Cybersecurity

Strengthened technological capabilities to protect individuals and institutions interacting with Klabin from emerging ethical challenges associated with technological advancements. 

2030 KODS

100% of employees and contractors were engaged in digital literacy initiatives necessary to keep up with the Company’s cybersecurity culture, ensuring the protection of personal data and corporate data.

Category 2022 2023 2024 2025 Meta 2030
Total number of employees 18.394 17.739 18.495 18.979 -
Total number of contractors 2.200 2.400 4.686 2.652 -
Employees trained 10.739 15.864 14.687 14.846 -
Contractors trained 726 960 3.165 1.002 -
Percentage of employees trained 58,4% 89,4% 79,4% 78,2% 100,0%
Percentage of contractors trained 33,0% 40,0% 67,5% 37,8% 100,0%

 

In 2025, Klabin continued its phishing simulation campaigns for both employees and third-party contractors using a new, more comprehensive platform. The Company also shared cybersecurity awareness content through the Minha Klabin portal and conducted targeted initiatives for senior management and the Board during the Managers' Convention, strengthening cybersecurity awareness across all levels of the organization.

Note: The decrease in the percentage of trained contractors is attributable to the inconsistent use of the digital training video during the onboarding of outsourced personnel at some units. Measures have already been implemented to ensure the training content is consistently delivered across all units.

Category 2022 2023 2024 2025
Number of complaints received from external parties and substantiated by the organization 0 0 0 0
Number of complaints from regulatory authorities 0 0 0 0
Total number of identified customer data breaches, thefts or losses 0 0 0 0

 

Consistent with previous years, no incidents involving customer privacy breaches or losses were recorded in 2025. 

In 2025, identity and access management (IAM)—the process of governing and managing access credentials across the technology environment—had become even more strategic due to the rapid growth of non-human identities, such as automation agents, scripts, and AI-driven processes. The compromise of these identities can have a direct impact on operations, underscoring the need for more robust security controls.

Furthermore, it has become essential to strengthen governance and increase supply chain visibility through the continuous assessment of suppliers' cybersecurity risks. There is also broad recognition across the market of the need to enhance incident response capabilities to improve operational resilience and minimize service disruptions. At Klabin, suppliers are integrated into incident response planning to help minimize downtime in the event of cyber incidents. Achieving this requires a robust supply chain management process, supported by a comprehensive inventory of technology assets and a clear understanding of their interdependencies.

Cybersecurity management is led by the Chief Information Security Officer (CISO), who reports to the Information Technology Committee, which in turn reports to the Executive Board and the Board of Directors. This governance structure is designed to support control initiatives aimed at mitigating cybersecurity risks and safeguarding the confidentiality, integrity, availability, and authenticity of information through an integrated approach encompassing both administrative and industrial environments.  Operations are guided by the Cybersecurity Policy—a summary of which is available online—approved by senior management and aligned with applicable standards and regulations, such as ISO 27001:2022 (information security management) and IEC 62443 (industrial systems security).

Cybersecurity at Klabin is guided by the mission of safeguarding the confidentiality, availability, and integrity of information through innovative processes and solutions that generate measurable business value and reinforce the trust of customers, employees, shareholders, and society. This commitment is underpinned by risk management focused on protecting information in both administrative and manufacturing environments.

Aligned with the Company's strategic priorities and industry best practices, Klabin developed an internal cybersecurity framework designed to address key challenges and support the ongoing evolution of its digital transformation.

The framework was developed in alignment with internationally recognized standards and frameworks, including ISO/IEC 27001:2022 (Information Security Management Systems), IEC 62443 (security for industrial automation and control systems), the NIST Cybersecurity Framework, a globally recognized benchmark for managing cybersecurity risk, and the CIS Critical Security Controls (CIS Controls), a prioritized set of safeguards designed to protect organizations and data from common cyber threats. It also incorporates the requirements of applicable data protection regulations, including Brazil's General Data Protection Law (LGPD) and the European Union's General Data Protection Regulation (GDPR). The framework aims to enhance the maturity of cybersecurity controls, mitigate identified risks, and support the secure adoption of emerging technologies.

