<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cyber security Archives - SustainCase - Sustainability Magazine</title>
	<atom:link href="https://sustaincase.com/tag/cyber-security/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Insights on how you can protect the environment, maintain and increase the value of your company, through a structured CSR/Sustainability process with the use of the GRI Standards. Learn how Today&#039;s Best-Run Companies are achieving Economic, Social, and Environmental Success - and How You Can Too...</description>
	<lastBuildDate>Fri, 03 Mar 2023 11:00:29 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>
	<item>
		<title>Case study: How Alperia promotes cybersecurity</title>
		<link>https://sustaincase.com/case-study-how-alperia-promotes-cybersecurity/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Wed, 28 Jul 2021 06:06:21 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Energy Utilities]]></category>
		<category><![CDATA[Alperia]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12770</guid>

					<description><![CDATA[<p>Alperia is South Tyrol’s leading energy service provider and one of the most important sustainable-energy companies in Italy. , deals with identity management and access control systems and intervenes in the event of any attacks. This case study is based on the 2019 Sustainability Report by Alperia published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing. [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-alperia-promotes-cybersecurity/">Case study: How Alperia promotes cybersecurity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Alperia is South Tyrol’s leading energy service provider and one of the most important sustainable-energy companies in Italy. <strong>Alperia deals with cybersecurity through a dedicated structure that defines and supervises cybersecurity architectures and systems</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=Alperia%20deals%20with%20cybersecurity%20through%20a%20dedicated%20structure%20that%20defines%20and%20supervises%20cybersecurity%20architectures%20and%20systems&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-alperia-promotes-cybersecurity%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a>, deals with identity management and access control systems and intervenes in the event of any attacks.</p>
<p><strong>This case study is based on the</strong><strong> 2019 Sustainability Report by</strong> <strong>Alperia</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/79861/" target="_blank" rel="noopener"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p>In 2019, Alperia’s protection systems blocked an average of 4.000 spam emails and 6.000 malicious connection attempts every day. In order to promote cybersecurity Alperia took action to:</p>
<ul>
<li>introduce new and better performing management systems</li>
<li>renew the ISO 27001 certification</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img fetchpriority="high" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="(max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) Alperia has identified;</li>
<li>How Alperia proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by Alperia to promote cybersecurity</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2019 Sustainability Report Alperia identified a range of material issues, such as security of supply, innovation, research and development, health and safety at work, asset integrity, energy consumption. Among these, promoting cybersecurity stands out as a key material issue for Alperia.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards               </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups </strong><strong>Alperia</strong> <strong>engages with:</strong></p>
<table width="261">
<tbody>
<tr>
<td width="261"><strong>Stakeholder Group</strong></td>
</tr>
<tr>
<td width="261">Customers</td>
</tr>
<tr>
<td width="261">Workforce</td>
</tr>
<tr>
<td width="261">Suppliers</td>
</tr>
<tr>
<td width="261">Owners and Investors</td>
</tr>
<tr>
<td width="261">Interest groups</td>
</tr>
<tr>
<td width="261">Citizens</td>
</tr>
<tr>
<td width="261">Research institutes</td>
</tr>
<tr>
<td width="261">Community</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics Alperia engaged with its stakeholders though an anonymous online survey which 176 participants answered.</p>
<p><strong>What actions were taken by</strong> <strong>Alperia</strong> <strong>to</strong> <strong>promote</strong> <strong>cybersecurity</strong><strong>?</strong></p>
<p>In its 2019 Sustainability Report Alperia reports that it took the following actions for promoting cybersecurity:</p>
<ul>
<li><strong>Introducing new and better performing management systems</strong></li>
<li>In 2019, Alperia introduced new and better performing management systems both inside and outside the Alperia world, also including Artificial Intelligence (AI) platforms. Attacks are becoming more frequent and high risk. Most are perpetrated by extremely sophisticated AI software, which is why it is necessary to use the same language in defence. In 2019, Alperia did not suffer from any significant cybersecurity incidents, but is aware of how important it is to protect yourself with increasingly sophisticated barrier systems. This is why Alperia introduced a double layer antivirus system for email and all the documents are classified according to a specific confidentiality level (public, restricted, confidential). Updating activities continue with trials of the disaster recovery plan and adoption of protection systems against ransomware threats.</li>
</ul>
<ul>
<li><strong>Renewing the ISO 27001 certification</strong></li>
<li>In 2019, Alperia renewed its ISO 27001 certification, which was extended to include even more stringent checking. This international standard recognises the group’s adoption of a secure system for the management of company information systems (IT and documentary), to monitor and reduce management costs, ensure adequate service levels and monitor and reduce the risk of possible outages. The certification is subject to an annual audit, with additional checks carried out by the group’s Internal Audit. During 2019, Alperia’s business continuity plan was also developed to be activated in the event of attacks. In compliance with the requirements of Europe’s GDPR regulation, a Data Protection Officer (DPO) was appointed external to the IT department. A new privacy-by-design procedure was developed, to be carried out at the start of each new project in order to check if it meets the standards set by privacy and GDPR legislation.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by Alperia, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to Alperia: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-alperia-promotes-cybersecurity/">Case study: How Alperia promotes cybersecurity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How Sempra Energy promotes cybersecurity</title>
		<link>https://sustaincase.com/case-study-how-sempra-energy-promotes-cybersecurity/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Fri, 23 Jul 2021 06:07:54 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Energy]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Sempra Energy]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12761</guid>

					<description><![CDATA[<p>Sempra Energy is an energy infrastructure company with 2019 revenues of $10.8 billion, investing in, developing and operating transmission and distribution infrastructure in the most attractive markets in North America. Cybersecurity at Sempra Energy is about people, processes and technology working together to protect systems, networks and programmes from digital attacks. This case study is based on the 2019 Corporate Sustainability Report by Sempra Energy published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-sempra-energy-promotes-cybersecurity/">Case study: How Sempra Energy promotes cybersecurity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Sempra Energy is an energy infrastructure company with 2019 revenues of $10.8 billion, investing in, developing and operating transmission and distribution infrastructure in the most attractive markets in North America. Cybersecurity at Sempra Energy is about people, processes and technology working together to protect systems, networks and programmes from digital attacks.</p>
<p><strong>This case study is based on the</strong><strong> 2019 Corporate Sustainability Report by</strong> <strong>Sempra Energy</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/78568/" target="_blank" rel="noopener"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p><strong>Sempra Energy is committed to dealing effectively with cybersecurity threats</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=Sempra%20Energy%20is%20committed%20to%20dealing%20effectively%20with%20cybersecurity%20threats&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-sempra-energy-promotes-cybersecurity%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a> to its energy grid, storage and pipeline infrastructure, as well as the information and systems used to operate its businesses. In order to promote cybersecurity Sempra Energy took action to:</p>
<ul>
<li>establish an information security team</li>
<li>implement an information security awareness programme</li>
<li>use an automated SPAM reporting button</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="(max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) Sempra Energy has identified;</li>
<li>How Sempra Energy proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by Sempra Energy to promote cybersecurity</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2019 Corporate Sustainability Report Sempra Energy identified a range of material issues, such as reliability, affordability, greenhouse gas emissions, public safety, disaster preparedness and response. Among these, promoting cybersecurity stands out as a key material issue for Sempra Energy.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards               </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups Sempra Energy engages with:</strong></p>
<table width="479">
<tbody>
<tr>
<td width="135"><strong>Stakeholder Group</strong></td>
<td width="344"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="135">Customers</td>
<td width="344">·      In-person meetings or phone calls</p>
<p>·      Open houses, town hall meetings</p>
<p>·      Ethics &amp; compliance helpline</p>
<p>·      Website content</p>
<p>·      Surveys</p>
<p>·      Print or social media</td>
</tr>
<tr>
<td width="135">Communities</p>
<p>&nbsp;</td>
<td width="344">·      In-person meetings or phone calls</p>
<p>·      Open houses, town hall meetings</p>
<p>·      Ethics &amp; compliance helpline</p>
<p>·      Website content</p>
<p>·      Corporate sustainability report</p>
<p>·      Facility tours</p>
<p>·      Surveys</p>
<p>·      Print or social media</td>
</tr>
<tr>
<td width="135">Employees</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      In-person meetings or phone calls</p>
<p>·      Open houses, town hall meetings</p>
<p>·      Ethics &amp; compliance helpline</p>
<p>·      Website content</p>
<p>·      Corporate sustainability report</p>
<p>·      Facility tours</p>
<p>·      Surveys</p>
<p>·      Print or social media</td>
</tr>
<tr>
<td width="135">Investors and shareholders</p>
<p>&nbsp;</td>
<td width="344">·      In-person meetings or phone calls</p>
<p>·      Open houses, town hall meetings</p>
<p>·      Ethics &amp; compliance helpline</p>
<p>·      Website content</p>
<p>·      Corporate sustainability report</p>
<p>·      Facility tours</p>
<p>·      Print or social media</td>
</tr>
<tr>
<td width="135">Regulators, elected officials, community leaders</p>
<p>&nbsp;</td>
<td width="344">·      In-person meetings or phone calls</p>
<p>·      Open houses, town hall meetings</p>
<p>·      Ethics &amp; compliance helpline</p>
<p>·      Website content</p>
<p>·      Corporate sustainability report</p>
<p>·      Facility tours</p>
<p>·      Print or social media</td>
</tr>
<tr>
<td width="135">Suppliers, contractors, business partners</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      In-person meetings or phone calls</p>
