Security and Cybersecurity

New platform to automate third-party privacy risk management (Vendor Management)

The aforementioned platform has been established as a tool to support the Poste Italiane Group acting as Data Controller under the GDPR, in overseeing the Privacy controls defined by the relevant functions when assigning its data processing to third parties. The objective is to support these functions in the performance of audits towards suppliers in accordance to the Article 28 of the GDPR, in order to guarantee the data protection (consumers, end users, employees, etc.) implemented by third parties in compliance with the Regulation and the relevant legislation.

Evolutionary maintenance of the data breach management platform - Data breach

With the aim of reinforcing data confidentiality and making data breach management more efficient, evolutionary mainte­nance of the data breach management platform has been carried out.

Evolutionary maintenance of the privacy plan management platform

With the aim of ensuring the effectiveness of second-level monitoring, improving and expanding the monitoring of priva­cy-related recovery actions, evolutionary maintenance of the dedicated platform has been carried out.

Security rating of the Group’s front end

To provide greater security of the Group’s front ends and better protection of consumer information, an external rating of the front end platform was requested via Bitsight, which resulted in a score of 770. An additional Bitsight rating is planned for 2026. The Bitsight platform rating is an independent assessment provided by an external platform that compares the security posture of different companies and provides a comparable company-to-company rating. This rating is an excellent support for the CERT function to understand the security level of its front ends compared to those of competitors. The rating ranges from a value of 250 to 900.

Incident drills

With the aim of improving coordination in incident response, reducing resolution times, and thus building greater confidence in the Group, three incident drills were conducted and an equal number is planned for 2026. In the drills, incident scenarios are created to test the communication flows between the different corporate functions, also simulating external players (media and authorities). In addition, an internal portal is provided where employees can read, watch features and web series, as well as practicing at Cybersecurity material.

Cyber Security Programme

The project aims to ensure a strengthening of consumer information protection also through phishing simulation campaigns aimed at employees most exposed to such risks. Campaigns vary in degree of complexity, allowing employees to train them-selves to recognise malicious emails and thus reduce the business risk of personal credentials being compromised.

Efficient resilience of IT services

With the aim of enhancing the availability, reliability and security of the ICT infrastructure, the negative impacts resulting from the unavailability and unreliability of the ICT infrastructure supporting business processes have been reduced by optimising and reducing the risk of the overall corporate service model. The Procedure for managing IT malfunctions and disruptions, together with the Incident and Problem Management processes, determines the definition of remediation plans and the monitoring of the resolution of related tickets.

Continuous updating on regulatory developments (e.g. DORA, NIS2, Quantum Computing, PSNC, eIDAS2, etc.)

With the aim of achieving high quality and safety standards, training activities were initiated on the impacts of new national and international legislation, to be achieved in the 2025-2027 timeframe.

Extending the scope of risk analysis to new Business Units and Group companies

In order to manage and mitigate corporate cyber risk and reduce negative impacts on end users, the scope of the risk analysis was extended to new Business Units and Group companies1, to be completed in the 2025-2027 timeframe. In 2025, Poste Vita was added to the perimeter.

Increasing the security level of transactions in Post Offices

With the aim of strengthening the protection of Poste Italiane Group customers against attempts at manipulation and fraud, the Group has launched an initiative to integrate and enhance the monitoring of transactions carried out at Post Offices, aimed at intercepting higher-risk transactions resulting from fraudulent contacts that induce customers to arrange transfers of funds in the presence of alleged anomalies or emergency situations. As part of this initiative, in 2025, developments in the regulatory framework were assessed, the processes most exposed to fraud risk were identified, the main fraud scenar­ios were mapped, and the necessary requirements and rule sets for fraud mitigation on physical channels were defined, in compliance with industry standards.

