Istanbul as a Regional Internet Hub: Türkiye’s Peering Gap and the Reform Window 2026

Istanbul as a Regional Internet Hub: Türkiye’s Peering Gap and the Reform Window 2026


An internet packet sent from Istanbul to Baku often travels this route: Istanbul → Izmir → Italy → Luxembourg → Austria → Bulgaria → Sweden → Azerbaijan. The shortest path between two neighbouring countries runs through six European nations and back. This is not a technical constraint. It is the result of missing peering relationships and an absent regulatory framework. This is what prevents Türkiye from becoming a regional internet hub.

Traffic between Türkiye and its neighbours — Georgia, Armenia, Iraq — largely routes through Europe and back. Even regional traffic does not stay regional. This is not a technical constraint. It is the result of missing peering relationships and an absent regulatory framework.

On 6 April 2026, the Turkish Network Operators Group (TRNOG) held its annual meeting in Istanbul under the title “Connection Point: Istanbul.” The gathering brought together network operators, content providers, data centre operators, and policy professionals in a rare convergence of technical and regulatory discussion. This article draws on those presentations and panel debates to map the opportunity — and the reform steps needed to seize it.

I. Geography Is Not Destiny — Economics Is

The core insight from TRNOG “Connection Point: Istanbul” is deceptively simple: internet traffic does not follow geography. It follows economics.

Every major router vendor — Cisco, Arista, Juniper, Nokia — implements the same BGP (Border Gateway Protocol) path-selection algorithm. The hierarchy runs through local preference, AS-path length, MED values, and IGP cost. Physical distance does not appear in the list. A packet chooses its route based on how operators have configured their peering relationships, not on which path is geographically shortest.

But the claim of “technical neutrality” stops being accurate at this point. The algorithm itself may be neutral. The parameters fed into it are not. Local preference values, AS-path lengths, MED settings — all are manually configured by operators, and those configurations reflect commercial agreements, transit payments, and market power.

A US content network paying a European transit provider raises that provider’s local preference value. A Turkish operator without a direct peering agreement with the same content network will see its traffic routed via Europe — not because geography demands it, but because the parameters were set that way.

The top-tier internet backbone — AT&T, Lumen, NTT and others — peers with each other settlement-free because traffic volumes are balanced. Smaller networks pay transit fees to join. “Technical neutrality” describes the algorithm’s indifference to geography; it says nothing about how market power is embedded in the architecture at a different layer.

RIPE Atlas measurements presented at the meeting made this concrete. Two-thirds of packets sent from Türkiye to Georgia do not transit Türkiye — they use European routes. Connections from Türkiye to Azerbaijan show measured latencies of 124ms in some samples, routed via Frankfurt. Only one in four packets from Türkiye to Iraq transits Türkiye directly. Armenia shows a similar pattern.

DE-CIX Senior Peering Manager Bernd Spiess put it plainly in his concluding slide — yellow background, black letters: “Make Türkiye an IP Hub first.” This is not a criticism. It is an accurate diagnosis.

Türkiye’s problem is not infrastructure absence. It is the absence of the economic and policy ecosystem that shapes routing decisions over that infrastructure.

Internet traffic flows according to economic relationships, not geographic reality. Türkiye is missing from that chain at every link. Until those relationships are restructured — through peering policy, regulatory incentives, and legal frameworks — packets will continue to route through Stockholm. This means Türkiye’s geographic advantage is not translating into economic value.

II. The September 2025 Cable Outages: What the Data Actually Shows

On 6 September 2025, SMW-4 and IMEWE were severed in the Red Sea near Jeddah; FALCON and EIG were also reported as affected. Latency increases hit Asia-Europe routes across the board. Microsoft Azure was among the few operators to publicly acknowledge higher latency for traffic transiting the Middle East — most other major cloud providers remained silent.

What happened at the internet exchange points? LINX Jeddah, SAIX, Equinix Muscat, UAE-IX Dubai — none showed a dramatic traffic spike at the moment of disruption. As Spiess observed: “Nothing spectacular.”

