Cybersecurity

We strive to offer clear and comprehensive guidance on the appropriate, safe and legal use of Information Technology (IT) and Operational Technology (OT) within our organisation.


Our cybersecurity policies are designed to align with the principles of the NIST Cybersecurity Framework (CSF) 2.0, ensuring that our practices meet industry cybersecurity standards.

IT & OT Acceptable Use Policy

Our IT & OT Acceptable Use Policy offers clear directives for the proper, safe, and lawful use of Todd's Information Technology (IT) and Operational Technology (OT).

Applicable to all employees and service providers who use Company IT and / or OT, the policy underscores the significance of IT and OT security and delineates compliance requirements. It ensures all parties understand their responsibilities, the importance of safeguarding data and operational processes, and the procedures for reporting non-compliance.

Cybersecurity Policy Suite

Our Cybersecurity Policy Suite provides comprehensive guidance on managing cyber risks and protecting digital assets, applicable to all entities within Todd. It sets out minimum requirements and expectations for cybersecurity in both IT and OT environments, emphasising compliance with regulations and outlining consequences for non-compliance.

Responsibilities span from employees to the Chief Information Security Officer (CISO), company managers, the Technology & Security team, and service providers. The suite includes supporting policies on cybersecurity management, data asset management, asset management, identity and access management, change management, response and recovery management, and digital cybersecurity awareness.