In this special edition, I wanted to bring in our CTO Fayez to cover the new data protection and information security management certification that we have.
So first of all, I should congratulate all of you for helping to achieve this. I mean, really I feel like it's an honor to be part of a company that has this kind of certification that lives up to these standards.
And I know that sometimes people see these things as kind of like a burden, you know, it's like more things to do. But to me, this is a test of do we meet the standard? Are we the best? And I can really see the opportunity and who doesn't wanna be tested to meet a high standard? So I'm really, um, proud of that.
And I can see all sorts of utility in the field when we think about our customers, especially some of these smaller players that try to come in and eat our lunch with cheap services. Certainly this level of investment and rigor and this great culture that we have and that we're developing around security management is gonna be something that helps us in the field.
So with that, Fayez I think that you've brought in a presentation so let's go through that and then I might have a few questions along the way.
Hello everyone. I don't know if you can see my screen. Okay. So yeah, today we are going to talk about, it's more about a celebration, about our achievement, about the ISO standard that we take that, we had really an interesting journey, which took almost 18 months. And the good news that yes, we did it in good timing without any obstacles.
And all the teams, they were a great help to to change their way of working and to quickly adapt to the ISO standards, which is not an easy thing that the company can do.So we'll start with what's the ISO? It's an international standard for information security management. It's not really an IT thing only, but it's more about the entire organization - how we can protect the information of the organization and this standards, it's operated in three and four teams, the organizational teams.
That means, how the organization in general, defines the process, analyzes their risks, and also how they can deal with customers and with vendors or suppliers.
After that, the other thing that we work on is the people in the organization, how we can make sure the people are secure, and also the process of acquiring the talent and retaining the talent and upscaling the talent - it's in place and also following the standards.
The other thing that we, we also work it in it's the technological part, that means when we develop a project.
So what's the procedures and the practices in terms of security that we are following? So what we are following, it's not something we define by ourselves. The ISO has the best security expertise in the world, so they come up with a lot of controls.
In general, there are 93 controls that you test your practice against them, and if you are good enough, you will be certificated. If you are not good enough, you will be rejected. And the other thing is the physicals environments. So to make sure that when you have employees and also you have information that you can make sure that you take all the consideration aspects on them.
So in general, the ISO certificate demonstrates that trust security practice, I mean, something
that world class when you match that kind of benchmark, you are certified and you are audited by external, third party companies to make sure that you are matching all the requirements.
Okay. So Fayez, if you just look at the numbers, it's jointly issued by ISO and IEC, right? That's why you've got the two names. It's jointly issued by those two organizations.
Yes. This is the option name for it, yeah.Yep. And then there's two standard numbers, those are the numbers of the standards that are...Yeah. 27001 is the standard itself. 2022 is the latest standard they updated because before -Oh, yeah, I wasn't sure if that was typo here. It's actually the year that it's been updated, which is what I understood but I thought I misunderstood it, reading the typo. Okay. Got it.
There's a typo there. Okay, good. But yeah, every year, every almost three years for us. It depends. So this is the last update. They made it in 2022. They reduce it and they included few things for example, the cloud, the AI - there's a lot of things that are included in the last update.So this journey, as I mentioned, took us almost 18 months to accomplish, which started last year in 2024, in June, and we concluded it by last week when we received the certificate.
So during these 18 months that we had a comprehensive documentation to streamline our process across all the departments. That means we set up with every single department to define what's their information, how we can protect them and what's the interaction between the departments or the external factors like clients or suppliers or whatever.So we defined to document this kind of process to make sure that we put all them in a documentation that aligned with the ISO standards.
The second thing, when we identify this kind of information now we analyze them based on the risk. A simple example for this is when we are working with HubSpot. HubSpot is a data provider for our... well, we call it a vendor for us. And we have some data that is hosted in their platform. So is their platform secure enough? What if HubSpot goes off our, if we no longer can access to HubSpot, what we should do?So we take a lot of scenarios based on every single entity or information that we are having. We try to apply multiple scenarios of risk. If we lose them, what will happen. Based on that analysis of risk we put the, what we call, mitigation. So to make sure that confirmation is protected based on the three factors that we are having for the security, which are the availability, the integrity and the confidentiality.
