A mid-sized manufacturing company’s general manager arrives at the office to find a single message on every screen: all files are encrypted, access is impossible without payment. The IT team confirms that backups were not taken regularly and the ERP system had not been patched in months. Production stops, customer orders stall, accounting records are unreachable. This is no longer a hypothetical scenario. Similar incidents are occurring across industries, including in Turkey, and they are fundamentally reshaping how organizations think about cyber risk.
For years, cybersecurity sat comfortably within the IT department’s remit. Firewalls were configured, antivirus licenses renewed, password policies set. That was considered sufficient. But this approach no longer reflects the actual threat landscape. Attacks exploit not just technical vulnerabilities but weaknesses in business processes, supply chain connections, and employee behavior. Ransomware typically enters corporate networks through a simple email attachment, then works its way through ERP databases, accounting records, and operational data. At that point, the problem ceases to be technical and becomes a strategic business continuity crisis.
The growing boardroom attention to cybersecurity is driven not only by the frequency of attacks but by their financial and legal consequences. A company that suffers a data breach faces a layered exposure: customer attrition, reputational damage, regulatory penalties, and potential legal liability. In Turkey, the mandatory adoption of e-Invoice and e-Ledger systems has expanded the volume of data companies share with tax authorities, which simultaneously broadens both compliance obligations and the attack surface. For a CFO or general manager, cybersecurity is no longer a line item in the IT budget — it is an operational risk factor that belongs in any serious total cost of ownership calculation.
What does it actually mean to integrate cybersecurity into an enterprise risk framework? The starting point is defining risk in measurable terms. Which systems are critical? What is the operational cost of one hour of downtime? What is the legal exposure from a customer data breach? When these questions are answered in the language the board understands — financial impact and probability — the conversation about security investment becomes concrete. The ROI calculation is admittedly difficult because the return on security spending often manifests as ‘harm that did not occur.’ But that ambiguity is not a reason to avoid investment; it is an argument for a more structured risk assessment methodology.
Looking at the ERP infrastructure of mid-to-large Turkish companies, security vulnerabilities tend to concentrate in three areas: outdated software versions, inadequate access controls, and backup processes that have never been tested under realistic conditions. ERP systems today hold far more than accounting entries and inventory counts — they carry the full operational memory of the business, including human resources, supply chain, and customer data. Securing these systems is not a technical upgrade; it is the foundation of a viable business continuity strategy. For companies moving toward cloud-based ERP solutions, the boundaries of responsibility must be clearly defined: which security layers rest with the service provider, and which remain with the company?
The most significant obstacle to this shift is organizational, not technical. In many companies, cybersecurity accountability remains unassigned at the senior level. The IT manager handles the technical infrastructure, but decisions about who can access which data, how supplier connections are monitored, or how the company communicates publicly after a breach are not being made at the governance level. The board’s role is not to understand technical specifications — it is to approve security policy, ensure adequate resources are allocated, and establish clear accountability mechanisms. Without that ownership at the top, even well-designed technical controls tend to erode over time.
For a general manager or CFO ready to bring cybersecurity to the board, the most effective starting point is a single question: if an attack happened right now, how many hours would it take to restore operations? The answer almost always reveals the true state of preparedness. The next step is integrating cyber risk into the annual budgeting and strategic planning cycle — not as an IT expenditure, but as a component of enterprise risk management. As digital transformation investments accelerate, security infrastructure must keep pace. That is no longer a choice; it is a structural requirement for any organization that depends on its data to operate.
This article was originally written in Turkish by Gökhan MERCANOĞLU on January 30, 2017 and has been automatically translated into English and other languages using machine translation.