Cyber Security

The IT Security team acts as the first line of defense for the Bauer Group against evolving cyber threats. Its responsibilities are organized across three key service areas:

Security Operations & Monitoring

  • Continuous monitoring the infrastructure to identify potential threats, anomalies, and vulnerabilities across the digital landscape.
  • Implement and maintain layered technical defences, deploying security tools and protocols to protect critical assets and sensitive data.
  • Educate and train employees to recognize security threats, fostering a security-aware culture and reducing human error.
  • Collaborate with cross-functional teams to embed security practices and controls organization-wide.
  • Monitor emerging cybersecurity threats and adopt industry best practices.
  • Operate security monitoring and alerting mechanisms to support timely detection of suspicious activities, unauthorized access attempts, and abnormal system behavior.
  • Strengthen identity, access, endpoint, email, and network security controls to reduce exposure to phishing, malware, data leakage, and other cyber risks.

Vulnerability & Patch Management

•    Conduct risk assessments and penetration testing to identify and remediate security loopholes proactively.
•    Systematically evaluate and prioritize vulnerabilities, devising effective mitigation strategies across all infrastructure layers.
•    Maintain comprehensive security documentation, policies, and procedures aligned with evolving threat landscapes.
•    Coordinate vulnerability scanning, assessment, and remediation tracking to ensure identified risks are addressed within defined timelines and priorities.
•    Support timely deployment of security patches, firmware updates, and configuration hardening across servers and applications.
 

Incidence response & Business Continuity

  • Respond swiftly to security incidents, minimizing impact and restoring operations while keeping stakeholders informed.
  • Maintain incident response readiness through defined escalation paths, response procedures, communication protocols, and coordination with relevant internal and external stakeholders.
  • Analyze security incidents to identify root causes, implement corrective actions, and prevent recurrence through improved controls and awareness measures.
  • Support business continuity and disaster recovery preparedness by aligning cybersecurity response activities with backup, recovery, and operational resilience plans.