This kind of effort leads us to more than 60 document of process and policies and records. Some of them that can share with everyone, some of them are really tied to a specific department. For example, the compliance department, they have specific documents. The developer, they have specific documents until we have, for example, the security chart that you all of you read, which is something global. But, I will show you in another slide how you can find all this kind of procedures and documents.
There was a really huge testament that we spent to make sure that we match all the bars. Any questions here? Okay, so why does this matter for Trading Central? First of all, I mean, our entire business runs on trust. So we have to gain the trust. The trust, you cannot gain it, you have to earn it. And in Trading Central, we have a lot of entities around the globe. We are serving really big names in the world, and we need to make sure that when you talk about rating and trust, you have a really trusted vendor that you can convey your information, that you can integrate their application on their side. And this is not only just we claim that we are secure, we are good at what we are doing.
We are certified about what we are doing, and we are ISO, which is a benchmark for all the global standards for the security.
Have we checked what competitors offer this? Like if you look at Acuity and Autochartist, do we see them having this certification? Most of themselves, they don't have it.
Okay, yeah. And as data security becomes mission critical in digital brokerage, I mean, this is a wise investment and no easy thing to catch up on, let's put it that way.
Yeah. I mean, it's a lengthy long process and most of the companies, they try to avoid it because it's not easy to get.
Yeah. And Fayez said it, but it's the highest standard. I mean, there is no nothing higher.Yeah, you're right Remy. To complement what you just said, it's, there is a strong barrier to entry to get that type of certification. Meaning, again, there's an 18 months work behind it and preparation to get certified. And it's also a high cost.
And it's a high competency. So, you know, each of us with our roles and duties to uphold this, meet that high standard. And I suppose that there is a recertification cycle as well, is that right, Fayez?Yeah. I mean, uh, as you mentioned this, the benchmark and also the restructuring. Most of the company view are adapting the ISO, you have to restructure the way that you are working if you don't do it. So that's why it's really a strong barrier to get into that kind of thing if you don't have the resources that you can allocate.
So right now the certificate that we got, is for three years and every year we will have an internal audit for one or two days to make sure that we still continue what we are doing.Yeah. An audit, that is, again, performed someone that is external. It's not done by us, it's done by external auditors will give us a stamp to say yes or no. And they will follow a roadmap of improvement and say, if yes or no, we applied what we said we were going to improve the previous year. So it's really an ongoing process that is compelling, because if you don't do what you said...
Yeah, we'll talk about this in another slide. So the most important for Trading Central is
for our client facing teams. Right now you have a trusted edge that you can talk about it.
When we talk about the security, not only the security but about how we operate in Trading Central, that we have really a framework, international framework that has proven and certified that you can build on.And one of the other things, maybe Lillian and Anne and some of the CS team that are getting
every year, we have some compliance assessment, what we call the security assessment that we get every year. So right now, this kind of security assessment is just a check, just attach the certificate and you should be done with it.
Also one thing that it's important for us, is also to define, I mean, as we work in different countries, we need to make sure that we are, we are aware about different regulations. So when we did the ISO, we did the exercise to go through the different countries where we have an entity there to make sure that we understand their legal requirement in our business, and we try to make sure that we are aligning with them.
Okay. Any question here or should I move to something else? Okay, good.So what does that mean for you? As a Trading Central employee, you have to understand that right now our process is documented, predictable, we have to follow it. So we already, every beginning of year, we share with you the documentation, the security policy and also we will put this information at your accessibility so they can be in different places. I would encourage everyone to go and read them because now that we are working from the book, there is no random decisions, there is no ad hoc protest.
