Measuring Our Success

Cyber security

Information Security Management Programs

Information Security Program

JSW Steel maintains a comprehensive information security program designed to protect information assets, operational technology systems, customer information, and business-critical data.

All the Information technology management systems are certified to ISO27001:2022.

Program considerations

Information security policies and procedures.

Business continuity and disaster recovery planning.

Periodic vulnerability assessments and risk reviews.

Incident reporting and escalation mechanisms.

Employee awareness and training initiatives.

Internal audits of information security controls.

Independent reviews and certifications, where applicable.

We continuously enhances our cyber resilience capabilities in response to evolving threats and technological developments.

Our information security business continuity plans are designed to maintain operational resilience, minimise downtime and protect sensitive data during disruptions. These plans are regularly reviewed and tested to evaluate their effectiveness and readiness.

We conduct regular vulnerability assessments, penetration testing, and cloud security risk reviews, alongside continuous monitoring and phishing simulations. Advanced measures such as dark web monitoring, Endpoint Detection & Response (EDR), Network Access Control (NAC), and multi-factor authentication (MFA) for critical services strengthen our defenses. Additionally, we subscribe to cyber insurance, deploy DDoS prevention mechanisms, and run awareness programs across all locations to mitigate evolving threats. These initiatives collectively enhance resilience and safeguard business continuity in an increasingly digital world.

We also conduct internal audits of our IT infrastructure and Information Security Management Systems to identify vulnerabilities, assess alignment with JSW Steel's requirements and applicable standards, and evaluate the effectiveness of IT general controls. These audits are undertaken in accordance with the Internal Audit Plan approved by the Head of Internal Audit.

All incident reports are managed through a structured and transparent process, beginning with a preliminary assessment of their validity and severity. Where required, a detailed investigation is initiated, with findings reviewed by the Ethics Committee and escalated to the Audit Committee, as appropriate. Outcomes are documented, corrective actions are implemented and follow-up reviews are conducted to reduce the risk of recurrence.

Regular training and awareness programmes help employees understand how to access reporting channels, the types of concerns that may be reported and the protections available to them. These efforts have helped us to ensure zero cybersecurity breaches and zero breaches of customer privacy data were reported during FY 2025-26.

Responsible and Ethical Use of Artificial Intelligence

At JSW Steel Limited, we are progressively strengthening our responsible artificial intelligence (AI) practices to support innovation while protecting people, data, operations and stakeholder trust. AI and machine-learning solutions are used across selected business and operational contexts, including decision support, analytics, productivity, predictive maintenance and process optimisation. Our governance approach is risk-based, with accountability, assessment, validation, human oversight and monitoring requirements increasing according to the potential impact, autonomy, data sensitivity and operational criticality of each use case.

Our approach is aligned with JSW Steel's Information Security Management System (ISMS) and requires the use of approved AI services, role-based access and cybersecurity controls proportionate to risk. AI use cases involving personal data, confidential business information, third-party platforms or material system integrations are subject to applicable privacy, information-security, legal, architecture and supplier-risk requirements. JSW information is not permitted to be used to train shared third-party models unless specifically authorised following the required reviews.

Access to sensitive AI capabilities, including biometric identification, facial recognition, surveillance technologies, emotion-recognition systems and other higher-risk AI applications, shall be restricted to specifically approved business purposes and authorised personnel. Such use cases shall be subject to enhanced governance, risk assessment, legal and privacy review, and additional security controls proportionate to the associated risks. Unauthorised deployment or use of sensitive AI capabilities is prohibited.

AI is intended to support, rather than replace, accountable human judgement. High-risk or irreversible decisions require meaningful human oversight, including the practical ability to question, override, escalate or stop the system. AI-generated outputs must be appropriately verified before being relied upon for legal, regulatory, financial, engineering, safety, employment, security or external-communication purposes. Material AI involvement, intended purpose, capabilities and limitations are to be communicated where required by law, contract, risk or reasonable stakeholder expectation.

Where appropriate and practicable, AI-generated content, recommendations, analyses, communications or AI-assisted decisions shall be clearly identified as AI-generated or AI-assisted to support transparency and informed decision-making. Material AI involvement in customer-facing, employee-facing or stakeholder-facing outputs shall be disclosed in accordance with applicable legal, regulatory, contractual and business requirements.

We have implemented processes to monitor the performance of AI models deployed in areas such as predictive maintenance and operational optimization, enabling early detection of model drift and periodic recalibration.

We maintain formal grievance and escalation mechanisms, allowing stakeholders to raise concerns related to algorithmic decisions. These mechanisms provide an accessible, fair, and responsive platform for users, enabling them to seek redress or clarification through clearly defined pathways.

Where AI systems may materially affect individuals or stakeholders, relevant risks of bias, discriminatory outcomes and accessibility are to be assessed and addressed using data, populations and operating contexts appropriate to the use case. JSW Steel also considers the environmental implications of AI and promotes energy-efficient infrastructure, appropriately sized models, optimised computing and responsible technology and supplier selection, in alignment with its broader sustainability objectives.

Our employees undergo continuous training on digital technologies, including the secure and ethical use of AI systems.

Monitoring and revalidation requirements are being strengthened across the AI lifecycle. Depending on the nature and risk of the use case, these may include monitoring of model performance, drift, data quality, harmful outputs, security events, user feedback, overrides, availability and operational impact. AI systems used for predictive maintenance, operational optimisation or other material applications are expected to operate within defined performance thresholds and approved operational boundaries, with accountable owners and appropriate escalation, recalibration, suspension or rollback mechanisms.

Responsible AI topics are being incorporated into periodic, role-based digital and information-security awareness programmes. AI-related concerns, including material errors, unfair outcomes, privacy, security, safety or misuse, are to be routed through the relevant information-security, privacy, ethics, grievance, safety or service-management channels so that they can be appropriately investigated, escalated and addressed.

Where relevant and feasible, JSW Steel shall assess and monitor the contribution of AI-enabled initiatives toward sustainability objectives. This may include the measurement of impacts such as energy-efficiency improvements, resource optimisation, emissions reduction, waste minimisation, equipment reliability, operational efficiency and other environmental or social performance indicators. Insights from such assessments may be used to support continuous improvement and informed decision-making.

AI governance controls and management practices are periodically reviewed to assess their effectiveness, alignment with applicable legal and regulatory requirements, and consistency with emerging responsible AI standards and best practices, and are aligned to ISO/IEC 42001. Such reviews may include internal assessments, independent evaluations and management reviews, as appropriate. Findings and recommendations from these reviews are used to strengthen AI governance, risk management, operational controls and continuous improvement across the AI lifecycle.

We use cookies on this website. Please indicate whether or not you accept our use of cookies. For more information read our Cookie Policy