<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GRI-418 Archives - SustainCase - Sustainability Magazine</title>
	<atom:link href="https://sustaincase.com/category/gri-standards/gri-418/feed/" rel="self" type="application/rss+xml" />
	<link>https://sustaincase.com/category/gri-standards/gri-418/</link>
	<description>Insights on how you can protect the environment, maintain and increase the value of your company, through a structured CSR/Sustainability process with the use of the GRI Standards. Learn how Today&#039;s Best-Run Companies are achieving Economic, Social, and Environmental Success - and How You Can Too...</description>
	<lastBuildDate>Fri, 03 Mar 2023 11:47:18 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>
	<item>
		<title>Case study: How Mediclinic promotes information security</title>
		<link>https://sustaincase.com/case-study-how-mediclinic-promotes-information-security/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Wed, 15 Sep 2021 06:06:46 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Healthcare Services]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[Mediclinic]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12898</guid>

					<description><![CDATA[<p>Mediclinic is an international private healthcare services group established in South Africa in 1983, with divisions in Switzerland, Southern Africa (South Africa and Namibia) and the UAE. , to conduct its business in a safe and secure manner. This case study is based on the 2020 Sustainable Development Report by Mediclinic published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-mediclinic-promotes-information-security/">Case study: How Mediclinic promotes information security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Mediclinic is an international private healthcare services group established in South Africa in 1983, with divisions in Switzerland, Southern Africa (South Africa and Namibia) and the UAE. <strong>Effective information and cyber security is paramount for Mediclinic</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=Effective%20information%20and%20cyber%20security%20is%20paramount%20for%20Mediclinic&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-mediclinic-promotes-information-security%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a>, to conduct its business in a safe and secure manner.</p>
<p><strong>This case study is based on the</strong> <strong>2020</strong> <strong>Sustainable Development Report </strong><strong>by</strong><strong> Mediclinic </strong><strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/79636/" target="_blank" rel="noopener"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p>With operations spanning multiple geographical areas and a global data network required in support of such scale, the protection of information assets is a top priority for Mediclinic. In order to promote information security Mediclinic took action to:</p>
<ul>
<li>implement a Group InfoSec programme</li>
<li>promote data privacy</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img fetchpriority="high" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="(max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) Mediclinic has identified;</li>
<li>How Mediclinic proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by Mediclinic to promote information security</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?             </strong></p>
<p>In its 2020 Sustainable Development Report Mediclinic identified a range of material issues, such as climate change, human rights, supply chain management, employee wellness and safety, waste and hazardous waste management. Among these, promoting information security stands out as a key material issue for Mediclinic.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards               </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups Mediclinic engages with:</strong></p>
<p>To identify and prioritise material topics Mediclinic engaged with its stakeholders through the following channels:<strong> </strong></p>
<table width="479">
<tbody>
<tr>
<td width="135"><strong>Stakeholder Group</strong></td>
<td width="344"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="135">Clients</p>
<p>&nbsp;</td>
<td width="344">·      Press Ganey® patient experience index surveys</p>
<p>·      Disclosure of clinical performance results</p>
<p>·      Systematic patient rounds during hospital stay</p>
<p>·      24-hour helplines</p>
<p>·      Health awareness days</p>
<p>·      Brochures and magazines</p>
<p>·      Websites and blogs offering health-related information</p>
<p>·       Social media</p>
<p>·      Client alliance programmes</td>
</tr>
<tr>
<td width="135">Communities</p>
<p>&nbsp;</td>
<td width="344">·      Corporate social responsibility (‘CSR’) initiatives</p>
<p>·      Supporting employee volunteer initiatives</p>
<p>·      Participation at national level in health training and education</p>
<p>·      Public-private initiatives and joint ventures at Hirslanden, Mediclinic Southern Africa and Mediclinic Middle East</p>
<p>·      Participation in the Public Health Enhancement Fund (‘PHEF’) in South Africa</td>
</tr>
<tr>
<td width="135">Employees and potential applicants</p>
<p>&nbsp;</td>
<td width="344">·      Annual Gallup® employee engagement surveys</p>
<p>·      Training and development</p>
<p>·      Growth opportunities</p>
<p>·      Intranet and social media</p>
<p>·      Newsflashes and regular electronic updates</p>
<p>·      Performance reviews and formal recognition</p>
<p>·      Leadership video conferences and roadshows</p>
<p>·      Employee wellness programmes</p>
<p>·      Magazines and newsletters</p>
<p>·      Non-executive director for workforce engagement</td>
</tr>
<tr>
<td width="135">Governments and authorities</p>
<p>&nbsp;</td>
<td width="344">·      Regular meetings</p>
<p>·      Participation in conferences and seminars</p>
<p>·      Representation on industry bodies and government boards</p>
<p>·      Participation in PPPs to enable healthcare, training and research</td>
</tr>
<tr>
<td width="135">Healthcare insurers</td>
<td width="344">·      Regular meetings regarding possible cost savings, clinical quality and healthcare delivery improvements</p>
<p>·      Annual tariff negotiations in a fair and transparent manner</td>
</tr>
<tr>
<td width="135">Industry associations</p>
<p>&nbsp;</td>
<td width="344">·      Membership of industry associations and representation on governing bodies</p>
<p>·      Participation in research commissioned by associations</p>
<p>·      Participation in conferences</td>
</tr>
<tr>
<td width="135">Industry partners</p>
<p>&nbsp;</td>
<td width="344">·      Direct engagement based on industry knowledge and market reputations</p>
<p>·      Cooperation and PPPs</p>
<p>·      Introductions through advisors</p>
<p>·      Industry conferences and events</td>
</tr>
<tr>
<td width="135">Investors</p>
<p>&nbsp;</td>
<td width="344">·      Investor Relations department</p>
<p>·      Shareholder annual general meetings</p>
<p>·      Financial results reporting and presentations</p>
<p>·      Investor meetings, roadshows and conferences</p>
<p>·      Operational site visits</p>
<p>·      Stock exchange announcements</p>
<p>·      Sell-side analyst and salesforce meetings</p>
<p>·      Corporate website</td>
</tr>
<tr>
<td width="135">Media</td>
<td width="344">·      Media releases</p>
<p>·      Press conferences</p>
<p>·      Financial results reporting and presentations</p>
<p>·      Interviews and responses to media enquiries</p>
<p>·      Paid advertisements</p>
<p>·      Monitoring industry-related news and proactive response</p>
<p>·      Social media</p>
<p>·      The Future of Healthcare blog</td>
</tr>
<tr>
<td width="135">Medical practitioners</td>
<td width="344">·      Regular meetings</p>
<p>·      Participation in hospital clinical committees</p>
<p>·      Continuous professional education events</p>
<p>·      Electronic newsletters</p>
<p>·      Networking and know-how exchange events at Hirslanden</p>
<p>·      Dedicated medical practitioner portals at Hirslanden and Mediclinic Southern Africa</p>
<p>·      Medical practitioner participation in hospital boards</p>
<p>·      Biannual engagement events at Mediclinic Middle East</p>
<p>·      Annual Research Day at Mediclinic Middle East</td>
</tr>
<tr>
<td width="135">Suppliers</td>
<td width="344">·      Regular meetings and business reviews</p>
<p>·      Contract negotiations and management post-signature</p>
<p>·      Electronic product approval processes</p>
<p>·      Product demonstrations and evaluations</p>
<p>·      Training on product specifications</p>
<p>·      Attendance at trade fairs</p>
<p>·      Factory visits</p>
<p>·      Annual Modern Slavery Act due diligence questionnaire</td>
</tr>
</tbody>
</table>
<p><strong>What actions were taken by</strong><strong> Mediclinic </strong><strong>to</strong> <strong>promote information security</strong><strong>?</strong></p>
<p>In its 2020 Sustainable Development Report Mediclinic reports that it took the following actions for promoting information security:</p>
<ul>
<li><strong>Implementing a Group InfoSec programme</strong></li>
<li>Mediclinic implements an elaborate Group InfoSec programme to optimally manage, monitor, detect and respond to InfoSec. The Group InfoSec Committee is represented by all divisions through dedicated Divisional Information Security Officers, while the proceedings of this committee are governed and informed through information security best practices sourced from several internationally acclaimed information and cyber security institutions. The Group InfoSec programme is based on the following guiding principles:
<ul>
<li>Adopting a risk-based approach towards cyber threats, which considers the likelihood of any risk materialising as well as its potential impact and measures for prevention and detection.</li>
<li>Expanding responsibility for cyber security beyond ICT to the whole organisation.</li>
<li>Ensuring end-to-end security across business processes, for mobile workers and teams as well as for data flows across geographic borders.</li>
<li>Implementing cyber-security-by-design, i.e. provision for effective protection against cyber threats from the outset when ICT capabilities are acquired or developed.</li>
</ul>
</li>
</ul>
<ul>
<li><strong>Promoting data privacy</strong></li>
<li>Mediclinic reaffirmed its commitment to protecting the personal data of its stakeholders by embarking on an extensive Group-wide data privacy project to align and ensure compliance with all relevant data protection legislation, as may be applicable in the various countries of operation, including the EU’s General Data Protection Regulation (‘GDPR’), widely regarded as the gold standard for data protection. The Group Privacy and Data Protection Policy has been reviewed to ensure alignment to the GDPR standards and various initiatives are underway to ensure that core components are compliant with the GDPR framework. The project has been rolled out to the entire Group to ensure that other applicable data protection legislation is also complied with, or where no such specific legislations exist (i.e. Namibia), GDPR standards are complied with as a minimum.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by Mediclinic, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to Mediclinic: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-mediclinic-promotes-information-security/">Case study: How Mediclinic promotes information security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How Alperia promotes cybersecurity</title>
