BANNER TEXT

Information Security Statement

CCHBC Information Security Statement

Fuelling our growth requires investment behind digital technology and new business models, blended with our continuous focus on productivity and efficiency improvement. We continuously focus on embedding digital ways of working throughout the Group to deliver prioritised business outcomes. We consider three critical categories when investing in digital, data and technology: consumer and customer centricity, employee experience and operational productivity.

This increased reliance on digital technology introduces more cyber risks, as the evolving threat landscape brings new vulnerabilities and sophisticated attacks that can exploit digital systems - ultimately impacting business operations, reputation, and financial stability. We recognize the critical role of digital technology in supporting business operations across the Information Technology (IT) and Operational Technology (OT) environments as well as the associated cyber risks that are introduced for our business. Our information security program addresses these risks by safeguarding corporate data, systems, and communications to ensure their availability, confidentiality, integrity, and safety from malicious threats.

Our commitment to protecting our digital environment is formally expressed in our Information Security Statement, which provides a high-level overview of our philosophy and strategic approach to information security. We are committed to establishing and maintaining strong internal controls related to cyber security across our business. The Information Security Statement serves as a high-level policy foundation of our information security program and provides customers, consumers, employees, partners, and third parties with a high-level overview of our information security practices and control framework.

We have aligned our practices with internationally recognized industry best practices and regulatory requirements, ensuring a mature, robust, and consistent level of cyber security across the Group. Furthermore, the statement reflects the commitment of our Executive Leadership Team to prioritize information security at a strategic level and demonstrates leadership’s recognition that information supports our long-term strategic and financial objectives and maintain stakeholder trust in an increasingly connected and threat-prone environment.