Information Security
Information Security
Overview
Section titled “Overview”Information Security at WillDom is the set of principles, policies, roles, standards, and operational practices used to protect the company’s most critical assets and the services delivered to customers. The program is built with a risk-based approach, meaning security controls, governance, and priorities are defined according to the criticality of assets, the sensitivity of data, customer requirements, and the potential business impact of threats.
This section consolidates the main components of WillDom’s Information Security framework into one place. It should be used as the entry point for understanding how WillDom manages cybersecurity, privacy, resilience, incident response, technical safeguards, and security governance across the business. The goal is not only to define rules, but to provide a unified operational model that connects business leadership, technical teams, branch operations, talent processes, and customer-facing service delivery.
At a high level, this framework is organized around seven pillars:
-
Cybersecurity and resilience governance
-
Risk management
-
Security fundamentals and baseline controls
-
Data privacy and protection
-
Incident response
-
Technical standards
-
Security service levels by delivery model
1. Purpose
The purpose of Information Security at WillDom is to protect the confidentiality, integrity, and availability of information, regardless of the medium where that information is stored, accessed, transmitted, or used. This includes digital assets as well as non-digital information such as paper, voice, and organizational know-how. The program also aims to ensure that cybersecurity and business continuity are managed in a structured way through an Information Security Management System aligned with recognized standards.
From an operational perspective, the Information Security function exists to:
-
protect critical business services and assets,
-
protect customer data and sensitive information,
-
support secure service delivery,
-
define and monitor security rules,
-
manage cybersecurity risks,
-
coordinate response to incidents,
-
and continuously improve the maturity of the program.
2. Scope
Section titled “2. Scope”The Information Security program covers the most critical assets and processes of WillDom. According to the Security Handbook, the scope includes assets related to:
-
main business functions,
-
main business services used by staff,
-
customer data,
-
sensitive data such as PII, health, financial, and customer business data,
-
and assets exposed to the internet, including websites, APIs, mobile assets, and domains.
The Risk Management document expands this operational scope further by stating that risk analysis considers:
-
buildings where systems and people are located,
-
people, including staff and subcontracted personnel,
-
technology associated with relevant technical resources,
-
and critical suppliers, meaning third parties necessary for the provision of services.
The Incident Response policy also clarifies that the program applies to collaborators and third parties working on critical services such as:
-
infrastructure services,
-
cloud services,
-
digital products,
-
and business-critical services.
3. Policy foundation
Section titled “3. Policy foundation”WillDom’s Information Security program is anchored in a formal Cybersecurity and Resiliency Policy. That policy states that information is one of the company’s most critical assets and that top management is committed to implementing an ISMS aligned with ISO/IEC 27001 and ISO/IEC 22301. It also establishes management’s commitment to:
-
define an adequate control framework,
-
assign roles and responsibilities,
-
allocate resources,
-
ensure training and awareness,
-
promote risk analysis,
-
and maintain continuous improvement.
This means Information Security is not treated as a purely technical function. It is a business management responsibility supported by technical controls, operational governance, and formal risk treatment.
4. Security and privacy references
Section titled “4. Security and privacy references”The Security Handbook states that WillDom’s cybersecurity program is created, maintained, and monitored in line with major international standards and frameworks, including:
-
ISO 27001
-
ISO 27002
-
ISO 27032
-
ISO 22301
-
PCI-DSS
-
CIS Controls
-
NIST Cybersecurity Framework.
For privacy, the same document states that WillDom’s privacy practices are aligned with:
-
GDPR
-
HIPAA
-
LGPD.
The Risk Management document adds ISO 27005 and ISO 31000 to the list of reference frameworks for risk analysis and treatment, and notes that treatment decisions may also consider ISO 27002, CIS Controls, PCI-DSS, and the NIST Cybersecurity Framework.
5. Governance model
Section titled “5. Governance model”The Security Handbook defines a governance structure where cybersecurity is managed through a mix of leadership accountability, regular governance forums, and operational follow-up. The main governance mechanisms are:
-
Cybersecurity Monthly Steerco, a monthly session with top management,
-
Weekly Monitoring Calls, focused on action plans, incidents, risk treatment, and compliance challenges,
-
and Customer Monthly or Ad-Hoc Calls, depending on the service and the customer’s expectations.
These governance spaces are used to review:
-
roadmap status,
-
action plan progress,
-
risk treatment decisions,
-
incident status,
-
and compliance topics.
The Risk Management document complements this by stating that the monitoring of treatment plans and risk status is discussed in the Cybersecurity Committee or any other forum involving the Business Board, and that a Risk Committee / Security Committee should exist as a joint decision-making body.
6. Roles and responsibilities
Section titled “6. Roles and responsibilities”The Security Handbook defines the key roles for the cybersecurity program.