		<link>https://sustaincase.com/case-study-how-alperia-promotes-cybersecurity/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Wed, 28 Jul 2021 06:06:21 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Energy Utilities]]></category>
		<category><![CDATA[Alperia]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12770</guid>

					<description><![CDATA[<p>Alperia is South Tyrol’s leading energy service provider and one of the most important sustainable-energy companies in Italy. , deals with identity management and access control systems and intervenes in the event of any attacks. This case study is based on the 2019 Sustainability Report by Alperia published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing. [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-alperia-promotes-cybersecurity/">Case study: How Alperia promotes cybersecurity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Alperia is South Tyrol’s leading energy service provider and one of the most important sustainable-energy companies in Italy. <strong>Alperia deals with cybersecurity through a dedicated structure that defines and supervises cybersecurity architectures and systems</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=Alperia%20deals%20with%20cybersecurity%20through%20a%20dedicated%20structure%20that%20defines%20and%20supervises%20cybersecurity%20architectures%20and%20systems&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-alperia-promotes-cybersecurity%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a>, deals with identity management and access control systems and intervenes in the event of any attacks.</p>
<p><strong>This case study is based on the</strong><strong> 2019 Sustainability Report by</strong> <strong>Alperia</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/79861/" target="_blank" rel="noopener"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p>In 2019, Alperia’s protection systems blocked an average of 4.000 spam emails and 6.000 malicious connection attempts every day. In order to promote cybersecurity Alperia took action to:</p>
<ul>
<li>introduce new and better performing management systems</li>
<li>renew the ISO 27001 certification</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="(max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) Alperia has identified;</li>
<li>How Alperia proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by Alperia to promote cybersecurity</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2019 Sustainability Report Alperia identified a range of material issues, such as security of supply, innovation, research and development, health and safety at work, asset integrity, energy consumption. Among these, promoting cybersecurity stands out as a key material issue for Alperia.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards               </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups </strong><strong>Alperia</strong> <strong>engages with:</strong></p>
<table width="261">
<tbody>
<tr>
<td width="261"><strong>Stakeholder Group</strong></td>
</tr>
<tr>
<td width="261">Customers</td>
</tr>
<tr>
<td width="261">Workforce</td>
</tr>
<tr>
<td width="261">Suppliers</td>
</tr>
<tr>
<td width="261">Owners and Investors</td>
</tr>
<tr>
<td width="261">Interest groups</td>
</tr>
<tr>
<td width="261">Citizens</td>
</tr>
<tr>
<td width="261">Research institutes</td>
</tr>
<tr>
<td width="261">Community</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics Alperia engaged with its stakeholders though an anonymous online survey which 176 participants answered.</p>
<p><strong>What actions were taken by</strong> <strong>Alperia</strong> <strong>to</strong> <strong>promote</strong> <strong>cybersecurity</strong><strong>?</strong></p>
<p>In its 2019 Sustainability Report Alperia reports that it took the following actions for promoting cybersecurity:</p>
<ul>
<li><strong>Introducing new and better performing management systems</strong></li>
<li>In 2019, Alperia introduced new and better performing management systems both inside and outside the Alperia world, also including Artificial Intelligence (AI) platforms. Attacks are becoming more frequent and high risk. Most are perpetrated by extremely sophisticated AI software, which is why it is necessary to use the same language in defence. In 2019, Alperia did not suffer from any significant cybersecurity incidents, but is aware of how important it is to protect yourself with increasingly sophisticated barrier systems. This is why Alperia introduced a double layer antivirus system for email and all the documents are classified according to a specific confidentiality level (public, restricted, confidential). Updating activities continue with trials of the disaster recovery plan and adoption of protection systems against ransomware threats.</li>
</ul>
<ul>
<li><strong>Renewing the ISO 27001 certification</strong></li>
<li>In 2019, Alperia renewed its ISO 27001 certification, which was extended to include even more stringent checking. This international standard recognises the group’s adoption of a secure system for the management of company information systems (IT and documentary), to monitor and reduce management costs, ensure adequate service levels and monitor and reduce the risk of possible outages. The certification is subject to an annual audit, with additional checks carried out by the group’s Internal Audit. During 2019, Alperia’s business continuity plan was also developed to be activated in the event of attacks. In compliance with the requirements of Europe’s GDPR regulation, a Data Protection Officer (DPO) was appointed external to the IT department. A new privacy-by-design procedure was developed, to be carried out at the start of each new project in order to check if it meets the standards set by privacy and GDPR legislation.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by Alperia, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to Alperia: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-alperia-promotes-cybersecurity/">Case study: How Alperia promotes cybersecurity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How Sempra Energy promotes cybersecurity</title>
		<link>https://sustaincase.com/case-study-how-sempra-energy-promotes-cybersecurity/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Fri, 23 Jul 2021 06:07:54 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Energy]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Sempra Energy]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12761</guid>

					<description><![CDATA[<p>Sempra Energy is an energy infrastructure company with 2019 revenues of $10.8 billion, investing in, developing and operating transmission and distribution infrastructure in the most attractive markets in North America. Cybersecurity at Sempra Energy is about people, processes and technology working together to protect systems, networks and programmes from digital attacks. This case study is based on the 2019 Corporate Sustainability Report by Sempra Energy published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-sempra-energy-promotes-cybersecurity/">Case study: How Sempra Energy promotes cybersecurity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Sempra Energy is an energy infrastructure company with 2019 revenues of $10.8 billion, investing in, developing and operating transmission and distribution infrastructure in the most attractive markets in North America. Cybersecurity at Sempra Energy is about people, processes and technology working together to protect systems, networks and programmes from digital attacks.</p>
<p><strong>This case study is based on the</strong><strong> 2019 Corporate Sustainability Report by</strong> <strong>Sempra Energy</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/78568/" target="_blank" rel="noopener"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p><strong>Sempra Energy is committed to dealing effectively with cybersecurity threats</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=Sempra%20Energy%20is%20committed%20to%20dealing%20effectively%20with%20cybersecurity%20threats&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-sempra-energy-promotes-cybersecurity%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a> to its energy grid, storage and pipeline infrastructure, as well as the information and systems used to operate its businesses. In order to promote cybersecurity Sempra Energy took action to:</p>
<ul>
<li>establish an information security team</li>
<li>implement an information security awareness programme</li>
<li>use an automated SPAM reporting button</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="(max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) Sempra Energy has identified;</li>
<li>How Sempra Energy proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by Sempra Energy to promote cybersecurity</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2019 Corporate Sustainability Report Sempra Energy identified a range of material issues, such as reliability, affordability, greenhouse gas emissions, public safety, disaster preparedness and response. Among these, promoting cybersecurity stands out as a key material issue for Sempra Energy.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards               </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups Sempra Energy engages with:</strong></p>
<table width="479">
<tbody>
<tr>
<td width="135"><strong>Stakeholder Group</strong></td>
<td width="344"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="135">Customers</td>
<td width="344">·      In-person meetings or phone calls</p>
<p>·      Open houses, town hall meetings</p>
<p>·      Ethics &amp; compliance helpline</p>
<p>·      Website content</p>
<p>·      Surveys</p>
<p>·      Print or social media</td>
</tr>
<tr>
<td width="135">Communities</p>
<p>&nbsp;</td>
<td width="344">·      In-person meetings or phone calls</p>
<p>·      Open houses, town hall meetings</p>
<p>·      Ethics &amp; compliance helpline</p>
<p>·      Website content</p>
<p>·      Corporate sustainability report</p>
<p>·      Facility tours</p>
<p>·      Surveys</p>
<p>·      Print or social media</td>
</tr>
<tr>
<td width="135">Employees</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      In-person meetings or phone calls</p>
<p>·      Open houses, town hall meetings</p>
<p>·      Ethics &amp; compliance helpline</p>
<p>·      Website content</p>
<p>·      Corporate sustainability report</p>
<p>·      Facility tours</p>
<p>·      Surveys</p>
<p>·      Print or social media</td>
</tr>
<tr>
<td width="135">Investors and shareholders</p>
<p>&nbsp;</td>
<td width="344">·      In-person meetings or phone calls</p>
<p>·      Open houses, town hall meetings</p>
<p>·      Ethics &amp; compliance helpline</p>
<p>·      Website content</p>
<p>·      Corporate sustainability report</p>
<p>·      Facility tours</p>
<p>·      Print or social media</td>
</tr>
<tr>
<td width="135">Regulators, elected officials, community leaders</p>
<p>&nbsp;</td>
<td width="344">·      In-person meetings or phone calls</p>
<p>·      Open houses, town hall meetings</p>
<p>·      Ethics &amp; compliance helpline</p>
<p>·      Website content</p>
<p>·      Corporate sustainability report</p>
<p>·      Facility tours</p>
<p>·      Print or social media</td>
</tr>
<tr>
<td width="135">Suppliers, contractors, business partners</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      In-person meetings or phone calls</p>
<p>·      Open houses, town hall meetings</p>
<p>·      Ethics &amp; compliance helpline</p>
<p>·      Website content</p>
<p>·      Corporate sustainability report</p>
<p>·      Facility tours</p>
<p>·      Print or social media</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics Sempra Energy interviewed stakeholders to gain their perspectives on current and emerging priorities.</p>
