Alcon
Subprocessors
None extracted.
ComplianceCSVof Alcon's compliance · Atomfeed of Alcon's compliance
- Certified
Security program
How Alcon says it manages cybersecurity risk, in its annual report to the SEC.
- Led by
- Chief Information Security Officer · 30+ years of experience
quote
The CISO manages a team of approximately 60 certified professionals who work closely with
Our CISO, with over 30 years of experience in global information security and IT leadership, leads our cybersecurity strategy and programs.
- Board oversight
- Audit and Risk Committee
quote
The Audit and Risk Committee oversees risks from Cybersecurity Threats.
- Frameworks named
- NIST
- ISO 27001
quote
We maintain a cybersecurity-specific risk assessment process aligned with industry frameworks, including National Institute of Standards and Technology ("NIST") and ISO 27001, and engage experts to test our Information Systems.
- Outside review
- Engages outside assessors or consultants
quote
Our Information Security team regularly engages with Alcon's Data Privacy and Legal team, as well as external assessors, including through annual reviews by a Qualified Security Assessor.
- Its own suppliers
- Reviews their security
quote
We also manage third-party risks through due diligence, contractual requirements and audits.
- Practices named
- Incident response plan
- Tabletop exercises
- Penetration testing
- Vulnerability management
- Phishing simulations
- Cyber insurance
Since the fiscal 2024 report: board oversight by the Audit and Risk Committee (was the Audit and Risk Committee, Risk Committee); ISO 27001 now named.
Read Item 16K in full
Cybersecurity Risk Management and Strategy
We recognize the importance of assessing, preventing, identifying, and managing risks associated with Cybersecurity Threats, as defined in Form 20-F, Part II, Item 16K(a). These risks include operational disruptions, intellectual property theft, fraud, extortion, harm to associates, customers or patients, privacy violations, litigation exposure and reputational damage. We have implemented processes, technologies and controls to help address these risks.
Our Enterprise Risk Management program considers Cybersecurity Threat risks alongside other company risks. Internal Audit works with specialists to evaluate likelihood, severity and mitigation strategies. We use tools such as network and endpoint monitoring, vulnerability assessments, penetration testing and tabletop exercises to detect, mitigate and respond to risk.
We maintain a cybersecurity-specific risk assessment process aligned with industry frameworks, including National Institute of Standards and Technology ("NIST") and ISO 27001, and engage experts to test our Information Systems. To support data availability, regulatory compliance and effective incident response, we:
•Follow the NIST incident handling framework in our IT Security Incident Response policy, and coordinate with IT, Data Privacy and Legal teams to meet notification and legal obligations;
•Monitor data protection laws and update safeguards as needed;
•Review consumer-facing cybersecurity policies and notify customers of substantive changes;
•Provide a structured governance model to ensure AI/ML systems are secure, ethical and compliant;
•Maintain a Security Control Matrix mapping controls to industry frameworks and regulatory requirements, supporting controls applied based on risk;
•Deliver annual training on data privacy, cybersecurity and compliance for all associates, and conduct phishing simulations and incident response tabletop exercises; and
•Maintain cybersecurity insurance coverage and an incident response retainer with a leading provider.
We require associates and third-party service providers to handle Alcon data in accordance with our policies. Our incident response process includes triage, containment, investigation, remediation and compliance with legal obligations.
We also manage third-party risks through due diligence, contractual requirements and audits. Cybersecurity considerations influence vendor selection and oversight.
Our Information Security team regularly engages with Alcon's Data Privacy and Legal team, as well as external assessors, including through annual reviews by a Qualified Security Assessor. In the last three fiscal years, we have not experienced any material Cybersecurity Incidents, and related expenses have been immaterial. We have not paid any penalties or settlements in the past three years. For further discussion on cybersecurity risks, see Item 3.D. Risk Factors–Cybersecurity breaches and technology failures could disrupt operations, adversely impact reputation and compromise confidential or protected data.
Cybersecurity Governance
Cybersecurity is an integral part of our risk management program and a growing focus for our Board and management.
The Audit and Risk Committee oversees risks from Cybersecurity Threats. At least annually, the Committee receives updates on security posture, third-party assessments, progress toward risk mitigation goals, incident response plans and material Cybersecurity Threats risks or incidents. These sessions include a cybersecurity scorecard and discussions with our Chief Information Security Officer (CISO). Committee members also engage in ad hoc discussions on emerging threats and program updates.
Cybersecurity Threat risks are considered during Board discussions on enterprise risk management, budgeting, strategic planning, business continuity, mergers and acquisitions and brand management.
Our CISO, with over 30 years of experience in global information security and IT leadership, leads our cybersecurity strategy and programs. The CISO manages a team of approximately 60 certified professionals who work closely with
regional privacy officers and the Global Data Privacy Officer. This team oversees prevention, detection, classification, and remediation of incidents and reports to the Audit and Risk Committee at least annually.
Certifications as Alcon's trust center lists them; reports are usually shared on request (evidence) Security program from ALCON INC's Form 20-F for fiscal 2025, filed Feb 24, 2026, Item 16K, in its words (evidence)
Security recordCSVof Alcon's security record · Atomfeed of Alcon's security record
What public security catalogs list for Alcon, in their words.
Data breaches
- Alcon 218,395 accounts Email addresses; Names; Phone numbers; Physical addresses
In August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including name, phone number and physical address.
Have I Been Pwned
Breach data: Have I Been Pwned (CC BY 4.0), which calls every entry a breach, including data scraped from public pages (evidence)
ChangesCSVof Alcon's changes · Atomfeed of Alcon's changes
None since tracking began.