RESCUE PLAN

1. PURPOSE AND SCOPE

This Recovery Plan has been prepared in order to ensure the security of customer assets, to ensure operational continuity and to maintain market confidence in the event of extraordinary circumstances, systemic interruptions, cyber-attacks, crypto asset losses and other crisis scenarios that Whitebit Kripto Varlık Alım Satım Platformu A.Ş. (hereinafter referred to as the "Company") may encounter during its activities. The Plan covers all business units, information systems, customer relationships and external service providers of the Company.

2. RISK DEFINITIONS AND PRIORITIZATION

2.1. Risks are systematically identified and prioritized in order to prepare for crisis situations that may arise in the Company's operations. Risk assessments are based on both local regulatory authorities (CMB, MASAK, BRSA) and international standards (ISO/IEC 27001, NIST SP 800-34, FSB Recovery & Resolution Principles). The main risk categories that stand out in this context are detailed below:

2.2.1. Cyber Security Risks

It covers digital threats such as unauthorized system access, leakage of customer information and wallet data, exposure to ransomware, crypto asset theft, phishing attacks and DDoS. These risks are positioned as the most critical threat group for operational continuity and customer security.

2.2.2. Operational Risks

They include process-oriented weaknesses such as human errors, procedural errors, unauthorized decision-making, internal control weaknesses, and outsourced disruptions. The impact of these risks is often focused on continuity, service quality and regulatory compliance.

2.2.3. Technological Infrastructure Risks

It covers risks arising from technical failures such as server hardware failures, database corruption, interruptions in network infrastructure and integration problems with third party technological solutions. Such risks require prioritized intervention as they have a direct impact on customer services.

2.2.4. Natural Disasters and Physical Threats

It includes risk factors such as earthquake, fire, flood, sabotage and physical vulnerabilities in building access systems. In these cases, the physical integrity of data centers and operation centers is prioritized.

2.2.5. Market and Liquidity Risks

2.2.5.1. Situations such as sudden and high fluctuations in prices due to the volatility of crypto assets, liquidity congestion, order book imbalances and user panic sales are considered in this group. Such risks are monitored at a strategic level as they directly affect customer account balances and confidence in the market.

2.2. For all these risk categories, probability-impact analyses are conducted on an annual basis, risk scores are determined and positioned on the risk matrix. Detailed control measures, incident response procedures and recovery scenarios are prepared for high priority risks.

2.2.6. External Service Provider Risks

Due to the services carried out through external providers on the Company's critical systems such as cloud infrastructure, networking and data centers, the actions of third parties can directly affect crisis operations. For this reason, the recovery commitments of the relevant providers are regularly tested and service continuity agreements (SLAs) are reviewed.

3. RECOVERY STRATEGIES AND WORKFLOWS

3.1. In order to maintain the operational and technological continuity of the Company, to ensure customer safety in possible crisis situations and to fulfill its obligations before public authorities without interruption, the following multi-layered recovery strategies have been developed:

3.1.1. System Isolation and Quarantine Protocols

When any cyber threat or unusual system behavior is detected, the affected system components are immediately isolated and disconnected from the network. During this process, crypto assets in hot wallets are transferred to predefined secure cold wallets with automated transaction rules. Isolation processes are designed to ensure uninterrupted transaction sustainability without degrading system performance. Recovery scenarios are structured to ensure secure recovery of customer assets on a one-to-one correspondence basis. The integrity and accessibility of cold wallet reserves are prioritized in the event of a crisis.

3.1.2. Data Backup, Synchronization and Restore

All system data is backed up daily in encrypted form in at least two different geographical locations. In case of sudden data loss or system damage, restoration processes are initiated using these backups. The process is documented in accordance with ISO 22301 Business Continuity Management System. Backup systems are structured in accordance with the principles of data consistency, encryption security and geographical redundancy within the scope of Capital Markets Board ("CMB") legislation provisions. Backed up data is restored at least once a year and the results of these tests are reported to the Board of Directors.

3.1.3. Internal and External Communication Management

In times of crisis, a simultaneous and transparent communication strategy is followed with customers, employees, media outlets and relevant regulatory bodies. Information sharing with authorities such as the CMB, Financial Crimes Investigation Board ("MASAK") and the Personal Data Protection Authority ("KVKK") is carried out immediately. Communication protocols are carried out through public platforms, call center and e-mail/application notifications.

