-4943-b92d-1bfa28c6f18f_1666x1172.heic" width="1456" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/693552de-ac14-4943-b92d-1bfa28c6f18f_1666x1172.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:208005,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ziyagokalp.substack.com/i/197249517?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F693552de-ac14-4943-b92d-1bfa28c6f18f_1666x1172.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lbaH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F693552de-ac14-4943-b92d-1bfa28c6f18f_1666x1172.heic 424w, https://substackcdn.com/image/fetch/$s_!lbaH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F693552de-ac14-4943-b92d-1bfa28c6f18f_1666x1172.heic 848w, https://substackcdn.com/image/fetch/$s_!lbaH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F693552de-ac14-4943-b92d-1bfa28c6f18f_1666x1172.heic 1272w, https://substackcdn.com/image/fetch/$s_!lbaH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F693552de-ac14-4943-b92d-1bfa28c6f18f_1666x1172.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Bu rakamlar asl&#305;nda siber g&#252;venlik d&#252;nyas&#305;n&#305;n nas&#305;l d&#246;n&#252;&#351;mekte oldu&#287;unu da g&#246;stermektedir. Ge&#231;mi&#351;te d&#252;&#351;&#252;k seviyeli web uygulamas&#305; a&#231;&#305;klar&#305; y&#252;zlerce dolar de&#287;erindeyken, bug&#252;n geli&#351;mi&#351; <strong>Exploit</strong> zincirleri <strong>milyon dolarl&#305;k</strong> stratejik dijital varl&#305;klar haline gelmi&#351;tir.</p><p>&#214;zellikle:</p><ul><li><p><strong>iPhone Zero-Click Exploit&#8217;leri,</strong></p></li><li><p><strong>Android Kernel Privilege Escalation a&#231;&#305;klar&#305;,</strong></p></li><li><p><strong>Browser Sandbox Escape teknikleri,</strong></p></li><li><p><strong>Cloud Escape senaryolar&#305;,</strong></p></li><li><p><strong>AI model Jailbreak mekanizmalar&#305;</strong></p></li></ul><p>Modern <strong>Bug Bounty</strong> d&#252;nyas&#305;n&#305;n en de&#287;erli alanlar&#305; aras&#305;nda yer almaktad&#305;r.</p><p>Nitekim baz&#305; kritik a&#231;&#305;klar/zafiyetler resmi <strong>Bug Bounty</strong> programlar&#305;ndan &#231;ok daha y&#252;ksek fiyatlarla <strong>Exploit Broker &#351;irketlerine</strong> veya <strong>Devlet Destekli yap&#305;lara</strong> sat&#305;labilmektedir. Bir ba&#351;ka ifade ile bu yap&#305;lar taraf&#305;ndan sat&#305;n al&#305;m yapmak ad&#305;na talep g&#246;rmektedirler. </p><p>B&#246;ylece yukar&#305;da birka&#231; defa ifade etti&#287;im &#252;zere, modern &#231;a&#287;da bir g&#252;venlik a&#231;&#305;&#287;&#305;, yaln&#305;zca teknik bilgi de&#287;il; <strong>Ayn&#305; zamanda ekonomik g&#252;&#231;, stratejik &#252;st&#252;nl&#252;k ve dijital egemenlik arac&#305; haline gelmektedir.</strong></p><p><strong>Not:</strong> <em>&#8220;Tablodaki veriler; ilgili &#351;irketlerin resmi Bug Bounty program a&#231;&#305;klamalar&#305;, kamuya a&#231;&#305;k payout duyurular&#305; ve HackerOne sekt&#246;r raporlar&#305; temel al&#305;narak derlenmi&#351;tir. Baz&#305; de&#287;erler maksimum teorik &#246;d&#252;l miktar&#305;n&#305;, baz&#305;lar&#305; ise kamuya a&#231;&#305;klanan &#246;rnek payout&#8217;lar&#305; temsil etmektedir.&#8221;</em></p><p></p><h1>Sonu&#231;</h1><p>Modern d&#252;nyada siber g&#252;venlik art&#305;k kusursuz sistemler &#252;retme sanat&#305; de&#287;ildir. </p><p>De&#287;erli olan, her sistemin i&#231;inde ka&#231;&#305;n&#305;lmaz olarak bulunan k&#305;r&#305;lganl&#305;klar&#305;, zafiyetleri ve a&#231;&#305;klar&#305; <strong>kimden &#246;nce ke&#351;fedebilece&#287;ini belirlemektir.</strong></p><p><strong>Bug Bounty</strong> ara&#351;t&#305;rmac&#305;lar&#305; bu nedenle yaln&#305;zca teknik uzmanlar de&#287;ildirler. </p><p>Onlar art&#305;k dijital d&#252;nyan&#305;n g&#246;r&#252;nmeyen &#231;atlaklar&#305;n&#305; ke&#351;feden <strong>modern ka&#351;ifler</strong> haline gelmi&#351;tirler. </p><p>Bu noktada de&#287;erlendirilmesi gereken <strong>en hassas</strong> konu; </p><p><strong>Bir g&#252;venlik a&#231;&#305;&#287;&#305; bulundu&#287;unda, onun ger&#231;ek de&#287;erinin g&#252;venli&#287;i art&#305;rmak ve zafiyeti kapatmak olmas&#305; m&#305;d&#305;r, yoksa g&#252;c&#252; elinde tutan akt&#246;rlere stratejik &#252;st&#252;nl&#252;k sa&#287;lamas&#305; m&#305;d&#305;r?</strong></p><p><strong>Nitekim dijital d&#252;nyada g&#252;venlik ile tehdit aras&#305;ndaki s&#305;n&#305;r, &#231;o&#287;u zaman ayn&#305; sat&#305;r kodun i&#231;inde sakl&#305;d&#305;r.</strong></p><p></p><p><strong>Ziya G&#214;KALP</strong><br><strong>Cyber Security Leader &amp; Advisor</strong><br>MSc.IT, SSCP&#174;, ECSA, CEH, ITIL, CEA, CIRS&#8482;,<br>MPM&#174;, OCOE, OOSE, Certified ISO/IEC 27001 LA,<br>CompTIA Project+ Professional,<br>CIW Security Analyst,<br>Certified Cyber Threat Intelligence Analyst,<br>Certified Information Security Executive&#8482;,<br>Senior Certified Leadership Practitioner</p><p></p><h1>Kaynak&#231;a:</h1><ul><li><p><strong>OECD</strong>. <em>Encouraging Vulnerability Treatment</em>. OECD Digital Security Papers, 2024.</p></li><li><p><strong>Google</strong> Vulnerability Reward Program (VRP)</p></li><li><p><strong>Microsoft</strong> Bug Bounty Programlar&#305;</p></li><li><p><strong>Meta</strong> Whitehat / Bug Bounty Program&#305;</p></li><li><p><strong>HackerOne</strong> Hacker-Powered Security Report</p></li><li><p><strong>Bugcrowd</strong> Platformu ve Vulnerability Disclosure Yakla&#351;&#305;mlar&#305;</p></li><li><p><strong>The Hacker News</strong> &#8211; Bug Bounty News &amp; Analysis<br>Bug bounty ekosistemi, Meta, HackerOne, WhatsApp ara&#351;t&#305;rmalar&#305; ve etik hacker topluluklar&#305; hakk&#305;nda s&#252;rekli g&#252;ncellenen haber ve analizler</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ziyagokalp.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Ziya's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>