Skip to main content
Co-Founder, CTO and Head of Cybersecurity

Ali Recai Yekta

Ali Recai Yekta has worked as a penetration tester for more than 15 years, across classic IT security and OT security alike. His work runs from network infrastructure and web applications to systems such as power grids, rail and automotive. As co-founder and CTO of Yekta IT he builds security operations centres for operators of critical infrastructure, runs OT penetration tests, and develops the detection logic, use cases, playbooks and incident exercises that keep them running.

Ali Recai Yekta

For research and training, Yekta IT runs its own OT lab with physical demonstrators for vehicle and rail systems and a training environment built on real industrial protocols. In the FINESSE joint project he led the development of the VATT&EK framework.

Education and certifications

Education

  • M.Sc. IT Security (Networks and Systems), Ruhr University Bochum
  • B.Sc. Computer Science, TU Dortmund

Certifications

  • Offensive Security Certified Professional (OSCP), OffSec
  • Offensive Security Experienced Penetration Tester (OSEP), OffSec
  • Offensive Security Web Expert (OSWE), OffSec
  • Certified Red Team Operator (CRTO), Zero-Point Security

Academic publications

  • Yekta, A. R., Spychalski, D., Yekta, C., Heinrich, M., Krauß, C., Katzenbeisser, S. (2026). Towards a Holistic and Multi-modal Vehicle Security Monitoring. In: Critical Information Infrastructures Security. CRITIS 2025. Lecture Notes in Computer Science, vol. 16291. Springer, Cham. pp. 143–162. DOI: 10.1007/978-3-032-19540-1
  • Yekta, A. R., Loza, N., Gramm, J., Schneider, M. P., Katzenbeisser, S. (2025). UDS Attack Taxonomy: Systematic Classification of Vehicle Diagnostic Threats. IEEE Conference on Communications and Network Security (CNS), France.
  • Yekta, A. R., Loza, N., Gramm, J., Schneider, M. P., Katzenbeisser, S. (2025). From ECU to VSOC: UDS Security Monitoring Strategies. SECURWARE, Barcelona.
  • Yekta, A. R., Spychalski, D., Yekta, E., Yekta, C., Katzenbeisser, S. (2023). VATT&EK: Formalization of Cyber Attacks on Intelligent Transport Systems – a TTP based approach for Automotive and Rail. Proceedings of the 7th ACM Computer Science in Cars Symposium (CSCS). DOI: 10.1145/3631204.3631867

Trade articles

  • Yekta, A. R. (2025). Multi-modales Intrusion Detection System: Angriffserkennung für Mobilitätssysteme. Signal+Draht.
  • Yekta, A. R. (2024). KI auf Schienen – Beschleunigung der digitalen Transformation des Bahnbetriebs. Signal+Draht, 116(4), 15–21.
  • Yekta, A. R., Yekta, E. (2008). File Inclusion Attacks. Hakin9, 4/2008.
  • Yekta, A. R. (2008). Advanced SQL Injection in MySQL. Hakin9.
  • Yekta, A. R. (2008). Einführung und Sicherheit von Sessions. PHP Solutions.
  • Yekta, A. R. (2008). Regex – Reguläre Ausdrücke. PHP Solutions.
  • Yekta, A. R. (2007). File Inclusion Attacken. Hakin9.

Talks (selection)

  • Angewandte OT-Security-Forschung: Praxiserfahrungen aus KRITIS-Sektoren in Bahn & Energie. Forschungstag Cybersicherheit NRW, eurobits e.V. (2026)
  • Wenn die Anlage steht: OT-Angriffe erkennen, verstehen, verhindern. Security meets OT, eco – Verband der Internetwirtschaft, Cologne. (05/2025)
  • Fahrzeughacking: Hollywood vs. Realität. Nationale Konferenz IT-Sicherheitsforschung, Berlin. (03/2025)
  • Moderne Technologien & OT-Sicherheit. Transferreihe Industrielle Sicherheit – OT-Sicherheit für IT-Verantwortliche, Wirtschaftsförderung Kreis Soest. (01/2025)
  • OT-Sicherheit für KMUs: Die unsichtbare Gefahr in der Industrie. IT-Sicherheitstag NRW, Dortmund. (12/2024)
  • Social Engineering – die einfachste Form, eine medizinische Einrichtung zu hacken. Zukunftskongress Bochum. (06/2024)
  • VATT&EK: Formalization of Cyber Attacks on Intelligent Transport Systems. ACM CSCS. (12/2023)
  • Wie werden KMUs angegriffen und wie kann ich mich schützen? Digitale Woche Dortmund. (09/2023)
  • Security Operations Center for Multi Modal Transport Systems. ARES, Vienna. (08/2022)