ESG STRATEGY

For a security company, ESG starts with data

A firm that handles client personal data owes it a discipline, not a campaign: collect less, and keep it for less time.

Governance structure

Since 2023 an ESG council reporting directly to the CEO has met quarterly, reviewed the indicators and published the results to all staff. External disclosure is an annual integrated report.

Environment — start with what is reducible

Assessment work involves a lot of travel. By classifying which checks can be run remotely we cut on-site visits by 30%, and in 2024 we moved all internal infrastructure to the cloud and closed our server room.

Social — collect the minimum

Data obtained during a client assessment is destroyed within 30 days of contract closure, with a certificate of destruction issued. The personal data fields on our recruitment and inquiry forms are reviewed annually and trimmed.

Governance — separation of duties

Author and approver are separated inside our own systems too. Nobody publishes their own document, and every publish and approval is written to an audit log. Enforced by the system rather than declared in a policy.

2030 targets

  • 40% emissions reduction

    Against a 2022 baseline, driven by workspace efficiency and travel substitution.

  • Zero unnecessary personal data

    Nothing stored beyond what the work requires, audited once a year.

  • 30% women in management

    18% as of 2025. Promotion criteria are published and leadership training expanded.

2025 progress

Emissions reduction vs 2022
31 %
Post-contract data destruction rate
100 %
Women in management
18 %
ESG council meetings per year
4