Wesco 2024 Sustainability Report: Cybersecurity and Data Protection

In This Article:

Wesco International
Read the 2024 Wesco Sustainability Report here

Cybersecurity and Data Protection

Cybersecurity and data protection is an enterprise wide priority and is reflected in engagements with our customers and suppliers. Our comprehensive approach to securing our data and business systems from attack, compromise, or loss includes a combination of leading technologies, policies and procedures and a 24/7 cybersecurity operations team monitoring our environment for signs of attack and responding in real time.

We conduct mandatory information security awareness training for our employees at least annually and enhanced training for specialized personnel. We have instituted regular attack or malicious activity simulations for employees to enhance awareness and responsiveness to such possible threats, and we also employ third parties to perform penetration and vulnerability tests.

Our security policies are evaluated and updated annually to address changes in the regulatory and threat landscapes and evolving best practices. We identify potential cybersecurity risks using internal measures and external resources. Identified risks are captured and prioritized on our risk register. Results are regularly reported back to a cross-functional, executive cybersecurity risk committee which then validates risks. While we focus heavily on prevention and detection, response and recovery plans, service agreements and partner engagements are in place should there be a need for us to respond to an attack. We have adopted a security incident response plan that provides controls and procedures for timely and accurate reporting of material cybersecurity incidents. We also maintain cyber liability insurance coverage.

To more effectively prevent, detect and respond to information security threats, we have a dedicated Chief Information Security Officer whose team is responsible for leading enterprise-wide information security strategy, policy, standards, architecture and processes. As part of its oversight of cybersecurity risk, the Audit Committee of our Board of Directors meets at least quarterly with our Chief Information Security Officer, Chief Information and Digital Officer and other senior leaders to receive updates on cybersecurity risks and threats, the status of initiatives to strengthen our information security systems and management's assessments of our security program. Wesco has achieved ISO 27001 certification for its Information Security Management System.

With these security measures in place, we did not experience any material data breaches in 2023. We also finalized our planned three-year infrastructure and security integration between Wesco and Anixter, making significant progress in Zero Trust configuration and data loss prevention implementation.