<p>·      Open houses, town hall meetings</p>
<p>·      Ethics &amp; compliance helpline</p>
<p>·      Website content</p>
<p>·      Corporate sustainability report</p>
<p>·      Facility tours</p>
<p>·      Print or social media</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics Sempra Energy interviewed stakeholders to gain their perspectives on current and emerging priorities.</p>
<p><strong>What actions were taken by</strong> <strong>Sempra Energy</strong> <strong>to</strong> <strong>promote</strong> <strong>cybersecurity</strong><strong>?</strong></p>
<p>In its 2019 Corporate Sustainability Report Sempra Energy reports that it took the following actions for promoting cybersecurity:</p>
<ul>
<li><strong>Establishing an information security team</strong></li>
<li>Sempra Energy’s information security team conducts regular penetration tests and analyses the results to improve existing controls and identify opportunities for improvement. Members of this team also participate in department staff meetings, safety stand downs and safety congresses to provide perspective and training on cybersecurity issues. Individual employees across the company support these efforts as “cybersecurity champions,” sharing relevant information with their teams.</li>
</ul>
<ul>
<li><strong>Implementing an information security awareness programme</strong></li>
<li>Sempra Energy’s information security awareness programme includes periodic communications, companywide events and campaigns, mandatory annual web-based training, facility-specific town hall events and a cross-business advocacy programme. Sempra Energy supports these efforts with articles, webpage communications and digital signage.</li>
</ul>
<ul>
<li><strong>Using an </strong><strong>automated SPAM reporting button</strong></li>
<li>An automated SPAM reporting button in Microsoft Outlook allows easy one-click reporting of suspicious and unwanted emails. In fact, to keep this reporting option top-of-mind, Sempra Energy’s cybersecurity team utilises “fake” phishing attempts and sends congratulatory messages when employees take the correct action by clicking the SPAM button. Sempra’s 24/7 Information Security Operations Centre (SOC) also responds to reports of suspicious email. The SOC can pull a suspicious email from the enterprise, reducing the risk of infecting other users or devices.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by Sempra Energy, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to Sempra Energy: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-sempra-energy-promotes-cybersecurity/">Case study: How Sempra Energy promotes cybersecurity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How SCB promotes cyber security</title>
		<link>https://sustaincase.com/case-study-how-scb-promotes-cyber-security/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Wed, 17 Mar 2021 07:14:47 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Financial Services]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[SCB]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12325</guid>

					<description><![CDATA[<p>Siam Commercial Bank (SCB) is a leading global bank and the first local bank that has been part of the Thai society for 114 years, creating and offering end-to-end financial solutions to fulfill the needs of all groups of customers. To ensure continuity and effectiveness in its operation, SCB places heavy emphasis on data governance and cyber security by developing systems and infrastructure, investing in technologies, enhancing employee capabilities, and improving processes to keep pace with change. This case study is based on the 2019 Sustainability Report by SCB published on the Global Reporting Initiative Sustainability Disclosure Database that can be [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-scb-promotes-cyber-security/">Case study: How SCB promotes cyber security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Siam Commercial Bank (SCB) is a leading global bank and the first local bank that has been part of the Thai society for 114 years, creating and offering end-to-end financial solutions to fulfill the needs of all groups of customers. To ensure continuity and effectiveness in its operation, SCB places heavy emphasis on data governance and cyber security by developing systems and infrastructure, investing in technologies, enhancing employee capabilities, and improving processes to keep pace with change.</p>
<p><strong>This case study is based on the</strong><strong> 2019 Sustainability Report</strong> <strong>by SCB </strong><strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/79548/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p><strong>SCB seeks to continuously improve its data governance and cyber security</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=SCB%20seeks%20to%20continuously%20improve%20its%20data%20governance%20and%20cyber%20security&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-scb-promotes-cyber-security%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a> so as to make sure that data on all of its systems and digital platforms are managed with care and adequately protected against new threats, and that there shall be no breach in customer data privacy. In order to promote cyber security SCB took action to:</p>
<ul>
<li>implement an Information Security Policy</li>
<li>integrate cyber security into its software development and operations</li>
<li>build a data and cyber security culture</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="(max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) SCB has identified;</li>
<li>How SCB proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by SCB to promote cyber security</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified? </strong></p>
<p>In its 2019 Sustainability Report SCB identified a range of material issues, such as corporate governance and risk management, customer experience, financial inclusion, responsible lending. Among these, promoting cyber security stands out as a key material issue for SCB.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards                         </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups SCB engages with:</strong><strong> </strong></p>
<table width="479">
<tbody>
<tr>
<td width="128"><strong>Stakeholder Group</strong></td>
<td width="351"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="128">Customers</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="351">·      Customer relationship-building activity</p>
<p>·      Information sessions on SCB financial products and services</p>
<p>·      Providing financial advice and knowledge to customers through online media, branch network and other electronic channels</p>
<p>·      Customer satisfaction surveys through telephone, questionnaire and electronic channels</p>
<p>·      Complaint and service channels through Customer Centre, Branch network and SCB Easy app</td>
</tr>
<tr>
<td width="128">Employees</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="351">·      Meetings and online channels for policy and news announcement</p>
<p>·      Employee meetings, seminars and CSR activities</p>
<p>·      Annual performance evaluation</p>
<p>·      Employment engagement survey</p>
<p>·      Employee development programme</p>
<p>·      Employee recognition programme</p>
<p>·      Employee hotline</td>
</tr>
<tr>
<td width="128">Shareholders</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="351">·      Annual general meeting</p>
<p>·      Extraordinary general meeting</p>
<p>·      56-1 Report</p>
<p>·      Annual report (Form 56-2)</p>
<p>·      Press release</p>
<p>·      Quarterly financial report</p>
<p>·      Investor meeting/conference</p>
<p>·      Investor call</p>
<p>·      Equity analyst meeting</p>
<p>·      Global roadshow event</td>
</tr>
<tr>
<td width="128">Society and Environment</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="351">·      Projects and initiatives by SCB and the Siam Commercial Bank Foundation</p>
<p>·      Community and social surveys</p>
<p>·      Community engagement activities</td>
</tr>
<tr>
<td width="128">Regulators</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="351">·      Assign Compliance unit to serve as SCB’s regulatory liaison</p>
<p>·      Attend meetings and hearings on regulatory policies and guidance from relevant authorities</p>
<p>·      Attend forums on regulatory compliance</p>
<p>·      Seek feedback and guidance on regulatory compliance</p>
<p>·      Offer feedback on regulations through public hearings</p>
<p>·      Prepare and provide support for regulatory audit</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics SCB conducted in-depth interviews with selected groups of stakeholders to collect suggestions, feedback and information on economic, social and environmental material topics.</p>
<p><strong><a href="https://fbrh.co.uk/en/gri-certified-training/2-day-fbrh-gri-standards-certified-training-course-about" target="_blank" rel="noopener noreferrer"><img loading="lazy" decoding="async" class="alignright size-full wp-image-11761" src="https://sustaincase.com/wp-content/uploads/2020/08/sustainability-GRI-report-key-doc-for-success-ad-sustaincase-GRI-SDG-ESG-Sustainability-report-200x320px.jpg" alt="" width="200" height="320" /></a>What actions were taken by</strong> <strong>SCB</strong> <strong>to</strong> <strong>promote cyber security</strong><strong>?</strong></p>
<p>In its 2019 Sustainability Report SCB reports that it took the following actions for promoting cyber security:</p>
<ul>
<li><strong>Implementing an</strong> <strong>Information Security Policy</strong></li>
<li>Based on the Confidentiality-Integrity-Availability (CIA) triad, the SCB Financial Group Information Security Policy is communicated to all employees, including those in probationary periods and on temporary contracts, suppliers and consultants, from whom strict compliance is expected. The Policy also assigns the Audit Unit to perform an audit and make recommendations for further improving cyber security. SCB has adopted a proactive approach to cyber security by focusing on developing technology and processes for cyber threat detection, such as the Cybersecurity Threat Intelligent Surveillance system and machine learning technology to study the pattern of cyber-attacks, both internally and externally. This proactive approach enables SCB to assess the situation and be ready to respond and prevent potential losses. Additionally, for data storage with comparable effectiveness to on-premise storage, SCB uses Cloud Computing Technology to keep potential risk under its risk appetite level, to increase operational speed, and to lower the cost of maintaining the internal computer network and systems. Moreover, cyber security performance is regularly reported to senior management in a dashboard format. To be ready for an emergency situation and make sure that systems can be recovered back to normal service and operation in an appropriate timeframe, SCB has also established a policy and guideline for preparing an IT Contingency Plan, which is aligned with its Business Continuity Plan. This contingency plan defines processes, practices and the roles and responsibilities of the relevant business units in executing, testing, reviewing and revising the IT Contingency Plan according to the business context.</li>
</ul>
<ul>
<li><strong>Integrating cyber security into </strong><strong>software </strong><strong>development and operations </strong></li>
<li>In 2019, SCB upgraded its software development approach from DevOps to DevSecOps (Development Security Operations), whereby cyber security is integrated as part of SCB’s development and operations life cycle. This means that cyber security control measures are embedded throughout SCB’s software development life cycle to enhance the ability to create innovation and make further product and service improvements to deliver even greater speed, effectiveness, and security. Through this approach, SCB added security automation tools in the software development process to make security testing faster and more effective. The automation tools allow SCB’s software developers and system administrators to perform security testing on their own and detect any vulnerability after the software launch, receiving timely reports on potential problems.</li>