Top Management
Section titled “Top Management”Top Management is accountable for the cybersecurity of the business, the program budget, the decision-making associated with risk treatment, the allocation of resources, and the promotion of cybersecurity across business lines and services.
CSO / CISO
Section titled “CSO / CISO”The CSO/CISO is accountable for implementing and monitoring the cybersecurity program, leading risk management, awareness activities, incident response, documentation lifecycle, compliance activities, third-party assessments, customer audits, budget execution, and vendor security oversight.
CTO / DevOps / IT
Section titled “CTO / DevOps / IT”This group is accountable for the technical implementation of cybersecurity measures, DevOps security practices, monitoring, asset inventory accuracy, documentation, incident support, and vendor control in their technical domain.
Talent
Section titled “Talent”Talent is accountable for embedding cybersecurity requirements into hiring, onboarding, offboarding, and broader talent practices.
Branch Directors / Branch Delivery Manager
Section titled “Branch Directors / Branch Delivery Manager”Branch Directors and Branch Delivery Managers are responsible for monitoring execution of the awareness program, implementing training, ensuring the disciplinary process, and monitoring compliance with cybersecurity rules for their vendors.
All Staff
Section titled “All Staff”All staff are responsible for complying with cybersecurity and privacy rules, reporting threats, collaborating during incidents, following awareness and training programs, and performing their duties with security by default.
Additional risk-specific roles
Section titled “Additional risk-specific roles”The Risk Management document also defines roles for:
-
WillDom Business Board / Risk Committee
-
Delivery Manager
-
Business Developer
-
Head of Infrastructure / CTO
-
Head of Cybersecurity and Resilience / CSO / CISO
-
All employees and collaborators.
These roles are especially relevant when risk treatment decisions, mitigation plans, supplier analysis, and customer-impacting changes are involved.
7. Risk management
Section titled “7. Risk management”Risk management is one of the core mechanisms of the Information Security program. WillDom manages cybersecurity and resilience using a structured methodology based on analysis of scenarios that could affect service delivery, contractual commitments, daily operations, or significant changes in the environment.
Framework
Section titled “Framework”The Risk Management framework references:
-
ISO 22301
-
ISO 27005
-
ISO 31000
and treatment decisions may consider additional standards such as ISO 27002, CIS Controls, PCI-DSS, and NIST CSF.
Treatment decisions
Section titled “Treatment decisions”The accepted treatment options are:
-
accept the risk,
-
mitigate the risk,
-
transfer the risk,
-
eliminate the risk.
Treatment decisions must be formalized by the Business Board of WillDom, documented, and communicated when appropriate. If mitigation is selected, resources must be assigned and monitored. Accepted risks must also be documented and reviewed within the current year or based on the defined acceptance period.
Frequency
Section titled “Frequency”Risk management is described as a daily and continuous process, but it must be formalized annually or whenever relevant changes occur. Examples of relevant changes include:
-
technology replacement,
-
architecture changes,
-
physical relocation,
-
critical provider changes,
-
contract renewals,
-
new services,
-
new contracts,
-
and post-incident lessons.
Records
Section titled “Records”Each risk analysis exercise must generate evidence such as:
-
risk treatment matrix,
-
scenario description,
-
identified risks, impact, and likelihood,
-
treatment decisions,
-
management approval,
-
and residual risk acceptance.
Residual risk
Section titled “Residual risk”The Risk Management document defines residual risk calculation using:
Asset Criticality + Likelihood + Impact = Risk Rate. Risks in the lower range are considered accepted, while higher ratings may require mitigation plans and tracking.
8. Security fundamentals
Section titled “8. Security fundamentals”The Security Handbook defines WillDom’s security baseline as cybersecurity by default. These controls apply beyond specific risk-based adjustments and represent the foundational expectations across services and assets.
Access control
Section titled “Access control”The baseline requires:
-
authentication for all access to services,
-
separate personal and admin accounts,
-
service accounts assigned to a single service and owner,
-
least privilege and need-to-know,
-
RBAC,
-
centralized authentication,
-
2FA for IT services and sensitive data,
-
centralized authentication logging,
-
and deactivation/deletion of inactive accounts.
Hardening
Section titled “Hardening”All digital service components must be hardened using CIS Benchmarks when available or vendor best practices otherwise. Unused services must be disabled, assets must run current versions or patches, and logging should be configured for authentication, changes, and service lifecycle events. Sharing services in ways that create single points of failure should be avoided.
Networking
Section titled “Networking”All network services must be authenticated and authorized, access rules must be documented and periodically reviewed, services must have a reason and an owner, privileged access must come from a secure management network, and segmentation should reflect asset criticality.
