IT Security
We are ISO 27001 Certified
At Brisca BPO, we take data security and privacy seriously. We are proud to be ISO 27001:2022 certified, demonstrating our commitment to internationally recognized standards for information security management and aligning our practices with the latest global benchmarks.
In addition, we are actively working towards ISO/IEC 27701 certification for Privacy Information Management Systems (PIMS), which will further strengthen our ability to manage personal data responsibly and in compliance with privacy regulations.
To enhance our cybersecurity posture even further, we are also pursuing the Cyber Essentials certification, which we expect to complete by the end of 2025. These certifications reflect our proactive approach to protecting client data, maintaining trust, and continuously improving our security and privacy frameworks
Certifications You Can Trust
CERTIFIED
INPROGRESS
Our layered security approach includes:
- Physical Security
- Network & Perimeter Protection
- Endpoint Security
- Authentication
- Employee Controls
- Browser Security
- Monitoring
- ISMS & BCP
CCTV Servillence
Continuous video monitoring ensures a safe and secure workplace environment
Biometric Door Access Controls
Only authorized employees can enter restricted areas through biometric authentication.
Live Security Gaurds
Safety equipment and uninterrupted power systems protect people and operations during emergencies.
Fire Extinguisher & Generators
Round-the-clock security personnel safeguard facilities and maintain controlled access.
Physical Security
Secure Authentication
Identity & Access Management
IAM controls and manages user identities, ensuring only authorized individuals can access systems and data.
Single Sign On
SSO allows users to securely access multiple applications with a single set of login credentials.
Multi Factor Authentication
MFA adds an extra layer of security by requiring multiple verification methods beyond just a password.
Biometric and Yubico Authentication
Biometric scans and Yubico security keys provide strong, phishing-resistant authentication for enhanced protection.
Identity and Access Management (IAM)
Employees are given role-based access to systems, ensuring they only use what is necessary for their job.
Candidate background checks
New hires undergo background checks to verify trustworthiness before gaining access to company resources.
Ongoing security awareness training
Staff regularly receive training to stay alert against cyber threats and follow best security practices.
Signing of NDA & IT Acceptable Use Policy
Employees must sign confidentiality and IT usage agreements to protect company data and ensure responsible system use.
Employee Controls
Web Browser Security
Enforced enterprise-wide browser policies
Standardized browser settings are applied across the organization to ensure secure and consistent usage.
Extension whitelisting
Only approved browser extensions are allowed to reduce the risk of malicious add-ons.
Browser-based threat protection
Built-in security tools protect users from phishing, malware, and unsafe websites.
Next-generation firewalls
Advanced firewalls safeguard the network perimeter by blocking malicious traffic, scanning for viruses, managing application usage, and filtering harmful content before it reaches internal systems.
VPNs for secure remote access
(VPNs) encrypt communications and create secure tunnels, allowing employees to safely connect to corporate resources from remote locations.
Perimeter Protection
Endpoint Security control
Company-issued desktops and laptops
Employees use secured, pre-configured company devices to reduce risks from unmanaged hardware.
Remote monitoring and management
IT teams continuously monitor devices and apply fixes remotely to maintain security.
Endpoint Detection and Response (EDR)
EDR tools provide real-time monitoring, threat detection, and automated response on endpoints.
Data Loss Prevention (DLP)
DLP tools monitor and block unauthorized sharing of sensitive information.
Application whitelisting
Only approved applications can run, preventing unauthorized or harmful software.
Device Management via Microsoft Intune
Intune ensures centralized control, compliance, and security of all company devices.
Centralized patch management
Security patches and updates are deployed across all endpoints to close vulnerabilities quickly.
Company-issued full-disk encryption
Data on company devices is encrypted to protect against theft or loss.
Information Security Management System (ISMS)
ISMS establishes structured policies and controls to protect the confidentiality, integrity, and availability of company information.
IT Business Continuity Planning (BCP)
BCP ensures critical IT services can continue or quickly recover during disruptions or disasters.
IT Policies
Monitoring
Vulnerability assessments
Regular scans identify and address security weaknesses in systems and applications.
Continuous endpoint and network monitoring
Real-time monitoring detects and responds to suspicious activity across devices and networks.
Data Security & Privacy FAQs
As a BPO provider, Brisca handles sensitive client data across industries. Ensuring data security protects our clients’ trust, meets compliance requirements, and prevents reputational and financial damage.
- Personally Identifiable Information (PII)
- Financial records
- Operational and transactional data
- ISO 27001:2022 certified Information Security Management System (ISMS)
- Role-based access controls
- Encrypted data transmission and storage
- Regular audits and vulnerability assessments
- Employee training on data protection
Brisca follows a strict incident response protocol:
- Immediate containment and investigation
- Notification to affected clients
- Root cause analysis and remediation
- Transparent reporting and preventive measures
Yes. All employees undergo mandatory training on:
- Data handling procedures
- Cyber hygiene
- Recognizing phishing and social engineering
- Compliance with client-specific security protocols
Absolutely. We align with:
- GDPR (EU)
- PDPA (SL)
We use:
- Secure VPNs
- Endpoint protection
- Multi-factor authentication (MFA)
- Monitoring tools to ensure compliance with security policies
Yes. At Brisca, we maintain full transparency with our clients. We welcome client-led audits.
If clients require additional security services or custom controls beyond our standard offerings, we are open to providing tailored solutions, including enhanced monitoring, dedicated secure environments, or compliance-specific configurations.
We vet all vendors and partners through:
- Security assessments
- NDAs and data protection agreements
- Ongoing monitoring and compliance checks
Our policies are reviewed annually and updated as needed to reflect changes in technology, regulations, and client requirements.