</ul>
<ul>
<li><strong>Building a data and cyber security culture</strong></li>
<li>In parallel with continuously investing in technology and developing cyber security systems that meet global standards, SCB is committed to building a data and cyber security culture for employees at every level. SCB uses work processes, training and internal communication to promote awareness on appropriate and secure data handling, data protection, cyber risk, and cyber threat prevention. Accordingly, SCB provides a data classification training course on its e-learning system to promote appropriate and secure data usage throughout the organisation and offers a cyber security course to senior executives which covers topics such as causes of cyber-attacks and impacts of cyber threats. Employees at all levels are also required to take the mandatory course on cyber security on the system which focuses on basic knowledge regarding data protection, on understanding the forms and impacts of cyber threats through simulation, and on how to prevent and report an incident. Throughout 2019, SCB organised “Don’t Let It Happen” activities to promote awareness on cyber threats, cyber risks, and data security protection with an emphasis on safeguarding the data of both customers and SCB and building awareness on risk behaviours that may cause damage to the business or SCB ‘s One of the highlights that attracted many participants was the “Cybersecurity Awareness Day 2019,” which featured talks by external experts regarding cyber security on topics such as knowing tricks of cyber criminals inside out, understanding data risk, and using personal information on social media.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by SCB, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to SCB: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-scb-promotes-cyber-security/">Case study: How SCB promotes cyber security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How MKB promotes information security</title>
		<link>https://sustaincase.com/case-study-how-mkb-promotes-information-security/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Fri, 19 Feb 2021 07:06:09 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Financial Services]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[customer privacy]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[MKB]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12264</guid>

					<description><![CDATA[<p>MKB is one of the largest private banks in Russia, offering a full package of financial services through a regional network that includes more than 130 offices in 19 regions. Adhering to the principles of socially responsible business conduct, This case study is based on the 2019 Sustainability Report by MKB published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-mkb-promotes-information-security/">Case study: How MKB promotes information security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>MKB is one of the largest private banks in Russia, offering a full package of financial services through a regional network that includes more than 130 offices in 19 regions. Adhering to the principles of socially responsible business conduct, <strong>MKB complies with both Russian and international laws on personal data processing and protection.</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=MKB%20complies%20with%20both%20Russian%20and%20international%20laws%20on%20personal%20data%20processing%20and%20protection.&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-mkb-promotes-information-security%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a></p>
<p><strong>This case study is based on the</strong><strong> 2019 Sustainability Report by</strong> <strong>MKB</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/80711/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p>The design of MKB’s current and future processes and products assumes obtaining consents from customers, counterparties, and the bank’s employees for the processing of their personal data, for the minimum use of their data when in interaction between the employees and the bank’s systems, and for the provision of the “security by design” and “security by default” concepts. In order to promote information security MKB took action to:</p>
<ul>
<li>combat fraud</li>
<li>promote cybersecurity</li>
<li>identify and eliminate vulnerabilities</li>
<li>respond to information security incidents in a timely manner</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) MKB has identified;</li>
<li>How MKB proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by MKB to promote information security</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified? </strong></p>
<p>In its 2019 Sustainability Report MKB identified a range of material issues, such as customer satisfaction, increasing the accessibility of services, economic efficiency, professional development and training of employees. Among these, promoting information security stands out as a key material issue for MKB.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards               </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups MKB engages with:</strong></p>
<table width="479">
<tbody>
<tr>
<td width="135"><strong>Stakeholder Group</strong></td>
<td width="344"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="135">Customers</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Customer service, including development of the network of branch offices</p>
<p>·      Receiving queries</p>
<p>·      Remote banking service (mobile banking, contact centre, internet banking)</p>
<p>·      Information about bank products, reporting, availability of branch offices of the Bank, environmental plans and actions, and other important information as published on the MKB website (Russian or English version)</p>
<p>·      Analysis of customer satisfaction</td>
</tr>
<tr>
<td width="135">Employees</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Advanced training</p>
<p>·      Benefits package</p>
<p>·      Support and assistance in developing internal corporate sports clubs and events for the company employees</p>
<p>·      Participation in sports events, charitable, and other public and environmental events</p>
<p>·      Corporate portal</p>
<p>·      The hotline that allows sending complaints and queries to the members of the Audit and Risk Committee under the MKB Supervisory Board</td>
</tr>
<tr>
<td width="135">Society</td>
<td width="344">·      Participation in social and environmental projects of the Russian Government, other governmental bodies, and development of its own projects</p>
<p>·      Development of financial products for different categories of people</p>
<p>·      Support of small and medium business entities</p>
<p>·      Development of a regional network of offices and creation of additional jobs in the regions</p>
<p>·      Interaction with higher educational institutions, probation programmes, training</td>
</tr>
<tr>
<td width="135">Shareholders and investors</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Meetings of shareholders</p>
<p>·      Communication using different channels (including conference calls, meetings, correspondence via email, webcasts)</p>
<p>·      Disclosure of information important for shareholders and investors on the electronic page for investors (in Russian and English)</p>
<p>·      Publication of financial and nonfinancial reports</td>
</tr>
<tr>
<td width="135">Counterparties and partners</td>
<td width="344">·      A transparent competitive procurement system</p>
<p>&nbsp;</td>
</tr>
<tr>
<td width="135">Governmental bodies and regulators</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Information disclosure and compliance with all legislative requirements in the field of banking activities</p>
<p>·      Participation in projects and work meetings on the improvement of laws in different areas (expert councils, work groups, round-table discussions, and other forms of communications)</p>
<p>·      Contribution to the development of regions with the extension of the regional network of presence</td>
</tr>
<tr>
<td width="135">Mass media</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="344">·      Regular communications with the key media, prompt response to incoming questions</p>
<p>·      A high level of content mobility on the MKB website, in social networks, and other sources of communication</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics MKB engaged with its stakeholders through an interactive survey tool.</p>
<p><strong>What actions were taken by</strong> <strong>MKB</strong> <strong>to</strong> <strong>promote information security</strong><strong>?</strong></p>
<p>In its 2019 Sustainability Report MKB reports that it took the following actions for promoting information security:</p>
<ul>
<li><strong>Combating fraud</strong></li>
<li>MKB pursues a zero-tolerance policy toward illegal actions against its customers. For this purpose, MKB:
<ul>
<li>has implemented and maintains fraud monitoring processes for remote banking;</li>
<li>investigates any attempts of stealing funds from the bank’s customers;</li>
<li>interacts with the Bank of Russia and other credit institutions, communication service providers, and law enforcement agencies for the exchange of information about the actions of fraudsters and for the timely prevention of fraudulent activities;</li>
<li>implements the programme for enhanced protection of systems and data, which is reviewed annually and updated completely every three years.</li>
</ul>
</li>
<li>The above activities resulted in dozens of prevented attempts of stealing funds from legal entities and individuals, which saved them dozens of million rubles. The only loss by a legal entity because of the fraudster’s actions in the remote business education system (RBES) in 2019 amounted to RUB 3,000; the transaction was marked as suspicious but was additionally confirmed by the customer itself.</li>
</ul>
<ul>
<li><strong>Promoting cybersecurity</strong></li>
<li>MKB pays much attention to information security and resistance to cyber threats. The following biggest threats for MKB were identified within the frames of its information security strategy:
<ul>
<li>External attacks as a result of actions of hacker groups, which are aimed at stealing data or money via payment systems</li>
<li>Attacks aimed at customers and stealing customers’ funds via remote banking services</li>
<li>Fraudulent actions of the bank’s employees or counterparties, which may cause data leaks or thefts using authorised access to MKB’s information systems</li>
<li>Logical attacks at ATMs (use of special software for money disbursement without using cards and for debiting accounts) and payment terminals (use of special software to reload cards without cash)</li>
</ul>
</li>
<li>The following projects were initiated and successfully finished for the implementation of measures to prevent the materialisation of threats:
<ul>
<li>Implementation of the next generation firewall as a basic element of protection against external attacks</li>
<li>Implementation of a solution to counter targeted attacks made using malicious emails or malicious websites, which use 0-day vulnerabilities and are not detected by standard means of protection, for example, antivirus software (as a result of system operation, over 650 targeted attacked were repelled)</li>
<li>Implementation and development of the personnel training system simulating sending of malicious attachments and fishing links by hackers and appointing testing automatically if an employee opens such attachments or types a password to their account on the websites available at the fishing links</li>
<li>Development and implementation of an antifraud system to identify abnormal and illegal payments sent to the Bank of Russia or to the international data transfer and payment system SWIFT</li>
</ul>
</li>
</ul>
<ul>
<li><strong>Identifying and eliminating vulnerabilities</strong></li>
