IT Security


We are ISO 27001 Certified

At Brisca BPO, we take data security and privacy seriously. We are proud to be ISO 27001:2022 certified, demonstrating our commitment to internationally recognized standards for information security management and aligning our practices with the latest global benchmarks.

In addition, we are actively working towards ISO/IEC 27701 certification for Privacy Information Management Systems (PIMS), which will further strengthen our ability to manage personal data responsibly and in compliance with privacy regulations.

To enhance our cybersecurity posture even further, we are also pursuing the Cyber Essentials certification, which we expect to complete by the end of 2025. These certifications reflect our proactive approach to protecting client data, maintaining trust, and continuously improving our security and privacy frameworks

Certifications You Can Trust

CERTIFIED

INPROGRESS

Our layered security approach includes:

CCTV Servillence

Continuous video monitoring ensures a safe and secure workplace environment

Biometric Door Access Controls

Only authorized employees can enter restricted areas through biometric authentication.

Live Security Gaurds

Safety equipment and uninterrupted power systems protect people and operations during emergencies.

Fire Extinguisher & Generators

Round-the-clock security personnel safeguard facilities and maintain controlled access.

Physical Security

Secure Authentication

Identity & Access Management

IAM controls and manages user identities, ensuring only authorized individuals can access systems and data.

Single Sign On

SSO allows users to securely access multiple applications with a single set of login credentials.

Multi Factor Authentication

MFA adds an extra layer of security by requiring multiple verification methods beyond just a password.

Biometric and Yubico Authentication

Biometric scans and Yubico security keys provide strong, phishing-resistant authentication for enhanced protection.

Identity and Access Management (IAM)

Employees are given role-based access to systems, ensuring they only use what is necessary for their job.

Candidate background checks

New hires undergo background checks to verify trustworthiness before gaining access to company resources.

Ongoing security awareness training

Staff regularly receive training to stay alert against cyber threats and follow best security practices.

Signing of NDA & IT Acceptable Use Policy

Employees must sign confidentiality and IT usage agreements to protect company data and ensure responsible system use.

Employee Controls

Web Browser Security

Enforced enterprise-wide browser policies

Standardized browser settings are applied across the organization to ensure secure and consistent usage.

Extension whitelisting

Only approved browser extensions are allowed to reduce the risk of malicious add-ons.

Browser-based threat protection

Built-in security tools protect users from phishing, malware, and unsafe websites.

Next-generation firewalls

Advanced firewalls safeguard the network perimeter by blocking malicious traffic, scanning for viruses, managing application usage, and filtering harmful content before it reaches internal systems.

VPNs for secure remote access

(VPNs) encrypt communications and create secure tunnels, allowing employees to safely connect to corporate resources from remote locations.

Perimeter Protection

Endpoint Security control

Company-issued desktops and laptops

Employees use secured, pre-configured company devices to reduce risks from unmanaged hardware.

Remote monitoring and management

IT teams continuously monitor devices and apply fixes remotely to maintain security.

Endpoint Detection and Response (EDR)

EDR tools provide real-time monitoring, threat detection, and automated response on endpoints.

Data Loss Prevention (DLP)

DLP tools monitor and block unauthorized sharing of sensitive information.

Application whitelisting

Only approved applications can run, preventing unauthorized or harmful software.

Device Management via Microsoft Intune

Intune ensures centralized control, compliance, and security of all company devices.

Centralized patch management

Security patches and updates are deployed across all endpoints to close vulnerabilities quickly.

Company-issued full-disk encryption

Data on company devices is encrypted to protect against theft or loss.

Information Security Management System (ISMS)

ISMS establishes structured policies and controls to protect the confidentiality, integrity, and availability of company information.

IT Business Continuity Planning (BCP)

BCP ensures critical IT services can continue or quickly recover during disruptions or disasters.

IT Policies

Monitoring

Vulnerability assessments

Regular scans identify and address security weaknesses in systems and applications.

Continuous endpoint and network monitoring

Real-time monitoring detects and responds to suspicious activity across devices and networks.

Data Security & Privacy FAQs

As a BPO provider, Brisca handles sensitive client data across industries. Ensuring data security protects our clients’ trust, meets compliance requirements, and prevents reputational and financial damage.

  • Personally Identifiable Information (PII)
  • Financial records
  • Operational and transactional data
  • ISO 27001:2022 certified Information Security Management System (ISMS)
  • Role-based access controls
  • Encrypted data transmission and storage
  • Regular audits and vulnerability assessments
  • Employee training on data protection

Brisca follows a strict incident response protocol:

  • Immediate containment and investigation
  • Notification to affected clients
  • Root cause analysis and remediation
  • Transparent reporting and preventive measures

Yes. All employees undergo mandatory training on:

  • Data handling procedures
  • Cyber hygiene
  • Recognizing phishing and social engineering
  • Compliance with client-specific security protocols

Absolutely. We align with:

  • GDPR (EU)
  • PDPA (SL)

We use:

  • Secure VPNs
  • Endpoint protection
  • Multi-factor authentication (MFA)
  • Monitoring tools to ensure compliance with security policies

Yes. At Brisca, we maintain full transparency with our clients. We welcome client-led audits.

If clients require additional security services or custom controls beyond our standard offerings, we are open to providing tailored solutions, including enhanced monitoring, dedicated secure environments, or compliance-specific configurations.

We vet all vendors and partners through:

  • Security assessments
  • NDAs and data protection agreements
  • Ongoing monitoring and compliance checks

Our policies are reviewed annually and updated as needed to reflect changes in technology, regulations, and client requirements.

Discover the benefits for your business.