The fast-paced digital transformation taking place across industries and businesses has triggered serious cybersecurity challenges, necessitating a holistic approach to countering the same. Cybersecurity challenges have marked an increase in incidents such as ransomware attacks.
With its growing focus on adopting advanced technologies to boost operational and cost efficiencies, Adani Ports and Special Economic Zone Limited (APSEZ) is also facing several cybersecurity challenges. To combat these concerns, we have adopted a comprehensive approach to digitalisation. Going beyond simple automation, we harness data simulation and manipulation to deliver superior outcomes.

GRI 416, GRI 418
We make continuous investments in technological innovation to anticipate and respond with agility to market changes, capitalise on opportunities, and effectively meet the evolving customer demands.
Amid the evolving needs of our diverse stakeholders, we have adopted a well-crafted digital transformation strategy tailored to their unique aspirations. The strategy is designed to effectively cater to the needs of our employees, suppliers, vendors, and customers. The focus, at APSEZ, is on continuous technological and digital advancement and investment.
We pursue an integrated approach to transform our operations, catalysing new growth opportunities and ensuring sustained success. We consistently seek innovative methods to enhance our services and provide our customers with seamless and superior experience. Some key examples of such innovations are:
Enabling inventory assurance through multi-sensor yards via TLS, SLAM and aerial telemetry of ports.
Establishment of Automated Terminal at Vizinjham, OCR integration at gates and Ship-to-Shore (STS) cranes, and Position Detection Systems (PDS) for yard cranes have led to notable enhancement in real-time monitoring and operational efficiency.
We are continually harnessing advanced technologies to drive our efforts to scale up our ports into ‘smart’ ports.
Implementation of RFID mesh technology has helped establish a wireless network for connecting sensor devices.
We have successfully piloted the tracking of high-value containers in real-time, monitoring and detection of air pollution, automatic energy management and vehicle movement control, among other applications.
3D mapping technique was explored to obtain real-time profiles of bulk piles in the stock yard, for use in effective yard planning. This enabled us to measure the area occupied/available for cargo weight at any given point
Algorithmic optimisation was tested to create dynamic vessel plans, which were then implemented through a central control room for optimal utilisation of port equipment.
Use of advanced video analytics for test cases has helped in reducing human intervention errors. These include intrusion, tempering, over-speeding, trespassing, fire, smoke, colours, number plate identification, and crowd movement etc.








Middleware Integrating All Our Systems
(Central platform to plan & monitor end-to-end operations)
(Gateway for all external stakeholders for track & trace bookings, payment etc.)
The Command & Control (C&C) platform functions as a central hub for planning, monitoring, and managing end-to-end operations. It integrates with various systems to offer:
The Port Community System (PCS), also known as ITUP, acts as a gateway for all external stakeholders, offering services such as tracking and tracing, bookings, and payments. Key features include:
As we transition into an integrated transportation utility company, we recognise the importance of digitalisation and automation in driving efficiencies across our value chain. From customer interactions to port operations, storage, and real-time tracking of cargo, we have prioritised technology, and continue to invest in its adoption and implementation.
Navis Terminal Operating System – Efficiently manages port operations by:
IPOS (Integrated Port Operating System) –
Designed to manage operational activities within a port, IPOS handles transactions, marine operations, vessel operations, gate activities and documentation. Key features include:
(Used across all our ports, IPOS assists in managing Dry, Bulk, Break Bulk, ODC and Liquid Cargo)
Tracker – It is designed to provide comprehensive tracking and management of terminal operations. It offers real-time visibility of the location and status of containers, optimising yard and gate operations. The system integrates data from various sources, including GPS and vehicle tracking systems, to ensure smooth communication and decision-making.
CMS – A Cargo Management System (CMS) is a comprehensive platform designed to streamline logistics operations, from booking and tracking to inventory and revenue management. It enhances efficiency and provides real-time insights for optimised cargo handling.
Our port and logistics assets are seamlessly integrated through a comprehensive layer of technology, enabling us to anticipate and adapt promptly to market needs, competitive opportunities, and customer demands.
FarEye – Provides real-time cargo visibility across multiple modes (rail, road). Used in our command centres, it assists in centralised monitoring and control, proactively detecting and managing exceptions like delays and deviations
FOIS (Freight Operations Information System) – Developed by Indian Railways, FOIS provides real-time tracking of freight trains. It assists in planning and optimising rake movements for efficient operations, with timely updates on rake positions and schedules to improve reliability
LMS and facilitate logistics close-looping from order to delivery to invoicing, automating first mile to last mile, managing strategic decisions like capacity management, and operations management like shipping plans, loading receipts, cargo tracking, and exception management
FleetX – Fleet management software is aimed at improving safety and monitoring. A plug-and-play device is installed in the trucking fleet to detect route deviations (geofencing to prevent unauthorised movements), pilferage, long vehicle holds, and speed limit violations
Adani Customer Portal – Our Adani Customer Portal ensures smooth digital experience, providing real-time access to cargo status, transactions, and operational updates
We have successfully integrated cutting-edge technology into our hinterland connectivity strategy.
We have established a state-of-the-art Strategic Command Centre in Ahmedabad.
We have launched the Trucking Management Solution (TMS) to further complement the enhancements delivered by our command centre.
Our Vizhinjam Port is a remarkable example showcasing our continuous innovation in technology. High level of automation makes it one of the most technologically sophisticated global transshipment ports. With best-in-class efficiency, productivity, reduced vessel turnaround times, and remote handling of operations, Vizhinjam Port has set a new benchmark in port operations.
Key Automation Features:
Key Automation Benefits:
Recognising the need for technology-leading innovation to achieve end-to-end supply chain efficiency, we will continue to prioritise investments in technology as we transform into an integrated transport utility company, offering unmatched waterfront to last-mile connectivity solutions.
NextGen - TOS (Navis)
PCS Foundation
NextGen - TOS (Navis)
PCS Scaling
NextGen-TOS (Navis)
PCS Transformation
Logistics super app