<li>To minimise the probability of merely technical vulnerabilities typical of information systems and logical vulnerabilities affecting customer service processes and products, MKB started supporting the following processes in 2019:
<ul>
<li>External scanning of vulnerabilities; full coverage was reached for all 179 publications of MKB’s services on the web and external networks, scanning results are recognised by auditors as performed by the Approved Scanning Vendor as part of the PCI DSS (Payment Card Industry Data Security Standard) standard conformity audits.</li>
<li>A red team was set up—that is, a group of specialists with qualifications similar to hackers, whose main task is to conduct penetration tests and identify vulnerabilities through the eyes of hackers for the purpose of thorough identification of vulnerabilities that cannot be identified instrumentally.</li>
<li>The Information Security Department participates in, and controls, all tasks of IT development, including the following:
<ul>
<li>Analysis of business requirements</li>
<li>Analysis of technical assignments</li>
<li>Formation of a set of requirements for the implementation of security-by-design and security-by-default concepts for all services and products developed by MKB</li>
<li>Verification of the fulfilment of requirements before bringing the implemented tasks in action</li>
<li>Participation of red team specialists for the purpose of vulnerability analysis in any services published on the web and in any payment applications</li>
</ul>
</li>
<li>External penetration tests organised by the internal audit are performed by specialised companies with highly proficient specialists.</li>
</ul>
</li>
</ul>
<ul>
<li><strong>Responding to information security incidents in a timely manner</strong></li>
<li>To monitor and provide timely response to information security incidents, MKB has a security incidents response team. In 2019, the work of this team, operating as part of the Information Security Department, resulted in the creation of the monitoring system architecture, implementation of the subsystem of collection and primary analysis of incidents, implementation of the incident response platform, and automation of the formation of any incidents as tasks for the team members in the implemented platform. The ongoing processes are built so that the time from the attack to the analysis of the processes within the attack and to the termination of the attack usually does not exceed 4 hours.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed?</strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by MKB, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to MKB: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-mkb-promotes-information-security/">Case study: How MKB promotes information security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How Bank Muscat promotes cybersecurity</title>
		<link>https://sustaincase.com/case-study-how-bank-muscat-promotes-cybersecurity/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Mon, 11 Jan 2021 06:56:54 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Financial Services]]></category>
		<category><![CDATA[Bank Muscat]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=12119</guid>

					<description><![CDATA[<p>Bank Muscat is the leading financial institution in Oman, with a strong presence in corporate banking, personal banking, investment banking, Islamic banking, treasury, private banking and asset management. As cybercrimes can cause enormous financial and material losses for both victims and the economy, so as to safeguard, according to strict standards of security and confidentiality, any information customers share with the Bank. This case study is based on the 2019 Sustainability Report by Bank Muscat published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-bank-muscat-promotes-cybersecurity/">Case study: How Bank Muscat promotes cybersecurity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Bank Muscat is the leading financial institution in Oman, with a strong presence in corporate banking, personal banking, investment banking, Islamic banking, treasury, private banking and asset management. As cybercrimes can cause enormous financial and material losses for both victims and the economy, <strong>Bank Muscat remains vigilant in its cybersecurity efforts</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=Bank%20Muscat%20remains%20vigilant%20in%20its%20cybersecurity%20efforts&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-bank-muscat-promotes-cybersecurity%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a> so as to safeguard, according to strict standards of security and confidentiality, any information customers share with the Bank.</p>
<p><strong>This case study is based on the</strong><strong> 20</strong><strong>19 </strong><strong>Sustainability Report by</strong> <strong>Bank Muscat</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/80568/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p>Bank Muscat’s information/cybersecurity management function helps to secure information within the Bank, as well as keep the Bank secured from cybersecurity risks. In order to promote cybersecurity Bank Muscat took action to:</p>
<ul>
<li>identify and address cybersecurity risks</li>
<li>improve cybersecurity measures</li>
<li>launch an anti-fraud public awareness campaign</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) Bank Muscat has identified;</li>
<li>How Bank Muscat proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by Bank Muscat to promote cybersecurity</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2019 Sustainability Report Bank Muscat identified a range of material issues, such as customer relationship management, employee training and development, responsible investing, Anti-Money Laundering and Anti-Financing of Terrorism (AML and AFT). Among these, promoting cybersecurity stands out as a key material issue for Bank Muscat.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards              </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups</strong> <strong>Bank Muscat</strong> <strong>engages with:                     </strong></p>
<table width="638">
<tbody>
<tr>
<td width="180"><strong>Stakeholder Group</strong></td>
<td width="459"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="180">Employees</td>
<td width="459">·       Annual performance reviews</p>
<p>·       Regular dialogue and interaction with employees</p>
<p>·       Training and education programmes</p>
<p>·       Grievance mechanism</p>
<p>·       Polls and survey</td>
</tr>
<tr>
<td width="180">Customers</td>
<td width="459">·       Call Centre Feedback Management System (FMS)</p>
<p>·       Company website</p>
<p>·       Focus groups</p>
<p>·       Customer networking events for specific customer segments</p>
<p>·       Branches and access points including ATMs and CDMs</p>
<p>·       Media and social media channels</p>
<p>·       Annual report and sustainability report</p>
<p>·       Other bank publications including investor presentations</td>
</tr>
<tr>
<td width="180">Government (Including Regulatory Bodies)</td>
<td width="459">·       Government Business Division</p>
<p>·       Investment in the national economy</p>
<p>·       Supporting initiatives of national importance</td>
</tr>
<tr>
<td width="180">Correspondent / Other Banks / International Entities</td>
<td width="459">·       Financial Institutions Group (FIG)</p>
<p>·       Company website and other publications</p>
<p>·       Roadshows and presentations</td>
</tr>
<tr>
<td width="180">Shareholders/ Investors</p>
<p>&nbsp;</td>
<td width="459">·       Investor Relations Department</p>
<p>·       Shareholder meetings</p>
<p>·       Roadshows and presentations</p>
<p>·       Company website and other publications</td>
</tr>
<tr>
<td width="180">Local, Regional &amp; International Media</td>
<td width="459">·       Media, social media and other publications</p>
<p>·       Press conferences</p>
<p>·       Media networking events</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics Bank Muscat engaged with its stakeholders through interviews and surveys.</p>
<p><strong>What actions were taken by</strong><strong> Bank Muscat</strong> <strong>to</strong> <strong>promote</strong> <strong>cybersecurity</strong><strong>?</strong></p>
<p>In its 2019 Sustainability Report Bank Muscat reports that it took the following actions for promoting cybersecurity:</p>
<ul>
<li><strong>Identifying and addressing cybersecurity risk</strong><strong>s</strong></li>
<li>Bank Muscat continuously invests in maintaining and updating the systems and processes that are designed to ensure the security of the Bank’s computer systems, software, networks and other technology assets. Bank Muscat’s information/cybersecurity risk management function focuses on the following key aspects:
<ul>
<li>Cybersecurity incident response plans in order to implement effective management of cybersecurity incidents</li>
<li>Information security governance through security policies, procedures, guidelines and standards</li>
<li>Information security monitoring using the latest solutions and tools, including real time as well as fixed frequency monitoring</li>
<li>Implementing a robust security defence network as well as maintaining strong internal controls</li>
<li>Information security reviews comprising new and existing technologies, solutions, networks and also the various processes/ operations within each and every department of the Bank</li>
</ul>
</li>
</ul>
<ul>
<li><strong>Improv</strong><strong>ing</strong><strong> cybersecurity measures</strong></li>
<li>In 2019, Bank Muscat partnered with the Information Technology Authority (ITA) to improve cybersecurity measures. The Bank took part in a series of cybersecurity events organised by the ITA, including the 8th Regional Cybersecurity Summit, FIRST &amp; International Telecommunication Union Arab Regional Cyber Security Centre (ITU-ARCC), and the 7th Regional Cyber Drill. Bank Muscat also participated in the Cybersecurity Readiness drill, held under the theme “Intelligence of Malware” and organised by the National Computer Emergency Readiness Team (OCERT) to assess cybersecurity readiness in Organisation of Islamic Cooperation (OIC) countries.</li>
</ul>
<ul>
<li><strong>Launch</strong><strong>ing</strong><strong> an anti-fraud public awareness campaign</strong></li>
<li>In 2019, the Royal Oman Police (ROP) and Bank Muscat launched an anti-fraud public awareness campaign. The campaign focused on educating the community not to share their personal details or their banking/card details with anyone over the phone, and not to input them on links received through social media or messaging.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p><strong> </strong></p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by Bank Muscat, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to Bank Muscat: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-bank-muscat-promotes-cybersecurity/">Case study: How Bank Muscat promotes cybersecurity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How Wells Fargo promotes cybersecurity</title>
		<link>https://sustaincase.com/case-study-how-wells-fargo-promotes-cybersecurity/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Wed, 25 Nov 2020 06:44:34 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Financial Services]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[Wells Fargo]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=11918</guid>

					<description><![CDATA[<p>Wells Fargo is a diversified, community-based financial services company, with $1.97 trillion in assets and approximately 266,000 active, full-time equivalent employees serving one in three households in the United States. This case study is based on the 2020 ESG Report by Wells Fargo published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing. Abstract Wells Fargo is [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-wells-fargo-promotes-cybersecurity/">Case study: How Wells Fargo promotes cybersecurity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Wells Fargo is a diversified, community-based financial services company, with $1.97 trillion in assets and approximately 266,000 active, full-time equivalent employees serving one in three households in the United States. <strong>As Wells Fargo manages billions of customer interactions each year, it takes a proactive approach to information security and cybersecurity.</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=As%20Wells%20Fargo%20manages%20billions%20of%20customer%20interactions%20each%20year%2C%20it%20takes%20a%20proactive%20approach%20to%20information%20security%20and%20cybersecurity.&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-wells-fargo-promotes-cybersecurity%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a></p>
