Skip to content

Information Security

Information Security

Information Security at WillDom is the set of principles, policies, roles, standards, and operational practices used to protect the company’s most critical assets and the services delivered to customers. The program is built with a risk-based approach, meaning security controls, governance, and priorities are defined according to the criticality of assets, the sensitivity of data, customer requirements, and the potential business impact of threats.

This section consolidates the main components of WillDom’s Information Security framework into one place. It should be used as the entry point for understanding how WillDom manages cybersecurity, privacy, resilience, incident response, technical safeguards, and security governance across the business. The goal is not only to define rules, but to provide a unified operational model that connects business leadership, technical teams, branch operations, talent processes, and customer-facing service delivery.

At a high level, this framework is organized around seven pillars:

  1. Cybersecurity and resilience governance

  2. Risk management

  3. Security fundamentals and baseline controls

  4. Data privacy and protection

  5. Incident response

  6. Technical standards

  7. Security service levels by delivery model

1. Purpose

The purpose of Information Security at WillDom is to protect the confidentiality, integrity, and availability of information, regardless of the medium where that information is stored, accessed, transmitted, or used. This includes digital assets as well as non-digital information such as paper, voice, and organizational know-how. The program also aims to ensure that cybersecurity and business continuity are managed in a structured way through an Information Security Management System aligned with recognized standards.

From an operational perspective, the Information Security function exists to:

  • protect critical business services and assets,

  • protect customer data and sensitive information,

  • support secure service delivery,

  • define and monitor security rules,

  • manage cybersecurity risks,

  • coordinate response to incidents,

  • and continuously improve the maturity of the program.

The Information Security program covers the most critical assets and processes of WillDom. According to the Security Handbook, the scope includes assets related to:

  • main business functions,

  • main business services used by staff,

  • customer data,

  • sensitive data such as PII, health, financial, and customer business data,

  • and assets exposed to the internet, including websites, APIs, mobile assets, and domains.

The Risk Management document expands this operational scope further by stating that risk analysis considers:

  • buildings where systems and people are located,

  • people, including staff and subcontracted personnel,

  • technology associated with relevant technical resources,

  • and critical suppliers, meaning third parties necessary for the provision of services.

The Incident Response policy also clarifies that the program applies to collaborators and third parties working on critical services such as:

  • infrastructure services,

  • cloud services,

  • digital products,

  • and business-critical services.

WillDom’s Information Security program is anchored in a formal Cybersecurity and Resiliency Policy. That policy states that information is one of the company’s most critical assets and that top management is committed to implementing an ISMS aligned with ISO/IEC 27001 and ISO/IEC 22301. It also establishes management’s commitment to:

  • define an adequate control framework,

  • assign roles and responsibilities,

  • allocate resources,

  • ensure training and awareness,

  • promote risk analysis,

  • and maintain continuous improvement.

This means Information Security is not treated as a purely technical function. It is a business management responsibility supported by technical controls, operational governance, and formal risk treatment.

The Security Handbook states that WillDom’s cybersecurity program is created, maintained, and monitored in line with major international standards and frameworks, including:

  • ISO 27001

  • ISO 27002

  • ISO 27032

  • ISO 22301

  • PCI-DSS

  • CIS Controls

  • NIST Cybersecurity Framework.

For privacy, the same document states that WillDom’s privacy practices are aligned with:

  • GDPR

  • HIPAA

  • LGPD.

The Risk Management document adds ISO 27005 and ISO 31000 to the list of reference frameworks for risk analysis and treatment, and notes that treatment decisions may also consider ISO 27002, CIS Controls, PCI-DSS, and the NIST Cybersecurity Framework.

The Security Handbook defines a governance structure where cybersecurity is managed through a mix of leadership accountability, regular governance forums, and operational follow-up. The main governance mechanisms are:

  • Cybersecurity Monthly Steerco, a monthly session with top management,

  • Weekly Monitoring Calls, focused on action plans, incidents, risk treatment, and compliance challenges,

  • and Customer Monthly or Ad-Hoc Calls, depending on the service and the customer’s expectations.

These governance spaces are used to review:

  • roadmap status,

  • action plan progress,

  • risk treatment decisions,

  • incident status,

  • and compliance topics.