<p><strong>What actions were taken by</strong> <strong>Sempra Energy</strong> <strong>to</strong> <strong>promote</strong> <strong>cybersecurity</strong><strong>?</strong></p>
<p>In its 2019 Corporate Sustainability Report Sempra Energy reports that it took the following actions for promoting cybersecurity:</p>
<ul>
<li><strong>Establishing an information security team</strong></li>
<li>Sempra Energy’s information security team conducts regular penetration tests and analyses the results to improve existing controls and identify opportunities for improvement. Members of this team also participate in department staff meetings, safety stand downs and safety congresses to provide perspective and training on cybersecurity issues. Individual employees across the company support these efforts as “cybersecurity champions,” sharing relevant information with their teams.</li>
</ul>
<ul>
<li><strong>Implementing an information security awareness programme</strong></li>
<li>Sempra Energy’s information security awareness programme includes periodic communications, companywide events and campaigns, mandatory annual web-based training, facility-specific town hall events and a cross-business advocacy programme. Sempra Energy supports these efforts with articles, webpage communications and digital signage.</li>
</ul>
<ul>
<li><strong>Using an </strong><strong>automated SPAM reporting button</strong></li>
<li>An automated SPAM reporting button in Microsoft Outlook allows easy one-click reporting of suspicious and unwanted emails. In fact, to keep this reporting option top-of-mind, Sempra Energy’s cybersecurity team utilises “fake” phishing attempts and sends congratulatory messages when employees take the correct action by clicking the SPAM button. Sempra’s 24/7 Information Security Operations Centre (SOC) also responds to reports of suspicious email. The SOC can pull a suspicious email from the enterprise, reducing the risk of infecting other users or devices.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by Sempra Energy, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to Sempra Energy: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-sempra-energy-promotes-cybersecurity/">Case study: How Sempra Energy promotes cybersecurity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How Investec promotes information security</title>
		<link>https://sustaincase.com/case-study-how-investec-promotes-information-security/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Fri, 28 May 2021 05:33:09 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Financial Services]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[customer privacy]]></category>
		<category><![CDATA[Investec]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12615</guid>

					<description><![CDATA[<p>Investec is an international specialist bank and asset management group that provides a diverse range of financial products and services to a select client base in three principal markets, the UK and Europe, South Africa and Asia/Australia, as well as certain other countries. Investec builds information security and IT risk management capabilities across the group while promoting the responsible handling of personal data, so as to enable business continuity while protecting information assets by proactively identifying and mitigating threats to its people, processes, technology and data. This case study is based on the 2019 Corporate Sustainability and ESG Supplementary Report [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-investec-promotes-information-security/">Case study: How Investec promotes information security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Investec is an international specialist bank and asset management group that provides a diverse range of financial products and services to a select client base in three principal markets, the UK and Europe, South Africa and Asia/Australia, as well as certain other countries. Investec builds information security and IT risk management capabilities across the group while promoting the responsible handling of personal data, so as to enable business continuity while protecting information assets by proactively identifying and mitigating threats to its people, processes, technology and data.</p>
<p><strong>This case study is based on the</strong><strong> 2019 Corporate Sustainability and ESG Supplementary Report by</strong> <strong>Investec</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/70624/" target="_blank" rel="noopener"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p><strong>Investec recognises that information and technology resources are critical business assets</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=Investec%20recognises%20that%20information%20and%20technology%20resources%20are%20critical%20business%20assets&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-investec-promotes-information-security%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a>, which need to be appropriately managed and secured. In order to promote information security Investec took action to:</p>
<ul>
<li>provide information security training</li>
<li>promote cybersecurity</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) Investec has identified;</li>
<li>How Investec proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by Investec to promote information security</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified? </strong></p>
<p>In its 2019 Corporate Sustainability and ESG Supplementary Report Investec identified a range of material issues, such as gender, diversity and transformation, auditor independence, improving and sustainable returns, impact of the political and economic environment. Among these, promoting information security stands out as a key material issue for Investec.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups </strong><strong>Investec</strong> <strong>engages with:</strong></p>
<p>To identify and prioritise material topics Investec engaged with its stakeholders through the following channels:</p>
<table width="479">
<tbody>
<tr>
<td width="135"><strong>Stakeholder Group</strong></td>
<td width="344"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="135">Employees</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Quarterly magazine</p>
<p>·      Staff updates hosted by executive management</p>
<p>·      Group and subsidiary fact sheets</p>
<p>·      Tailored internal investor relations presentations</p>
<p>·      Induction training for new employees</p>
<p>·      Regular staff communications</p>
<p>·      Dedicated comprehensive intranet</p>
<p>·      Senior management engagement breakfasts</td>
</tr>
<tr>
<td width="135">Investors and shareholders</p>
<p>&nbsp;</td>
<td width="344">·      Annual general meeting</p>
<p>·      Four investor presentations</p>
<p>·      Stock exchange announcements</p>
<p>·      Comprehensive investor relations website</p>
<p>·      Shareholder roadshows and presentations</p>
<p>·      Regular meetings with investor relations team and executive management</p>
<p>·      Annual meeting with investor relations, group company secretarial, the chairman of the board, senior independent director and chairman of the remuneration committee</p>
<p>·      Regular email and telephone communication</p>
<p>·      Annual and interim reports</td>
</tr>
<tr>
<td width="135">Clients</p>
<p>&nbsp;</td>
<td width="344">·      Client relationship managers in each business</p>
<p>·      Regular face-to-face, telephone and email communications</p>
<p>·      Meetings with senior management</p>
<p>·      Comprehensive website and app</p>
<p>·      Industry relevant events</p>
<p>·      Client marketing events</td>
</tr>
<tr>
<td width="135">Rating agencies</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Meetings with investor relations team, group risk management and executive management</p>
<p>·      Tailored rating agency booklet</p>
<p>·      Tailored presentations</p>
<p>·      Regular email and telephone communications</p>
<p>·      Annual and interim reports</p>
<p>·      Four investor presentations</p>
<p>·      Comprehensive investor relations website</td>
</tr>
<tr>
<td width="135">Government and regulatory bodies</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Active participation in a number of policy forums</p>
<p>·      Response and engagement with all relevant bodies on regulatory matters</p>
<p>·      Consulted with industry bodies</td>
</tr>
<tr>
<td width="135">Equity and debt analysts</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Four investor presentations</p>
<p>·      Stock exchange announcements</p>
<p>·      Comprehensive investor relations website</p>
<p>·      Regular meetings with investor relations and executive management</p>
<p>·      Regular email and telephone communications</p>
<p>·      Annual and interim reports</td>
</tr>
<tr>
<td width="135">Media</p>
<p>&nbsp;</td>
<td width="344">·      Regular email and telephone communications</p>
<p>·      Stock exchange announcements</p>
<p>·      Comprehensive website</p>
<p>·      Meetings with executive management, economists and industry spokespersons</p>
<p>·      Dedicated third party public relations teams</td>
</tr>
<tr>
<td width="135">Suppliers</p>
<p>&nbsp;</td>
<td width="344">·      Centralised negotiation process</p>
<p>·      Ad hoc procurement questionnaires requesting information on suppliers’ environmental, social and ethical policies</td>
</tr>
</tbody>
</table>
<p><strong>What actions were taken by</strong> <strong>Investec</strong> <strong>to</strong> <strong>promote</strong> <strong>information security</strong><strong>?</strong></p>
<p>In its 2019 Corporate Sustainability and ESG Supplementary Report Investec reports that it took the following actions for promoting information security:</p>
<ul>
<li><strong>Providing information security training </strong></li>
<li>During the reporting year Investec ran a modular computer based training (CBT) information security awareness campaign, aimed to educate staff about the threats to Investec’s information, give them insight into the potential risks of data compromise, and to arm them with the knowledge they need to safeguard Investec’s (and their) data. A total of 81% of staff completed the training during the year. The campaign covered a broad range of topics consisting of the following modules:
<ul>
<li>Module 1 – Data protection: The different classifications of information, the importance of protecting it, and how to securely handle the information you access in your role</li>
<li>Module 2 – Cybersecurity: The threats you may face when you are online, the dangers of tricks and techniques used by cyber criminals, and how to guard against these</li>
<li>Module 3 – Mobile devices and social media: The risks associated with using mobile devices, the potential dangers of social media, and what you can do to keep your data and devices safe</li>
<li>Module 4 – Beyond the office: The importance of being vigilant and how to protect information when out of the office – be it at home, in public places, or while travelling</li>
<li>Module 5 – Security essentials: The fundamentals of information security, social engineering, and secure use of IT resources to safeguard both corporate and personal data.</li>
</ul>
</li>
</ul>
<ul>
<li><strong>Promoting cybersecurity</strong></li>