The instinctive reading — that IXPs proved irrelevant during the crisis — is wrong. The correct reading is more nuanced: traffic redistribution did not appear in aggregate IXP figures because it happened at the level of individual autonomous systems and operator decisions. The system worked. What drove it was not the IXP itself but routing policy.

Frankfurt tells the story directly. Fifty-three networks reorganized their outbound traffic within hours of the disruption. One major content network shifted traffic from Frankfurt to Marseille because working submarine capacity existed there. DE-CIX Istanbul absorbed approximately +50 Gbps of additional traffic from 8 September — reaching an all-time peak of 530 Gbps. A small shift, but a real one.

The question this raises is straightforward: why did Istanbul capture only a fraction of the potential redistribution? Spiess offered a practical constraint: a link above 70% utilization is effectively a dead link; at 100% it cannot absorb additional traffic without degrading existing flows. Türkiye’s backup headroom at the moment of the outages is itself a policy question.

A well-peered Istanbul with sufficient reserve capacity would have been the natural absorption point for Caucasus and Middle East traffic during the disruption. It was not. That gap is addressable — but only through the structural reforms discussed below.

III. The Gulf Security Variable

A new dimension entered the analysis in early 2026. According to analyst assessments, [attacks attributed to Iran in March 2026 reportedly targeted AWS data centres in the UAE, with a third facility in Bahrain also reported as damaged. If confirmed, this would represent the first instance of commercial data infrastructure being deliberately targeted in an armed conflict.

The immediate effect has been to force a re-evaluation of Gulf investment risk. Analysts are already [discussing capacity migration to less exposed locations. Global hyperscalers with large AI infrastructure commitments in the region are reassessing their geographic concentration.

Türkiye’s physical security profile — NATO member, stable land border environment for fibre transit, established data centre industry — is directly relevant to this reassessment. The question is whether Türkiye’s regulatory environment and peering ecosystem are ready to receive investment that the Gulf disruption may redirect. Currently, the answer is only partially yes.

IV. How Modern Content Networks Actually Work

Meta’s Edge Strategy Manager Mehmet Tik presented data that reframes the entire peering debate. Meta operates more than 25 origin data centre regions, over 80 edge points of presence, and more than 7,500 in-network appliances globally, serving 3.9 billion monthly users. Target network latency: 25 milliseconds. Istanbul infrastructure is being expanded to Ankara and Izmir.

The architecture is built around a simple principle: terminate every user session at the closest possible point. Meta Network Appliances deployed inside ISP networks handle static content. Edge points of presence handle dynamic sessions. Transit — routing through third-party networks — is, in the words of the presentation, “last resort, unless we don’t peer.”

This restructures the policy argument. The question is not whether Türkiye has an IXP. The question is whether Türkiye’s operators have established the bilateral peering relationships that cause Meta, Google, Cloudflare, and other major content networks to route traffic locally rather than through Frankfurt or Amsterdam. Meta’s IXP policy is explicit: target two IXPs per metro location; fewer than one means the ecosystem needs growth, more than two means consolidation.

The direction of travel in the commercial internet is clear: large content networks want direct relationships with the networks that serve their users. They are moving away from route-server peering toward bilateral agreements. Türkiye’s regulatory framework needs to make that possible at scale — and to incentivise domestic operators to participate.

V. Routing Security: From Technical Option to Legal Obligation

RIPE NCC’s Emine Akay and Andres Lerma presented two tools that move routing security from optional to obligatory in sophisticated regulatory frameworks.

RPKI (Resource Public Key Infrastructure) provides cryptographic validation of IP address and Autonomous System number ownership, enabling Route Origin Authorisation — the assertion that only a specified AS may announce a given IP block. Türkiye’s major operators have begun partial implementation, but adoption rates lag global averages significantly. Route Origin Validation of incoming announcements is even more limited.