The Risk Management document complements this by stating that the monitoring of treatment plans and risk status is discussed in the Cybersecurity Committee or any other forum involving the Business Board, and that a Risk Committee / Security Committee should exist as a joint decision-making body.

The Security Handbook defines the key roles for the cybersecurity program.

Top Management is accountable for the cybersecurity of the business, the program budget, the decision-making associated with risk treatment, the allocation of resources, and the promotion of cybersecurity across business lines and services.

The CSO/CISO is accountable for implementing and monitoring the cybersecurity program, leading risk management, awareness activities, incident response, documentation lifecycle, compliance activities, third-party assessments, customer audits, budget execution, and vendor security oversight.

This group is accountable for the technical implementation of cybersecurity measures, DevOps security practices, monitoring, asset inventory accuracy, documentation, incident support, and vendor control in their technical domain.

Talent is accountable for embedding cybersecurity requirements into hiring, onboarding, offboarding, and broader talent practices.

Branch Directors / Branch Delivery Manager

Section titled “Branch Directors / Branch Delivery Manager”

Branch Directors and Branch Delivery Managers are responsible for monitoring execution of the awareness program, implementing training, ensuring the disciplinary process, and monitoring compliance with cybersecurity rules for their vendors.

All staff are responsible for complying with cybersecurity and privacy rules, reporting threats, collaborating during incidents, following awareness and training programs, and performing their duties with security by default.

The Risk Management document also defines roles for:

  • WillDom Business Board / Risk Committee

  • Delivery Manager

  • Business Developer

  • Head of Infrastructure / CTO

  • Head of Cybersecurity and Resilience / CSO / CISO

  • All employees and collaborators.

These roles are especially relevant when risk treatment decisions, mitigation plans, supplier analysis, and customer-impacting changes are involved.

Risk management is one of the core mechanisms of the Information Security program. WillDom manages cybersecurity and resilience using a structured methodology based on analysis of scenarios that could affect service delivery, contractual commitments, daily operations, or significant changes in the environment.

The Risk Management framework references:

  • ISO 22301

  • ISO 27005

  • ISO 31000

    and treatment decisions may consider additional standards such as ISO 27002, CIS Controls, PCI-DSS, and NIST CSF.

The accepted treatment options are:

  • accept the risk,

  • mitigate the risk,

  • transfer the risk,

  • eliminate the risk.

Treatment decisions must be formalized by the Business Board of WillDom, documented, and communicated when appropriate. If mitigation is selected, resources must be assigned and monitored. Accepted risks must also be documented and reviewed within the current year or based on the defined acceptance period.

Risk management is described as a daily and continuous process, but it must be formalized annually or whenever relevant changes occur. Examples of relevant changes include:

  • technology replacement,

  • architecture changes,

  • physical relocation,

  • critical provider changes,

  • contract renewals,

  • new services,

  • new contracts,

  • and post-incident lessons.

Each risk analysis exercise must generate evidence such as:

  • risk treatment matrix,

  • scenario description,

  • identified risks, impact, and likelihood,

  • treatment decisions,

  • management approval,

  • and residual risk acceptance.

The Risk Management document defines residual risk calculation using:

Asset Criticality + Likelihood + Impact = Risk Rate. Risks in the lower range are considered accepted, while higher ratings may require mitigation plans and tracking.

The Security Handbook defines WillDom’s security baseline as cybersecurity by default. These controls apply beyond specific risk-based adjustments and represent the foundational expectations across services and assets.

The baseline requires:

  • authentication for all access to services,

  • separate personal and admin accounts,

  • service accounts assigned to a single service and owner,

  • least privilege and need-to-know,

  • RBAC,

  • centralized authentication,

  • 2FA for IT services and sensitive data,

  • centralized authentication logging,

  • and deactivation/deletion of inactive accounts.

All digital service components must be hardened using CIS Benchmarks when available or vendor best practices otherwise. Unused services must be disabled, assets must run current versions or patches, and logging should be configured for authentication, changes, and service lifecycle events. Sharing services in ways that create single points of failure should be avoided.

All network services must be authenticated and authorized, access rules must be documented and periodically reviewed, services must have a reason and an owner, privileged access must come from a secure management network, and segmentation should reflect asset criticality.