<li>Investec maintains a risk-based strategy incorporating prediction, prevention, detection and response capabilities, to ensure the group is adequately protected against advanced cyber attacks. Continual monitoring provides visibility and enables proactive response to evolving cyber threats. Investec maintains active participation in the global cybersecurity industry to stay current and relevant. Targeted attack simulations by external specialists are performed, to measure and improve cyber defences. These are complemented by non-technical exercises involving the board and senior leadership to evaluate and improve cyber incident response and crisis management.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by Investec, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to Investec: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-investec-promotes-information-security/">Case study: How Investec promotes information security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How BCV protects customer privacy</title>
		<link>https://sustaincase.com/case-study-how-bcv-protects-customer-privacy/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Fri, 07 May 2021 06:10:37 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Financial Services]]></category>
		<category><![CDATA[BCV]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[customer privacy]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12561</guid>

					<description><![CDATA[<p>Founded 175 years ago, BCV is the leading bank of Vaud Canton in Switzerland and one of the country’s five largest universal banks by total assets, offering a comprehensive range of financial products and services. Committed to providing excellent customer service, This case study is based on the 2019 Sustainability Report by BCV published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-bcv-protects-customer-privacy/">Case study: How BCV protects customer privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Founded 175 years ago, BCV is the leading bank of Vaud Canton in Switzerland and one of the country’s five largest universal banks by total assets, offering a comprehensive range of financial products and services. Committed to providing excellent customer service, <strong>BCV takes every precaution to prevent the disclosure of non-public information relating to BCV and its customers.</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=BCV%20takes%20every%20precaution%20to%20prevent%20the%20disclosure%20of%20non-public%20information%20relating%20to%20BCV%20and%20its%20customers.&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-bcv-protects-customer-privacy%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a></p>
<p><strong>This case study is based on the</strong><strong> 2019 Sustainability Report by</strong> <strong>BCV</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/78986/" target="_blank" rel="noopener"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p>In 2019, to combat cyber and other security threats, BCV carried out a cybersecurity awareness campaign to help customers and employees prevent cyberattacks. In order to protect customer privacy BCV took action to:</p>
<ul>
<li>tackle cybercrime</li>
<li>keep data secure</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) BCV has identified;</li>
<li>How BCV<span style="font-weight: 400;"> </span>proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by BCV to protect customer privacy</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2019 Sustainability Report BCV identified a range of material issues, such as contributing to Vaud&#8217;s economic development, products and services suited to customers’ needs and expectations, retirement, compensation, and other employee benefits, diversity and equal opportunity. Among these, protecting customer privacy stands out as a key material issue for BCV.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards               </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups</strong> <strong>BCV</strong> <strong>engages with:</strong></p>
<p>To identify and prioritise material topics BCV engaged with its stakeholders through the following channels:</p>
<table width="479">
<tbody>
<tr>
<td width="135"><strong>Stakeholder Group</strong></td>
<td width="344"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="135">Vaud Cantonal Government and Cantonal Parliament</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Regular contact with the Vaud Cantonal Government as part of BCV’s information-exchange agreement</p>
<p>·      Responsiveness by the Bank towards BCV-related questions and requests that Vaud’s Cantonal Parliament submits to the Cantonal Government (e.g., motions that ask or require the government to legislate)</td>
</tr>
<tr>
<td width="135">Employees</td>
<td width="344">·      Employee engagement surveys</td>
</tr>
<tr>
<td width="135">Customers</p>
<p>&nbsp;</td>
<td width="344">·      Market research and satisfaction surveys</p>
<p>·      Systematic analysis of customer complaints</td>
</tr>
<tr>
<td width="135">Shareholders (apart from the Canton of Vaud)</td>
<td width="344">·      Annual Shareholders’ Meeting</p>
<p>·      Regular meetings with professional investors</td>
</tr>
<tr>
<td width="135">Sustainable development interest groups</td>
<td width="344">·      Responding to questions, requests, and comments</p>
<p>&nbsp;</td>
</tr>
<tr>
<td width="135">Supervisory and federal authorities</p>
<p>&nbsp;</td>
<td width="344">·      Regular meetings with the Swiss Financial Market Supervisory Authority (FINMA) and the Swiss National Bank (SNB)</td>
</tr>
<tr>
<td width="135">Suppliers and partners</p>
<p>&nbsp;</td>
<td width="344">·      Formalised processes for managing relationships with main suppliers</td>
</tr>
<tr>
<td width="135">Cultural and sports associations</td>
<td width="344">·      Responding to questions, requests, and comments</p>
<p>·      Numerous exchanges about sponsoring and donations</td>
</tr>
</tbody>
</table>
<p><strong>What actions were taken by</strong> <strong>BCV</strong> <strong>to</strong> <strong>protect customer privacy</strong><strong>?</strong></p>
<p>In its 2019 Sustainability Report BCV reports that it took the following actions for protecting customer privacy:</p>
<ul>
<li><strong>Tackling cybercrime</strong></li>
<li>The growth of digital banking services means that cybercrime is an increasingly pressing concern, especially for a bank the size of BCV. Accordingly, BCV has assessed potential threats to its businesses, including cyberattacks and other security risks, and taken appropriate measures to protect its IT systems, data, and operations. BCV monitors these threats around the clock and because the methods used by cybercriminals are changing constantly, BCV regularly upgrades its practices and tests its capacity to withstand cyberattacks. Additionally, BCV works closely with specialised partner firms and Swiss government agencies in charge of combating cybercrime, such as the Reporting and Analysis Centre for Information Assurance (MELANI). BCV’s business continuity plans are also tested at regular intervals.</li>
</ul>
<ul>
<li><strong>Keeping data secure</strong></li>
<li>BCV makes sure that both customers and employees are guaranteed full confidentiality, in accordance with the law and established practices. If required to collect personal data about customers or employees, whether by law or by circumstances, BCV handles such data in compliance with data protection requirements. And whenever BCV shares data with authorised third parties, it adheres to the law and BCV’s General Conditions. Appropriate organisational and technical measures are also in place to prevent documents and records from being viewed, used, modified, or destroyed by unauthorised persons. In 2019, no legal action was taken against BCV for breach of confidentiality or customer data loss.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed?</strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by BCV, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to BCV: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-bcv-protects-customer-privacy/">Case study: How BCV protects customer privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How SCB promotes cyber security</title>
		<link>https://sustaincase.com/case-study-how-scb-promotes-cyber-security/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Wed, 17 Mar 2021 07:14:47 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Financial Services]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[SCB]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12325</guid>

					<description><![CDATA[<p>Siam Commercial Bank (SCB) is a leading global bank and the first local bank that has been part of the Thai society for 114 years, creating and offering end-to-end financial solutions to fulfill the needs of all groups of customers. To ensure continuity and effectiveness in its operation, SCB places heavy emphasis on data governance and cyber security by developing systems and infrastructure, investing in technologies, enhancing employee capabilities, and improving processes to keep pace with change. This case study is based on the 2019 Sustainability Report by SCB published on the Global Reporting Initiative Sustainability Disclosure Database that can be [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-scb-promotes-cyber-security/">Case study: How SCB promotes cyber security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Siam Commercial Bank (SCB) is a leading global bank and the first local bank that has been part of the Thai society for 114 years, creating and offering end-to-end financial solutions to fulfill the needs of all groups of customers. To ensure continuity and effectiveness in its operation, SCB places heavy emphasis on data governance and cyber security by developing systems and infrastructure, investing in technologies, enhancing employee capabilities, and improving processes to keep pace with change.</p>
<p><strong>This case study is based on the</strong><strong> 2019 Sustainability Report</strong> <strong>by SCB </strong><strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/79548/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p><strong>SCB seeks to continuously improve its data governance and cyber security</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=SCB%20seeks%20to%20continuously%20improve%20its%20data%20governance%20and%20cyber%20security&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-scb-promotes-cyber-security%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a> so as to make sure that data on all of its systems and digital platforms are managed with care and adequately protected against new threats, and that there shall be no breach in customer data privacy. In order to promote cyber security SCB took action to:</p>
<ul>
<li>implement an Information Security Policy</li>
<li>integrate cyber security into its software development and operations</li>
<li>build a data and cyber security culture</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) SCB has identified;</li>
<li>How SCB proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by SCB to promote cyber security</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified? </strong></p>
<p>In its 2019 Sustainability Report SCB identified a range of material issues, such as corporate governance and risk management, customer experience, financial inclusion, responsible lending. Among these, promoting cyber security stands out as a key material issue for SCB.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards                         </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups SCB engages with:</strong><strong> </strong></p>
<table width="479">
<tbody>
<tr>
<td width="128"><strong>Stakeholder Group</strong></td>
<td width="351"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="128">Customers</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="351">·      Customer relationship-building activity</p>