ASPA (Autonomous System Provider Authorisation) builds a layer above RPKI. Where RPKI answers “does this AS own that IP block?”, ASPA answers “is this AS legitimately using this provider for transit?” — enabling detection of route leaks and BGP hijacks.

RIPE NCC moved ASPA to production in December 2025; Cloudflare has begun global deployment. ASPA remains an IETF draft standard with limited router support — early-adopter territory, but the trajectory is clear.

The regulatory implication is significant. A BGP hijack attack can redirect user traffic to an attacker’s network — a personal data breach under GDPR equivalents, a critical infrastructure event under NIS2. A route leak can send sensitive traffic through unintended third-party networks.

The EU’s NIS2 directive is already imposing routing security obligations on critical infrastructure operators. Türkiye’s [Law No. 7545 on Cybersecurity establishes a critical infrastructure framework, but contains no specific RPKI adoption timeline or routing security mandate. That gap will become increasingly visible as EU-aligned operators set baseline requirements for their peering partners.

VI. The IXP Ecosystem: What the Panel Revealed

The afternoon panel — DE-CIX’s Bülent Şen, Erstream’s Uğur Kalaba, Turknet’s Rana Karaküçük, and Mars Data Center’s Selçuk Saraç — produced the clearest articulation of Türkiye’s structural regulatory gaps.

The most fundamental problem: Turkish telecommunications law does not define peering as a distinct concept. Law No. 5809 and its implementing Access and Interconnection Regulation govern interconnection — a paid, regulated access relationship.

Peering — the settlement-free bilateral exchange of traffic between networks — is legally invisible. There are no definitions, no obligations, and no incentive structures tied to it. This is not a minor drafting gap. It means the entire regulatory apparatus that could drive domestic traffic exchange simply does not exist.

The panel identified four specific areas requiring action:

Traffic classification. Which traffic categories must remain within Turkish networks? What constitutes critical traffic for routing purposes? Neither question has a regulatory answer. Karaküçük noted that traffic exits Türkiye unnecessarily and returns — a symptom of absent domestic routing policy, not technical incapacity.

The peering obligation gap. Saraç argued directly: peering must be defined, and major operators must be subject to IXP participation or peering obligations. The “yer sağlayıcı” (hosting provider) concept has been stretched beyond its useful meaning. Legal definitions need reconstruction.

The price paradox. Kalaba identified a tension that regulation must resolve: data centres need higher returns to invest, while peering ecosystem development requires lower access costs. Markets left to themselves have not resolved this. Regulatory intervention — through pricing frameworks, licence conditions, or investment obligations — is the only mechanism available.

The TNAP lesson. TNAP (Türkiye Network Altyapı Platformu) is a peering platform through which alternative ISPs exchange traffic directly, bypassing the Türk Telekom backbone, without charging each other for that traffic. It exists and operates — but Türk Telekom group is outside it, regulators do not classify such platforms as mandatory elements, and only a limited share of domestic traffic passes through it.

The lesson is not that peering platforms do not work in Türkiye. The lesson is that without participation obligations, dominant operators stay out, and the platform’s reach remains narrow. TRNOG is now working toward a community-owned, not-for-profit IXP. That effort needs a corresponding regulatory framework to make participation attractive — and for major operators, obligatory.

VII. DDoS: The Organizational Gap

Gökhan Kocaova (Loddos) and Cihan Yüceer (Barikat) presented DDoS trend data that reframes the security dimension. In a single six-month period, 6,867 DDoS attacks targeted Turkish infrastructure, with an average attack duration of 76 minutes.

Attack vectors are increasingly multi-layer: volumetric floods combined simultaneously with application-layer attacks. IoT botnets now incorporate home user devices whose owners have no awareness of participation.

The technical defence architecture — CDN layer, network layer, application layer, operational layer — is well understood. The gap identified was organizational: response runbooks must exist before an incident, not be created during one. This is a governance finding, not a technical one.