So we have all the process, we try to anticipate every single process and risk and ways to optimize our work. We document it, but definitely this kind of thing, it requires a continuous improvement.And also process clarity is key, right? It makes things simple, not ambiguous about what's to be done or not to be done. To me, this is a great way to reduce kind of the churn of conversations - Should we do this? Should we not do this? How do I go and figure out what are the right things to do? We've got some clarity. So I think having that documentation, as you say, and making sure each department knows where to get it or continues to refine theirs, I think that's great.
Yeah. This kind of, it's a continuous improvement that we have to lead every year. As Remy mentioned, we have an internal audit every year that comes from the company who certified us to see if we still doing the right things as we promised.
The second thing is, when it comes to the risk. Right now, all the systemic identifier is assisted and treated. So normally whatever happens, we should have a plan. If we don't have a plan that means we skip that kind of risk and we don't have it. But that's why we have the risk assessment plans and procedures.
Also when we have, for example, a new vendor or data provider, we have a list of security that we have to ask them. When we adapt a new technology, we have a list of security aspects that we need to check with them. So we need to make sure that anything that is involved in our products, is checked in terms of security and is aligned with the ISO requirement.
One important thing, we have a strong leadership involvement in the company, starting from Alain
and to all the execution managers. Right now, we need the effective or the collaboration work to make sure that we are doing the right thing. So when we send the training, when we send the policy, we need to make sure everyone from the employees, also for the manager, to take it seriously.
And also if there's anything that you don't like, anything you see that is envolving your work, you can communicate with us and we can see how we can make your life easier.So what do you need to do as a Trading Central employee? Well, the good news is, right now, as we stand today, you are already doing the right things in the right way. But it's just kind of a reminder that we have a policy that we need to follow to make sure that we don't breach them. We have some tools and platforms that we approve them. So when we approve them, that's mean they are matching all the security check that we had.
Also when you deal with the information in Trading Central, make sure to protect the data when you're sharing things, to make sure that what you are sharing is not really confidential. That it's meant to be public and shared, and to stay vigilant about all the different incidents that could happen. For example, the fishing. We have a lot of fishing, thanks to a lot of employees who can report that kind of things. Make sure that you protect your PC, lock off your screen.
So it's more about the security in general. It's not an IT job. It's basically everyone's job to make sure that you're doing the right things. And we are trying to provide all the assistant that you're needing. For example, we have an annual training, which some of them didn't do it yet until today, so please do it before the end of the year.
Also ask before acting, if you are not sure about anything, we are here to help you to make sure that you are doing the right things.
So after that, if you are asking about the different policy and procedures, you can find them in Google Drive for example, we have something called the Employee Hub, and in the Employee Hub, you have all of them, but... I have to log in here. So with a lot of policy and procedures... Where you can find them, you can go to the Employee Hub, resources, ethics and policies and here you can have all the different policies that we have for Trading Central.
And in the employee reference, you have a folder called ISS policy and security. You have all of that ones here, which is basically the links that you find here. It's pointed to the same place.So that's pretty much it. What I want to say is that to thank all the teams for the direction and collaboration, it was really smooth. And the auditors and the people that worked with us, they were impressed at how quickly we adapted to the new norm, and how we can make it in our day-to-day work.
Amazing. Okay. Can you go back to your slide where you had some of the ways that we can act? The next one. This one, yeah. Okay. So some of this is making sure we have the passwords, like you've sent out emails to people around what to do with LastPass, for example. So that's a big one. And we have to check that regularly, right? To make sure that we get the passing grade on LastPass or something like this.
Yes. Basically, with the ISO, we have the document procedure and we have the KPIs. So you get that email because one of our KPI doesn't match the threshold that we defined. For example, the password policy, all the employees should have 90% of strong passwords.
And I think you were even thinking about some shared LastPass accounts, right? Where people could get, you know, client logins or things that might not otherwise pass, or that kind of ruin your score. You've got some ways to work around that with people.
So if people have those problems, you know, I'm trying to save a client password and it's not matching, then we can talk to you about some of those ways to mitigate that.
Yeah, we can say that when your three threshold drops down the normal threshold, in this case, you will have someone who reachs out to you to say that you are under the, the normal threshold.
