Cybersecurity and data protection
The Group put the Information Security Department in place, which employs a comprehensive approach to ensuring the stability of business operations by protecting the confidentiality, integrity and availability of information and information systems.
Rusagro takes cybersecurity risks into account, particularly those pertaining to the safety of data belonging to partners, customers, employees, and shareholders. The Group employs cutting‑edge security technologies, continuously enhances cyber threat management mechanisms and takes measures against leaks of personal and other confidential data.
Business‑oriented information security system
After more than six years of collaboration between Rusagro Tech and Infosystems Jet JSC, a Russian information security (IS) solutions provider, the Group’s shift to a business‑oriented IS system was completed in 2024.
- Applied information security systems and cryptographic protection
- Monitoring of and response to incidents
- Network infrastructure protection
- Development of IS architecture and methodologies
History of development
2017
Stage 1
Comprehensive IS audit and development of a long‑term IS development strategy
The primary IS survey covered the head office and production sites of all Rusagro Group’s business segments: Meat, Oil and Fats, Sugar and Agriculture. To measure the IS level, Rusagro adapted the capability maturity model integration (CMMI), which allows for a unified assessment of the maturity level of IS processes in different divisions of the agroholding.
The strategy included various control mechanisms such as annual GAP‑analysis of changes in the maturity level of IS processes and an assessment of the required resources, which takes into account the specifics of the Company’s various business segments.
Result
Audit of IT infrastructure
key information systems
servers
AWS
IS controls
2018–2022
Stage 2
Assessment of processes and upgrade
Infosystems Jet conducted the annual assessment of the IS process maturity across Rusagro Group, which also provided a comparison of the results from the previous and current years.
The work covered not only the corporate segment of the IT infrastructure, but also the process segment, including industrial automated systems that support the operation of production chains.
sites
information systems
automated process control systems
Result
2023
Stage 3
Transition of the Group to the IS Health Model assessment system and annual audit of information security
Moving to a system of qualitative and quantitative indicators was the next step in the Company’s development.
The IS Department followed the overall business principle in implementing the transition to the IS Health Model assessment system.
The model is based on IS process management, linking IS and IT metrics to business objectives. It is used to identify operational and strategic level indicators to make the right management decisions and to capture the threshold and target states of the indicators.
Result
The introduction of the system allowed for better interaction with related functions through the introduction of joint performance indicators.
Since the transition to the new IS maturity assessment model, the Health Model, the development of IS processes and systems has continued. The key highlights of this stage are listed below: