As Şekerbank T.A.Ş., we act in accordance with applicable laws and regulations to ensure the highest level of security and confidentiality for our customers’ information, and we implement all necessary technical and administrative security measures using the most advanced information technology infrastructure.
For our Bank, our customers’ data is among our most valuable assets. To detect and prevent any type of cyberattack targeting our Bank’s information systems with the intent of obtaining data without authorization, we conduct 24/7 monitoring and tracking activities within the framework of our corporate responsibilities and authorities. We also implement the highest level of security measures to enhance the resilience and responsiveness of our systems against potential cyber threats.
Our employees’ access rights to customer information are established in accordance with legal compliance requirements and the “need-to-know” principle, and security measures are adapted to evolving technology.
Taking information security threats into account, our Bank implements an information systems risk management system that strikes an appropriate balance between risks and safeguards regarding our Bank’s information assets and services. Within this framework, all factors that could threaten the confidentiality, integrity, and availability of data stored on our Bank’s information systems are assessed under the information systems risk management framework, and all necessary measures are taken to analyze, manage, and mitigate potential risks that may arise.
To enhance information security awareness, ensure the achievement of our Bank’s information security objectives, and foster the development of technical and behavioral competencies, we regularly provide information security training—which includes guiding principles and responsibilities—as well as data protection training to our employees and external service providers. These efforts are further supported by regular publications and notifications.
The storage and processing of data in our Bank’s information systems are carried out in full compliance with all applicable legal regulations, primarily the Banking Regulation and Supervision Agency’s (BDDK) Regulation on Information Systems and Electronic Banking Services and the Personal Data Protection Law (KVKK). In cases where data sharing with public institutions and other organizations is necessary due to our banking activities and the legal obligations arising from the legislation to which our bank is subject, data may be transferred within the framework of the applicable laws and regulations.
Information Security Department