Okay. So then you've got the internal training. This is the Knowbe4 that you referred to, the emails about Knowbe4, is that right?
Yes. This is the Knowbe4. That's right. So we do the training every single years. Every year you will have a different training based on the new aspect that, or the new threats that are happening during this year. For example, this year you will have something about AI and we continue doing something called the social engineering, because most of the hackings are coming from social engineering, which is when someone sends an email to Kathryn from Alain, but it's not really Alain because the email is a different one. So we are trying to make sure that we pick up few courses that are relevant to our day-to-day work.
Okay. One thing I learned, by the way, years ago, I still remember leaving my computer without making sure it's shut down when I stepped away for lunch. And, you know, someone from ops as a joke sent a love note to our CEO at the time, to make the point - Hey, don't leave your desktop unattended.
Yeah, I think we're gonna make it a game.
That's right. We'll make it a game.
We're gonna catch people and send a love note to our...That's right. We send these, I call it having each other's backs. We gotta hold each other to these high standards.
So the other way that you've got that in here is around knowing your role. I think about, you know, as a developer, or as a data analyst or as a designer, we must think about to how to be security minded in our specific practices. And so I think everyone on the call should either understand where they're specific... like you should go away from where you're going, you know, these are my top three elements that I think about in my day to day. And if you're not sure, ask your manager. Refer to the documents.
Yeah. I mean, basically when we talk about this, we do have a risk analysis that we did for every single department based on their roles, based on the information that they are handling or treating.So this kind of information we already have, the only one thing that we need is, if something new comes, it should go through this process, which is the risk analysis that we are doing. And basically we're adapting to new technology, we are doing a new change, for example, in our products. We do have something called change management process. So not everyone can send an email to the developer or to the product guys saying I want to change this X, Y, Z in that product. No, we have what we call a change management process. Make a request and it will go to the right people. They will make a decision. If they approve it, it'll go to the normal teams that should do the implementation. If it's not approved, then we reject it.
So that kind of thing. I mean we do have this thing right now, this year we established the framework, now the next three years it's more about use it, enhance it. Also adjust it to our day-to-day work.Yeah. By using it, you get to adjust it and refine it and like not using it is the worst thing. So is that specific change management policy in the employee reference in G Drive?
Yes, it is.
I'm really curious, I wanna look at that and make sure I'm in line too.
Yes. I think one of your other points was about the software that we use. So we all use, you know, let's say YouTrack or Google for business tools.
Can you give me an example of where we might catch ourselves offside?
Also during this kind of exercise, we do have a list of all the white listed applications that we are using right now. So for example, let's talk about marketing. They are using Figma, they are using, um, Adobe for example, and they are using ClickUp and they have other few applications that are authorized. When it comes to the CS team, they have a HubSpot, they have Zoho, which right now they will migrate to a new product. So every, every department, they do have a whitelist platform for their work.
So now if we say you need something new, now we have to take it and look into it - if it's really needed first of all.
Second thing, does it have enough security that we can rely on it. If it threatened our product or something that if we lost it, we don't care.
So I'm trying to think of examples where people go offside, like maybe there was a time where people start tracking to-do lists in third party tools that they wanted to try out, right? Like that would be an example of, well, it's not an approved tool and you're typing in your day-to-day tasks. So, what's an example of what not to do, I suppose?
Not, not to do because we provide all the those things that you need. You have Google note, you have YouTrack, you have ClickUp and every team, they have their own day-to-day work. If they use something different, right now they are breaching our policy, which they're supposed to read and sign.
Yeah. So if there's some sort of unmet need or curiosity to use something, then we should be talking to your team.
Exactly. So they talk to us and after that we can guide them on how to use it.
Does that mean I can't use widgets and code pen anymore? Does that mean that goes away or does... We'll talk about that one. Anyway, so I just wanted to give an example of how you can think about in your day to day, um, you know, the things that you're doing and be security minded. That's part of the policy. And it becomes easy. Like it's harder at first, there's learning and then it just becomes how you do things and then you're part of the elite club. I think that's a good thing.