3.1.4. Alternative Transaction and Access Channels

In case of access interruptions on the main platform, pre-configured backup trading channels (web-based secondary panel, mobile application interface, manual order entry system, etc.) are activated. These alternative structures aim to mitigate the effects of service interruption by enabling users to access basic functions.

3.1.5. Post-Crisis Audit and Feedback Mechanism

After each crisis incident, a technical and operational analysis of the incident is conducted. The internal audit unit documents all steps related to the incident and submits them to the Board of Directors. When deemed necessary, independent audit institutions are involved in the process. In addition, the lessons learned from the process are recorded in the organizational knowledge base, contributing to the strengthening of future response capability.

4. RESPONSIBILITIES AND ORGANIZATIONAL STRUCTURE

4.4.1. The following organizational structure has been established within the company in order to effectively execute the Recovery Plan, to ensure rapid and coordinated response in times of crisis, and to fully fulfill the obligations before the regulatory authorities:

4.4.1.1. Recovery Plan Managers

At least two senior executives appointed by the Company's Board of Directors, who are competent in crisis management and have a high level of responsibility, are directly responsible for the preparation, implementation and revision process of this plan. One of these managers must be at least at the level of "Assistant General Manager". Within their areas of authority, they manage the coordination of the plan, resource allocation, communication with external organizations and operational governance processes.

4.4.1.2. Crisis Management Team

This team, consisting of senior representatives selected from the company's Information Technologies, Operations, Legal, Human Resources and Corporate Communications departments, is the primary intervention and decision-making body in times of crisis. The team can be expanded according to the nature of the incident. It can hold emergency meetings instantly online or physically; decisions are implemented with fast approval mechanisms. The team also carries out post-crisis recovery, documentation and reporting processes.

4.4.1.3. Contact Information and Disclosure Obligation

The name, surname, title, corporate e-mail address, fixed and mobile phone numbers, and fax information of all executives responsible for the Recovery Plan are regularly updated. This information is shared with the CMB, relevant public institutions and strategic service providers. Information updates are made within 7 business days at the latest when there is a change in the organizational structure.

5. TESTING, REVIEW AND UPDATE

5.1. The effectiveness of the Recovery Plan is ensured through regular testing, auditing and review processes in order to achieve results with minimum damage in a real crisis. It is essential that the plan is continuously improved and revised with sensitivity to internal and external variables.

5.1.1. Annual Review

The plan is reviewed by the Risk Management and Internal Control Unit at least once a year in accordance with the planned audit calendar. In case of significant changes in business processes, legislation or technological infrastructure, this review process may be brought forward without waiting for the usual calendar. The review report is submitted to and approved by the Board of Directors and necessary revisions are implemented.

5.1.2. Scenario Based Exercises

A full-scope recovery scenario drill is conducted at least once a year to test the real-life functionality of the plan. Drills are diversified and designed according to different risk types such as system outage, cyber attack, data breach, natural disaster. A performance evaluation report is prepared after each exercise and improvement suggestions are transferred to responsible units for implementation. Drills are conducted in accordance with the CMB legislation, based on scenarios that may affect information systems continuity (central database crash, DNS attack, API connection interruption, etc.) and the results are integrated with the internal audit system and recorded.

5.1.3. Internal Audit and Reporting

The level of implementation of the plan, the operability of control points and the appropriateness of crisis procedures are evaluated by the Internal Audit Unit within the scope of the annual audit plan. Within the scope of internal audit, annual system recovery capacity, log integrity and the achievability of RPO-RTO targets are audited in accordance with the Communiqué on Independent Audit of Information Systems (III-62.2.b). Audit findings are presented to the Board of Directors and the quality of implementation is confirmed by obtaining independent opinions from external audit firms when necessary. Exercise records, data recovery tests and incident response logs created within the scope of the Recovery Plan are stored in templates in accordance with the CMB format to be used in independent audits.

6. CUSTOMER INFORMATION AND TRANSPARENCY

6.1. The Company implements a multi-layered disclosure strategy to maintain customer confidence, prevent information asymmetry and ensure transparency in crisis situations. This strategy is based on timely, accurate and simplified information flow.

6.1.1. Instant Information

Immediately following the occurrence of a crisis situation, customers are informed via the company's website, mobile application notification system, e-mail and SMS channels. The content of the information is prepared to include the type and scope of the incident, the affected systems, the measures taken and the anticipated resolution time. Information is updated as developments occur.

