Information Security & Cybersecurity

The protection of information, data, and digital systems is a fundamental element of Plasser & Theurer’s responsible corporate governance. Information security and cybersecurity play a vital role in complying with legal and regulatory requirements, strengthening organizational resilience, and supporting sustainable, future-focused business operations.

Effective security measures help ensure stable business processes, safeguard sensitive information belonging to our customers and partners, and foster trust among external stakeholders.

Information Security as Part of Corporate Policy

At Plasser & Theurer, information security is firmly embedded within our Corporate Policy and forms an integral part of our governance and compliance framework. It supports the long-term continuity of our business operations and enhances the company’s resilience against operational and strategic risks.

The principles of information security are closely aligned with our mission, strategic objectives, and core corporate values.

More about cor­porate policy

Our Approach to Information Security

Plasser & Theurer operates a structured Information Security Management System (ISMS) designed to systematically ensure the confidentiality, integrity, availability, and authenticity of information.

Our approach is risk-based. Security measures are planned, implemented, monitored, and continuously improved to ensure that security measures are implemented in a targeted, proportionate and effective manner.

Alignment with International Standards – ISO/IEC 27001

Our ISMS is certified to ISO/IEC 27001, the internationally recognized standard for Information Security Management. The standard provides the governing framework for:

  • defining and implementing clear information security objectives;
  • applying appropriate technical and organizational security measures; and
  • regularly reviewing, assessing, and continually improving information security performance.

Our ISO/IEC 27001 certification demonstrates the effectiveness and maturity of our ISMS and reflects the company’s ongoing commitment to internationally recognized security standards.

Governance and Accountability

Executive management holds overall responsibility for information security.

A formally designated Information Security Manager is responsible for coordinating the operation of the ISMS, monitoring its effectiveness, and providing regular reports to executive management.

Dealing with Risks and Security Incidents

Information security risks are systematically identified, analysed, and assessed, and are incorporated into the company-wide risk management framework.

Security incidents are detected, managed, and documented in accordance with clearly defined procedures. The objective is to minimize disruption to business operations and continuously enhance the effectiveness of our security measures.

Training and Security Awareness

Plasser & Theurer promotes a sustainable security culture. Employees and other relevant stakeholder groups receive regular information security and cybersecurity awareness training to ensure that information security is firmly embedded within our organizational culture.

Public Information Security Policy

Our Public Information Security Policy outlines the fundamental principles and objectives of information security at Plasser & Theurer in a transparent and accessible manner.

It is intended primarily for customers, business partners, and other external stakeholders.

General Terms and Conditions of Purchase and Security Requirements

Information security is a fundamental element of our collaboration with suppliers and business partners. Plasser & Theurer is committed to ensuring that appropriate information security and cybersecurity standards are maintained throughout the entire supply and value chain.

Security-related requirements are set out as binding obligations in our General Terms and Conditions of Purchase and in supplementary contractual agreements. Together, these establish the framework for the responsible, secure, and trustworthy handling of information, data, and digital products.

Our security requirements include, in particular:

  • the protection of confidential and sensitive information;
  • the secure use and management of IT systems, digital services, and software components;
  • measures to ensure availability, confidentiality, integrity and, traceability;
  • a structured approach to the dealing with security incidents and risks.

Particular emphasis is placed on suppliers of products containing digital elements and providers of Information and Communication Technology (ICT). Such suppliers and providers are required to implement appropriate technical and organizational measures to effectively minimize risks to information assets, business processes and customers.

In this way, we ensure that information security and cybersecurity are implemented not only within our own company, but also across our partner network, in accordance with appropriate and internationally recognized security standards.

Transparency and Confidentiality

This website provides a public, high-level overview of our approach to information security and cybersecurity.

Additional internal policies, standards, and procedures exist to support the operational implementation of our security framework. In the interests of confidentiality and the protection of sensitive information, these documents are not publicly available.

back to top