The regulatory implication: Law No. 7545 establishes cybersecurity obligations for critical infrastructure operators but does not address IoT device security standards or manufacturer liability for botnet-capable devices. As IoT penetration increases, this gap will generate increasing systemic risk.

VIII. IPv6: The Regulatory Inertia Problem

Türk Telekom’s Tahsin Türkdoğan presented IPv6 adoption data that illustrates a broader pattern. Global IPv6 adoption stands at approximately 45% Türkiye is at roughly 20%, placing it around 100th globally. Only 58% of the world’s top 1,000 websites support IPv6.

The technical case for transition is not disputed. IPv4 address exhaustion is real; secondary market prices have reached $50-60 per address. CGNat allows continued IPv4 operation but at increasing complexity and cost. The transition question is not whether but when — and who accelerates it.

The comparative regulatory evidence is instructive. Brazil’s regulator Anatel mandated IPv6 support for all service providers in 2015; adoption reached 52% within a few years. The EU has used public sector procurement requirements and policy guidance to drive adoption. Türkiye has used neither mechanism. The result is predictable: a market left to its own pace moves at that pace.

The pattern here — technical solution available, private sector capable, regulatory framework absent — recurs across every topic addressed at TRNOG 2026.

IX. Three Questions for Regulators

The TRNOG discussions converge on three regulatory gaps that, if addressed, would materially shift Türkiye’s position in regional internet infrastructure.

When will peering be legally defined and obligated? The absence of peering as a distinct legal concept in Law No. 5809 is the foundational gap. Without definition, there can be no obligation, no incentive structure, and no enforcement mechanism. Operators with significant market power should be subject to IXP participation or bilateral peering requirements. The EU’s access and interconnection framework provides a working reference model.

How will the IXP ecosystem be supported? Tax treatment, licensing simplification, and investment incentives are all available instruments. The TNAP experience provides the key design principle: infrastructure without participation obligations produces narrow coverage. Policy support must accompany infrastructure investment — and for dominant operators, participation must be required, not merely encouraged. The TRNOG community-IXP initiative represents the right institutional approach; it needs the regulatory framework to match.

When will routing security become a compliance requirement? Law No. 7545 provides the critical infrastructure framework. Secondary regulation should specify RPKI adoption timelines and Route Origin Validation requirements for operators above a defined scale threshold. The NIS2 parallel is directly applicable — and as EU-aligned operators set baseline routing security requirements for peering partners, Turkish operators without RPKI compliance will face commercial pressure regardless of regulatory action.

Conclusion: Türkiye’s Internet Hub Moment

The picture that emerges from TRNOG 2026 is not one of irreversible disadvantage. It is one of unrealized potential at a moment when external circumstances are shifting in Türkiye’s favour.

The cable outage data shows that Istanbul can capture additional regional traffic when the routing ecosystem supports it — the +50 Gbps signal from September 2025 is small but real. Meta is expanding its Istanbul edge infrastructure to Ankara and Izmir. TRNOG is building toward a community-owned IXP. Global hyperscalers are reassessing Gulf infrastructure concentration. IPv6 transition is creating pressure for network modernization across the region.

The technical knowledge exists. The private sector appetite exists. What remains is the regulatory architecture to align incentives: peering definitions, IXP obligations, routing security timelines, traffic classification frameworks.

This transformation will not happen on its own. The current structure of economic incentives, regulatory gaps, and legal ambiguity will reproduce itself — and deepen as traffic volumes increase — unless it is deliberately changed. The reform window is open. The question is whether Türkiye’s regulatory institutions will move through it.

—

 

Gökhan Candoğan is an attorney practising telecommunications and administrative law in Ankara. He is lawyer of TELKODER and serves on the TRNOG Audit Board. This article draws on presentations and panel discussions at the TRNOG “Connection Point: Istanbul” meeting held on 6 April 2026. The author thanks DE-CIX (Bernd Spiess), Meta (Mehmet Tik), RIPE NCC (Emine Akay, Andres Lerma), and the IXP panel participants for their public contributions to the discussion.