Cybersecurity
Digital Transformation and Business Resilience at Aleatica
At Aleatica, since defining and implementing our cybersecurity strategy in 2022, we have evolved towards a maturity model inspired by international standards such as the NIST Cybersecurity Framework (NIST-CSF).
This has substantially strengthened our resilience and business continuity. By migrating to cloud data centres, centralising our technology infrastructure, and integrating Aleatica Labs and advanced analytics solutions, we have optimised our decision-making.
Adoption of the NIST 2.0 framework — 2025
In 2025, we updated our Cybersecurity Framework by adopting requirements and controls from NIST version 2.0, which includes specific guidelines on the supply chain and artificial intelligence.
Unlike version 1.1, which had a primarily technical focus, the new version places risk management and governance at its core. Cybersecurity is no longer solely an IT concern; it is now recognised as a strategic risk for the entire business.
Senior management encourages active participation in decision-making, the definition of legal strategy, and comprehensive risk management.
We establish clear policies, roles, and responsibilities, and strengthen the risk management strategy throughout our entire supply chain.
In Italy, the NIS 2 Directive has already been transposed, and in our organisation, we are addressing its requirements through our current framework. In Spain, although transposition is still pending, the current National Security Framework (Esquema Nacional de Seguridad, ENS) already covers a large part of the requirements. Additionally, we published a policy on the responsible use of AI and a process for screening and classifying AI systems based on their risk level.
Cybersecurity governance
SCC
Strategic Cybersecurity Committee
Cybersecurity Officer
TCIT
Tactical Cybersecurity Incident Team
CIRG
Cybersecurity Incident Response Group
Chief Executive Officer (CEO)
Legal & Information Security Services
Information Security (CISO / DPO)
Information Security Leads in the Business Units
Business Unit Employees
Cybersecurity Lead
2025 key management activities
Contingency and continuity plans
We validated compliance with Disaster Recovery Plan (DRP) management across all Business Units and corporate offices. We have procedures and matrices that classify the severity and impact of incidents.
Vulnerability analysis
Through an expert provider, we strengthened our resilience with incident response, attack simulation, infrastructure defence, and threat identification services. We conducted ethical penetration testing.
2025 cybersecurity training
We ran a webinar, three short videos and four workshops on cybersecurity, attended by 1,088 team members (74.0% participation rate) for a total of 4,051 hours of training. 99.99% of individuals in non-operational administrative roles successfully completed a cybersecurity certification course.
Cybersecurity performance indicators
|
Indicator
|
2022
|
2023
|
2024
|
2025
|
|---|---|---|---|---|
|
Cybersecurity events
|
205
|
175
|
219
|
602
|
|
Cybersecurity incidents
|
3
|
2
|
2
|
10
|
|
Data breaches
|
0
|
0
|
0
|
2
|
|
Customers and staff affected by a data breach
|
0
|
0
|
0
|
5
|
|
Total amount of fines/penalties for incidents (€)
|
0
|
0
|
0
|
0
|
Cybersecurity events
No Data Found
Cybersecurity events
No Data Found
Cybersecurity incident notification process
1
2
3
Cybersecurity contingency/business continuity plans
We have contingency plans and cybersecurity incident response procedures that identify critical business processes and establish manual or technological mechanisms to reactivate them in the event of disruptions. These mechanisms are defined in the Disaster Recovery Plans (DRPs) for each Business Unit and each corporate office, and they must be reviewed and approved at least once a year.
For cybersecurity incidents, we have procedures and matrices in place that classify the severity and impact, define the response, the type of report, the audience to be notified, and the logging requirements in the Systems Help Desk (MAS). These tools are tested and fine-tuned in response to any relevant threat or incident.
Cybersecurity vulnerability analysis
Through an expert provider, we strengthened our cybersecurity resilience with services such as incident response, attack simulation, infrastructure defence, and threat identification. We conducted ethical penetration testing to identify vulnerabilities and enhance the technical skills of our IT teams.
Throughout 2025, these services enabled us to identify risks and areas for improvement, implement and optimise IT security controls, and enhance Aleatica’s incident detection and response capabilities.
Additionally, each quarter, we proactively analyse vulnerabilities in the technological resources managed by the IT and Systems departments, including email, corporate and business websites, servers, antivirus software, and digital credential management.