Governance / Oakley: Cybersecurity and data protection
Strengthening our cybersecurity strategy
Cybersecurity and data protection
At Oakley, we understand the critical importance of cybersecurity and data protection in safeguarding our operations. As part of our commitment to fortifying our digital infrastructure, we continue to place cybersecurity and data protection as a core part of our operations.
Cybersecurity and data protection are critical to Oakley and our portfolio, and we continue to strengthen our systems to remain resilient against the ever-evolving threat landscape."
David Bosomworth IT Director
94%
of Oakley Capital employees completed cybersecurity training in 2024
96%*
of our employees successfully identified phishing tests
*Due to transition from the previous phishing simulation platform to the current platform in 2024, this figure represents July 2024 - December 2024 when accurate data was available.
Building resilience
In 2024, we continued to build resilience in our systems, with initiatives aligned with the main pillars of the NIST-2 security framework to ensure that our infrastructure remains robust against an increasingly sophisticated threat landscape. To further strengthen our data security, we have implemented a Managed Data Discovery and Response (MDDR) service that allows us to identify and monitor access to sensitive data and track anomalous activity.
The deployment of a Security Information and Event Management (SIEM) solution has also enabled Oakley to collate and analyse security telemetry, providing deeper insights into potential cybersecurity threats. An additional priority for the IT Team was end point security, with extended controls and coverage implemented to protect against evolving risks.
This ongoing effort strengthens our capacity to protect, detect and respond to cyber threats swiftly and effectively.
Testing and training
Employee training and awareness remain foundational to our cybersecurity strategy. We continue to refine and update our security training materials, which are completed annually by all employees. In 2024, we deployed an AI-based phishing testing solution, providing personalised, meaningful tests for each employee. This solution has further increased the number of individuals able to successfully identify phishing attempts, demonstrating the effectiveness of our proactive approach.
Compliance
In 2024, Oakley also implemented several additional IT controls in preparation for the EU Digital Operational Resilience Act (DORA), as the regulation’s provisions became applicable in January 2025. This has particularly strengthened Oakley’s supplier management processes and the overall strategy to maintain the highest standards of data protection and resilience.
Through our continuous improvement initiatives, ongoing training, and a proactive approach to emerging threats, we are committed to maintaining the trust of our stakeholders and driving sustainable growth in an increasingly digital world.