Increasing the security level of online transactions

With the aim of satisfying the needs of a major institutional stakeholder such as Cassa Depositi e Prestiti (CDP), as well as strengthening the protection of its customers and facilitating their user experience, the Group launched an initiative to integrate the monitoring of postal savings transactions. As part of this initiative, in 2025, the needs of BancoPosta and CDP stakeholders were assessed, the processes most exposed to the risk of fraud were identified, and requests to simplify the customer experience were analysed, in order to define the macro-requirements necessary for the project to start in 2026, also with a view to streamlining the processes for managing passbooks and vouchers.

PIAF scope extension

With the aim of strengthening customer protection, the Group will start to extend monitoring to Postepay top-ups arranged at Post Offices in 2026, in order to ensure protection on all fund transfer transactions identified as having a higher risk of fraud. In addition, with the aim of responding to the requests of the Cassa Depositi e Prestiti stakeholder, the Group has started to extend monitoring to Postal Savings transactions carried out at Post Offices, in order to ensure complete and consistent protection across all channels for high-risk transactions.

Evolutionary maintenance for the management of the Privacy Review Process for Poste Italiane and Group Companies

With the aim of ensuring full compliance with the General Data Protection Regulation (GDPR) and the management sys­tem as part of the privacy review process, it was planned to strengthen the safeguards to protect data confidentiality. The initiative aims to consolidate the privacy management system, ensuring a higher level of information protection and greater effectiveness in controlling the risks associated with the processing of personal data.

Robbery risk analysis and mitigation

With the aim of strengthening the protection of its employees and customers, the Group initiated an intervention to update the robbery risk assessment within the Risk Assessment Document (DVR) of the post offices. The aim of this initiative is to ensure a more effective supervision of safety in the workplace and in the service, to protect employees and customers of post offices. Subsequently, in order to mitigate the robbery risk and keep its level within the thresholds defined in the Group’s risk appetite, a gap analysis of the security measures installed at post offices was undertaken. The purpose of this initiative is to assess the adequacy of existing safeguards and to identify possible compensatory measures (upgrading alarm systems, video surveillance and surveillance), in order to strengthen the protection of employees and customers of post offices and to ensure a structured and consistent risk management.

Security Lab: performing accredited verification activities

With the aim of ensuring the maintenance of regulatory compliance and strengthening the IT security levels of digital services, the Group has initiated the periodic production of accredited reports to support the verification and certification processes of the services falling within the scope of control, including trust services and SPID. The systematic production of reports also makes it possible to generate timely documented evidence for each certified service, helping to strengthen the security of systems and infrastructures and to guarantee a high level of reliability of the services offered.

Extending the scope of risk analysis to new Business Units and Group companies and related economic quan­tification methodology

With the aim of monitoring and mitigating corporate cyber risk to protect the Group’s Business Units and companies, the scope of cyber risk analysis and management activities has been expanded, and the implementation of a new risk manage­ment methodology has been initiated; this is currently being finalised. The initiatives are aimed at preventing and reducing potential negative impacts on end-users, guaranteeing the continuity, reliability and security of the services offered. Cyber risk management involves the production of dedicated risk analysis reports for each analysed service, allowing for a timely assessment of vulnerabilities and the mitigation measures implemented.

Extending the Group’s business continuity plan management scope

With the aim of ensuring the operational continuity of the Group’s activities and minimising any potential negative impact on end users, risk management relating to business continuity within the organisation has been strengthened. In particular, the perimeter of the Group’s business continuity includes 3 of the Group’s business areas and the commercial channels responsible for the sale of products/services, which are flanked by corporate functions of policy, governance, control and the provision of services to support business processes. The initiative involves periodic testing of technological, organisa­tional and institutional aspects in order to verify the effectiveness of resilience and prevention processes.

Security equipment: installation of mechatronic keys at Polis Post Offices

This initiative is intended to overcome the need for the physical passing of keys between employees. In this way, it will be possible to manage a single protected key to access the Post Offices and disable lost or stolen keys in real time, enabling centralised management of reporting by tracking access events and maintenance operations. The mechatronic lock is a special security cylinder that combines mechanical and electronic technology allowing remote, programmable and secure control of entrances.

1. For 2026, the extension of the perimeter will concern the companies LisHolding, LisPay, SDA and Poste Logistics.