Information Security Policy
5 October 2026 · Initial version · Approved by Management
Introduction
VIRTUABROKER’s Security Policy sets out the concepts, principles, responsibilities, and objectives relating to security, the implementation of which enables the company to maintain the necessary freedom of action.
The objective of VIRTUABROKER’s comprehensive security framework is to protect the people who work within the company, the confidentiality of their communications, and the availability and integrity of its information. It also protects the company’s other assets, including its facilities and content of all kinds.
Comprehensive Security encompasses the traditional concepts of physical security and logical (technological) security in order to maintain business continuity in the event of any adverse circumstances.
Increasing the company’s security culture among its personnel provides clear benefits by improving the security of systems and procedures while minimizing the risk of potentially malicious actions.
It is essential that all information relating to security matters flows through the appropriate channels to the company’s decision-making bodies.
Principles
- Integration. Comprehensive Security is an integrated process aligned with the business and involving the entire company.
- Cost-effectiveness. Security is managed according to business criteria, taking into account the relationship between expenditure and investment. Security criteria are established centrally while taking advantage of available synergies. This approach enables an overall reduction in expenditure and improves the return on resources dedicated to security.
- Continuity. Security must be present throughout its entire lifecycle: protection, prevention, detection, response, and recovery.
- Appropriateness. The measures implemented must be adapted to the business environment. Factors that may affect the business and the organization’s security levels include competition from other companies, social, political, and economic disruption, and amateur or professional hacking.
Responsibilities
Ultimate responsibility for security lies with the management team, which is directly responsible for managing its development and implementation.
The management team will analyse security risks and vulnerabilities that may affect the proper operation of the business and will propose the appropriate policies, resources, and measures to minimise them.
All personnel within the organisation must take responsibility for maintaining the security of the assets under their control and must comply with the security standards implemented by the management team.
Objectives
- Achieve and maintain the level of security required to adequately guarantee business continuity, including under adverse circumstances.
- Increase the integration and mutual support of the physical and logical aspects of security.
- Support the management of other security-related disciplines, including occupational and environmental matters, in accordance with criteria that promote Corporate Social Responsibility.
- Establish the corporate security structure defined by the organisation’s decision-making bodies and create appropriate communication channels among all parties involved.
- Comply with applicable security regulations and other relevant requirements.
- Establish and implement security training and awareness programmes to improve personnel knowledge and preparedness.
- Maintain an explicit commitment to continuous improvement.
- Integrate the company’s different departments into a security management system that uses common criteria, takes advantage of synergies, and ensures consistency in resources and actions.
- All VIRTUABROKER personnel shall be familiar with and comply with the rules and standards developed under this Security Policy.