forumNew topic

We need to comply with MEB's cyber incident response procedure — as a school, where do we start?

RRecep K***Member
Job title
Customer service representative
Sector
Leather
Organization type
family business
Joined
May 2024
Message
1
#1

We are a private educational institution in Istanbul with 850 students from kindergarten through high school and around 90 staff members. We have a two-person IT team. We recently received an audit notice from the district national education directorate regarding cybersecurity directives and cyber incident response processes. We are required to set up a framework compliant with the ministry's incident response procedure, designate an authorized in-house team, and document the entire workflow in writing.

Our school network runs a basic firewall and centralized logging system, but we are unsure about the standardized procedures required by the ministry, the exact nature of the mandatory logs to be kept, and the official notification deadlines. In the event of ransomware, website defacement, or a student data breach, it is not entirely clear when and with which documentation we must notify the relevant ministry departments.

I would appreciate guidance from colleagues who have gone through similar audits or successfully implemented this procedure at their institution: Which documents should we begin drafting first, who must mandatorily sit on the commission, and how should technical logs be archived to remain fully compliant with the regulations?

TTuğçe Y***Expert
Job title
Content Editor
Sector
E-commerce
Organization type
20-person company
Joined
Oct 2025
Message
215
Most Helpful#2

Short answer: To comply with MEB procedures, you must first officially assign an institutional SOME team headed by the school principal, consisting of at least one administrator and one IT staff member, prepare an incident response flowchart, and retain time-stamped network logs retroactively for at least two years. In the event of an incident or attack, an incident report form must be completed without delay and submitted through official channels to the district national education directorate and the ministry's cyber incident coordination center.

Here are the essential steps you should follow: 1) Team Formation: Issue an official assignment order appointing the school principal, an assistant principal, the IT coordinator, and the institution's data protection contact person. 2) Asset Inventory and Classification: Catalog assets including administrative records, student affairs servers, CCTV systems, and guest networks; strictly segregate the administrative network from the student network, either physically or via VLANs. 3) Logging Framework: Cryptographically sign internal IP assignment records, firewall traffic logs, and admin console logins with valid time stamps in compliance with Law No. 5651 and ministry standards.

When a cyber incident occurs, the initial reaction must not be wiping systems in a panic; it should be isolating potential evidence, including logs and memory dumps. Once the scope of the incident is determined, the incident report must be submitted to the ministry SOME unit via the district MEB within 24 hours. If there is a suspected personal data breach, regulatory reporting to the relevant data protection authority must occur within 72 hours. These documents, along with annual drill records, must be kept ready in your compliance binder.

HHakan A***Member
Job title
Software team lead
Sector
Catering
Organization type
20-person company
Joined
Oct 2023
Message
86
#3

The thing they scrutinize most during audits is log verifiability. Storing raw text files on a log server won't cut it; they require time stamps and hash records compliant with Law No. 5651. If you fail to map the internal IP assigned to a parent or student on the guest Wi-Fi to the external IP, you'll be cited for non-compliance on the spot.

ÖÖmer Ş***Member
Job title
Project manager
Sector
Software
Organization type
chain store
Joined
Feb 2025
Message
179

Doki · Brand identity · 2025

#4

Are student and staff computers sitting on the same network subnet? If you don't have proper VLAN separation, you'll fail the technical audit regardless of how well your procedures are drafted. Have you verified whether the ministry inspectors specifically check for administrative network isolation?

TTolga Y***Expert
Job title
Export manager
Sector
Printing
Organization type
chain store
Joined
Aug 2023
Message
3
#5

The formal decision establishing your institution's Cyber Incident Response Team must be officially documented with the school principal's signature and recorded in the dated board decision registry. Submitting a copy of your incident response plan to the private education institutions department of the district national education directorate alongside an official cover letter will significantly smooth out your audit process.

GGürkan B***MemberCommunity member
Joined
Oct 2024
Message
407
#6

Last term, we went through a similar audit at our 1,100-student campus. They asked us to fill out the ministry's standard printed forms and provide timestamped DHCP and firewall logs going back 730 days. Without hiring any outside consultants, we passed the inspector's audit with flying colors after two weeks of organizing our files.

edit: fixed a few typos.