<p>·      Information sessions on SCB financial products and services</p>
<p>·      Providing financial advice and knowledge to customers through online media, branch network and other electronic channels</p>
<p>·      Customer satisfaction surveys through telephone, questionnaire and electronic channels</p>
<p>·      Complaint and service channels through Customer Centre, Branch network and SCB Easy app</td>
</tr>
<tr>
<td width="128">Employees</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="351">·      Meetings and online channels for policy and news announcement</p>
<p>·      Employee meetings, seminars and CSR activities</p>
<p>·      Annual performance evaluation</p>
<p>·      Employment engagement survey</p>
<p>·      Employee development programme</p>
<p>·      Employee recognition programme</p>
<p>·      Employee hotline</td>
</tr>
<tr>
<td width="128">Shareholders</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="351">·      Annual general meeting</p>
<p>·      Extraordinary general meeting</p>
<p>·      56-1 Report</p>
<p>·      Annual report (Form 56-2)</p>
<p>·      Press release</p>
<p>·      Quarterly financial report</p>
<p>·      Investor meeting/conference</p>
<p>·      Investor call</p>
<p>·      Equity analyst meeting</p>
<p>·      Global roadshow event</td>
</tr>
<tr>
<td width="128">Society and Environment</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="351">·      Projects and initiatives by SCB and the Siam Commercial Bank Foundation</p>
<p>·      Community and social surveys</p>
<p>·      Community engagement activities</td>
</tr>
<tr>
<td width="128">Regulators</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="351">·      Assign Compliance unit to serve as SCB’s regulatory liaison</p>
<p>·      Attend meetings and hearings on regulatory policies and guidance from relevant authorities</p>
<p>·      Attend forums on regulatory compliance</p>
<p>·      Seek feedback and guidance on regulatory compliance</p>
<p>·      Offer feedback on regulations through public hearings</p>
<p>·      Prepare and provide support for regulatory audit</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics SCB conducted in-depth interviews with selected groups of stakeholders to collect suggestions, feedback and information on economic, social and environmental material topics.</p>
<p><strong><a href="https://fbrh.co.uk/en/gri-certified-training/2-day-fbrh-gri-standards-certified-training-course-about" target="_blank" rel="noopener noreferrer"><img loading="lazy" decoding="async" class="alignright size-full wp-image-11761" src="https://sustaincase.com/wp-content/uploads/2020/08/sustainability-GRI-report-key-doc-for-success-ad-sustaincase-GRI-SDG-ESG-Sustainability-report-200x320px.jpg" alt="" width="200" height="320" /></a>What actions were taken by</strong> <strong>SCB</strong> <strong>to</strong> <strong>promote cyber security</strong><strong>?</strong></p>
<p>In its 2019 Sustainability Report SCB reports that it took the following actions for promoting cyber security:</p>
<ul>
<li><strong>Implementing an</strong> <strong>Information Security Policy</strong></li>
<li>Based on the Confidentiality-Integrity-Availability (CIA) triad, the SCB Financial Group Information Security Policy is communicated to all employees, including those in probationary periods and on temporary contracts, suppliers and consultants, from whom strict compliance is expected. The Policy also assigns the Audit Unit to perform an audit and make recommendations for further improving cyber security. SCB has adopted a proactive approach to cyber security by focusing on developing technology and processes for cyber threat detection, such as the Cybersecurity Threat Intelligent Surveillance system and machine learning technology to study the pattern of cyber-attacks, both internally and externally. This proactive approach enables SCB to assess the situation and be ready to respond and prevent potential losses. Additionally, for data storage with comparable effectiveness to on-premise storage, SCB uses Cloud Computing Technology to keep potential risk under its risk appetite level, to increase operational speed, and to lower the cost of maintaining the internal computer network and systems. Moreover, cyber security performance is regularly reported to senior management in a dashboard format. To be ready for an emergency situation and make sure that systems can be recovered back to normal service and operation in an appropriate timeframe, SCB has also established a policy and guideline for preparing an IT Contingency Plan, which is aligned with its Business Continuity Plan. This contingency plan defines processes, practices and the roles and responsibilities of the relevant business units in executing, testing, reviewing and revising the IT Contingency Plan according to the business context.</li>
</ul>
<ul>
<li><strong>Integrating cyber security into </strong><strong>software </strong><strong>development and operations </strong></li>
<li>In 2019, SCB upgraded its software development approach from DevOps to DevSecOps (Development Security Operations), whereby cyber security is integrated as part of SCB’s development and operations life cycle. This means that cyber security control measures are embedded throughout SCB’s software development life cycle to enhance the ability to create innovation and make further product and service improvements to deliver even greater speed, effectiveness, and security. Through this approach, SCB added security automation tools in the software development process to make security testing faster and more effective. The automation tools allow SCB’s software developers and system administrators to perform security testing on their own and detect any vulnerability after the software launch, receiving timely reports on potential problems.</li>
</ul>
<ul>
<li><strong>Building a data and cyber security culture</strong></li>
<li>In parallel with continuously investing in technology and developing cyber security systems that meet global standards, SCB is committed to building a data and cyber security culture for employees at every level. SCB uses work processes, training and internal communication to promote awareness on appropriate and secure data handling, data protection, cyber risk, and cyber threat prevention. Accordingly, SCB provides a data classification training course on its e-learning system to promote appropriate and secure data usage throughout the organisation and offers a cyber security course to senior executives which covers topics such as causes of cyber-attacks and impacts of cyber threats. Employees at all levels are also required to take the mandatory course on cyber security on the system which focuses on basic knowledge regarding data protection, on understanding the forms and impacts of cyber threats through simulation, and on how to prevent and report an incident. Throughout 2019, SCB organised “Don’t Let It Happen” activities to promote awareness on cyber threats, cyber risks, and data security protection with an emphasis on safeguarding the data of both customers and SCB and building awareness on risk behaviours that may cause damage to the business or SCB ‘s One of the highlights that attracted many participants was the “Cybersecurity Awareness Day 2019,” which featured talks by external experts regarding cyber security on topics such as knowing tricks of cyber criminals inside out, understanding data risk, and using personal information on social media.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by SCB, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to SCB: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-scb-promotes-cyber-security/">Case study: How SCB promotes cyber security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How MKB promotes information security</title>
		<link>https://sustaincase.com/case-study-how-mkb-promotes-information-security/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Fri, 19 Feb 2021 07:06:09 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Financial Services]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[customer privacy]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[MKB]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12264</guid>

					<description><![CDATA[<p>MKB is one of the largest private banks in Russia, offering a full package of financial services through a regional network that includes more than 130 offices in 19 regions. Adhering to the principles of socially responsible business conduct, This case study is based on the 2019 Sustainability Report by MKB published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-mkb-promotes-information-security/">Case study: How MKB promotes information security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>MKB is one of the largest private banks in Russia, offering a full package of financial services through a regional network that includes more than 130 offices in 19 regions. Adhering to the principles of socially responsible business conduct, <strong>MKB complies with both Russian and international laws on personal data processing and protection.</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=MKB%20complies%20with%20both%20Russian%20and%20international%20laws%20on%20personal%20data%20processing%20and%20protection.&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-mkb-promotes-information-security%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a></p>
<p><strong>This case study is based on the</strong><strong> 2019 Sustainability Report by</strong> <strong>MKB</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/80711/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p>The design of MKB’s current and future processes and products assumes obtaining consents from customers, counterparties, and the bank’s employees for the processing of their personal data, for the minimum use of their data when in interaction between the employees and the bank’s systems, and for the provision of the “security by design” and “security by default” concepts. In order to promote information security MKB took action to:</p>
<ul>
<li>combat fraud</li>
<li>promote cybersecurity</li>
<li>identify and eliminate vulnerabilities</li>
<li>respond to information security incidents in a timely manner</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) MKB has identified;</li>
<li>How MKB proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by MKB to promote information security</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified? </strong></p>
<p>In its 2019 Sustainability Report MKB identified a range of material issues, such as customer satisfaction, increasing the accessibility of services, economic efficiency, professional development and training of employees. Among these, promoting information security stands out as a key material issue for MKB.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards               </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups MKB engages with:</strong></p>
<table width="479">
<tbody>
<tr>
<td width="135"><strong>Stakeholder Group</strong></td>
<td width="344"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="135">Customers</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Customer service, including development of the network of branch offices</p>
<p>·      Receiving queries</p>
<p>·      Remote banking service (mobile banking, contact centre, internet banking)</p>
<p>·      Information about bank products, reporting, availability of branch offices of the Bank, environmental plans and actions, and other important information as published on the MKB website (Russian or English version)</p>
<p>·      Analysis of customer satisfaction</td>
</tr>
<tr>
