Research

State of Cyber Governance in Turkey: a plan to publish evidence, not claims.

vciso.tr intends to publish original benchmark research on cyber governance, AI governance, vendor risk, assurance, and incident readiness using anonymous, voluntary participation. No benchmark dataset has been published yet.

Do the current free assessments collect research data?

No. Readiness assessments on vciso.tr are calculated in your browser by default. There is no hidden mechanism that submits your answers into a research dataset.

If research participation is introduced later: it will require a separate, explicit opt-in. Receiving a free assessment result will not mean joining research.

Planned research areas

  • Cybersecurity maturity and governance ownership
  • AI/LLM inventory and AI-governance maturity
  • ISO 27001 / SOC 2 assurance readiness
  • Vendor and third-party risk management
  • Customer security questionnaires and enterprise-sales trust
  • Board cyber-risk reporting
  • Incident response and ransomware readiness
  • Shadow AI / shadow IT governance

Publication standard

  1. Methodology first: question set, sample, collection window, and calculation method will be disclosed.
  2. Minimum sample: small groups will not be generalized into headline percentages; insufficient segments will be marked accordingly.
  3. Anonymization: person- or company-identifying information will not appear in research outputs.
  4. No cherry-picking: findings will not be selected only because they support a marketing narrative.
  5. Uncertainty: limitations of self-assessment data and sampling bias will be stated.
  6. Raw-count context: where practical, percentages will be accompanied by respondent counts.

Planned report

The State of Cyber Governance in Turkey report will not be presented as published until there is sufficient, ethically collected data. When released, date, version, sample size, and methodology changes will be visible.