MMehmet Ç***MemberCommunity member
Joined
Apr 2023
Message
277
#7

at our school they made the assistant principal the lead and put me down as technical staff... we downloaded the sample incident response plan template from the MEB site and tweaked it for our school. it feels like pure formality but district MEM approved it when we submitted the papers, no need to panic.

AAyşe O***Veteran
Job title
Quality control inspector
Sector
Energy
Organization type
120-person company
Joined
Dec 2023
Message
126
#8

The templates published by the ministry are usually designed for the massive staff sizes of public institutions. You can't expect a 2-person IT team at a private school to generate reports like a 24/7 SOME team. Write a realistic internal directive; don't trap yourself by including steps in the procedure that you can't actually carry out.

TTaner V***MemberCommunity member
Joined
Jan 2023
Message
307
#9

First thing tomorrow, download the 'Cyber Incident Notification Form' attached to MEB's Information Security Directive to your computer. Then, test whether the timestamp license on your internet gateway's logging device is active; these are the two most critical tangible items.

BBurcu A***Member
Job title
Operations director
Sector
Cosmetics
Organization type
regional distributor
Joined
Jan 2022
Message
5

Doki · Mobile app · 2026

#10

I'd say don't rush. Your time to detect an issue directly determines its cost.

If you post the result here it will help others too.

GGizem Y***Expert
Job title
Marketing manager
Organization type
a company within a holding
Joined
Sep 2023
Message
168
#11

You're right, I've been down that road too. Start with a small trial; don't commit to everything at once.

Taking measures without an inventory leaves doors you haven't seen open. Proven by experience.

BBurak U***MemberCommunity member
Joined
Jun 2024
Message
331
#12

This thread is archived. The harder it is to reverse a decision, the slower you should make it.

Hope this helps.

KKadir A***Expert
Job title
Customer service representative
Sector
Food wholesale
Organization type
a company within a holding
Joined
Sep 2024
Message
392
#13

I agree with this. If you scold false alarms, nobody will report again.

When making decisions, write down the worst-case scenario too, not just the best. Hope this helps.

İİlker K***Member
Job title
Information Security Specialist
Sector
Glass
Organization type
a company within a holding
Joined
Jul 2025
Message
185
#14

How did you solve this? The biggest time-waster for us was not knowing who had the final say.

Of course, it varies if your situation is different.

NNuri Y***Member
Job title
Co-founder
Sector
Jewelry
Organization type
a company within a holding
Joined
May 2023
Message
2

Doki · Phishing awareness training · 2024

#15

My perspective changed after experiencing that. btw people defend habits, not processes. Resistance comes from there.

Most time waste accumulates in tasks waiting for approval. That's all, sorry if I went on too long.

ZZerrin U***Member
Job title
Logistics planning
Sector
Construction
Organization type
regional distributor
Joined
Aug 2022
Message
307
#16

I feel the same way. When you try to change everything at once, nothing settles.

If permission and scope aren't in writing, don't start that test. This is my opinion I'm not claiming it's absolute truth.

ZZerrin S***Expert
Job title
Sales Manager
Sector
Software
Organization type
120-person company
Joined
Apr 2023
Message
43
#17

i can't fully agree with this. everything goes well for the first thhree months; problems arise in the fourth.

if the notification path is long, notifications dont arrive; missing notifications mean delayed incident detection but corrct me if Im wrong.

KKayahanMember
Job title
Full-stack
Joined
Jun 2024
Message
118
#18

Correct.

HHüsniye S***MemberCommunity member
Joined
Dec 2025
Message
28
#19

Id appreciate it if you shared the outcome.

RRecep Y***Member
Job title
System administrator
Sector
Sports and fitness
Organization type
boutique agency
Joined
Jun 2022
Message
9
#20

You're right. An untested backup is not a backup.

I'm also curious if anyone does it differently.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic