Cybersecurity is a fundamental priority for Italtherm. This policy establishes the commitment of the Management to adopt a “Cybersecurity Model”, aimed at protecting the company’s IT systems, as well as the information contained therein, from internal and external threats. In developing the Model, Italtherm avails itself of the support of a company specialized in consultancy services in the field of “Data Governance & Protection”, which collaborates in the certification of what is attested in this document. In developing the Model, Italtherm identifies EU Directive 2022/2555 “NIS2” as the reference regulatory framework, certifying its full implementation.
The adoption of an effective “Cybersecurity Model” pursues the following objectives:
Italtherm undertakes to adopt adequate and proportionate technical, operational and organizational measures to manage the risks posed to the security of IT and network systems, used in its business or in the provision of its services, as well as to prevent or minimize the impact of incidents for the recipients of its services. The measures adopted are based on a multi-risk approach, aimed at protecting IT systems and include:
Italtherm will provide regular training and updates on cybersecurity to all employees, to ensure awareness and understanding of Cybersecurity best practices. Italtherm will select suppliers who guarantee adequate security standards, periodically monitoring their level of reliability.
The application of this policy will be regularly monitored and, if necessary, integrated in the event of significant changes in cyber threats or regulatory requirements. The Management is therefore committed to continuously improving its Cybersecurity posture, to protect its resources, consolidate the trust of stakeholders and contribute to the development, security and progress of the company.