6.1.2. Frequently Asked Questions (FAQ) Page

In the event that the crisis is linked to a personal data breach, the relevant persons and KVKK are notified in accordance with the Personal Data Protection Law No. 6698. The process regarding this notification is completed within 72 hours in accordance with Article 33 of the European Union General Data Protection Regulation ("GDPR"). A "Crisis FAQ" section is published, which covers curious topics related to the crisis and is prepared by anticipating customer questions in advance. On this page, customers are provided with technical and legal answers such as system access, fund security, transaction history, and refund process.

6.1.3. Feedback Mechanisms

Interactive channels through which customers can directly communicate their problems, suggestions and complaints are activated. Notifications received via the call center, live support application and support e-mail address are recorded, prioritized and integrated into solution processes. All notifications are collected in a central data pool to be taken into account in the post-crisis analysis process.

7. POST-CRISIS RECOVERY ACTIVITIES

Crisis management does not only consist of immediate intervention, but is complemented by structural improvement processes carried out after the crisis. The Company is committed to turning crises into learning opportunities and implements a comprehensive "Post-Incident Recovery Protocol". The recovery process includes the following basic steps:

  • Comprehensive forensic investigations are carried out regarding the crisis. System logs, access records and transaction histories are analyzed in detail to determine the technical origin of the incident and the adequacy of intervention.
  • An annual report is prepared using all the data obtained. The report is submitted to the Board of Directors via the internal audit unit. When necessary, official reporting is also made to regulatory bodies such as CMB, MASAK and ICTA.
  • Security patches, configuration updates and access protocol revisions are performed for all crisis-related software and infrastructure components.
  • Learning sessions and situational awareness trainings are organized for company employees. Mistakes and correct interventions made during a crisis are shared; collective memory is created.
  • Independent external consultancy services are obtained when necessary. Penetration tests, attack simulations and risk assessment services are requested from expert organizations.
  • In order to restore customer confidence, compensation and reputation improvement programs are implemented for customers directly affected by the crisis. Practices such as fee refunds, transaction fee exemptions and special campaigns are implemented.

8. CRITICAL INDICATORS AND TRIGGERS

8.1. In order to increase the effectiveness of the Recovery Plan and to be able to implement it without delay, the Company monitors predefined early warning indicators (Early Warning Indicators). These indicators are categorized into three main categories: technical, operational and reputational. Sample triggers are listed below:

  • Sudden performance drops in internal systems, slowdowns in database queries, processing delays or timeouts
  • Multiple and simultaneous outflows of large sums of money from customer accounts
  • Attempted access to the same user account from multiple IP addresses in a short period of time
  • External IP addresses sending an excessive amount of requests, bot traffic, spam, signs of DDoS attack
  • Sudden volatility of 20% or more in the prices of crypto assets, volumetric imbalances
  • Sudden increase in negative content spread against the company on social media platforms, forums or media outlets (monitored through sentiment analysis integrations)

8.2. When one or more of these indicators occur, the Crisis Management Team is immediately alerted through automated monitoring systems (SIEM, IDS/IPS, anomaly detection). The team evaluates the situation and activates the plan when necessary.

9. COORDINATION WITH THIRD PARTY SERVICE PROVIDERS

9.1. The Company procures some vital systems and infrastructure components from third party service providers. These providers operate in areas such as data centers, cloud computing infrastructure, external API services, network security solutions and communication infrastructure. In this context, it is aimed to ensure absolute integration between the Company's business continuity and crisis management processes and the business continuity plans of third parties.

9.2. All service contracts and level agreements (SLA) signed with third parties shall include the following provisions in an explicit and binding manner:

9.2.1. Service Continuity and Disaster Recovery Commitments

Providers commit to restore critical services within predetermined timeframes (Recovery Time Objective - RTO, Recovery Point Objective - RPO). In case of a state of emergency, alternative server infrastructures are activated to ensure uninterrupted continuity of services.

9.2.2. Obligation to Notify in Case of Interruptions

All third party service providers are obliged to notify the Company in writing and/or through the automated system within a maximum of 30 minutes in case of service interruption or security breach.

9.2.3. Joint Exercises and Integration Tests

Providers actively participate in recovery drills organized by the company at least once a year. During these drills, the provider's business continuity plans are tested against the company's crisis scenarios.