Additionally, Klabin uses predictive monitoring to oversee its cybersecurity control portfolio, with related initiatives consolidated under the Corporate Risk Committee, strengthening integrated risk management and strategic decision-making.

 

Management of Information Security plans/programs

Business Continuity Plans Related to Information Security The Company maintains a critical systems recovery plan, which is assessed by the Internal Audit function through simulations of recovery times, data availability, and data integrity.
Information Security Vulnerability Assessments – Internal Audit The Company continuously monitors its internet-facing systems and promptly addresses identified vulnerabilities. In 2025, Klabin achieved an A rating from SecurityScorecard, a market-recognized platform that monitors cybersecurity-related information and exposures available on the internet. Klabin's strategic direction has been guided by the implementation of ISO 27001, the Brazilian Civil Rights Framework for the Internet (Marco Civil da Internet), LGPD, GDPR, CISP, NIST, and IEC 62443 as key references and best practice frameworks. These initiatives aim to ensure the confidentiality, integrity, availability, and authenticity of information, while promoting an integrated approach across both corporate and industrial environments.
Information Security Vulnerability Assessments – External Audit As part of the annual financial audit process, PwC conducted an assessment of Cybersecurity controls in 2025, using ISO/IEC 27001:2022 as its primary benchmark and reviewing systems that directly impact the Company's financial results. Additionally, during the annual cyber insurance renewal process, Marsh conducted an assessment of the Company's cybersecurity maturity level based on the NIST Cybersecurity Framework, validating the controls implemented in alignment with ISO/IEC 27001:2022 and IEC 62443 standards.
Escalation Process for Reporting Incidents, Vulnerabilities, or Suspicious Activities Employees can report incidents and suspicious activities through the "Report Phishing" buttons available in the corporate email system or by contacting the Cybersecurity team directly. Preventively, other incidents are managed through the Security Information and Event Management process. Significant cases are escalated to the Executive Management Committee and, when appropriate, may be reported to the Board-level governance structure through the Company's Advisory Committees.
Information security awareness training. Klabin promotes the dissemination of Cybersecurity principles and guidelines through awareness and training programs. In addition to mandatory training for all employees, the Company has established a 2030 target to ensure that 100% of direct and indirect employees are equipped with the digital literacy required to support a strong cybersecurity culture and safeguard both personal data and Company information. In 2024, the Company continued its phishing simulation campaigns, developed targeted training programs for the automation team, and maintained the publication of cybersecurity-related content on the Klabin intranet. Cybersecurity was also discussed during managerial, coordinator, and specialist conventions, reinforcing awareness at multiple organizational levels.

Cybersecurity is a cornerstone of Klabin’s strategy. We are committed to protecting the Company’s operations, information, and digital assets while fostering a secure and resilient digital environment for employees, partners, customers, and shareholders. To support this commitment, Klabin adopts internationally recognized standards and best-practice frameworks, including ISO 27001, the Brazilian Internet Civil Rights Framework (Marco Civil da Internet), LGPD, GDPR, CISP, NIST, and IEC 62443. This approach helps ensure the confidentiality, integrity, availability, and authenticity of information while providing an integrated view of both corporate and industrial environments. 

Klabin’s cybersecurity efforts are built on four pillars: 

  • Confidentiality: ensuring that information is accessible only to authorized individuals; 

  • Availability: ensuring that information is available to authorized users whenever required; 

  • Integrity: ensuring that data is modified only through authorized means; 

  • Authenticity: ensuring that the origin of information can be verified. 

Governance of cybersecurity is overseen by a multidisciplinary committee comprising representatives from Risk Management, Internal Controls, Internal Audit, Information Technology, Industrial Automation, and the business units. This governance structure provides an integrated and strategic approach to cyber risk management, enabling preventive, corrective, and awareness-building initiatives. 

