Information Security Policy
Homepage / Corporate Governance / Policies / Information Security Policy
The Information Security Policy (“Policy”) of Ülker Bisküvi Sanayi A.Ş. (the “Company”) has been established to ensure the security of all information assets and processes used in the conduct of our operations, in line with the principles of confidentiality, integrity, availability, and security, and to implement the necessary measures to protect the physical and environmental security of Information Systems. This Policy has been approved by our Board of Directors.
In implementing this Policy, our Company aims to comply with the requirements of applicable laws and regulations and, where appropriate, to align with generally accepted best practices.
As Ülker Bisküvi Sanayi A.Ş. is a publicly listed company, this Information Security Policy has been developed and is implemented in compliance with the Capital Markets Board of Türkiye’s Communiqué No. VII-128.9 on Information Systems Management.
The preparation, updating, and implementation of the Information Security Policy are overseen by the Company’s senior management and approved by the Board of Directors. The Board of Directors appoints the senior management member responsible for this area. Ensuring effective and adequate controls over information systems within the scope of this Policy is the responsibility of the Board of Directors.
The Company maintains information security-related business continuity and disaster recovery plans to ensure the resilience and availability of critical systems and information assets during disruptive events. These plans are tested and reviewed periodically to enhance preparedness and minimize potential operational impacts.
To protect our Information Assets, it is essential to define and implement processes and controls governing the storage, transfer, transmission, modification, access, sharing, and logging of all information processing activities.
A framework compliant with the requirements of the ISO 27001 Information Security Management System has been established, and our Company holds ISO 27001 certification. In addition, the Information Security Management System is subject to independent external audits as part of the ISO 27001 certification process. In addition, the Company is committed to continuously improving its information security systems by regularly updating technologies, implementing advanced threat detection tools, and adopting best practices to address emerging cyber risks and vulnerabilities.
Internal audit activities are carried out to audit the implementation of the Information Security Management System, and audit results are shared with senior management. Necessary measures and sanctions are implemented in order not to repeat the security violations to be detected as a result of the audit. The Company has established a comprehensive framework for monitoring and responding to information security threats in real time. Advanced threat detection systems and continuous network monitoring tools are deployed to identify potential vulnerabilities and malicious activities. A dedicated incident response team ensures that any detected threat is assessed, contained, and remediated promptly, minimizing operational impact and safeguarding critical information assets. Regular threat intelligence updates and simulations are conducted to enhance preparedness and resilience against evolving cyber risks.
Information Security standards are taken into consideration in the selection and performance evaluation of suppliers, contractors, and all other external service providers. Our Company collaborates closely with external parties to ensure the effective implementation of Information Security practices.
Information Security standards are taken into consideration for the selection of suppliers, contractors and all other external sources and to control their performance. The Company enforces strict information security requirements for all third parties, embedding these standards into contractual agreements and conducting regular audits to ensure compliance. Any non-compliance triggers corrective actions or termination of engagement. In Information Security practices of external sources, our Company acts in cooperation with them
The Information Security Policy is communicated to all Company employees and stakeholders. All employees are required to act in compliance with the Information Security Policy, related procedures, and principles; participate in the necessary awareness training programs; and promptly report any information security incidents or concerns to the Information Security Manager.
We are committed to ensuring that the use and development of Artificial Intelligence (AI) solutions align with the principles of data privacy, cybersecurity, fairness, transparency, accountability, and ethical conduct. AI systems shall be designed, implemented, and operated in a manner that protects confidential information, minimizes cybersecurity risks, and actively mitigates potential biases that may affect outcomes. Human oversight shall be maintained for material or critical decisions, with appropriate mechanisms in place to enable human review and intervention when necessary. AI-generated outputs and decisions should be transparent and, where feasible, explainable, with clear accountability assigned for their use and resulting impacts. The capabilities, limitations, and authorized uses of AI systems shall be clearly defined and communicated. We seek to utilize AI technologies and supporting infrastructure with a low environmental footprint and require our own and third-party AI providers to adhere to applicable security, privacy, and sustainability standards.
The organization prohibits the use or deployment of AI systems that engage in manipulative practices, exploit individual vulnerabilities, perform social scoring, or enable unauthorized biometric surveillance, in line with applicable regulations, including the EU AI Act. Access to sensitive AI capabilities, including biometric recognition and surveillance-related functionalities, is restricted to authorized personnel based on legitimate business needs and applicable legal requirements. AI models are subject to ongoing monitoring to identify performance degradation, model drift, or emerging bias risks, and corrective actions are implemented where necessary. Employees receive regular training on the ethical, secure, and responsible use of AI technologies.
Individuals affected by significant AI-supported decisions have access to appropriate review and escalation mechanisms, including human oversight where applicable. We seek to minimize the environmental footprint of AI infrastructure by considering energy efficiency and sustainability criteria in the selection and operation of AI models and service providers. Furthermore, our AI governance framework is periodically reviewed and may be subject to independent assessment or certification against recognized standards, such as ISO 42001.