Cybersecurity

Digital Transformation and Business Resilience at Aleatica

At Aleatica, since defining and implementing our cybersecurity strategy in 2022, we have evolved towards a maturity model inspired by international standards such as the NIST Cybersecurity Framework (NIST-CSF).

This has substantially strengthened our resilience and business continuity. By migrating to cloud data centres, centralising our technology infrastructure, and integrating Aleatica Labs and advanced analytics solutions, we have optimised our decision-making.

Adoption of the NIST 2.0 framework — 2025

In 2025, we updated our Cybersecurity Framework by adopting requirements and controls from NIST version 2.0, which includes specific guidelines on the supply chain and artificial intelligence.

Unlike version 1.1, which had a primarily technical focus, the new version places risk management and governance at its core. Cybersecurity is no longer solely an IT concern; it is now recognised as a strategic risk for the entire business.

Senior management encourages active participation in decision-making, the definition of legal strategy, and comprehensive risk management.

We establish clear policies, roles, and responsibilities, and strengthen the risk management strategy throughout our entire supply chain.

In Italy, the NIS 2 Directive has already been transposed, and in our organisation, we are addressing its requirements through our current framework. In Spain, although transposition is still pending, the current National Security Framework (Esquema Nacional de Seguridad, ENS) already covers a large part of the requirements. Additionally, we published a policy on the responsible use of AI and a process for screening and classifying AI systems based on their risk level.

Cybersecurity governance

The governance structure is led by the Chief Executive Officer. The Executive Department of Legal Services and Information Security includes the Information Security Department. The Chief Information Security Officer (CISO) takes on specific leadership in cybersecurity, collaborating with the Data Protection Officer (DPO). At the Business Unit level, directors or managers, supported by their IT teams, implement and monitor policies. We operate four support teams at different levels, from Senior Management to operational staff.

SCC
Strategic Cybersecurity Committee

Cybersecurity Officer

TCIT
Tactical Cybersecurity Incident Team

CIRG
Cybersecurity Incident Response Group

Chief Executive Officer (CEO)

Legal & Information Security Services

Information Security (CISO / DPO)

Information Security Leads in the Business Units

Business Unit Employees

Cybersecurity Lead

2025 key management activities

Contingency and continuity plans

We validated compliance with Disaster Recovery Plan (DRP) management across all Business Units and corporate offices. We have procedures and matrices that classify the severity and impact of incidents.

Vulnerability analysis

Through an expert provider, we strengthened our resilience with incident response, attack simulation, infrastructure defence, and threat identification services. We conducted ethical penetration testing.

2025 cybersecurity training

We ran a webinar, three short videos and four workshops on cybersecurity, attended by 1,088 team members (74.0% participation rate) for a total of 4,051 hours of training. 99.99% of individuals in non-operational administrative roles successfully completed a cybersecurity certification course. 

100% of the Business Units increased their cybersecurity maturity level or at least maintained it.

Cybersecurity performance indicators

Indicator
2022
2023
2024
2025
Cybersecurity events
205
175
219
602
Cybersecurity incidents
3
2
2
10
Data breaches
0
0
0
2
Customers and staff affected by a data breach
0
0
0
5
Total amount of fines/penalties for incidents (€)
0
0
0
0

Cybersecurity events

Cybersecurity events

Cybersecurity incident notification process

1

Internal or external employees who suspect or are the target of any cybersecurity threat or incident must report it to the Systems Help Desk (Mesa de Ayuda de Sistemas, MAS) via email or phone call.

2

Each cybersecurity event or incident is assigned a ticket number, which the department uses to investigate and resolve the issue.

3

If a potential violation of data protection guidelines is identified or suspected, the Data Protection Department is notified so that they can take action within their management and responsibility.

Cybersecurity contingency/business continuity plans

We have contingency plans and cybersecurity incident response procedures that identify critical business processes and establish manual or technological mechanisms to reactivate them in the event of disruptions. These mechanisms are defined in the Disaster Recovery Plans (DRPs) for each Business Unit and each corporate office, and they must be reviewed and approved at least once a year.

In 2025, we validated compliance with DRP management across all Business Units and in each corporate office.

For cybersecurity incidents, we have procedures and matrices in place that classify the severity and impact, define the response, the type of report, the audience to be notified, and the logging requirements in the Systems Help Desk (MAS). These tools are tested and fine-tuned in response to any relevant threat or incident.

Cybersecurity vulnerability analysis

Through an expert provider, we strengthened our cybersecurity resilience with services such as incident response, attack simulation, infrastructure defence, and threat identification. We conducted ethical penetration testing to identify vulnerabilities and enhance the technical skills of our IT teams.

Throughout 2025, these services enabled us to identify risks and areas for improvement, implement and optimise IT security controls, and enhance Aleatica’s incident detection and response capabilities.

Additionally, each quarter, we proactively analyse vulnerabilities in the technological resources managed by the IT and Systems departments, including email, corporate and business websites, servers, antivirus software, and digital credential management.