Vulnerability management
Section titled “Vulnerability management”All services must be under a patch management process. The DevOps and Security Handbook documents specify:
-
emergency patches in less than 7 days,
-
critical patches in less than 30 days,
-
regular authenticated security scans,
-
monitoring of public attack surface,
-
and go-live only after clean vulnerability reporting without critical or high findings.
Encryption
Section titled “Encryption”Sensitive data must be encrypted in transit and at rest using current best-practice mechanisms. The documentation references:
-
TLS 1.2 or higher,
-
hash + salt for authentication,
-
AES 256 / RSA,
-
KMS,
-
workstation and laptop encryption,
-
and encryption of external drives where approved.
Backup
Section titled “Backup”All business-supporting or contract-relevant information must be covered by a backup strategy applying the 3-2-1 rule, with encryption at rest, inventory and documentation of backup media, and restore test calendars.
9. Human resources security
Section titled “9. Human resources security”The Security Handbook states that human resources are among the most critical assets because they execute services and business activities. For that reason, Talent must maintain cybersecurity processes covering:
-
NDA before contact with external resources, parties, or candidates,
-
security requirements in hiring,
-
background checks based on risk,
-
documented job terms and conditions,
-
disciplinary process,
-
awareness and training,
-
and communication of security rules and policies.
The Service Levels document reinforces that, across all levels, WillDom’s responsibilities include:
-
security of the hiring process,
-
NDA,
-
awareness and training,
-
onboarding security fundamentals,
-
disciplinary process,
-
offboarding notification,
-
retirement of access notification,
-
asset return,
-
data disposal notification,
-
and incident notification.
10. Data privacy and protection
Section titled “10. Data privacy and protection”The Security Handbook defines a Data Privacy & Security Program with several core principles:
-
all data must have an owner,
-
data owners must keep inventory updated,
-
inventory should be centralized and automated when possible,
-
data must be classified as Public, Internal, or Confidential,
-
storage, retention, disposal, access, and security must depend on criticality,
-
by default, all customer data is Confidential,
-
unnecessary data must not be requested,
-
data that is no longer needed must be deleted,
-
and data in transit or at rest must be encrypted unless it is classified as Public.
The Strategic Alliance also had personal data obligations, but within the security documents themselves, privacy is clearly treated as a first-class control area rather than a side topic. The Incident Response and Service Levels documents also show that different service models affect how customer data is handled and which safeguards must apply.
11. Incident response
Section titled “11. Incident response”The Incident Response Policy defines the activities carried out to respond to cybersecurity incidents and covers all collaborators and third parties working on critical services.
Reporting
Section titled “Reporting”Potential incidents must be reported through the formal channel:
security@willdom.com. End users are required to report and collaborate in investigations and response activities.
The policy identifies the incident response team and responsibilities:
-
Mariano del Río – vCISO
-
Román Giachetti – Infrastructure Lead
-
Leandro Viadas – Network-wide Communications
-
Agustín Cortés – Incident Coordination and Follow-up.
The Security Team leads the response process, while Infrastructure / DevOps leads the technical response and application teams support investigation, configuration, and lessons learned. Third parties must report incidents tied to their services and provide logs, alerts, and technical evidence when requested.
Incident types
Section titled “Incident types”Examples of cybersecurity incidents that must be reported include:
-
phishing,
-
spam,
-
ransomware,
-
malware infection,
-
cyber attack,
-
security policy violations,
-
denial of service,
-
information leakage,
-
loss or theft of assets.
Response phases
Section titled “Response phases”The policy describes the process through:
-
incident report,
-
detection and analysis,
-
containment,
-
eradication and recovery,
-
and post-incident lessons learned.
Containment may involve isolation of devices or disabling users/services. Eradication and recovery may include preserving evidence, reinstalling systems, reconfiguring users/software, patching, network changes, and data recovery. Serious incidents may justify forensic imaging and notarized documentation.
Post-incident review
Section titled “Post-incident review”Incidents are reviewed monthly to identify improvements, resource needs, and lessons learned. A summary is presented to the Security Steer Committee. The policy establishes KPIs requiring 100% of incidents to be attended, documented, closed monthly, and reported.
12. Technical Standard – Endpoint
Section titled “12. Technical Standard – Endpoint”The Technical Standard – Endpoint defines technical guidelines for WillDom digital assets assigned to customer service execution. It states that requirements are mandatory for Agile Teams and recommended for Remote Staffing, with reference to the Security Service Levels for more detail. Exceptions must follow a formal exception management workflow and require approval from the Branch Director and Global Delivery.
Level 1 – Low Risk
Section titled “Level 1 – Low Risk”Baseline controls include:
-
strong passwords,
-
2FA for sensitive or privileged access,
-
licensed and updated software,
-
antimalware/HIPS/firewall controls,
-
updated signatures,
-
and weekly scans.
