CYBERSECURITY
We have implemented a comprehensive cybersecurity program designed to safeguard SABIC's business and manufacturing operations.
SABIC's corporate-wide cybersecurity maturity plan is overseen by the Corporate Cybersecurity Committee, chaired by the CEO, and integrated into the global Enterprise Risk Management (ERM) framework. This plan aims to enhance SABIC's cybersecurity defenses, improve resilience, strengthen data protection measures, maintain regulatory compliance, and promote cybersecurity awareness across the organization.
Securing SABIC's operational technology environment is a key focus area. Technology and information assets are protected by enforcing technical and procedural controls, using predictive alerts for response and mitigation, and through automation and integration. Identity management, access controls, and data protection for cloud-based systems are also regularly enhanced as SABIC's business accelerates toward digitalization.
Applying the right level of classification is important to secure data in transit and at rest and for secure usage, processing, and storage.
SABIC fosters an inclusive, people-centric culture of cyber awareness and empowerment through customized, multilingual programs for employees, families, and third parties. These programs are delivered globally using multiple modes and channels throughout the year and include tailored learning interventions designed for employees in distinct functions and roles.
Evolving technologies and the increasing sophistication of cyber threats require constant monitoring. Considering these changes in the threat landscape, the cybersecurity program is reviewed and updated annually to prioritize risks, assess resilience, and evaluate maturity against industry benchmarks.
2024 DEVELOPMENTS
In 2024, SABIC achieved the following milestones in its cybersecurity journey:
- The launch of the Foresight Program reflects our commitment to a proactive approach in enhancing cybersecurity resilience and securing business practices. This is achieved through continuous evaluation and improvement of technology controls, promoting an inclusive culture, and monitoring the “people aspects” of cybersecurity.
- The start of the CyberTrust program for suppliers, in collaboration with Global Procurement Services, integrates cybersecurity requirements into the procurement life cycle. This provides guidance and certification to help third parties meet SABIC's cybersecurity standards before onboarding.
- SABIC implemented numerous data protection initiatives during the year under review, including a new layer of protection, Data Loss Prevention (DLP). This will safeguard intellectual property and secure data privacy by applying the right level of sensitivity and classification to data, enabling its secure usage, processing, and storage.
Read more about our cybersecurity initiatives .
Disclaimer: This abridged interactive version of the SABIC Integrated Annual Report 2024 is based on the original PDF report published on this website. In case of any discrepancy, the original PDF report will prevail.