<td width="135">Employees</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Advanced training</p>
<p>·      Benefits package</p>
<p>·      Support and assistance in developing internal corporate sports clubs and events for the company employees</p>
<p>·      Participation in sports events, charitable, and other public and environmental events</p>
<p>·      Corporate portal</p>
<p>·      The hotline that allows sending complaints and queries to the members of the Audit and Risk Committee under the MKB Supervisory Board</td>
</tr>
<tr>
<td width="135">Society</td>
<td width="344">·      Participation in social and environmental projects of the Russian Government, other governmental bodies, and development of its own projects</p>
<p>·      Development of financial products for different categories of people</p>
<p>·      Support of small and medium business entities</p>
<p>·      Development of a regional network of offices and creation of additional jobs in the regions</p>
<p>·      Interaction with higher educational institutions, probation programmes, training</td>
</tr>
<tr>
<td width="135">Shareholders and investors</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Meetings of shareholders</p>
<p>·      Communication using different channels (including conference calls, meetings, correspondence via email, webcasts)</p>
<p>·      Disclosure of information important for shareholders and investors on the electronic page for investors (in Russian and English)</p>
<p>·      Publication of financial and nonfinancial reports</td>
</tr>
<tr>
<td width="135">Counterparties and partners</td>
<td width="344">·      A transparent competitive procurement system</p>
<p>&nbsp;</td>
</tr>
<tr>
<td width="135">Governmental bodies and regulators</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Information disclosure and compliance with all legislative requirements in the field of banking activities</p>
<p>·      Participation in projects and work meetings on the improvement of laws in different areas (expert councils, work groups, round-table discussions, and other forms of communications)</p>
<p>·      Contribution to the development of regions with the extension of the regional network of presence</td>
</tr>
<tr>
<td width="135">Mass media</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Regular communications with the key media, prompt response to incoming questions</p>
<p>·      A high level of content mobility on the MKB website, in social networks, and other sources of communication</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics MKB engaged with its stakeholders through an interactive survey tool.</p>
<p><strong>What actions were taken by</strong> <strong>MKB</strong> <strong>to</strong> <strong>promote information security</strong><strong>?</strong></p>
<p>In its 2019 Sustainability Report MKB reports that it took the following actions for promoting information security:</p>
<ul>
<li><strong>Combating fraud</strong></li>
<li>MKB pursues a zero-tolerance policy toward illegal actions against its customers. For this purpose, MKB:
<ul>
<li>has implemented and maintains fraud monitoring processes for remote banking;</li>
<li>investigates any attempts of stealing funds from the bank’s customers;</li>
<li>interacts with the Bank of Russia and other credit institutions, communication service providers, and law enforcement agencies for the exchange of information about the actions of fraudsters and for the timely prevention of fraudulent activities;</li>
<li>implements the programme for enhanced protection of systems and data, which is reviewed annually and updated completely every three years.</li>
</ul>
</li>
<li>The above activities resulted in dozens of prevented attempts of stealing funds from legal entities and individuals, which saved them dozens of million rubles. The only loss by a legal entity because of the fraudster’s actions in the remote business education system (RBES) in 2019 amounted to RUB 3,000; the transaction was marked as suspicious but was additionally confirmed by the customer itself.</li>
</ul>
<ul>
<li><strong>Promoting cybersecurity</strong></li>
<li>MKB pays much attention to information security and resistance to cyber threats. The following biggest threats for MKB were identified within the frames of its information security strategy:
<ul>
<li>External attacks as a result of actions of hacker groups, which are aimed at stealing data or money via payment systems</li>
<li>Attacks aimed at customers and stealing customers’ funds via remote banking services</li>
<li>Fraudulent actions of the bank’s employees or counterparties, which may cause data leaks or thefts using authorised access to MKB’s information systems</li>
<li>Logical attacks at ATMs (use of special software for money disbursement without using cards and for debiting accounts) and payment terminals (use of special software to reload cards without cash)</li>
</ul>
</li>
<li>The following projects were initiated and successfully finished for the implementation of measures to prevent the materialisation of threats:
<ul>
<li>Implementation of the next generation firewall as a basic element of protection against external attacks</li>
<li>Implementation of a solution to counter targeted attacks made using malicious emails or malicious websites, which use 0-day vulnerabilities and are not detected by standard means of protection, for example, antivirus software (as a result of system operation, over 650 targeted attacked were repelled)</li>
<li>Implementation and development of the personnel training system simulating sending of malicious attachments and fishing links by hackers and appointing testing automatically if an employee opens such attachments or types a password to their account on the websites available at the fishing links</li>
<li>Development and implementation of an antifraud system to identify abnormal and illegal payments sent to the Bank of Russia or to the international data transfer and payment system SWIFT</li>
</ul>
</li>
</ul>
<ul>
<li><strong>Identifying and eliminating vulnerabilities</strong></li>
<li>To minimise the probability of merely technical vulnerabilities typical of information systems and logical vulnerabilities affecting customer service processes and products, MKB started supporting the following processes in 2019:
<ul>
<li>External scanning of vulnerabilities; full coverage was reached for all 179 publications of MKB’s services on the web and external networks, scanning results are recognised by auditors as performed by the Approved Scanning Vendor as part of the PCI DSS (Payment Card Industry Data Security Standard) standard conformity audits.</li>
<li>A red team was set up—that is, a group of specialists with qualifications similar to hackers, whose main task is to conduct penetration tests and identify vulnerabilities through the eyes of hackers for the purpose of thorough identification of vulnerabilities that cannot be identified instrumentally.</li>
<li>The Information Security Department participates in, and controls, all tasks of IT development, including the following:
<ul>
<li>Analysis of business requirements</li>
<li>Analysis of technical assignments</li>
<li>Formation of a set of requirements for the implementation of security-by-design and security-by-default concepts for all services and products developed by MKB</li>
<li>Verification of the fulfilment of requirements before bringing the implemented tasks in action</li>
<li>Participation of red team specialists for the purpose of vulnerability analysis in any services published on the web and in any payment applications</li>
</ul>
</li>
<li>External penetration tests organised by the internal audit are performed by specialised companies with highly proficient specialists.</li>
</ul>
</li>
</ul>
<ul>
<li><strong>Responding to information security incidents in a timely manner</strong></li>
<li>To monitor and provide timely response to information security incidents, MKB has a security incidents response team. In 2019, the work of this team, operating as part of the Information Security Department, resulted in the creation of the monitoring system architecture, implementation of the subsystem of collection and primary analysis of incidents, implementation of the incident response platform, and automation of the formation of any incidents as tasks for the team members in the implemented platform. The ongoing processes are built so that the time from the attack to the analysis of the processes within the attack and to the termination of the attack usually does not exceed 4 hours.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed?</strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by MKB, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to MKB: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-mkb-promotes-information-security/">Case study: How MKB promotes information security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How Bank Muscat promotes cybersecurity</title>
		<link>https://sustaincase.com/case-study-how-bank-muscat-promotes-cybersecurity/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Mon, 11 Jan 2021 06:56:54 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Financial Services]]></category>
		<category><![CDATA[Bank Muscat]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12119</guid>

					<description><![CDATA[<p>Bank Muscat is the leading financial institution in Oman, with a strong presence in corporate banking, personal banking, investment banking, Islamic banking, treasury, private banking and asset management. As cybercrimes can cause enormous financial and material losses for both victims and the economy, so as to safeguard, according to strict standards of security and confidentiality, any information customers share with the Bank. This case study is based on the 2019 Sustainability Report by Bank Muscat published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-bank-muscat-promotes-cybersecurity/">Case study: How Bank Muscat promotes cybersecurity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Bank Muscat is the leading financial institution in Oman, with a strong presence in corporate banking, personal banking, investment banking, Islamic banking, treasury, private banking and asset management. As cybercrimes can cause enormous financial and material losses for both victims and the economy, <strong>Bank Muscat remains vigilant in its cybersecurity efforts</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=Bank%20Muscat%20remains%20vigilant%20in%20its%20cybersecurity%20efforts&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-bank-muscat-promotes-cybersecurity%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a> so as to safeguard, according to strict standards of security and confidentiality, any information customers share with the Bank.</p>
<p><strong>This case study is based on the</strong><strong> 20</strong><strong>19 </strong><strong>Sustainability Report by</strong> <strong>Bank Muscat</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/80568/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p>Bank Muscat’s information/cybersecurity management function helps to secure information within the Bank, as well as keep the Bank secured from cybersecurity risks. In order to promote cybersecurity Bank Muscat took action to:</p>
<ul>
<li>identify and address cybersecurity risks</li>
<li>improve cybersecurity measures</li>
<li>launch an anti-fraud public awareness campaign</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) Bank Muscat has identified;</li>
