.jpg)
Every Regulator Has Its Own Rulebook.
A bank in Istanbul answers to BDDK for its information systems, to KVKK for personal data and, since 2025, to the Cybersecurity Presidency for cyber incidents. A broker adds SPK’s new information systems rules. A payment institution adds TCMB’s.
Most teams still stitch this together with spreadsheets, email trails and a tool that only covers IT controls. Governance and enterprise risk stay manual. Keep your advisors; give them one platform to work from.
LockThreat maps your obligations once, tests your controls continuously, and gives your board and Early Risk Detection Committee one current view of risk.
The Stakes Have Risen.
Built for Türkiye’s Most Regulated Sectors
BDDK IS rules, in-country systems and annual penetration tests.
TCMB information systems rules, updated in September 2026.
SPK VII-128.10, independent IS audits and crypto-asset rules.
SEDDK internal systems rules, aligned to the ICT Security Guide.
EPDK cybersecurity competency model and Law 7545.
KVKK at home; GDPR and the EU AI Act for EU clients.
Spreadsheets and IT-Only Tools Leave agapRegulators Will Find.
GRC
Frameworks for Türkiye
Mapped to one control library, so a control tested once serves every framework it supports. Tracking something not listed? Ask us.
Data Protection
National Cybersecurity
Banking & Payments
Capital Markets, Insurance & Energy
Governance & Risk
.webp)
.webp)
Your teams are already using AI on customer and employee data. Under KVKK, you’re accountable for it. Do you know which AI tools and agents are breaching your controls?
.png)
.png)
Your Data. Your Boundary.
Turkish financial regulators expect core systems to stay in the country: BDDK, TCMB and SPK require primary and secondary systems in Türkiye, and Presidential Circular 2019/12 keeps critical public data at home.
Choose how LockThreat runs: in your own private cloud, on-premises in your Turkish data centre, or as managed SaaS. The same full G+R+C depth, regardless of deployment.
One Platform for the Whole Buying Committee
- BDDK, SPK and Cybersecurity Law evidence collected continuously, not the week before an audit.
- Third-party and outsourcing risk tracked alongside your own controls.

- KVKK obligations mapped to controls, with the 72-hour breach clock tracked in incident workflows.
- Transfer safeguards and policies documented against the frameworks you answer to.

- Risk quantified in financial terms with FAIR modelling and Monte Carlo simulation.
- One enterprise risk register across business units and locations.

- Continuous control testing instead of periodic sampling.
- Board and committee reporting drawn from live data, not spreadsheets.

Everything Enterprise GRC Should Have Been.
Most GRC tools deliver compliance, with governance and risk as an afterthought.
Here, governance comes first: the policies that move your organisation forward, the controls that contain risk across every department, and the compliance that follows naturally from both.
No spreadsheets. No disconnected tools. No point-in-time snapshots. One centralised, ongoing view of your risk and compliance posture.

.webp)
Your regulatory obligations don’t respect org charts or borders.
Every department, from finance, legal and HR to operations, cyber and IT, managed in one place, without the sprawl.
The locations you operate in, from Istanbul, Ankara and İzmir to your plants, branches and offices worldwide, managed in one place without adding more tools.

.png)
Which AI tools are your employees using? Are they approved? Are they handling personal data your KVKK notices and consents don’t cover?
And when AI agents act autonomously, accessing systems, making decisions, breaching controls, who’s watching? Now you are.
From shadow AI discovery and ISO/IEC 42001 alignment to real-time prompt protection and agentic control enforcement, reported directly into your GRC framework.

.png)
Every stakeholder needs a different view of the same risk reality, from one source of truth.
Express risk in financial terms your board and CFO can act on, using FAIR modelling and Monte Carlo simulation.
Detailed enough for the analyst, clear enough for the Chief Risk Officer and the CISO, compelling enough for the board.

.png)
Compliance isn’t an annual exercise; it’s an ongoing operating requirement.
LockThreat validates that your controls are working, right now, across cloud infrastructure, cyber endpoints and enterprise applications.
Far less scrambling for evidence before a BDDK inspection, an independent IS audit or a KVKK review.

.png)
Map KVKK, BDDK, SPK and TCMB requirements, Law 7545 and the ICT Security Guide to ISO 27001, NIST and SOC 2, and to each other, eliminating redundant work.
Tie everything to your own policy library and control framework, so governance becomes a living system, not a compliance filing cabinet.

.png)
Enterprise GRC depth without the 18-month implementation. Up and running in weeks to months, on the technology stack you already have.
Minimal dependence on scarce specialists once you’re live.
Already running another GRC platform? Run LockThreat alongside it during transition, no rip-and-replace required.

.png)
.png)
.png)
What GRC Leaders Say
.png)
.png)
See LockThreat on Your Turkish Frameworks
A focused 30-minute walkthrough, plus pricing for your deployment. No generic pitch, no obligation.
Tell us which regulators and frameworks you answer to (KVKK, BDDK, SPK, TCMB or Law 7545) and how you want to deploy. We’ll tailor the session to your programme.
- A 30-minute walkthrough on your frameworks, following your priorities.
- Your deployment path: private cloud, on-premises in your data centre, or SaaS.
- Pricing for your scope, based on your entities, frameworks and deployment model.
Prefer email? info@lockthreat.com
.webp)
.webp)
.webp)


.png)