Log in

Register

Please choose the option that matches your business

That looks like a track and trace number, do you want to track on this number?

How do you want to track your shipment?

Find exactly what you are looking for

Select your location and language

DSV and Schenker have joined forces

dbschenker.com has been merged into DSV.com. Go to your DB Schenker self-services or close this message to visit DSV.com. 

PLEASE UPDATE YOUR FAVOURITES / BOOKMARKS.

Schenker self-service tools Read more about the Schenker acquisition
Cyber security

POLICY

Cyber security

Prevention and protection

We dedicate significant time and resources to cyber security

DSV’s business is reliant on successful operation of information technology and systems to fulfil its mission and deliver high-quality service to its customers. As a result, the organisation considers its information and information systems important assets that are crucial to its operational excellence. To protect these assets, DSV has established an Information Security Programme that follows information security best practices and is based on principles from leading international standards, and DSV is ISO27001:2022 certified.

Information Security Policy
The Information Security Programme in DSV is underpinned by our corporate Information Security Policy, which is the top-level policy for the security of information and information systems in DSV that ensures that information security is an integral part of DSV’s business. The policy outlines top management’s direction and commitment to information security, sets objectives and principles for information security, and defines DSV’s approach to managing information security in accordance with business requirements and relevant laws and regulations. The Information Security Policy applies to DSV globally, covers all types of information and information systems, and compliance with it is mandatory.

Core Information Security Objectives and Principles 
In its approach to information security DSV strives to support the corporate strategy and values as well as to ensure that appropriate safeguards are in place to preserve the confidentiality, integrity and availability of information. This enables DSV to maintain its information in a secure manner, reduce the risk and potential impact of disruptive events, support business continuity, comply with laws and regulations as well as to ensure that our customers’ information is treated with utmost care and confidentiality.

As such, our core principles are as follows:

Employee Awareness and Acceptable Use Policies Our employees are our first line of defence for protecting DSV from potential information security threats and breaches. Therefore, we are running a global information security awareness programme to foster a culture of information security and support correct security behaviour among employees.

The programme is aimed at all employees in the company. Our goal is therefore to make it accessible, understandable and engaging to all employees regardless of their work area.

To do this, we have created training that supports principles of sustainable learning by regularly subjecting our employees to training and practise along with identifying risk users and providing targeted training. We aim to promote awareness through different platforms such as traditional frequent organised elearning, newsletters on current events and relevant topics, simulated phishing campaigns as well as training based on behavioural science to impact positive secure behaviour.

 Additionally, we have created and published an Acceptable Use Policy for our employees to ensure that they are aware of their responsibility when it comes to using and protecting the information of DSV and its customers.

Information Security Governance We have established a DSV Security Board to oversee that our global information security priorities are in alignment with our business and IT strategies. The Security Board is chaired by our CFO with the purpose of setting the direction for information security and governance of our portfolio of security initiatives and risks. Furthermore, the Security Board evaluates and approves the necessary response based on the current information security threat landscape. The Security Board approves deadlines on security initiatives, defines security key controls and sets the direction of strategic information security priorities. Security Board meetings are held bi-monthly. Reporting to the Board of Directors (Audit Committee) on information security is performed three times per year.

Customer Assurance We strive to communicate openly and transparently to our customers when it comes to information security. In DSV we have an internal IT compliance programme driven by Group IT Compliance which provides IT assurance globally on a risk-based approach. Scope and priorities are aligned with the Security Board – and findings are reported to the Security Board. Furthermore, we have engaged with our external IT auditors to validate that we deliver on our information security promises to our customers. The validation is performed through the independent and internationally recognised ISAE 3402 Type 2 report that demonstrates assurance and provides a unique insight into our information security practices. The assurance report is updated on an annual basis. Both the ISAE 3402 report and the ISO 27001 certificate can be shared with customers and collaboration partners for assurance purposes upon request.

Read more about our Management Systems

Any questions? Contact Thomas Zakarias, CISO / Senior Director, Group IT Compliance