Commitment to Security & Operational Resilience
CTO2B is proudly ISO/IEC 27001:2022 certified. Our comprehensive Information Security Management System (ISMS) has been independently audited and verified to meet strict international standards. The scope of our certification covers the development, hosting, delivery, and support of our cloud infrastructure management platform as a service.
Because our platform is built on Infrastructure as Code (IaC) principles — leveraging strict version control, immutable infrastructure, and automated deployments — we inherently provide our customers with high operational resilience, rapid disaster recovery, and comprehensive audit trails. This architectural approach, combined with our ISO-certified ISMS, directly supports our customers in meeting the stringent requirements of the NIS2 Directive, the Digital Operational Resilience Act (DORA), and other global regulatory frameworks.
1. Governance, risk & compliance
Does CTO2B have approved information security policies, and are they regularly reviewed?
Yes. Our Information Security Management System (ISMS) aligns with the ISO/IEC 27001:2022 standard. Our policies are approved by the CEO and top management, communicated to all employees, and reviewed at least annually or upon significant operational changes.
Is there a defined organisational structure for Information Security, including risk governance and segregation of duties (SOD)?
Yes. Information security governance is driven by top management:
- CEO — ultimate accountability
- CTO — technical infrastructure and secure development
- CISO — compliance, audits, and risk management
We enforce strict segregation of duties (e.g., separating development from production operations) to prevent conflicts of interest and unauthorised access.
Do you have a risk management framework linking risks to controls?
Yes. We maintain a formalised Risk Management Policy. Risks are assessed at least annually (or upon significant change), recorded in a Risk Register, and linked to specific mitigating controls.
Do you have a process to ensure ongoing compliance with regulations and contractual requirements?
Yes. Compliance is continuously monitored via internal audits, external certification audits, and regular Management Review meetings.
2. Infrastructure, network & architecture
Do you provide an architecture overview, including data center locations and connectivity?
CTO2B provides an IaC-based cloud infrastructure management platform. Our customers' environments are hosted on top-tier public cloud providers, meaning data center locations are determined by the customer's selected region — typically within the EU/EEA to ensure data sovereignty. Detailed architecture diagrams for specific customer implementations can be provided under NDA.
How is network segregation and security managed?
CTO2B implements strict network segregation (using VPCs, subnets, and micro-segmentation) within the cloud environments we build and manage for our customers. We utilise gateways, firewalls, and filtering routers to prevent unauthorised connections.
Shared Responsibility: CTO2B cannot guarantee or enforce compliance for external networks or on-premise environments managed outside of the CTO2B-provisioned cloud.
Are network connections encrypted, and how are idle sessions handled?
Yes. All confidential data transmitted across networks (data in motion) is encrypted using TLS 1.2 or higher. Access to our internal systems and customer cloud environments requires Multi-Factor Authentication (MFA), and inactive sessions are automatically configured to terminate after 15 minutes of inactivity.
Do you use standardised and hardened component builds?
Yes. Our platform leverages Infrastructure as Code (IaC) practices. This ensures that infrastructure components are standardised, immutable, hardened by design, and strictly version-controlled.
3. Software development life cycle (SDLC) & change management
Do you have a documented SDLC policy and Change Management process?
Yes. We maintain a Secure Development Policy and a Change Management Policy. All changes to infrastructure and code are tracked through a centralised change management system and version control.
How do you prevent unauthorised changes to systems and data?
Because we utilise an IaC model, direct human access to production environments is minimised. Code changes require:
- Peer review by someone other than the author
- Automated security testing
- Approval from an Engineering Lead before deployment into production
Development, testing, and production environments are strictly separated.
Do you have a process for addressing system vulnerabilities and patch management?
Yes. Vulnerabilities are identified through a combination of scheduled and event-driven scanning and reviews, then triaged by severity, exposure, exploitability, and business criticality. There is no fixed patch SLA — remediation is handled in a timely, risk-based manner, prioritising Critical and High-risk findings. See Vulnerability Management for the full scope and process.
4. Access control, cryptography & physical security
How are access rights, including privileged accounts, restricted and reviewed?
Access is granted based on the principle of least privilege and requires line manager approval. Privileged/administrator accounts are tightly controlled, uniquely identifiable, not shared, and monitored. User access is reviewed every 90 days, and all access is revoked immediately upon an employee's termination.
Do you enforce strong passwords and protect authentication information?