9.2.4. Priority Access and Technical Support during Crisis

In case of emergency, technical support is requested from the provider 24/7 through predefined contacts. Technical experts are expected to be physically or digitally involved in the crisis response process.

9.2.5. Data Security, Encryption and Backup Compatibility

Third parties are required to fully comply with the Company's standards in terms of data integrity, backup frequency, encryption algorithms and geographic redundancy principles. These conditions are re-evaluated and updated every year. Backup solutions used by the Company support encryption algorithms compliant with FIPS 140-2 or equivalent standards. In addition, data integrity is ensured by time stamping and hash verification checks in accordance with the CMB Communiqué No. VII-128.10.

9.2.6. All third party contracts are reviewed at least once a year by the Company's Legal and Risk Management departments. Updates are made when deemed necessary and the recovery plans of these providers are harmonized with the Company's plans.

10. CORPORATE COMMUNICATION AND STAKEHOLDER MANAGEMENT

In times of crisis, in accordance with CMB Communiqués No. III-35/B.1 and III-35/B.2, a 'Crisis Notification Process' is implemented to ensure that the Board and MASAK are immediately notified for service interruptions or events affecting customer asset security. This process is supported by ready-made templates containing notification content and timing and is initiated by the corporate communication officer.

The flow of information to the public and communication with stakeholders in times of crisis is carried out by the Company in a centralized and controlled structure. In this context, only one or more "Corporate Communications Officers" authorized in writing by the Board of Directors are authorized to make public statements in times of crisis. The communication strategy for public and private stakeholders is based on the following basic principles:

  • Balance Transparency and Information Security: Information provided to stakeholders is prepared to include the scope of the incident, its impacts, response process and estimated time of resolution. However, information security principles are meticulously observed to ensure that disclosures do not undermine customer security and trigger secondary risks such as fraud.
  • Simultaneity of Official Statements and Digital Announcements: Written statements regarding the crisis are published simultaneously on the website, social media accounts and investor information panels. Internal disclosures and public announcements are synchronized.
  • Special Notification to Regulatory Authorities: Depending on the nature of the crisis, a special "Crisis Information Report" is prepared for the CMB, MASAK, BTK, KVKK and, when necessary, international regulatory authorities and communicated immediately. These notifications include the technical details of the incident, the response process and additional measures to be taken.
  • Mandatory Notification in case of Personal Data Breach: Pursuant to Article 12/5 of the LPPD and the European Union General Data Protection Regulation (GDPR), in the event of a personal data breach, official notification is made to the data subjects and the Personal Data Protection Board within 72 hours.
  • Reputation Management and Recovery Media Strategies: Social media, press releases and digital PR activities are carried out to protect the company's reputation and rebuild customer trust in the post-crisis period. Positive content, especially on user experiences, is highlighted to support post-crisis visibility.

In the event of a critical security breach, system crash or loss of customer assets, the incident will be immediately detected and notified to the CMB, MASAK and KVKK. 'Corporate Communication Officer' and 'Recovery Plan Manager' are jointly responsible for such notification.

11. MONITORING METRICS AND RTO/RPO COMPLIANCE

Within the scope of the Recovery Plan, the following metrics are regularly monitored in accordance with the provisions of the CMB's Communiqué on Procedures and Principles Regarding Information Systems Management (VII-128.10) and the Communiqué on Independent Audit of Information Systems (III-62.2.b) Annex/2:

  • Recovery Time Objective (RTO): 6 hours
  • Data Recovery Point (RPO): 15 minutes
  • Exercise success rate: close to 100%
  • Average detection time of automatic warning systems: < 2 minutes
  • Initial notification time to the relevant regulator: maximum 30 minutes

12. INTEGRATION AND COHERENCE BETWEEN POLICIES

The Recovery Plan is integrated with the Company's Information Security Policy, Business Continuity Plan, Backup Policy and Emergency Response Protocols. These documents are reviewed in coordination at least once a year and the consistency between them is audited within the scope of internal audit.

13. ENFORCEMENT

This Recovery Plan shall enter into force on 25.03.2025. The Board of Directors of the Company is responsible for the preparation and approval of the Plan. The plan must be reviewed at least once a year. During the period it remains in force, studies are carried out in coordination with the Information Technologies and Risk Management Unit to update it according to changing conditions.