<li>How Bank Muscat proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by Bank Muscat to promote cybersecurity</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2019 Sustainability Report Bank Muscat identified a range of material issues, such as customer relationship management, employee training and development, responsible investing, Anti-Money Laundering and Anti-Financing of Terrorism (AML and AFT). Among these, promoting cybersecurity stands out as a key material issue for Bank Muscat.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards              </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups</strong> <strong>Bank Muscat</strong> <strong>engages with:                     </strong></p>
<table width="638">
<tbody>
<tr>
<td width="180"><strong>Stakeholder Group</strong></td>
<td width="459"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="180">Employees</td>
<td width="459">·       Annual performance reviews</p>
<p>·       Regular dialogue and interaction with employees</p>
<p>·       Training and education programmes</p>
<p>·       Grievance mechanism</p>
<p>·       Polls and survey</td>
</tr>
<tr>
<td width="180">Customers</td>
<td width="459">·       Call Centre Feedback Management System (FMS)</p>
<p>·       Company website</p>
<p>·       Focus groups</p>
<p>·       Customer networking events for specific customer segments</p>
<p>·       Branches and access points including ATMs and CDMs</p>
<p>·       Media and social media channels</p>
<p>·       Annual report and sustainability report</p>
<p>·       Other bank publications including investor presentations</td>
</tr>
<tr>
<td width="180">Government (Including Regulatory Bodies)</td>
<td width="459">·       Government Business Division</p>
<p>·       Investment in the national economy</p>
<p>·       Supporting initiatives of national importance</td>
</tr>
<tr>
<td width="180">Correspondent / Other Banks / International Entities</td>
<td width="459">·       Financial Institutions Group (FIG)</p>
<p>·       Company website and other publications</p>
<p>·       Roadshows and presentations</td>
</tr>
<tr>
<td width="180">Shareholders/ Investors</p>
<p>&nbsp;</td>
<td width="459">·       Investor Relations Department</p>
<p>·       Shareholder meetings</p>
<p>·       Roadshows and presentations</p>
<p>·       Company website and other publications</td>
</tr>
<tr>
<td width="180">Local, Regional &amp; International Media</td>
<td width="459">·       Media, social media and other publications</p>
<p>·       Press conferences</p>
<p>·       Media networking events</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics Bank Muscat engaged with its stakeholders through interviews and surveys.</p>
<p><strong>What actions were taken by</strong><strong> Bank Muscat</strong> <strong>to</strong> <strong>promote</strong> <strong>cybersecurity</strong><strong>?</strong></p>
<p>In its 2019 Sustainability Report Bank Muscat reports that it took the following actions for promoting cybersecurity:</p>
<ul>
<li><strong>Identifying and addressing cybersecurity risk</strong><strong>s</strong></li>
<li>Bank Muscat continuously invests in maintaining and updating the systems and processes that are designed to ensure the security of the Bank’s computer systems, software, networks and other technology assets. Bank Muscat’s information/cybersecurity risk management function focuses on the following key aspects:
<ul>
<li>Cybersecurity incident response plans in order to implement effective management of cybersecurity incidents</li>
<li>Information security governance through security policies, procedures, guidelines and standards</li>
<li>Information security monitoring using the latest solutions and tools, including real time as well as fixed frequency monitoring</li>
<li>Implementing a robust security defence network as well as maintaining strong internal controls</li>
<li>Information security reviews comprising new and existing technologies, solutions, networks and also the various processes/ operations within each and every department of the Bank</li>
</ul>
</li>
</ul>
<ul>
<li><strong>Improv</strong><strong>ing</strong><strong> cybersecurity measures</strong></li>
<li>In 2019, Bank Muscat partnered with the Information Technology Authority (ITA) to improve cybersecurity measures. The Bank took part in a series of cybersecurity events organised by the ITA, including the 8th Regional Cybersecurity Summit, FIRST &amp; International Telecommunication Union Arab Regional Cyber Security Centre (ITU-ARCC), and the 7th Regional Cyber Drill. Bank Muscat also participated in the Cybersecurity Readiness drill, held under the theme “Intelligence of Malware” and organised by the National Computer Emergency Readiness Team (OCERT) to assess cybersecurity readiness in Organisation of Islamic Cooperation (OIC) countries.</li>
</ul>
<ul>
<li><strong>Launch</strong><strong>ing</strong><strong> an anti-fraud public awareness campaign</strong></li>
<li>In 2019, the Royal Oman Police (ROP) and Bank Muscat launched an anti-fraud public awareness campaign. The campaign focused on educating the community not to share their personal details or their banking/card details with anyone over the phone, and not to input them on links received through social media or messaging.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p><strong> </strong></p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by Bank Muscat, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to Bank Muscat: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-bank-muscat-promotes-cybersecurity/">Case study: How Bank Muscat promotes cybersecurity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How Vodafone Egypt promotes data security and privacy</title>
		<link>https://sustaincase.com/case-study-how-vodafone-egypt-promotes-data-security-and-privacy/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Fri, 18 Dec 2020 06:46:25 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Telecommunications]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[customer privacy]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<category><![CDATA[Vodafone Egypt]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12031</guid>

					<description><![CDATA[<p>&#160; Vodafone Egypt is a subsidiary of the Vodafone Group and the largest mobile network operator in Egypt, offering a range of communication services to both consumers and businesses all over Egypt. Vodafone Egypt is committed to processing personal data honestly, ethically, with integrity, and always in accordance with applicable laws and its values. This case study is based on the 2018-2020 Sustainability Report by Vodafone Egypt published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-vodafone-egypt-promotes-data-security-and-privacy/">Case study: How Vodafone Egypt promotes data security and privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<p>Vodafone Egypt is a subsidiary of the Vodafone Group and the largest mobile network operator in Egypt, offering a range of communication services to both consumers and businesses all over Egypt. Vodafone Egypt is committed to processing personal data honestly, ethically, with integrity, and always in accordance with applicable laws and its values.</p>
<p><strong>This case study is based on the</strong><strong> 20</strong><strong>18-2020 </strong><strong>Sustainability Report by</strong> <strong>Vodafone Egypt</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/80533/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p><strong>Respect for privacy is a key component in the design, development, and delivery of Vodafone Egypt’s products and services.</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=Respect%20for%20privacy%20is%20a%20key%20component%20in%20the%20design%2C%20development%2C%20and%20delivery%20of%20Vodafone%20Egypt%E2%80%99s%20products%20and%20services.&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-vodafone-egypt-promotes-data-security-and-privacy%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a> In order to promote data security and privacy Vodafone Egypt took action to:</p>
<ul>
<li>implement the Vodafone Group GDPR Programme</li>
<li>apply a Privacy Programme</li>
<li>implement a Privacy Policy</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) Vodafone Egypt has identified;</li>
<li>How Vodafone Egypt proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by Vodafone Egypt to promote data security and privacy</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2018-2020 Sustainability Report Vodafone Egypt identified a range of material issues, such as Covid-19 pandemic and crisis management, market leadership, business continuity, customer service excellence, community development. Among these, promoting data security and privacy stands out as a key material issue for Vodafone Egypt.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards              </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups</strong> <strong>Vodafone Egypt</strong> <strong>engages with:                </strong></p>
<p>To identify and prioritise material topics Vodafone Egypt engaged with its stakeholders through the following channels:</p>
<table width="638">
<tbody>
<tr>
<td width="180"><strong>Stakeholder Group</strong></td>
<td width="459"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="180">Employees</td>
<td width="459">·       Daily direct communication</p>
<p>·       Digital Communication</p>
<p>·       Workplace and Workchat</p>
<p>·       Annual surveys</p>
<p>·       Events and newsletters</p>
<p>·       Emails</p>
<p>·       Meetings</p>
<p>·       Social media</td>
</tr>
<tr>
<td width="180">Consumer and enterprise customers</td>
<td width="459">·       Call centres</p>
<p>·       Satisfaction surveys</p>
<p>·       Website</p>
<p>·       Social media</p>
<p>·       Sales channels and retail stores</p>
<p>·       My Vodafone application</p>
<p>·       Advertisements</p>
<p>·       Digital marketing</td>
</tr>
<tr>
<td width="180">Shareholders, investors and Vodafone Group</td>
<td width="459">·       Financial information disclosure</p>
<p>·       Annual reports</p>
<p>·       Quarterly updates</p>
<p>·       General assembly meetings</p>
<p>·       Website</td>
</tr>
<tr>
<td width="180">Suppliers and partners</td>
<td width="459">·       Direct communication channels</p>
<p>·       Suppliers events</p>
<p>·       Trainings and awareness campaigns</p>
<p>·       Evaluation and qualification</td>
</tr>
<tr>
<td width="180">Regulator</p>
<p>&nbsp;</td>
<td width="459">·       Public forums</p>
<p>·       Meetings</p>
<p>·       Industry consultations</p>
<p>·       Financial information disclosure</p>
<p>·       Audits</p>
<p>·       Participation in public policies</td>
</tr>
<tr>
<td width="180">Local communities</td>
<td width="459">·       Vodafone Foundation’s activities</p>
<p>·       Employees volunteering activities</p>
<p>·       Community partnerships</p>
<p>·       Public participation</p>
<p>·       Social media</p>
<p>·       Events</p>
<p>·       Word of mouth</td>
</tr>
<tr>
<td width="180">Civil society and NGOs</td>
<td width="459">·       Vodafone Foundation’s activities</p>
<p>·       Events in universities</p>
<p>·       Partnerships and collaborations</p>
<p>·       Social media</td>
</tr>
</tbody>
</table>
<p><strong>What actions were taken by</strong> <strong>Vodafone Egypt</strong> <strong>to</strong> <strong>promote</strong> <strong>data security and privacy</strong><strong>?</strong></p>
<p>In its 2018-2020 Sustainability Report Vodafone Egypt reports that it took the following actions for promoting data security and privacy:</p>
<ul>
<li><strong>Implementing the </strong><strong>Vodafone Group GDPR Program</strong><strong>me</strong></li>
<li>Vodafone Egypt follows and implements the Vodafone Group GDPR (General Data Protection Regulation) Programme to ensure compliance with the new European GDPR, since it is mandated by Vodafone Group even for non-European Markets that do not primarily deal with European personal data and are not directly impacted by the new regulation. This direction ensures consistency, maturity and standards for the Vodafone Privacy Programme across Vodafone’s global footprint, to meet the requirements of the changing global regulatory and reputational privacy landscape. In addition, it puts Vodafone Egypt in the leading position in the Egyptian Market, being pioneers in this field and allows Vodafone Egypt to be the first compliant telecom operator with the intended Data Protection Law that is adopting GDPR, to be released soon in Egypt. Vodafone sets the required controls for protection against transactions with a sanctioned entity in breach of the sanctions legislation, potentially resulting in reputational damage, large fines, criminal penalties for individuals, and termination of the Vodafone Group’s financing arrangements. The objective is to make sure that Vodafone Egypt has a clear and robust set of controls in place, to minimise the risk of Vodafone breaching sanctions legislation.</li>
</ul>
<ul>
<li><strong>Applying a </strong><strong>Privacy Program</strong><strong>me</strong></li>
<li>Vodafone Egypt has initiated a customised Privacy Programme to ensure compliance with GDPR and with the planned Egyptian Data Protection Law through its various domains that correspond to GDPR’s requirements. The Privacy Programme assumes 10 basic commandments, reflecting Vodafone Egypt’s obligations according to the legal and global standards:
<ul>
<li>Design for Privacy</li>
<li>Protect Confidentiality</li>
<li>Collect relevant data</li>
<li>Provide a Privacy Notice</li>
<li>Provide Choices</li>
<li>Manage Data Carefully</li>
<li>No unauthorised disclosure</li>
<li>Secure Data</li>
<li>Protect Children’s Privacy</li>
<li>Respect Individual Rights</li>
</ul>
</li>
</ul>
<ul>
<li><strong>Implementing a </strong><strong>Privacy Policy</strong></li>
<li>Vodafone Egypt’s Customer Privacy Policy concerns the handling of Data Subject’s personal information, including the collection, storage, access, use, updating, disclosure, disposal, destruction, or any other processing of such information. Gathering information from customers serves the purpose of operating Vodafone Egypt’s business and enhancing its customer experience. Vodafone Egypt’s Privacy Notice was updated in April 2020.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by Vodafone Egypt, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to Vodafone Egypt: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-vodafone-egypt-promotes-data-security-and-privacy/">Case study: How Vodafone Egypt promotes data security and privacy</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How Challenger promotes business integrity</title>
		<link>https://sustaincase.com/case-study-how-challenger-promotes-business-integrity/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Fri, 11 Dec 2020 06:46:37 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-415]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[GRI-419]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Financial Services]]></category>
		<category><![CDATA[business integrity]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[Challenger]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12015</guid>

					<description><![CDATA[<p>&#160; Challenger is Australia’s largest provider of annuities, providing reliable, guaranteed income payments to thousands of Australian retirees. Challenger recognises that its ability to continue to deliver value for its stakeholders relies on trust and confidence in its business. Accordingly, and actively engages in industry-wide commitments. This case study is based on the 2020 Sustainability Report by Challenger published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-challenger-promotes-business-integrity/">Case study: How Challenger promotes business integrity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<p>Challenger is Australia’s largest provider of annuities, providing reliable, guaranteed income payments to thousands of Australian retirees. Challenger recognises that its ability to continue to deliver value for its stakeholders relies on trust and confidence in its business. Accordingly, <strong>Challenger has set and maintains high standards of conduct</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=Challenger%20has%20set%20and%20maintains%20high%20standards%20of%20conduct&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-challenger-promotes-business-integrity%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a> and actively engages in industry-wide commitments.</p>
<p><strong>This case study is based on the</strong><strong> 2020 Sustainability Report by</strong> <strong>Challenger</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/80335/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p>Challenger’s values are integral to its culture and linked to everything Challenger does. They represent what makes Challenger’s culture special and set out the behaviours Challenger needs to meet community expectations and make sure it can deliver on its vision and strategy. In order to promote business integrity Challenger took action to:</p>
<ul>
<li>implement a Code of Conduct</li>
<li>apply a Political Donations policy</li>
<li>implement a Privacy policy</li>
<li>develop a Whistleblower policy</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) Challenger has identified;</li>
<li>How Challenger proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by Challenger to promote business integrity</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2020 Sustainability Report Challenger identified a range of material issues, such as long-term risk management, better customer outcomes, changing operating environment, public policy settings, economic uncertainty. Among these, promoting business integrity stands out as a key material issue for Challenger.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards              </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups</strong> <strong>Challenger</strong> <strong>engages with:</strong></p>
<p>To identify and prioritise material topics Challenger engaged with its stakeholders through the following channels:</p>
<table width="638">
<tbody>
<tr>
<td width="180"><strong>Stakeholder Group</strong></td>
<td width="459"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="180">Customers</td>
<td width="459">·       Survey</p>
<p>·       Call centre</p>
<p>·       Website and social media</p>
<p>·       Presentations</td>
</tr>
<tr>
<td width="180">Shareholders</td>
<td width="459">·       Regular financial reporting</p>
<p>·       Investor Days</p>
<p>·       Management meetings with investors and prospective investors</p>
<p>·       Chair engagement with significant investors</td>
</tr>
<tr>
<td width="180">Employees</td>
<td width="459">·       Intranet and Yammer</p>
<p>·       Employee briefings</p>
<p>·       Surveys</p>
<p>·       Senior leadership forums</p>
<p>·       ESG workshops</p>
<p>·       Ongoing team meetings</td>
</tr>
<tr>
<td width="180">Government &amp; regulators</td>
<td width="459">·       Policy analysis</p>
<p>·       Government and industry submissions</p>
<p>·       Industry forums and conferences</p>
<p>·       Ongoing meetings</td>
</tr>
<tr>
<td width="180">Communities</p>
<p>&nbsp;</td>
<td width="459">·       Strategic partnership</p>
<p>·       Volunteering</p>
<p>·       Workplace giving &amp; matching</p>
<p>·       Fundraising initiatives</p>
<p>·       Shared research activities</td>
</tr>
</tbody>
</table>
<p><strong>What actions were taken by</strong> <strong>Challenger</strong> <strong>to</strong> <strong>promote</strong> <strong>business integrity</strong><strong>?</strong></p>
<p>In its 2020 Sustainability Report Challenger reports that it took the following actions for promoting business integrity:</p>
<ul>
<li><strong>Implementing a </strong><strong>Code of Conduct</strong></li>
<li>In February 2020 Challenger refreshed and updated its Code of Conduct. The Code sets out expectations for how Challenger acts, solves problems and makes fair and balanced decisions. It brings together Challenger’s corporate values and its group policies and statements, outlining what is expected of leaders, how consequences are managed, and where employees can go to speak up. Challenger’s Code of Conduct sits across all areas of its business and applies to everyone, irrespective of their role, seniority or any other factor, and all Challenger employees have a shared Delivering on the UN SDGs responsibility to apply it consistently.</li>
</ul>
<ul>
<li><strong>Applying a Political Donations policy</strong></li>
<li>Challenger has taken the approach of not making political donations and understands the importance of following best practice approaches and remaining flexible to changing community expectations. At the same time, Challenger engages actively with politicians and other government representatives to contribute to effective public policy outcomes in a way that meets the expectations of its stakeholders and supports its customers and business.</li>
</ul>
<ul>
<li><strong>Implementing a</strong><strong> Privacy policy</strong></li>
<li>Challenger follows a ‘privacy-by-design’ approach, where privacy drives decision-making processes. This approach applies to every stakeholder and is used throughout Challenger’s Challenger’s Privacy policy sets out its approach for making sure it manages its customers’ information in a way that meets existing privacy regulations and customers’ expectations. Challenger has had no significant privacy complaints or breaches during the 2020 financial year and was not required to make any data breach reports to the Office of the Australian Information Commissioner under Australia’s Notifiable Data Breaches scheme during the year.</li>
</ul>
<ul>
<li><strong>Developing a </strong><strong>Whistleblower policy</strong></li>
<li>Challenger is committed to demonstrating transparency and enhancing stakeholder trust. Through its whistleblower provisions, employees, contractors, former employees, suppliers, service providers and relatives are encouraged to speak up. Challenger’s Whistleblower policy outlines the process for raising concerns and the protections and support available to whistleblowers. Challenger provides an independent whistleblower service so users can easily raise concerns through multiple channels and be assured of their anonymity if they desire.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standards addressed in this case are:</p>
<p>1) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-415-public-policy-2016/" target="_blank" rel="noopener noreferrer">Disclosure 415-1 Political contributions</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p>3) <a href="https://www.globalreporting.org/standards/media/1034/gri-419-socioeconomic-compliance-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 419-1 Non-compliance with laws and regulations in the social and economic area</a></p>
<p>&nbsp;</p>
<p><strong>Disclosure 415-1 </strong>Political contributions corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.5</li>
</ul>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p><strong>Disclosure 419-1</strong> Non-compliance with laws and regulations in the social and economic area corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by Challenger, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to Challenger: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-challenger-promotes-business-integrity/">Case study: How Challenger promotes business integrity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
