Kao Data_ESG Report 25-26_SP - Flipbook - Page 55
Introduction
Environmental
Risk
management
Social Sustainability
Governance
Customer Security
CUSTOMER RESILIENCY
Kao Data is fully committed to managing, mitigating and
avoiding risks that could affect our customers, stakeholders
and the wider environment – including cybersecurity risks,
data privacy risks and climate-related risks. Kao Data is
subject to regional, national and international legislative
drivers around the sustainability performance of the entire
ICT industry, which the management team monitor carefully
as active members of the European Data Centre Association.
Our engagement 昀椀rst approach is helping us continually
reduce our risk exposure, building long term trust with our
employees, stakeholders, customers and regulators.
Customer Privacy
Energy Security
Risk management oversight
Our Board of Directors is responsible for oversight of our
enterprise risk management program. Our risk management
processes are formalised and managed through all our
governance policies, delivered through our IMS, which
is externally assured by UKAS. This is supported by our
Sustainability working group, and HSE Committee, with
members of the Board and working group overseeing
speci昀椀c risks that pertain to their area of expertise. The
group also involves other stakeholders, such as our investors,
to discuss risk exposure and identify credible, realistic
mitigation measures.
Business continuity: Managing systemic risks
Our approach to systemic risk, which includes environmental
and social risks, is outlined in our business continuity policy.
The policy sets out the management direction for ensuring
business continuity via adherence to all relevant laws and
regulations, in support of the business’s requirements,
managed through our IMS, certi昀椀ed to the ISO 9001 standard.
The policy covers issues such as climate risk, environment,
information security, quality, energy and health & safety.
Managing customer risks
Our customers use our facilities to carry out mission critical
tasks, handling sensitive data, 24 hours a day. As such,
customer risks span similar categories to those Kao Data
manages for its own business. These include climate risk,
security risks, data sovereignty risks, legislative risks and
market risks, among others. In 2025-26, energy security,
customer privacy and information security risk mitigation
continued to be critical factors for all data centre and
colocation customers.
Kao Data procures clean energy to match its usage and
deploys military grade levels of physical security and
monitoring across all campus facilities, providing maximum
resiliency and protection for customers’ infrastructure and
data assets. Furthermore, Kao Data is also certi昀椀ed against
the Cyber Essentials and Cyber Essentials PLUS scheme,
a government supported scheme to help organisations
protect themselves against common online threats.
See accreditations table for a full list of our
Standards and accreditations
Kao Data ESG Report 2025-26
55