Cybersecurity
Cybersecurity
2030 KODS
100% of employees and contractors were engaged in digital literacy initiatives necessary to keep up with the Company’s cybersecurity culture, ensuring the protection of personal data and corporate data.
| Category | 2022 | 2023 | 2024 | 2025 | Meta 2030 |
| Total number of employees | 18.394 | 17.739 | 18.495 | 18.979 | - |
| Total number of contractors | 2.200 | 2.400 | 4.686 | 2.652 | - |
| Employees trained | 10.739 | 15.864 | 14.687 | 14.846 | - |
| Contractors trained | 726 | 960 | 3.165 | 1.002 | - |
| Percentage of employees trained | 58,4% | 89,4% | 79,4% | 78,2% | 100,0% |
| Percentage of contractors trained | 33,0% | 40,0% | 67,5% | 37,8% | 100,0% |
In 2025, Klabin continued its phishing simulation campaigns for both employees and third-party contractors using a new, more comprehensive platform. The Company also shared cybersecurity awareness content through the Minha Klabin portal and conducted targeted initiatives for senior management and the Board during the Managers' Convention, strengthening cybersecurity awareness across all levels of the organization.
Note: The decrease in the percentage of trained contractors is attributable to the inconsistent use of the digital training video during the onboarding of outsourced personnel at some units. Measures have already been implemented to ensure the training content is consistently delivered across all units.
| Category | 2022 | 2023 | 2024 | 2025 |
| Number of complaints received from external parties and substantiated by the organization | 0 | 0 | 0 | 0 |
| Number of complaints from regulatory authorities | 0 | 0 | 0 | 0 |
| Total number of identified customer data breaches, thefts or losses | 0 | 0 | 0 | 0 |
Consistent with previous years, no incidents involving customer privacy breaches or losses were recorded in 2025.
In 2025, identity and access management (IAM)—the process of governing and managing access credentials across the technology environment—had become even more strategic due to the rapid growth of non-human identities, such as automation agents, scripts, and AI-driven processes. The compromise of these identities can have a direct impact on operations, underscoring the need for more robust security controls.
Furthermore, it has become essential to strengthen governance and increase supply chain visibility through the continuous assessment of suppliers' cybersecurity risks. There is also broad recognition across the market of the need to enhance incident response capabilities to improve operational resilience and minimize service disruptions. At Klabin, suppliers are integrated into incident response planning to help minimize downtime in the event of cyber incidents. Achieving this requires a robust supply chain management process, supported by a comprehensive inventory of technology assets and a clear understanding of their interdependencies.
Cybersecurity management is led by the Chief Information Security Officer (CISO), who reports to the Information Technology Committee, which in turn reports to the Executive Board and the Board of Directors. This governance structure is designed to support control initiatives aimed at mitigating cybersecurity risks and safeguarding the confidentiality, integrity, availability, and authenticity of information through an integrated approach encompassing both administrative and industrial environments. Operations are guided by the Cybersecurity Policy —a summary of which is available online—approved by senior management and aligned with applicable standards and regulations, such as ISO 27001:2022 (information security management) and IEC 62443 (industrial systems security).
Cybersecurity at Klabin is guided by the mission of safeguarding the confidentiality, availability, and integrity of information through innovative processes and solutions that generate measurable business value and reinforce the trust of customers, employees, shareholders, and society. This commitment is underpinned by risk management focused on protecting information in both administrative and manufacturing environments.
Aligned with the Company's strategic priorities and industry best practices, Klabin developed an internal cybersecurity framework designed to address key challenges and support the ongoing evolution of its digital transformation.
The framework was developed in alignment with internationally recognized standards and frameworks, including ISO/IEC 27001:2022 (Information Security Management Systems), IEC 62443 (security for industrial automation and control systems), the NIST Cybersecurity Framework, a globally recognized benchmark for managing cybersecurity risk, and the CIS Critical Security Controls (CIS Controls), a prioritized set of safeguards designed to protect organizations and data from common cyber threats. It also incorporates the requirements of applicable data protection regulations, including Brazil's General Data Protection Law (LGPD) and the European Union's General Data Protection Regulation (GDPR). The framework aims to enhance the maturity of cybersecurity controls, mitigate identified risks, and support the secure adoption of emerging technologies.