Klabin also adopts an approach to third-party management regarding cybersecurity and privacy, ensuring that all suppliers and partners align with its internal policies and regulatory compliance requirements.  Furthermore, the Information Security department acts proactively to protect the company’s systems and ensure data integrity and protection through internal commitments to specific actions and continuous system improvements, such as: 

  • Implementations of layered technologies for risk mitigation; 

  • Continuous monitoring of security threats and incident response; 

  • Compliance of industrial systems with manufacturer recommendations; 

  • Execution and testing of business continuity plans; 

  • Assessment of security requirements with suppliers and partners; 

  • Raising awareness among employees and third parties, establishing individual responsibilities for information security; 

  • Support for the secure development of software and technology projects; 

  • Responsible adoption of new technologies, including artificial intelligence; 

  • Compliance with internal policies and controls.

RESPONSIBLE ARTIFICIAL INTELLIGENCE POLICY

Klabin’s approach to Responsible Artificial Intelligence is supported by the Cybersecurity Policy and governance framework. The Company maintains internal procedures and controls designed to protect information assets, manage cyber risks, ensure secure access to digital resources, preserve data confidentiality, integrity and availability, and promote responsible use of technology. These principles establish the security, governance and accountability foundations applicable to artificial intelligence solutions deployed across the organization.

Criteria As established in the Cybersecurity Policy
Protecting the cybersecurity of systems in the use and/or development of AI The Cybersecurity Policy establishes commitments to protecting digital assets, managing cyber risks, preventing incidents, monitoring threats, and continuously strengthening the security of corporate systems. As a corporate technology, Artificial Intelligence (AI) is expected to operate within this protection framework.
Respecting data privacy in the use and/or development of AI The Company's information security governance framework encompasses data protection, confidentiality, integrity, and availability of corporate information, in alignment with privacy requirements and the protection of sensitive information.
Establishing clear accountability for outcomes produced by AI models/tools The Policy assigns responsibilities related to security, risk management, and compliance, establishing governance roles and mechanisms for digital technologies and corporate information.
Defining clear boundaries for what AI can and cannot do Information security controls define rules and restrictions regarding the access, use, sharing, and processing of corporate information, creating boundaries that also apply to the use of AI solutions.
Ensuring transparency of AI systems and explainability of AI generated results/decisions The use of AI may also be supported by the Policy's requirements for governance, monitoring, risk management, and compliance.

 

RESPONSIBLE ARTIFICIAL INTELLIGENCE

Klabin maintains an enterprise AI adoption and governance program through the AI Office, Luna platform and Microsoft Copilot initiatives. The program includes employee training on responsible and secure use of AI, governance controls, role-based access management, content safety guardrails, monitoring and auditability mechanisms, cybersecurity requirements, and controls to prevent unauthorized access to sensitive information. AI initiatives are supported by awareness programs, communities of practice, governance processes and continuous monitoring of AI-enabled solutions.

The responsible artificial intelligence program contains the following elements:

Criteria Responsible artificial intelligence practices
Limiting access to sensitive AI capabilities Governance controls, role-based access management, content safety guardrails, and monitoring mechanisms that limit access to sensitive AI capabilities.
Distinct labeling of AI-generated content and outcomes of AI-driven decisions Where applicable, AI-generated content and AI-assisted outputs may be identified in accordance with platform capabilities and internal governance practices.
Training of employees on the ethical use and/or security of AI Klabin provides training, workshops and awareness initiatives on the responsible, ethical, and secure use of AI, including cybersecurity and information protection requirements.
Regular assessments of deployed AI models for fairness/bias Klabin's AI Office monitors AI-enabled solutions and may assess risks, performance, auditability, and fairness considerations as part of governance processes.
Appeals process for users/affected third parties Employees and external stakeholders may report concerns related to AI-enabled solutions through Klabin's Ethics and Integrity Channel including Privacy and Data Protection concerns. Reported cases are reviewed and handled in accordance with the Company's governance and compliance procedures.

Updated and verified on: 04/09/2026