ANACAM MAGAZINE - n. 3 luglio | settembre 2024

58 SICUREZZA DEI SISTEMI INFORMATICI DI MAURIZIO MORETTI* TELESAN E LA CYBERSECURITY TELESAN AND CYBERSECURITY NATA come centrale operativa per l’erogazione del servizio di telesoccorso domiciliare, da sempre Telesan è particolarmente sensibile alle tematiche di sicurezza e continuità dei servizi erogati. Se inizialmente, nel 2001, l’attenzione era quasi esclusivamente rivolta alla continuità operativa, per la quale l’azienda ha ottenuto la certificazione ISO 22301 (Business continuity management) da IMQ nel 2009, nel corso degli anni gli investimenti in materia di cybersecurity sono costantemente aumentati. Questo ha consentito di integrare le misure di sicurezza informatica con quelle tradizionalmente adottate, con particolare attenzione ai servizi di call center e telesoccorso per ascensori in conformità con la normativa EN 81-28. Negli ultimi anni le normative alle quali tutte le aziende sono obbligate a rispondere in materia di cybersecurity hanno contribuito alla diffusione di una certa sensibilità verso la materia. Da parte nostra, abbiamo sempre avuto un approccio ancora più stringente verso questo argomento, data la particolarità dei servizi erogati e dei prodotti messi a disposizione degli ascensoristi. I nostri investimenti sono in costante crescita e ci porteranno, nel corso del prossimo anno, a dotarci di un sistema di gestione della cybersecurity secondo la norma ISO 27002. Da un punto di vista organizzativo, le azioni che Telesan mette in campo per la cybersecurity sono: a) sicurezza perimetrale dell’infrastruttura basata su firewall ridondanti, segregazione della rete, gestione degli accessi alla rete, sistema centralizzato per la rilevazione e la risoluzione delle minacce; b) sicurezza e disponibilità dei dati mediante sistemi di backup automatizzati e crittografati, sistema di replica dei dati in tempo reale su sito di disaster recovery; c) verifica periodica tramite vulnerability assesment per la ricerca e la risoluzione delle vulnerabilità; d) formazione costante del proprio personale in materia di cybersecurity anche tramite apposite campagne di attacco simulate per valutare le capacità dei singoli operatori; e) security by design delle applicazioni messe a disposizione del settore ascensoristico che compongono il sistema CMD Lift (Cloudlift, Mobile Lift e Datalift). * Responsabile SGQ e SGCO Telesan Srl FOUNDED as an operations centre for the providing of home teleservice, Telesan has always been particularly sensitive to the issues of security and continuity of the services provided. If initially, in 2001, the focus was almost exclusively on business continuity, for which the company obtained the ISO 22301 (Business continuity management) certification from IMQ in 2009, over the years investment in cybersecurity has steadily increased. This has made it possible to integrate cybersecurity measures with those traditionally adopted, with particular attention to call centre and lift services in compliance with the EN 81-28. In recent years, the regulations to which all companies are obliged to respond with regard to cybersecurity have contributed to the spread of a certain awareness of the subject. For our part, we have always had an even more stringent approach to this subject, given the special nature of the services provided, and the products made available to lift contractors. Our investments are constantly growing, and will lead us, in the course of next year, to equip ourselves with a cybersecurity management system in accordance with the ISO 27002 standard. From an organisational point of view, the actions that Telesan implements for cybersecurity are: a) infrastructure perimeter security based on redundant firewalls, network segregation, network access management, centralised system for threat detection and resolution; b) data security and availability through automated and encrypted backup systems, real-time data replication system on disaster recovery site; c) periodic verification through vulnerability assessment for the detection and resolution of vulnerabilities; d) constant training of its staff in cybersecurity, also through special simulated attack campaigns to assess the capabilities of individual operators; e) security by design of the applications made available to the lift sector that make up the CMD Lift system (Cloudlift, Mobile Lift and Datalift). * SGQ and SGCO Responsible Telesan Srl

RkJQdWJsaXNoZXIy NDUyNTU=