Additionally, Klabin uses predictive monitoring to oversee its cybersecurity control portfolio, with related initiatives consolidated under the Corporate Risk Committee, strengthening integrated risk management and strategic decision-making.
Management of Information Security plans/programs
| Information security-related business continuity plans. | The Company maintains a recovery plan for critical systems, which is evaluated by the internal audit function through exercises that test recovery time objectives, system availability, and data integrity. |
| Information security vulnerability analysis (internal and external audits) | The Company monitors its internet-facing systems and remediates vulnerabilities. In 2025, Klabin received an "A" rating from SecurityScorecard, a market platform that monitors publicly available internet data. Klabin’s strategic approach involved implementing ISO/IEC 27001, the Marco Civil da Internet (Brazilian Civil Rights Framework for the Internet), Brazil's General Data Protection Law (LGPD), the European Union's General Data Protection Regulation (GDPR), the NIST Cybersecurity Framework, the CIS Critical Security Controls (CIS Controls), and IEC 62443—to guide best practices and help ensure the confidentiality, integrity, availability, and authenticity of information across both corporate and industrial environments. |
| An escalation process enabling employees to report incidents, vulnerabilities, or suspicious activities. | Incidents and suspected threats can be reported using the "Report Phishing" button in email or by forwarding suspicious messages directly to the Cybersecurity team. Other security incidents are identified and managed proactively through the Security Information and Event Management (SIEM) process. Significant incidents are escalated to the Executive Committee and, where appropriate, to the Board through its advisory committees. |
| Information security awareness training. | Klabin promotes cybersecurity awareness and reinforces its cybersecurity principles and guidelines through ongoing training and awareness initiatives. In addition to mandatory training for all employees, the Company has established a 2030 target to ensure that 100% of its employees and contractors are proficient in the digital skills and cybersecurity practices needed to foster a strong security culture and protect both personal and Company data. In 2024, Klabin continued its phishing simulation campaigns and delivered targeted training for the automation team. Cybersecurity content continued to be published on the Klabin Intranet, and the topic was also featured at conventions attended by managers, coordinators, and specialists. |
Cybersecurity is a cornerstone of Klabin’s strategy. We are committed to protecting the Company’s operations, information, and digital assets while fostering a secure and resilient digital environment for employees, partners, customers, and shareholders. To support this commitment, Klabin adopts internationally recognized standards and best-practice frameworks, including ISO 27001, the Brazilian Internet Civil Rights Framework (Marco Civil da Internet), LGPD, GDPR, CISP, NIST, and IEC 62443. This approach helps ensure the confidentiality, integrity, availability, and authenticity of information while providing an integrated view of both corporate and industrial environments.
Klabin’s cybersecurity efforts are built on four pillars:
Confidentiality: ensuring that information is accessible only to authorized individuals;
Availability: ensuring that information is available to authorized users whenever required;
Integrity: ensuring that data is modified only through authorized means;
Authenticity: ensuring that the origin of information can be verified.
Governance of cybersecurity is overseen by a multidisciplinary committee comprising representatives from Risk Management, Internal Controls, Internal Audit, Information Technology, Industrial Automation, and the business units. This governance structure provides an integrated and strategic approach to cyber risk management, enabling preventive, corrective, and awareness-building initiatives.
Klabin also adopts an approach to third-party management regarding cybersecurity and privacy, ensuring that all suppliers and partners align with its internal policies and regulatory compliance requirements. Furthermore, the Information Security department acts proactively to protect the company’s systems and ensure data integrity and protection through internal commitments to specific actions and continuous system improvements, such as:
Implementations of layered technologies for risk mitigation;
Continuous monitoring of security threats and incident response;
Compliance of industrial systems with manufacturer recommendations;
Execution and testing of business continuity plans;
Assessment of security requirements with suppliers and partners;
Raising awareness among employees and third parties, establishing individual responsibilities for information security;
Support for the secure development of software and technology projects;
Responsible adoption of new technologies, including artificial intelligence;
Compliance with internal policies and controls.