All services must be under a patch management process. The DevOps and Security Handbook documents specify:

  • emergency patches in less than 7 days,

  • critical patches in less than 30 days,

  • regular authenticated security scans,

  • monitoring of public attack surface,

  • and go-live only after clean vulnerability reporting without critical or high findings.

Sensitive data must be encrypted in transit and at rest using current best-practice mechanisms. The documentation references:

  • TLS 1.2 or higher,

  • hash + salt for authentication,

  • AES 256 / RSA,

  • KMS,

  • workstation and laptop encryption,

  • and encryption of external drives where approved.

All business-supporting or contract-relevant information must be covered by a backup strategy applying the 3-2-1 rule, with encryption at rest, inventory and documentation of backup media, and restore test calendars.

The Security Handbook states that human resources are among the most critical assets because they execute services and business activities. For that reason, Talent must maintain cybersecurity processes covering:

  • NDA before contact with external resources, parties, or candidates,

  • security requirements in hiring,

  • background checks based on risk,

  • documented job terms and conditions,

  • disciplinary process,

  • awareness and training,

  • and communication of security rules and policies.

The Service Levels document reinforces that, across all levels, WillDom’s responsibilities include:

  • security of the hiring process,

  • NDA,

  • awareness and training,

  • onboarding security fundamentals,

  • disciplinary process,

  • offboarding notification,

  • retirement of access notification,

  • asset return,

  • data disposal notification,

  • and incident notification.

The Security Handbook defines a Data Privacy & Security Program with several core principles:

  • all data must have an owner,

  • data owners must keep inventory updated,

  • inventory should be centralized and automated when possible,

  • data must be classified as Public, Internal, or Confidential,

  • storage, retention, disposal, access, and security must depend on criticality,

  • by default, all customer data is Confidential,

  • unnecessary data must not be requested,

  • data that is no longer needed must be deleted,

  • and data in transit or at rest must be encrypted unless it is classified as Public.

The Strategic Alliance also had personal data obligations, but within the security documents themselves, privacy is clearly treated as a first-class control area rather than a side topic. The Incident Response and Service Levels documents also show that different service models affect how customer data is handled and which safeguards must apply.

The Incident Response Policy defines the activities carried out to respond to cybersecurity incidents and covers all collaborators and third parties working on critical services.

Potential incidents must be reported through the formal channel:

security@willdom.com. End users are required to report and collaborate in investigations and response activities.

The policy identifies the incident response team and responsibilities:

  • Mariano del Río – vCISO

  • Román Giachetti – Infrastructure Lead

  • Leandro Viadas – Network-wide Communications

  • Agustín Cortés – Incident Coordination and Follow-up.

The Security Team leads the response process, while Infrastructure / DevOps leads the technical response and application teams support investigation, configuration, and lessons learned. Third parties must report incidents tied to their services and provide logs, alerts, and technical evidence when requested.

Examples of cybersecurity incidents that must be reported include:

  • phishing,

  • spam,

  • ransomware,

  • malware infection,

  • cyber attack,

  • security policy violations,

  • denial of service,

  • information leakage,

  • loss or theft of assets.

The policy describes the process through:

  • incident report,

  • detection and analysis,

  • containment,

  • eradication and recovery,

  • and post-incident lessons learned.

Containment may involve isolation of devices or disabling users/services. Eradication and recovery may include preserving evidence, reinstalling systems, reconfiguring users/software, patching, network changes, and data recovery. Serious incidents may justify forensic imaging and notarized documentation.

Incidents are reviewed monthly to identify improvements, resource needs, and lessons learned. A summary is presented to the Security Steer Committee. The policy establishes KPIs requiring 100% of incidents to be attended, documented, closed monthly, and reported.

The Technical Standard – Endpoint defines technical guidelines for WillDom digital assets assigned to customer service execution. It states that requirements are mandatory for Agile Teams and recommended for Remote Staffing, with reference to the Security Service Levels for more detail. Exceptions must follow a formal exception management workflow and require approval from the Branch Director and Global Delivery.

Baseline controls include:

  • strong passwords,

  • 2FA for sensitive or privileged access,

  • licensed and updated software,

  • antimalware/HIPS/firewall controls,

  • updated signatures,

  • and weekly scans.

