Governance / Oakley: Cybersecurity and data protection
Cybersecurity and data protection at Oakley
At Oakley, we recognise the critical importance of cybersecurity and data protection in maintaining the resilience of our operations and protecting information. As cyber threats continue to evolve in scale and sophistication, we maintain a proactive approach to strengthening our controls, improving resilience and embedding good security practices across the organisation.
Building resilience
During 2025, Oakley further enhanced its cybersecurity capabilities through a combination of strengthened monitoring, improved processes and additional technical safeguards. This included introducing a new security operations and incident response service to strengthen our ability to detect, respond to and recover from potential incidents. We also significantly strengthened the secure onboarding process for new SaaS applications, helping ensure that security and data protection considerations are assessed before new tools are adopted.
Alongside these measures, Oakley initiated an enhanced patch and vulnerability management programme to enable timely remediation of system weaknesses. We also launched a cyber intelligence programme to improve our capability to identify emerging threats and anticipate new attack vectors, reinforcing a more preventative approach.
People, training and response readiness
Employee awareness remains a core component of our cybersecurity approach. In 2025, we strengthened user awareness training for new starters, including live sessions to ensure all new joiners are trained in Oakley’s cybersecurity practices. This helps build good habits from the outset and reinforces day-to-day vigilance across the firm. In parallel, the IT team has continued to upskill in cyber response, improving preparedness and strengthening our ability to manage incidents effectively if they arise.
Maintaining and strengthening our approach
Cybersecurity is an area of continuous improvement, and Oakley remains committed to strengthening its security programme over time. This means maintaining focus on the fundamentals – identity and access management, incident response, and staff awareness – while continuing to develop the capabilities and processes that underpin a resilient and well-governed security posture.