BDDK Penetration Testing
BDDK (Banking Regulation and Supervision Agency) regulations require banks in Turkey to have their information systems tested regularly by independent, competent parties. As a TSE-accredited penetration testing firm, Omniverse provides end-to-end BDDK penetration testing for banks and financial institutions, from scoping to audit evidence.
Why is BDDK penetration testing required?
The Regulation on Banks’ Information Systems and Electronic Banking Services requires banks to assess the security of their information systems through regular penetration tests and to track the remediation of identified vulnerabilities. In practice, tests are expected at least once a year and after significant system changes, and the results are reviewed as evidence in independent audits.
Similar requirements apply to payment and e-money institutions under CBRT regulations, and to brokerage houses and other capital markets firms under the information systems management regulations of the Capital Markets Board (SPK).
During scoping we confirm the current requirements of the regulation you are subject to (test frequency, scope and reporting format) against the legislation together with you.
BDDK penetration testing scope
- Internet and mobile banking: web and mobile channels, customer authentication and transaction security, back-end APIs.
- External network and internet-facing services: perimeter security, remote access, email and DNS infrastructure.
- Internal network and Active Directory: privilege escalation, lateral movement, paths to critical systems and segmentation.
- Card and payment systems: card processing infrastructure and environments in PCI DSS scope.
- Critical banking applications: core banking interfaces, branch and call centre applications, integration services.
- Social engineering: phishing and awareness tests where in scope.
How we work
- Scoping and regulatory mapping: we map the test scope to the articles of the regulation and to internal audit expectations.
- Test plan and rules of engagement: test windows and a communication plan are agreed to protect service continuity on live banking systems.
- Testing and validation: findings are validated through manual exploitation and false positives are removed.
- Reporting in BDDK format: the executive summary, technical findings and remediation guidance are prepared in an audit-ready structure.
- Finding closure tracking and retest: fixes are retested and their closure is reported.
- Audit support: we support the independent audit with an evidence file and technical explanations.
Why Omniverse?
- TSE TS 13638 accredited penetration testing firm: our methodology, people and reporting processes are independently audited.
- Certified team: TSE senior penetration testers and consultants holding OSCP, OSCE, CRTO and CISSP certifications.
- Manual validation: not automated scan output; every finding is proven through exploitation and false positives are removed.
- Audit-ready reporting: an executive summary and a CVSS-scored technical report that can be used as evidence in BDDK, CBRT, PCI DSS, ISO 27001 and DORA audits.
- Support through closure: once fixes are in place, we retest and report that the findings are closed.
- Sector experience: more than 50 enterprise clients, primarily in banking and finance, insurance, energy and critical infrastructure, automotive, retail and healthcare.
Let’s define your scope together
Tell us what you need and we will prepare a tailored proposal.