Protecting data and systems

Protecting our customers, our organisation, and our intellectual property is part of how we work. We take a proactive approach to helping keep our data secure, reliable, and available.

Our approach is guided by business needs and aligned with applicable regulations and industry standards. It is based on understanding and managing risks in a structured and responsible way.

We continuously work to strengthen controls and improve how we work. Security considerations are built into the design from the start shaping the way we develop products and solutions.

We draw on leading frameworks and standards such as NIST, OWASP, and ISA/IEC, and work closely with customers and partners to meet shared requirements. Our policies and practices are regularly reviewed to meet evolving threats and expectations.

 

How we manage information security

Cybersecurity is part of everyday work across Tetra Pak.  It’s a shared responsibility, combining people, processes, and technology.

We assess risks, monitor threats, and act to assess and address vulnerabilities in a timely manner. Our employees and consultants complete ongoing security training to help protect systems and data in their daily work.

Access to systems is controlled and regularly reviewed, and our environments are constantly tested and strengthened. We work closely with suppliers and partners to uphold consistent security standards.

Clear processes and controls – such as access management, encryption, and secure backups – help protect both our data and our customers’ data.

This is how we manage and protect  our customers, organisation, and our intellectual property, in close collaboration with customers, partners, and suppliers.

Security advisories

A security advisory is a notice issued to inform users about a significant security vulnerability or incident that may affect a product, system, or service, and where applicable, any recommended actions to help mitigate the impact.

Proceed to the security advisories page