<p><strong>This case study is based on the</strong><strong> 2020 ESG Report by</strong> <strong>Wells Fargo</strong> <strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/80299/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p>Wells Fargo is continuously investing in emerging technologies and leveraging its digital channels and assets with the goal of making digital banking faster, easier, smarter, and safer for its customers. In order to promote cybersecurity Wells Fargo took action to:</p>
<ul>
<li>implement the Information Security Programme</li>
<li>increase cybersecurity awareness</li>
<li>implement a Third-Party Information Security Risk Management Programme</li>
<li>train employees to protect customer information</li>
<li>educate customers on digital security</li>
<li>protect data in open banking environments</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) Wells Fargo has identified;</li>
<li>How Wells Fargo proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by Wells Fargo to promote cybersecurity</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2020 ESG Report Wells Fargo identified a range of material issues, such as business ethics, climate risk management, community development, environmental and social due diligence, fair and responsible lending and pricing. Among these, promoting cybersecurity stands out as a key material issue for Wells Fargo.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards               </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups </strong><strong>Wells Fargo</strong> <strong>engages with:</strong><strong> </strong></p>
<table width="261">
<tbody>
<tr>
<td width="261"><strong>Stakeholder Group</strong></td>
</tr>
<tr>
<td width="261">Customers</td>
</tr>
<tr>
<td width="261">Employees</td>
</tr>
<tr>
<td width="261">Community members</td>
</tr>
<tr>
<td width="261">Suppliers</td>
</tr>
<tr>
<td width="261">Shareholders</td>
</tr>
<tr>
<td width="261">Regulators</td>
</tr>
<tr>
<td width="261">Media</td>
</tr>
<tr>
<td width="261">Analysts</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics Wells Fargo interviewed internal and external stakeholders, including more than 30 Wells Fargo leaders and subject matter experts from across the company and members of its external Stakeholder Advisory Council. Wells Fargo also included content from stakeholders representing Wells Fargo customers, employees, ESG (Environmental, Social and Governance) investors, government, media, NGOs, and financial peers.</p>
<p><strong>What actions were taken by</strong> <strong>Wells Fargo</strong> <strong>to</strong> <strong>promote</strong> <strong>cybersecurity?</strong></p>
<p>In its 2020 ESG Report Wells Fargo reports that it took the following actions for promoting cybersecurity:</p>
<ul>
<li><strong>Implementing the Information Security Programme </strong></li>
<li>Wells Fargo’s Information and Cyber Security (ICS) organisation aims to protect Wells Fargo systems, networks, and customer data through the design, execution, and oversight of its Information Security Programme (ISP). ICS is led by Wells Fargo’s chief information security officer, who reports to the head of Wells Fargo Technology. The Wells Fargo Board of Directors annually approves the ISP and is kept informed of the ongoing status of the programme. Wells Fargo organisations and employees, as well as vendors, nonemployees, and third parties with access to its systems or sensitive information, must adhere to the ISP’s policies, procedures, and requirements. Those requirements are designed to help make certain that information security risks are effectively identified, assessed, mitigated, and reported throughout Wells Fargo. The Wells Fargo ISP is designed to comply with applicable laws and regulations, and uses guidance from many industry best practices, including the National Institute of Standards and Technology (NIST) Cybersecurity Framework, the International Organization for Standardization (ISO) 27002 standard, the Payment Card Industry Data Security Standards, and COBIT 5.</li>
</ul>
<ul>
<li><strong>Increasing cybersecurity awareness</strong></li>
<li>From malicious software to phishing emails, cyberattacks on the internet have created an urgent need to increase Wells Fargo’s cybersecurity awareness. Wells Fargo’s ICS Cyber Threat Management team supports threat and vulnerability management, and intrusion detection policies. It also develops best practices based on an assessment of the internal and external threat landscape, and leads companywide efforts to reduce Wells Fargo’s exposure through continuous monitoring of several key information security control areas, including:
<ul>
<li>Management of security patches and security configurations</li>
<li>Condition and activity monitoring</li>
<li>Threat and vulnerability management</li>
<li>Patch management processes</li>
</ul>
</li>
<li>Wells Fargo’s defense strategy includes continuous monitoring, integrated risk management, identification of human risk factors, enhanced customer awareness, and external engagement on best practices. Wells Fargo prepares the enterprise for cyberattack scenarios through education, training and simulations, also conducting cyber exercises with other financial services companies and government agencies to help build a stronger, more secure environment for the entire industry. Effective data protection reduces Wells Fargo’s risk from incidents related to information theft, loss, or disclosure. Wells Fargo requires hard drive encryption on all laptops and also requires email encryption for all sensitive data. USB ports are locked down and only available for use with a company-approved encrypted thumb drive. Wells Fargo has also implemented data loss prevention technology across the enterprise to help identify or block the transmission or release of confidential customer information.</li>
</ul>
<ul>
<li><strong>Implementing a Third-Party Information Security Risk Management Programme</strong></li>
<li>Wells Fargo has an established Third-Party Information Security Risk Management Programme that reviews and assesses third parties prior to engagement and throughout the third-party relationship. The programme also requires periodic risk assessments to be carried out throughout the term of the engagement, the type of interval of which are driven by the risk associated with the engagement. In providing products and services to Wells Fargo, third parties and their employees are required to adhere to information security standards and requirements. These standards also apply to third parties located outside of the U.S. who have access to company and consumer information for purposes of delivering products or services to or on behalf of Wells Fargo. As part of this compliance obligation, Wells Fargo has contracts in place with third parties that include confidentiality language, nondisclosure obligations, and security provisions.</li>
</ul>
<ul>
<li><strong>Training employees to protect customer information</strong></li>
<li>Employees and contingent resources with access to Wells Fargo’s systems or customer information are required to complete annual training on customer information protection and Gramm Leach Bliley Act (GLBA) 501(b) compliance. They are also required to abide by Wells Fargo’s Code of Ethics and Business Conduct, including its provisions related to the treatment of confidential information. Wells Fargo regularly updates companywide training, policies, and information-handling standards to help employees understand their role in protecting customer information. Wells Fargo also performs employee background checks, which it also requires for nonemployees and third-party service providers who handle Wells Fargo’s customer information.</li>
</ul>
<ul>
<li><strong>Educating customers on digital security</strong></li>
<li>Wells Fargo encourages digitally active customers to protect their accounts by offering security options like two-factor authentication, biometrics, and the ability to turn debit cards on and off. Wells Fargo’s online security centre provides customers with resources to explore security options, spot scams, report fraud, and more. Wells Fargo also provides educational materials that encourage customers to create strong passwords, avoid suspicious links, keep their software updated, limit the personal information they share online, and use a screen lock on mobile devices.</li>
</ul>
<ul>
<li><strong>Protecting data in open banking environments</strong></li>
<li>With the growing number of apps designed to help customers lead healthier financial lives, there’s an increased chance that customers’ banking information can be accessed and used without their knowledge or permission. Wells Fargo believes it’s important to support its customers’ ability to use these apps to share their Wells Fargo account information in a seamless and more secure way. So far, Wells Fargo has reached data exchange agreements with at least 15 platforms, including Plaid and Intuit. This gives its customers greater control over the bank account information they share with supported apps, including the ability to turn data sharing on or off through Wells Fargo’s Control Tower℠ digital experience.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by Wells Fargo, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to Wells Fargo: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-wells-fargo-promotes-cybersecurity/">Case study: How Wells Fargo promotes cybersecurity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How CAL promotes cyber security</title>
		<link>https://sustaincase.com/case-study-how-cal-promotes-cyber-security/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Mon, 26 Oct 2020 06:51:49 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-206]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Aviation]]></category>
		<category><![CDATA[CAL]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=11583</guid>

					<description><![CDATA[<p>China Airlines (CAL) is the largest airline in Taiwan, offering flights to / from 29 countries and 160 destinations worldwide. , which are incorporated into daily business operations. In addition, CAL proactively reports cyber security issues and carries out contingency drills, to review the effect of defence and resilience to such incidents. This case study is based on the 2019 Corporate Sustainability Report by CAL published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-cal-promotes-cyber-security/">Case study: How CAL promotes cyber security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>China Airlines (CAL) is the largest airline in Taiwan, offering flights to / from 29 countries and 160 destinations worldwide. <strong>All of CAL’s information operations comply with international cyber security standards and domestic cyber security laws and regulations</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=All%20of%20CAL%E2%80%99s%20information%20operations%20comply%20with%20international%20cyber%20security%20standards%20and%20domestic%20cyber%20security%20laws%20and%20regulations&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-cal-promotes-cyber-security%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a>, which are incorporated into daily business operations. In addition, CAL proactively reports cyber security issues and carries out contingency drills, to review the effect of defence and resilience to such incidents.</p>
