SUSTAINABILITY REPORT 2024

Operating in a sector where data protection is essential, Privacy and cybersecurity are two core topics within PRT’s strategy and policies. Rapid technological progress and the continuous evolution of regulations require ongoing updates to our IT infrastructure in order to maintain high security standards. To address these needs, PRT has long implemented an ISO/IEC 27001:2022-certified management system for information security, supported by state-of-the-art technological infrastructure and monitored by a dedicated IT service. Within this management system, PRT has formalised an Information Security Policy, a document that provides clear and detailed guidance on how to protect information assets from all organisational and technological threats, whether internal or external, accidental or intentional. Its purpose is to ensure confidentiality, integrity and compliance with applicable legislation. This is complemented by the Information Security Incident Management Procedure, which describes the actions to be taken in the event of incidents, both from a technical and regulatory perspective, including notification to the competent authorities. In compliance with the GDPR, PRT continues to invest in infrastructure and protection systems, including the use of secure SSL protocols for remote access, in order to ensure secure communications and reduce the risk of unauthorised interception. The foundations of our cybersecurity strategy Confidentiality: Ensuring confidentiality means guaranteeing that data and resources are protected from unauthorised use or access. Confidentiality must be ensured throughout the entire data lifecycle, from storage to use, and during transmission across a network. Integrity: Integrity refers to the ability to preserve the accuracy and reliability of data and resources, ensuring that they are not modified or deleted in any way except by authorised parties. Availability: Availability refers to the ability of authorised users to access the resources they need for a defined period and on a continuous basis. This helps prevent service interruptions and ensures that infrastructure resources are ready to deliver what is required. Managing information security means ensuring the protection of our information assets and, therefore, of the Company’s digital data. The Group has structured its strategy around three core principles that are essential when implementing security solutions, taking into account vulnerabilities and risks. Page 52 Sustainability Report 2024 2.3. Privacy protection and the importance of Cybersecurity 2.3.1. The information security management system

RkJQdWJsaXNoZXIy NDUyNTU=