Backups should follow customer requirements first, or otherwise be kept weekly in WillDom’s cloud.
Level 2 – High Risk
Section titled “Level 2 – High Risk”Additional requirements include:
-
BIOS password,
-
full disk encryption,
-
external drive encryption when required,
-
DLP / USB block,
-
and internet protection controls such as proxy, SSL inspection, and threat protection.
The document also states privacy rules requiring confidentiality of service information and storage/backup of source code or customer data according to customer rules.
13. Technical Standard – DevOps
The Technical Standard – DevOps defines the security practices and requirements applicable when DevOps work is performed, including sysadmin, network admin, and configuration-through-code activities.
In addition to repeating core controls on access control, hardening, networking, vulnerability management, encryption, and backup, this standard adds several DevOps-specific expectations:
Documentation
Section titled “Documentation”Mandatory documentation includes:
-
high-level architecture diagrams,
-
interconnections and protocols,
-
third-party dependencies,
-
network segmentation,
-
technical management,
-
and documented operation tasks.
CI/CD best practices
Section titled “CI/CD best practices”The standard lists best practices for CI and CD such as:
-
fail fast,
-
commit regularly,
-
fix broken builds quickly,
-
automate continuously,
-
document release and rollback steps,
-
integrate security early,
-
and maintain feedback loops.
Cloud security
Section titled “Cloud security”For cloud environments, baseline expectations include:
-
minimizing subscription owner roles,
-
trusted SSO,
-
2FA,
-
resilience thinking,
-
formal RACI with vendors and customers,
-
keeping software updated,
-
encrypting data in transit and at rest,
-
minimizing unnecessary data handling,
-
and executing regular cloud security assessments.
Monitoring
Section titled “Monitoring”Each service must be under monitoring, including:
-
health checks,
-
CPU,
-
memory,
-
network bandwidth,
-
storage,
-
cybersecurity signals,
-
port scanning,
-
malicious activity,
-
DDoS attempts,
-
and notifications from critical vendors.
14. Service Levels – Security
The Service Levels – Security document explains that WillDom offers different security levels depending on the customer context and delivery model. The objective is to let customers choose the level aligned with their risk appetite and service maturity.
Level 1
Section titled “Level 1”WillDom’s responsibility is mainly focused on human resources security because access, assets, platforms, and data security are managed by the customer. This level is associated with Remote Staff and applies the endpoint technical standard at Level 1.
Level 2
Section titled “Level 2”WillDom is responsible for human resources and asset assignment, while the customer remains mainly responsible for access and platforms, and data security is shared. This level is also associated with Remote Staff and includes computer assignment plus Level 1 endpoint controls.
Level 3
Section titled “Level 3”WillDom has responsibilities for human resources, asset assignment, access, platforms, and technology services, while data security remains a shared responsibility with the customer. This level is associated with Agile Teams and includes broader responsibilities such as:
-
access control,
-
2FA,
-
SDLC / secure coding,
-
security scans,
-
remediation,
-
intrusion tests,
-
DevOps,
-
antimalware protection,
-
security monitoring,
-
data disposal,
-
third-party security,
-
and backup / offline backup.
This service-level model is important because it connects security expectations to the actual service delivery structure.
15. Compliance and continuous improvement
Section titled “15. Compliance and continuous improvement”The Security Handbook states that WillDom maintains a compliance program based mainly on customer requirements, with special focus on cybersecurity and privacy. It also states that, under its roadmap, WillDom has defined certification goals with focus on:
-
ISO 27001,
-
SOC 2 Type 2,
-
and PCI-DSS when required by customers.
The policy and handbook repeatedly reinforce that the program must be continuously improved, and that new customer, legal, regulatory, and business requirements may be incorporated over time as part of that improvement cycle.
16. Exception management
Exception handling is explicitly documented at least in the Endpoint standard, which states that exceptions should be formalized through an exception management workflow and require approval from Branch Director and Global Delivery. Risk Management also states that exception decisions must be approved or rejected by the Business Board / Risk Committee.
This means any deviation from documented security requirements should be:
-
formally documented,
-
justified,
-
approved by the correct decision-makers,
-
and monitored when relevant.
17. Summary
Section titled “17. Summary”WillDom’s Information Security model is a risk-based, management-led, and operationally integrated framework designed to protect critical assets, support secure service delivery, and maintain resilience across the business. It is grounded in formal policy commitments, international standards, documented governance, structured risk treatment, defined roles, incident response capabilities, technical baselines, privacy controls, and service-level differentiation according to customer needs.
The Security Handbook should remain the conceptual backbone of the section, while Risk Management, Incident Response, Endpoint Security, DevOps Security, and Service Levels operate as specialized components within the same Information Security framework.