forumNew topic

should i keep records of attack findings? how long should i store them? will i get in trouble for deleting them later?

ÜÜlkü K***Member
Job title
Content Editor
Sector
Sports and fitness
Organization type
40-person manufacturing company
Joined
Dec 2024
Message
330
#1

we filed a complaint with the police. the prosecutor said 'keep all the evidence'. how long do i have to keep it? what does turkish law say? can i delete it if the complaint is dropped?

is encryption required when storing evidence? do i need a secure location (safe, data center)?

if you mention the notification error to the business, is that also considered evidence? is there any risk?

NNuri K***Member
Job title
Product Manager
Sector
Real estate
Organization type
sole proprietorship
Joined
Apr 2023
Message
3
Most Helpful#2

Digital Evidence Retention: Turkish Penal Code Article 162 (6-year retention period). Evidence types: 1) Disk image (hard drive copy), 2) Memory dump (RAM capture), 3) Log files (access.log, syslog), 4) Screenshots (attack evidence), 5) Malware samples (restricted access, sandbox environment), 6) Incident reports (internal written report), 7) Forensic report (by an expert). Storage methods: 1) Encrypted storage (AES-256 minimum), 2) Access restriction (legal/IR team only), 3) Offsite backup (secondary location, physical security), 4) Chain of custody documentation (who held it and when), 5) Audit logs (access trail). Retention period: 6 years if a criminal complaint is filed (Turkish judicial system), 5 years for insurance claims (compensation demands), 5 years if a KVKK violation is reported (audit requirement). Deletion: Even if you receive a 'complaint dropped' letter from the prosecutor, you must wait 6 years (risk of reopening). Secure deletion (Eraser tool, secure overwrite) — formatting is not enough, requires bit-by-bit overwrite. Legal risk: Destroying evidence constitutes 'obstruction of justice' (TCK Article 278). Business note: Acceptance of 'human error' or 'control weakness' must be in writing by the responsible individual, serving as proof that responsible oversight was exercised.

TTaner Y***Expert
Job title
Regional Manager
Sector
Electrical-electronics
Organization type
cooperative
Joined
Sep 2025
Message
3

Doki · Vulnerability scanning · 2025

#3

keep evidence for 6 years, even if the complaint drops. like keep it encrypted in a safe etc. if the prosecutor says its done you can delete it but waiting 6 years is safer. forensic disk, malware samples — restricted access...

OOkyanusMember
Job title
Embedded software
Organization type
regional distributor
Joined
Apr 2024
Message
96
#4

Evidence preservation: 1) Disk image (dd if=/dev/sda | openssl enc -aes-256-cbc -out image.enc), 2) Integrity verification (SHA-256 hash documented, recalculate periodically), 3) Storage (encrypted partition, external hard drive, encrypted cloud), 4) Access control (key escrow: two-person rule for access), 5) Audit trail (access logs with timestamps), 6) Regular integrity checks (quarterly hash re-verification). Retention calendar: criminal case 6 years (from judgment), civil/administrative 5 years (from resolution), deletion procedure (secure wipe, certificate of destruction). Malware sample handling: isolated VM, no internet connection, physical lock on device.

OOrhan G***Member
Job title
Courier coordinator
Sector
Livestock
Organization type
workshop
Joined
Feb 2024
Message
173
#5

keep the disk image encrypted store it in a safe. evidence min 6 years — wait even if the prosecutor says go ahead. malware samples in a locked room nobody touch and anyway even if the complaint is dropped there's a risk it could be reopened...

SSelin C***Member
Job title
Secretary
Sector
Law
Organization type
40-person manufacturing company
Joined
Jul 2025
Message
6
#6

Evidence management policy: Identification (tag all evidence with case number, date, handler), Preservation (encryption, access controls, integrity verification), Retention (legal hold dates, retention calendar), Destruction (secure deletion method, sign-off approval, certificate of destruction). Legal timeline: statute of limitations (TCK Article 71: 5 or 6 years depending on the crime), civil action limitation (5 years for damage claims). Documentation: chain of custody form (every handoff recorded), evidence log (inventory of all items), access log (who viewed evidence when). Special handling: classified information (government security clearance required), victim confidentiality (redacted evidence if disclosure risks safety).

GGizem Y***Member
Job title
Board member
Sector
Livestock
Organization type
a company within a holding
Joined
Jan 2024
Message
209

Doki · Server maintenance contract · 2025

#7

Absolutely. If I were to add anything: The answer varies greatly by industry; there is no one-size-fits-all rule.

If you scold false alarms nobody will report again.

TTolga K***ExpertCommunity member
Joined
Apr 2025
Message
24
#8

Saved. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Hope this helps.

ZZehra Y***Expert
Job title
Board member
Sector
Sports and fitness
Organization type
regional distributor
Joined
Oct 2022
Message
3
#9

I completely agree. Mistakes made on the evidence retention side are usually reversible but expensive.

Proven by experience.

GGürkan V***Member
Job title
Customer service representative
Sector
Printing
Organization type
workshop
Joined
Aug 2023
Message
118
#10

There's a part I don't understand. An untested backup is not a backup.

Of course, it varies if your situation is different.

KKemal S***Member
Job title
Field sales representative
Sector
Machinery manufacturing
Organization type
two-branch business
Joined
Jun 2023
Message
62
#11

There's also a measurement aspect to this. If 2FA is on, a stolen password alone is useless.

That's all, sorry if I went on too long.

ÜÜlkü B***New memberCommunity member
Joined
Sep 2026
Message
240
#12

There's a part I don't understand. Security isn't absolute; it's about making attacks not worth the effort.

PPolat G***Member
Job title
Chief Technology Officer
Sector
Printing
Organization type
8-person team
Joined
Aug 2023
Message
275
#13

I agree, and I'd like to emphasize that. Hasty decisions become decisions you have to fix six months later.

Solutions that work at a small scale collapse when you grow; I learned this late. Of course, it varies if your situation is different.

JJülide A***MemberCommunity member
Joined
Jul 2025
Message
75
#14

I'm curious too.

JJülide K***ExpertCommunity member
Joined
Dec 2022
Message
108
#15

Following. People defend habits, not processes. Resistance comes from there.

ÖÖmer D***Member
Job title
Field sales representative
Sector
Automotive aftermarket
Organization type
medium-sized business
Joined
Aug 2024
Message
341
#16

My questions are cleared up thanks.

İİlker G***Member
Job title
Operations manager
Sector
Cosmetics
Organization type
medium-sized business
Joined
Jun 2024
Message
75
#17

There's a common mistake people make when doing this. Trying to do this alone is the most expensive way.

Of course it varies if your situation is different.

GGülayMember
Job title
Textile workshop
Joined
Oct 2023
Message
84
#18

I didn't know that.

FFatih G***Member
Job title
Production planning
Sector
IT services
Organization type
medium-sized business
Joined
Nov 2024
Message
31
#19

If you're going this route, sort this out first. If you get three different answers on a topic, the question was asked wrong.

Taking notes for two weeks yields better results than a six-month estimate.

İİlknur A***New member
Job title
General coordinator
Sector
Textile
Organization type
early-stage startup
Joined
Jun 2026
Message
59
#20

I've been down this road let me tell you. If it's your first time, start small; scaling comes later.

Reply