<p><strong>This case study is based on the</strong><strong> 2019 Corporate Sustainability Report</strong> <strong>by</strong> <strong>CAL </strong><strong>published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/79875/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p>To continuously enhance its cyber security governance system and organisation CAL has established the CAL Cyber Security Team, with the Vice President of Information Management Division as its convener, who is responsible for overseeing the cyber security governance plan and its implementation. In order to promote cyber security CAL took action to:</p>
<ul>
<li>carry out regular evaluations and exercises</li>
<li>provide cyber security training</li>
<li>implement a cyber security incident notification and response mechanism</li>
<li>carry out cyber security audits</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) CAL has identified;</li>
<li>How CAL proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by CAL to promote cyber security</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2019 Corporate Sustainability Report CAL identified a range of material issues, such as financial performance, flight safety management, climate change mitigation and adaptation, risk and crisis management, governance and integrity management. Among these, promoting cyber security stands out as a key material issue for CAL.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards               </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups</strong> <strong>CAL </strong><strong>engages with:</strong><strong> </strong></p>
<table width="479">
<tbody>
<tr>
<td width="128"><strong>Stakeholder Group</strong></td>
<td width="351"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="128">Employees</p>
<p>&nbsp;</td>
<td width="351">·      Labour-management meetings</p>
<p>·      Labour unions</p>
<p>·      Employee suggestion boxes</p>
<p>·      Employee feedback website</p>
<p>·      China Airlines newsletter</p>
<p>·      China Airlines Retirees Portal</td>
</tr>
<tr>
<td width="128">Customers</p>
<p>&nbsp;</td>
<td width="351">·      Customer satisfaction survey</p>
<p>·      Global business meetings</p>
<p>·      Taiwan business meetings</p>
<p>·      Discussions with travel agencies</p>
<p>·      CAL’s website, CSR website, Facebook, e-mail, and text messages</p>
<p>·      Customer service hotline</p>
<p>·      Corporate customer visits</td>
</tr>
<tr>
<td width="128">Investors</p>
<p>&nbsp;</td>
<td width="351">·      Shareholders&#8217; meetings</p>
<p>·      Shareholder’s hotline / mailbox</p>
<p>·      Road shows</p>
<p>·      Interviews</td>
</tr>
<tr>
<td width="128">Government</p>
<p>&nbsp;</td>
<td width="351">·      Missives</p>
<p>·      Visits</p>
<p>·      Participation in projects</p>
<p>·      Participation in public hearings, seminars, conferences, and negotiation forums</p>
<p>·      Participation in initiatives</p>
<p>·      Audits</td>
</tr>
<tr>
<td width="128">Partners (Suppliers and Contractors)</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="351">·      Telephone</p>
<p>·      E-mail</p>
<p>·      Coordination meetings</p>
<p>·      Business visits</p>
<p>·      On-site audits</td>
</tr>
<tr>
<td width="128">Community</p>
<p>&nbsp;</td>
<td width="351">·      Charity events</p>
<p>·      Community activities</p>
<p>·      News releases</p>
<p>·      Online mailbox</td>
</tr>
<tr>
<td width="128">Media</td>
<td width="351">·      News releases</p>
<p>·      Press conferences</p>
<p>·      Interviews</p>
<p>·      Active communication of industry information</td>
</tr>
<tr>
<td width="128">Associations (including Aviation Organisations)</p>
<p>&nbsp;</p>
<p>&nbsp;</td>
<td width="351">·      Participation in project meetings</p>
<p>·      Participation in work seminars</p>
<p>·      Organising or participating in summits, executive summits, committees, and coordination meetings</p>
<p>·      Participation in government-convened meetings</p>
<p>·      Telephone, e-mail, and exchange platforms</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics, CAL engaged with its stakeholders through 307 questionnaires.</p>
<p><strong>What actions were taken by CAL </strong><strong>to</strong> <strong>promote</strong> <strong>cyber security</strong><strong>?</strong></p>
<p>In its 2019 Corporate Sustainability Report CAL reports that it took the following actions for promoting cyber security:</p>
<ul>
<li><strong>Carrying out regular evaluations and exercises</strong></li>
<li>In accordance with the Cyber Security Management Act regarding cyber security responsibility levels, CAL conducts risk assessment of information and information and communication systems every year, and evaluates the cyber security responsibility levels of the core information and communication systems with regard to confidentiality, integrity, availability, and compliance. CAL also developed a business continuity plan for the core information and communication systems and carries out a business continuity drill every year, to control relevant operational risks. Risk response mechanisms are also reviewed and adjusted to minimise potential losses.</li>
</ul>
<ul>
<li><strong>Providing cyber security training</strong></li>
<li>Each year, for CAL’s Cyber security and Information Technology personnel, at least 4 persons receive the cyber security professional programme training or the cyber security competence training for not less than 12 hours. For general user and officer, each person receives the general cyber security education training for not less than 3 hours. CAL requires every employee to take basic cyber security training to master cyber security risks and self-discipline and communicates cyber security policies and goals to all employees every year, through education and training, internal meetings, and announcements. CAL has also incorporated ethical corporate management into employee performance evaluations and human resources policies and established clear and effective rewards and disciplinary actions. Compliance with the Employee Code of Conduct is also a criterion used in annual performance evaluation. If employees do not comply with or violate the Employee Code of Conduct, they, depending upon the severity of the case, will have to undergo disciplinary action as per internal regulations. The Information Management Division carries out self-inspections and compliance self-assessments every half year, to effectively control cyber security. Audits are carried out by the audit unit independently, to ensure the overall mechanism operations.</li>
</ul>
<ul>
<li><strong>Implementing a </strong><strong>cyber security incident notification and response mechanism</strong></li>
<li>CAL’s cyber security incident notification and response mechanism is initiated based on the level of cyber security incidents and emergency preparedness. Notification and response procedures are in place to control their impact and post-incident recovery. In this regard, CAL develops the security incident notification &amp; contingency drill plan at the beginning of each year, and completes the internal cyber security exercise by the end of each year. Through cyber security exercises, CAL can evaluate the relevance of incident notification and response procedures and familiarise units in charge and support units with their roles and functions during rescue and equip them to respond to cyber security threats quickly and effectively, to minimise their impact on CAL’s customers and the company as a whole.</li>
</ul>
<ul>
<li><strong>Carrying out cyber security audits</strong></li>
<li>CAL&#8217;s Cyber Security Team conducts an internal audit at least once a year to make sure that all employees comply with the Cyber Security Management Act and CAL’s standard operating procedures, and effectively implement and maintain the management system. System reliability is constantly enhanced by refining security designs, including network regions, access control, vulnerability management, and other security protection strategies. In 2019, the Information Management Division reviewed the monitoring of data and warnings for cyber security threats detected by defence systems and found no cyber security threats by cyber-attacks or viruses.</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standards addressed in this case are:</p>
<p>1) <a href="https://www.globalreporting.org/standards/media/1007/gri-206-anti-competitive-behavior-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 206-1 Legal actions for anti-competitive behavior, anti-trust, and monopoly practices</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p>&nbsp;</p>
<p><strong>Disclosure 206-1 </strong>Legal actions for anti-competitive behavior, anti-trust, and monopoly practices corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3</li>
</ul>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Peace, Justice and Strong Institutions</li>
<li><strong>Targets: </strong>16.3, 16.10</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a><br />
References:</p>
<p>1) This case study is based on published information by CAL, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to CAL: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-cal-promotes-cyber-security/">Case study: How CAL promotes cyber security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How USPS promotes cybersecurity</title>
		<link>https://sustaincase.com/case-study-how-usps-promotes-cybersecurity/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Sun, 08 Mar 2020 15:20:14 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Non-Profit / Services]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<category><![CDATA[sustainability report]]></category>
		<category><![CDATA[USPS]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=10497</guid>

					<description><![CDATA[<p>A self-supporting, independent federal agency, the United States Postal Service (USPS) is the only delivery service that reaches every address in the US: 155 million residences, businesses and Post Office Boxes. This case study is based on the 2018 Annual Sustainability Report by USPS published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing. Abstract Cybersecurity ensures [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-usps-promotes-cybersecurity/">Case study: How USPS promotes cybersecurity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>A self-supporting, independent federal agency, the United States Postal Service (USPS) is the only delivery service that reaches every address in the US: 155 million residences, businesses and Post Office Boxes. <strong>As cyberattacks evolve, USPS responds by raising cyber awareness, fortifying network monitoring and strengthening telecommunications response capabilities.</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=As%20cyberattacks%20evolve%2C%20USPS%20responds%20by%20raising%20cyber%20awareness%2C%20fortifying%20network%20monitoring%20and%20strengthening%20telecommunications%20response%20capabilities.&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-usps-promotes-cybersecurity%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a></p>
<p><strong>This case study is based on the</strong><strong> 2018 Annual Sustainability Report </strong><strong>by USPS published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/65246/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing.</strong></p>
<p><strong>Abstract</strong></p>
<p>Cybersecurity ensures operational continuity, protects USPS’s employees and keeps USPS ‘s customers’ information safe. Accordingly, USPS invests in platforms that increase security as well as improve employee safety, benefit sustainability and enhance customer experiences. In order to promote cybersecurity USPS took action to:</p>
<ul>
<li>provide cybersecurity training</li>
<li>implement the “Cyber Guardians” programme</li>
<li>raise cybersecurity awareness</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) USPS has identified;</li>
<li>How USPS proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by USPS to promote cybersecurity</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2018 Annual Sustainability Report USPS identified a range of material issues, such as customer service and satisfaction, optimising delivery and network operations, financial stability, employee health, safety and wellness. Among these, promoting cybersecurity stands out as a key material issue for USPS.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards               </strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The reporting organization shall identify its stakeholders, and explain how it has responded to their reasonable expectations and interests.”</a></p>