    Backups should follow customer requirements first, or otherwise be kept weekly in WillDom’s cloud.

Additional requirements include:

  • BIOS password,

  • full disk encryption,

  • external drive encryption when required,

  • DLP / USB block,

  • and internet protection controls such as proxy, SSL inspection, and threat protection.

The document also states privacy rules requiring confidentiality of service information and storage/backup of source code or customer data according to customer rules.

13. Technical Standard – DevOps

The Technical Standard – DevOps defines the security practices and requirements applicable when DevOps work is performed, including sysadmin, network admin, and configuration-through-code activities.

In addition to repeating core controls on access control, hardening, networking, vulnerability management, encryption, and backup, this standard adds several DevOps-specific expectations:

Mandatory documentation includes:

  • high-level architecture diagrams,

  • interconnections and protocols,

  • third-party dependencies,

  • network segmentation,

  • technical management,

  • and documented operation tasks.

The standard lists best practices for CI and CD such as:

  • fail fast,

  • commit regularly,

  • fix broken builds quickly,

  • automate continuously,

  • document release and rollback steps,

  • integrate security early,

  • and maintain feedback loops.

For cloud environments, baseline expectations include:

  • minimizing subscription owner roles,

  • trusted SSO,

  • 2FA,

  • resilience thinking,

  • formal RACI with vendors and customers,

  • keeping software updated,

  • encrypting data in transit and at rest,

  • minimizing unnecessary data handling,

  • and executing regular cloud security assessments.

Each service must be under monitoring, including:

  • health checks,

  • CPU,

  • memory,

  • network bandwidth,

  • storage,

  • cybersecurity signals,

  • port scanning,

  • malicious activity,

  • DDoS attempts,

  • and notifications from critical vendors.

14. Service Levels – Security

The Service Levels – Security document explains that WillDom offers different security levels depending on the customer context and delivery model. The objective is to let customers choose the level aligned with their risk appetite and service maturity.

WillDom’s responsibility is mainly focused on human resources security because access, assets, platforms, and data security are managed by the customer. This level is associated with Remote Staff and applies the endpoint technical standard at Level 1.

WillDom is responsible for human resources and asset assignment, while the customer remains mainly responsible for access and platforms, and data security is shared. This level is also associated with Remote Staff and includes computer assignment plus Level 1 endpoint controls.

WillDom has responsibilities for human resources, asset assignment, access, platforms, and technology services, while data security remains a shared responsibility with the customer. This level is associated with Agile Teams and includes broader responsibilities such as:

  • access control,

  • 2FA,

  • SDLC / secure coding,

  • security scans,

  • remediation,

  • intrusion tests,

  • DevOps,

  • antimalware protection,

  • security monitoring,

  • data disposal,

  • third-party security,

  • and backup / offline backup.

This service-level model is important because it connects security expectations to the actual service delivery structure.

The Security Handbook states that WillDom maintains a compliance program based mainly on customer requirements, with special focus on cybersecurity and privacy. It also states that, under its roadmap, WillDom has defined certification goals with focus on:

  • ISO 27001,

  • SOC 2 Type 2,

  • and PCI-DSS when required by customers.

The policy and handbook repeatedly reinforce that the program must be continuously improved, and that new customer, legal, regulatory, and business requirements may be incorporated over time as part of that improvement cycle.

16. Exception management

Exception handling is explicitly documented at least in the Endpoint standard, which states that exceptions should be formalized through an exception management workflow and require approval from Branch Director and Global Delivery. Risk Management also states that exception decisions must be approved or rejected by the Business Board / Risk Committee.

This means any deviation from documented security requirements should be:

  • formally documented,

  • justified,

  • approved by the correct decision-makers,

  • and monitored when relevant.

WillDom’s Information Security model is a risk-based, management-led, and operationally integrated framework designed to protect critical assets, support secure service delivery, and maintain resilience across the business. It is grounded in formal policy commitments, international standards, documented governance, structured risk treatment, defined roles, incident response capabilities, technical baselines, privacy controls, and service-level differentiation according to customer needs.

The Security Handbook should remain the conceptual backbone of the section, while Risk Management, Incident Response, Endpoint Security, DevOps Security, and Service Levels operate as specialized components within the same Information Security framework.