Yes. Passwords must meet strict complexity requirements (minimum 12 characters, mixed case, numbers, special characters) and are rotated regularly. Passwords are securely stored using an enterprise password manager, and MFA is mandatory for accessing sensitive systems and data.
Do you have a standard on cryptography and key management?
Yes:
- Data at rest: AES-256 bit encryption
- Data in transit: RSA 2048 and TLS 1.2+
- Key management: Cryptographic keys managed within secure vaults or hardware security modules (HSMs) under our Cryptographic Key Management Policy
How do you protect the physical perimeter and enforce clean desk policies?
We maintain a Physical and Environmental Security Policy and a Clear Desk and Clear Screen Policy. Office access requires electronic entry cards, and visitors are escorted at all times.
Since customer data is hosted in public clouds, the physical security of the data centers processing customer data is governed by the hyperscalers' own industry-leading physical security compliance programmes.
5. HR security, remote work & training
Do you conduct background checks and manage Conflicts of Interest (COI)?
Yes. Background verification checks are conducted for new hires, proportionate to business requirements and applicable local legislation. Employees must sign confidentiality/NDAs that remain valid after employment ends.
How do you manage risks associated with BYOD and remote working?
Remote working requires the use of approved, encrypted devices, secure connections (VPN), and MFA. The BYOD policy restricts personal devices to accessing company communication tools only (via MFA) — personal devices cannot access or store sensitive company or customer data without explicit authorisation and enforced security controls.
Do employees receive Information Security awareness training?
Yes. All employees and contractors undergo mandatory security awareness and GDPR training during onboarding and at least annually thereafter. We also conduct periodic social engineering and phishing simulations.
6. Business continuity & disaster recovery (BCDR)
Does your organisation have a Business Continuity / Disaster Recovery programme?
Yes. CTO2B maintains a comprehensive Business Continuity Policy and a Disaster Recovery Plan approved by management. The plans outline response strategies for major incidents including regional cloud outages, ransomware, and infrastructure failures.
Is the BCP/DR programme tested, and are key roles backed by succession planning?
Yes. BCP and DR capabilities are tested at least annually (e.g., tabletop exercises or alternative workplace tests). Our HR practices include functional substitution and succession planning for key personnel to ensure critical knowledge is not lost during an emergency.
What is your data backup and restoration policy?
- Scope: production databases and mission-critical data
- Frequency: daily backups
- RTO and RPO: 1 day
- Encryption: all backups encrypted
- Redundancy: stored across multiple regions
- Retention: at least 7 days (longer depending on asset class)
- Testing: backup restorations tested periodically
7. Third-Party management & incident response
How do you manage third-party relationships and sub-contractors?
We maintain a Third-Party Supplier Security Policy and a Cloud Service Policy. Suppliers are risk-assessed, required to hold appropriate certifications (e.g., ISO 27001, SOC 2), and bound by Data Processing Agreements (DPAs). We maintain substitution procedures in the event of vendor failure.
Do you have a process for monitoring IT events and escalating incidents?
Yes. System activity, exceptions, and security events are centrally logged and monitored. We have a Major Incident Response Procedure. In the event of a breach or significant disruption, a Major Incident Management Team (MIMT) is activated.
Are personal data breaches reported in line with contractual obligations?
Yes. Our Personal Data Breach Policy mandates that any confirmed or suspected breach involving customer data must be evaluated and reported to the affected customer (and the supervisory authority, where applicable) within 72 hours, or as stipulated by the specific customer contract.
Have there been any incidents affecting our data in the last 12 months?
No. CTO2B has not experienced any material security incidents affecting customer data in the preceding 12 months.
8. Data protection & privacy
Is there a policy governing data protection and data retention?
Yes. We maintain a Data Protection Policy, a Data Retention Policy, and an Information Classification Policy. Data is retained only as long as necessary for legal or business purposes.
At the end of the retention period, how is data handled?
Data is securely disposed of (e.g., cryptographic wiping, secure overwrite, or certified destruction) or anonymised. Destruction logs are maintained.
Is there a Data Protection Officer (DPO) and a process for DPIAs?
Yes. Data privacy oversight is managed by the CISO and legal/compliance team. Data Privacy Impact Assessments (DPIAs) are conducted to address privacy risks during significant changes or when onboarding new processing activities.
Is personal data processed or stored outside the EU/EEA?
Customer data remains within the public cloud environments hosted in the regions chosen by the customer — typically within the EU/EEA — ensuring compliance with EU data residency and GDPR requirements.
Updated about 5 hours ago