<p>Stakeholders must be consulted in the process of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups</strong> <strong>USPS </strong><strong>engages with:</strong></p>
<table width="261">
<tbody>
<tr>
<td width="261"><strong>Stakeholder Group</strong></td>
</tr>
<tr>
<td width="261">Employees</td>
</tr>
<tr>
<td width="261">Customers</td>
</tr>
<tr>
<td width="261">Suppliers</td>
</tr>
<tr>
<td width="261">Industry groups</td>
</tr>
<tr>
<td width="261">Non-profit associations</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues</strong></p>
<p>To identify and prioritise material topics USPS engaged with its stakeholders (USPS customers) through focused surveys, with over 75 respondents providing input on the relative importance of sustainability topics.</p>
<p><strong><a href="https://fbrh.co.uk/en/gri-certified-training/2-day-fbrh-gri-standards-certified-training-course-about" target="_blank" rel="noopener noreferrer"><img loading="lazy" decoding="async" class="alignright size-full wp-image-11761" src="https://sustaincase.com/wp-content/uploads/2020/08/sustainability-GRI-report-key-doc-for-success-ad-sustaincase-GRI-SDG-ESG-Sustainability-report-200x320px.jpg" alt="" width="200" height="320" /></a>What actions were taken by USPS to</strong> <strong>promote cybersecurity?</strong></p>
<p>In its 2018 Annual Sustainability Report USPS reports that it took the following actions for promoting cybersecurity:</p>
<ul>
<li><strong>Providing cybersecurity training</strong></li>
<li>During FY 2018 USPS’s CyberSafe at USPS team trained more than 220,000 employees and contractors on cybersecurity fundamentals. The team also engages employees using interactive touchpoints, including monthly phishing simulations to help employees recognise and report cyberscams. Related events include the Annual Cyber Security Awareness Fair at USPS’s national headquarters, which promotes best practices to employees and USPS contractors.</li>
</ul>
<ul>
<li><strong>Implementing the “Cyber Guardians” programme</strong></li>
<li>USPS also initiated the “Cyber Guardians” ambassador programme, empowering USPS field employees to serve as the eyes and ears of USPS’s cybersecurity programme. These individuals facilitate the exchange of critical cybersecurity information between the Corporate Information Security Office (CISO) organisation and co-workers within their local offices. By year end 2018, CISO had enlisted 55 Cyber Guardians across 19 states.<strong> </strong></li>
</ul>
<ul>
<li><strong>Raising cybersecurity awareness</strong></li>
<li>USPS’s CISO continues to promote its website, CyberSafe at USPS, which provides employees, customers and suppliers with information they need to stay safe online. Visitors can learn more about cybersecurity best practices, and how USPS safeguards their personal and financial information. Throughout the year, CyberSafe at USPS features content that raises awareness and promotes safe online behaviours on a range of topics, which include:
<ul>
<li>Texting scams involving bank notifications, IRS (Internal Revenue Service) notifications and contests.</li>
<li>Tech support scams that involve individuals impersonating information technology employees.</li>
<li>Risks from using public Wi-Fi in airports and coffee shops.</li>
<li>Risks of ransomware and other malware attacks through email attachments.</li>
<li>New “Report to CyberSafe” button in Outlook to make reporting suspicious emails easier.</li>
<li>Dangers and consequences of sharing user logins, passwords and accounts.</li>
</ul>
</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed?</strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Promote peaceful and inclusive societies for sustainable development, provide access to justice for all and build effective, accountable and inclusive institutions at all levels</li>
<li><strong>Business theme: </strong>Compliance with laws and regulations, Protection of privacy</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a></p>
<p>&nbsp;</p>
<p>References:</p>
<p>1) This case study is based on published information by USPS, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to USPS: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-usps-promotes-cybersecurity/">Case study: How USPS promotes cybersecurity</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Case study: How ANZ promotes cyber security</title>
		<link>https://sustaincase.com/case-study-how-anz-promotes-cyber-security/</link>
		
		<dc:creator><![CDATA[Gerasimos]]></dc:creator>
		<pubDate>Mon, 15 Jul 2019 06:25:00 +0000</pubDate>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[GRI Standards]]></category>
		<category><![CDATA[GRI-418]]></category>
		<category><![CDATA[SDG16]]></category>
		<category><![CDATA[SDGs category]]></category>
		<category><![CDATA[Sector: Financial Services]]></category>
		<category><![CDATA[ANZ]]></category>
		<category><![CDATA[case study]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[sustain case]]></category>
		<category><![CDATA[sustainability]]></category>
		<guid isPermaLink="false">https://ccprowebs.com/new-sustaincase.com/?p=9861</guid>

					<description><![CDATA[<p>Founded in 1835 and headquartered in Australia, ANZ provides banking and financial products and services to around eight million individual and business customers, across 34 markets globally. ANZ takes the security of its customers, employees and services very seriously as, when impacted by cybercrime, customers can lose trust in its digital banking products and services. This case study is based on the 2018 Sustainability Review by ANZ published on the Global Reporting Initiative Sustainability Disclosure Database that can be found at this link. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it [&#8230;]</p>
<p>The post <a href="https://sustaincase.com/case-study-how-anz-promotes-cyber-security/">Case study: How ANZ promotes cyber security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Founded in 1835 and headquartered in Australia, ANZ provides banking and financial products and services to around eight million individual and business customers, across 34 markets globally. ANZ takes the security of its customers, employees and services very seriously as, when impacted by cybercrime, customers can lose trust in its digital banking products and services.</p>
<p><strong>This case study is based on the </strong><strong>2018 Sustainability Review b</strong><strong>y </strong><strong>ANZ</strong><strong> published on the Global Reporting Initiative </strong><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer"><strong>Sustainability Disclosure Database</strong></a><strong> that can be found at this </strong><a href="https://database.globalreporting.org/reports/62395/" target="_blank" rel="noopener noreferrer"><strong>link</strong></a><strong>. Through all case studies we aim to demonstrate what CSR/ ESG/ sustainability reporting done responsibly means. Essentially, it means: a) identifying a company’s most important impacts on the environment, economy and society, and b) measuring, managing and changing</strong><strong>. </strong></p>
<p><strong>ANZ’s Cyber Defence team proactively scans ANZ systems for vulnerabilities, to prevent malicious activity</strong>&nbsp;<a href="https://twitter.com/intent/tweet?text=ANZ%E2%80%99s%20Cyber%20Defence%20team%20proactively%20scans%20ANZ%20systems%20for%20vulnerabilities%2C%20to%20prevent%20malicious%20activity&url=https%3A%2F%2Fsustaincase.com%2Fcase-study-how-anz-promotes-cyber-security%2F&via=sustaincase" target="_blank"><i class="fa fa-twitter">&nbsp;</i>Tweet This!</a> and manages threats to minimise impact to customer operations. Additionally, ANZ works to build awareness, through an extensive education and influence programme of work, across employees and customers. In order to promote cyber security ANZ took action to:</p>
<ul>
<li>raise cyber awareness among customers and employees</li>
<li>participate in industry collaborations to address the skills shortage in cyber security</li>
</ul>
<p><a href="https://sustaincase.com/good-communication-with-responsible-csr-reporting/" target="_blank" rel="attachment wp-att-1719 noopener noreferrer"><img loading="lazy" decoding="async" class="wp-image-1719 size-large tie-appear" src="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg" width="618" height="84" srcset="https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-1024x139.jpg 1024w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-300x41.jpg 300w, https://sustaincase.com/wp-content/uploads/2016/10/Identify-measure-manage-change-768x104.jpg 768w" sizes="auto, (max-width: 618px) 100vw, 618px" /></a></p>
<div class="subscribe-for-free">
<h3>Subscribe for free and read the rest of this case study</h3>
<p>Please subscribe to the SustainCase Newsletter to keep up to date with the latest sustainability news and gain access to over <strong>2000 case studies.</strong> These case studies demonstrate how companies are dealing responsibly with their most important impacts, building trust with their stakeholders (Identify &gt; Measure &gt; Manage &gt; Change).</p>
<h4>With this case study you will see:</h4>
<ul>
<li>Which are the <strong>most important impacts</strong> (material issues) ANZ has identified;</li>
<li>How ANZ proceeded with <strong>stakeholder engagement</strong>, and</li>
<li><strong>What actions</strong> were taken by ANZ to promote cyber security</li>
</ul>
</div>
<div class='subscribe_login' style='margin:30px;'><a class='casestd_pop' href='https://sustaincase.com/subscribe-to-sustaincase-newsletter/' style='color: #ea7622; margin: 20px 0;'><strong>I would like to subscribe</strong></a><div id='subsciber'><p class='sub_p'>Already Subscribed? Type your email below and click submit</p>
	<form method='post' id='sub_form' class='sub_form' action=''>
	<input id='subEmail' class='sub_email' type='email' required='required' name='sub_email'>
	<p class='sub_error'></p>
	<button type='submit' id='subSubmit' name='sub_submit'>Submit</button></form></div></div>
<div class='actions-taken'> </p>
<p><strong>What are the material issues the company has identified?</strong></p>
<p>In its 2018 Sustainability Review ANZ identified a range of material issues, such as fairness and ethical conduct, responsible business lending, financial system stability and regulation, climate change, labour rights end employee wellbeing. Among these, promoting cyber security stands out as a key material issue for ANZ.</p>
<p><strong>Stakeholder engagement in accordance with the GRI Standards</strong></p>
<p>The Global Reporting Initiative (GRI) defines the Principle of Stakeholder Inclusiveness when identifying material issues (or a company’s most important impacts) as follows:</p>
<p><a href="https://www.globalreporting.org/standards/gri-standards-download-center/gri-101-foundation-containing-standard-interpretation-1/" target="_blank" rel="noopener noreferrer">“The organization should identify its stakeholders, and explain how it has responded to their reasonable expectations.”</a></p>
<p>Stakeholders must be consulted in the process s of identifying a company’s most important impacts and their reasonable expectations and interests must be taken into account. This is an important cornerstone for CSR / sustainability reporting done responsibly.</p>
<p><strong>Key stakeholder groups </strong><strong>ANZ</strong> <strong>engages with: </strong></p>
<table width="479">
<tbody>
<tr>
<td width="124"><strong>Stakeholder Group</strong></td>
<td width="354"><strong>               Method of engagement </strong></td>
</tr>
<tr>
<td width="124">Customers</p>
<p>&nbsp;</td>
<td width="354">·      ‘Your Say’ Research Community online customer panel</p>
<p>·      Customer research and focus groups</p>
<p>·      ‘Voice of Customer’ platform</p>
<p>·      Customer Advocate Office</p>
<p>·      Complaints Resolution Centre</p>
<p>·      Social media</p>
<p>·      Australian Bankers’ Association (ABA) survey of trust in banks and banking industry reform program</td>
</tr>
<tr>
<td width="124">Employees</p>
<p>&nbsp;</td>
<td width="354">·      ANZ Jam, a bank-wide digital conversation, engaging employees about ANZ’s purpose and values</p>
<p>·      ‘My Voice’ pulse survey of employee engagement</p>
<p>·      ‘ANZ Way’ People Leaders’ quarterly webcasts with CEO and Executive Committee members</p>
<p>·      ‘ANZ Way’ Podcast series</p>
<p>·      Direct communication and formal twice-yearly performance appraisals with line managers</p>
<p>·      ANZ intranet, MAX, a resource for employees to receive updates and information about developments and initiatives at ANZ</p>
<p>·      ANZ’s internal collaboration tool, MAX Connect, which connects ANZ’s people in real-time</p>
<p>·      Meetings with the unions representing ANZ employees, including the Finance Sector Union of Australia and FIRST Union in New Zealand</p>
<p>·      ABA survey of employees about trust in banks and banking industry reform program</td>
</tr>
<tr>
<td width="124">Shareholders</td>
<td width="354">·      Results briefings</p>
<p>·      Strategy briefings and other market updates</p>
<p>·      Annual General Meeting</p>
<p>·      Disclosure documents, including results announcements, investor presentations, annual reports and other ASX lodgements</p>
<p>·      Electronic communications and webcasts</p>
<p>·      Dedicated ANZ shareholder website</td>
</tr>
<tr>
<td width="124">Government and regulators</td>
<td width="354">·      Regular meetings with political stakeholders, officials and regulators by ANZ’s CEO and senior executives</p>
<p>·      Submissions to parliamentary committee inquiries and other government and regulatory consultations</p>
<p>·      Participation in industry engagement and forums</p>
<p>·      Meetings with trade negotiators regarding free trade agreements</p>
<p>·      Providing information and technical advice on international practices to regulators in developing countries</p>
<p>·      Meetings with departmental representatives responsible for implementation of programs aligned with or co-funded by ANZ</td>
</tr>
<tr>
<td width="124">Industry associations</td>
<td width="354">·      Participated in the development and implementation of the industry consumer protection reform program in Australia</p>
<p>·      Participated in industry discussions about sector issues and broad industry strategy</p>
<p>·      Participated on the Business Council of Australia’s (BCA) climate change policy working group</p>
<p>·      Provided input into industry association responses to parliamentary inquiries and government consultations</td>
</tr>
<tr>
<td width="124">Non-government organisations (NGOs)</td>
<td width="354">·      Direct engagement with relevant human rights, consumer and environment NGOs and academics</p>
<p>·      Regular engagement with peak bodies for professional community services such as financial counselling</p>
<p>·      Regular partnership meetings with community organisations delivering MoneyMinded, Saver Plus and MoneyBusiness programs</p>
<p>·      Engagement with NGOs providing oversight of key social commitments such as ANZ’s Reconciliation Action Plan, Accessibility and Inclusion Plan and Financial Inclusion Action Plan</p>
<p>·      A regular program of CEO and senior executive meetings with civil society leaders to exchange ideas and discuss material social, economic and environmental issues of mutual interest</p>
<p>·      Consultation with a wide variety of external stakeholders to refine ANZ’s approach to its purpose and with particular focus on financial wellbeing, environmental sustainability and housing</p>
<p>·      External steering committees for flagship programs and research related to financial capability and wellbeing</td>
</tr>
</tbody>
</table>
<p><strong>How stakeholder engagement was made to identify material issues </strong></p>
<p>To identify and prioritise material topics ANZ conducted a survey among both internal and external stakeholders, who ranked material topics according to their importance, and also carried out one-on-one interviews with 29 stakeholders who informed its understanding of the current and future context of each topic.</p>
<p><strong><a href="https://fbrh.co.uk/en/gri-certified-training/2-day-fbrh-gri-standards-certified-training-course-about" target="_blank" rel="noopener noreferrer"><img loading="lazy" decoding="async" class="alignright size-full wp-image-11761" src="https://sustaincase.com/wp-content/uploads/2020/08/sustainability-GRI-report-key-doc-for-success-ad-sustaincase-GRI-SDG-ESG-Sustainability-report-200x320px.jpg" alt="" width="200" height="320" /></a>What actions were taken by</strong> <strong>ANZ</strong> <strong>to</strong> <strong>promote cyber security?</strong></p>
<p>In its 2018 Sustainability Review ANZ reports that it took the following actions for promoting cyber security:</p>
<ul>
<li><strong>Raising cyber awareness among customers and employees</strong></li>
<li>In response to the rapid increase in cybercrime, ANZ implemented, in 2018, a range of initiatives to raise the cyber security awareness of both its customers and employees, which included the following:
<ul>
<li>the introduction of ‘TECH Talks’, facilitated by employees within ANZ’s Australian branch network, where cyber security and technology related topics are discussed with customers;</li>
<li>presentations to small business, corporate and commercial customers carried out by regional and local bankers as part of a wider series of client engagement sessions;</li>
<li>in-application pop-up cyber security messages in the Wholesale Digital Transactive banking platform, which customers must acknowledge before being able to proceed;</li>
<li>the launch of a new cyber security alert page on anz.com, providing examples of the latest cyber threats that could impact customers;</li>
<li>the commencement of a ‘Change Champion’ Cyber Security Ambassador Programme within the New Zealand and Australian Operations teams to improve cyber security capabilities among employees, while also acting as an advocate for cyber security within their respective areas;</li>
<li>the implementation of an internal phishing email ‘triage service’ (suspicious email sorting capability) to ensure a timely response to potential cyber attacks on ANZ;</li>
<li>the establishment of an executive education programme to improve cyber knowledge;</li>
<li>the development of ANZ’s new cyber security campaign to raise awareness on simple steps customers and employees can take to protect their virtual valuables.</li>
</ul>
</li>
</ul>
<ul>
<li><strong>Participating in industry collaborations to address the skills shortage in cyber security </strong></li>
<li>During 2018, ANZ participated in various industry collaborations to help alleviate the skills shortage in cyber security and to support a cyber-smart community. These included:
<ul>
<li>a partnership with Deakin University to sponsor graduate roles into ANZ’s Security Domain to address resourcing gaps, while developing talent;</li>
<li>a leadership role through the Australia Women in Security Network (AWSN), which aims to increase the number of women in cyber security across Australia;</li>
<li>delivering a research programme to investigate human susceptibility to phishing emails in conjunction with Data61, CSIRO’s (Commonwealth Scientific and Industrial Research Organisation) data, technology and innovation industry body;</li>
<li>a partnership with the Australian Computer Academy (Sydney University), ANZ’s Australian banking peers, British Telecom and Aust Cyber (a not-for-profit organisation promoting Australian cyber security industry and innovation) to write the cyber security content for the national digital curriculum for Australian high schools (Years 7–10);</li>
<li>collaboration across industry and government to deliver content for Safer Internet Day, National Scams Awareness week, Stay Smart Online week and International Cyber Security month.</li>
</ul>
</li>
</ul>
<p><strong>Which GRI Standards and corresponding Sustainable Development Goals (SDGs) have been addressed? </strong></p>
<p>The GRI Standard addressed in this case is: <a href="https://www.globalreporting.org/standards/media/1033/gri-418-customer-privacy-2016.pdf" target="_blank" rel="noopener noreferrer">Disclosure 418-1 Substantiated complaints concerning breaches of customer privacy and losses of customer data</a></p>
<p>&nbsp;</p>
<p><strong>Disclosure 418-1 </strong>Substantiated complaints concerning breaches of customer privacy and losses of customer data corresponds to:</p>
<ul>
<li><a href="https://www.globalreporting.org/standards/resource-download-center/sdg-compass-annex-linking-the-sdgs-and-gri-standards/" target="_blank" rel="noopener noreferrer">Sustainable Development Goal (SDG) 16</a>: Promote peaceful and inclusive societies for sustainable development, provide access to justice for all and build effective, accountable and inclusive institutions at all levels</li>
<li><strong>Business theme: </strong>Compliance with laws and regulations, Protection of privacy</li>
</ul>
<p>&nbsp;</p>
<p><strong>78% of the world’s 250 largest companies report in accordance with the GRI Standards</strong></p>
<p>SustainCase was primarily created to demonstrate, through case studies, the importance of dealing with a company’s most important impacts in a structured way, with use of the GRI Standards. To show how today’s best-run companies are achieving economic, social and environmental success – and how you can too.</p>
<p>Research by well-recognised institutions is clearly proving that <a href="https://sustaincase.com/articles-research/" target="_blank" rel="noopener noreferrer">responsible companies can look to the future with optimism</a>.</p>
<p><span style="font-size: 18pt;"><b>7 GRI sustainability disclosures get you started</b></span></p>
<p><b>Any size business can start taking sustainability action</b></p>
<p><span style="font-weight: 400;">GRI, ISEP, CPD Certified Sustainability courses (2-5 days): Live Online or Classroom  (venue: London School of Economics)</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Exclusive</span> <span style="font-weight: 400;">FBRH template to begin reporting from day one</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your most important impacts on the Environment, Economy and People</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Formulate in group exercises your plan for action. Begin taking solid, focused, all-round sustainability action ASAP. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Benchmarking methodology to set you on a path of continuous improvement</span></li>
</ul>
<p><a href="https://fbrh.co.uk/en/gri-sustainability-courses" target="_blank" rel="noopener"><span style="font-weight: 400;">See upcoming training dates.</span></a></p>
<p>&nbsp;</p>
<p>References:</p>
<p>1) This case study is based on published information by ANZ, located at the link below. For the sake of readability, we did not use brackets or ellipses. However, we made sure that the extra or missing words did not change the report’s meaning. If you would like to quote these written sources from the original, please revert to the original on the Global Reporting Initiative’s Sustainability Disclosure Database at the link:</p>
<p><a href="http://database.globalreporting.org/" target="_blank" rel="noopener noreferrer">http://database.globalreporting.org/</a></p>
<p>2) <a href="https://www.globalreporting.org/standards/gri-standards-download-center/" target="_blank" rel="noopener noreferrer">https://www.globalreporting.org/standards/gri-standards-download-center/</a></p>
<p>Note to ANZ: With each case study we send out an email requesting a comment on this case study. If you have not received such an email please <a href="mailto:editor@sustaincase.com" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
<p> </div>
<p>The post <a href="https://sustaincase.com/case-study-how-anz-promotes-cyber-security/">Case study: How ANZ promotes cyber security</a> appeared first on <a href="https://sustaincase.com">SustainCase - Sustainability Magazine</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