At APSEZ, we prioritise customer relationships and satisfaction through sustained investments in cutting-edge technologies. Besides enhancing consumer experience, these investments are designed to integrate a forward-thinking approach into our services. They lend a strong competitive and market leading edge to the company in terms of customer service. They also enable us to reduce operational costs, augmenting productivity and efficiency, while effectively helping us steer our sustainability goals.
Our IT system provided the following information – Cargo status report: SMS-based VCN status: Vessel declaration and auto PPA: auto alerts on compliance: vessel closure and NOC: weather reports on SMS
We installed a laser-based feedback system that minimised the zig-zag movement of RTGs. The stack profiling system analysed the height of the stack and prevented collision with RTGs through automatic immobilisation, enhancing safety and equipment efficiency.
We employed cranes in our ports, and these could be operated remotely, enhancing our technological capability.
When maintenance dredgers became critical, we converted CSD to WID without external fabrication, saving crores of rupees in capital expenditure.
We modified existing e-RTGs to account for 50,000 possibilities of a container in our yard and relayed to the TOS, avoiding delays and errors.
We developed expertise in handling special cargo, ranging from metro rail bogies to helicopters, cranes and wind turbines, among other applications.
We developed a robust capability to address futuristics vessels – especially large – at the design stage, thereby future-proofing our ports.
We developed a facility to handle 35,00 MT of coated urea per day, capable of filling 11 rakes of 52 wagons each, in line with the national priority for the fertiliser sector.
We introduced a photo sensor in the management of RTGs, equipped to lift two 20 feet containers in one go, enhancing judgement calls and safety.
We launched India’s first Ro-Ro terminal that could be operated 24*7, even with a sea level variation as high as 6 metres.
We developed the largest dredging capacity, by size, in India (equivalent to 80 times the Vatican City ).
We created a laser sensor system to provide graphical information using customised software (developed at a quarter of the prevailing cost), to provide information (berthing velocity, distance and approach angle) and maintain low berthing velocity (less than 0.1m/s) to avoid collision.
We designed a system to detect the number of gaseous hydrocarbons in the ambient air, integrated with the SCADA system to provide real-time information and raise automatic alarms when necessary.
We completely (100%) treated and recycled solid and liquid waste generated by incoming vessels.
We have developed a robust customer-centric model rooted in our deep understanding of the evolving customer needs. We use world-class infrastructure, cutting-edge technology, and service excellence to not just meet but exceed customer expectations. This gives us a distinctive leadership edge in the competitive market and aids our growth trajectory.
Serving wide range of customer categories, such as exporters, importers, shipping lines, refineries, etc.
Providing extensive portfolio of services, including handling, storage, transportation, and value-added services like customs clearance, warehousing, and container repair
Offering efficient end-to-end logistics solutions by capitalising on our vertically integrated business model and strategic coastal locations, enabling faster transit times and lower transportation costs
The model is designed to drive our sustained, long-term growth and give us a strong competitive advantage.
Our efforts to build long-term relationships with our customers are steered by our commitment to deliver reliable, efficient and cost-effective logistics solutions. We use advanced technologies, such as APMS, SAP, Data Lake and Realtime dashboards, and web-based mobile applications, to provide real-time visibility into the cargo value chain, and help in precise tracking of port-based vessels and cargo. Our ‘smart port’ initiative boosts service delivery via IoT devices and data analytics, ensuring seamless customer experience and convenience.
We conduct surveys to get customer feedback and strengthen our customer service proposition. Our goal is to achieve a customer satisfaction score of 4.5/5 by 2026.
APSEZ conducts an annual Customer Satisfaction Survey to understand customer needs, evaluate service performance, and identify improvement opportunities. The survey is hosted on a web-based platform and includes a comprehensive set of questions covering service quality, customer experience, and sustainability aspects such as environment, health & safety, and governance. All responses are recorded on a 1–5 rating scale for objective assessment.
Under the updated survey methodology, the recent survey was carried out across multiple business verticals. This enhanced approach focusses on evaluating ESG compliance, tracking alignment with sustainability goals, and highlighting areas requiring attention. Insights from the survey support continuous improvement, strengthen customer engagement, and reinforce APSEZ’s commitment to responsible and sustainable business practices.
The following questionnaire was sent to customers as part of the survey.
| FY 2022-23 | FY 2023-24 | FY 2024-25 | FY 2025-26 | |
|---|---|---|---|---|
| Customers Satisfaction Score | 4.3/5 | 4.5/5 | 4.3/5 | 4.5/5 |
| % of Satisfied Customers | 86 | 90 | 86 | 90 |
| Coverage (%) | 100 | 100 | 100 | 100 |
To ensure the protection of our systems and data against potential cyber threats during the adoption of advanced technologies and digital processes, we have integrated cybersecurity with digitisation. This helps in protecting the integrity and confidentiality of our critical infrastructure, besides enabling its seamless availability for delivery of secure logistics solutions.
Our Cybersecurity Policy (https://www.adaniports.com/investors/corporate-governance) is crafted to help us effectively address and manage the complexities of cyber risks. This ensures the protection of our IT and business operations against cyber threats.
We are continually investing in strengthening our cybersecurity framework and minimising our risk exposure through a structured governance framework, encompassing robust monitoring mechanisms and stringent reviews. This underlines our commitment to maintaining the highest standards of digital security and operational excellence in the face of evolving cyber threats.
Cybersecurity Governance Framework at APSEZ
The Information Technology & Data Security (IT & DS) Committee plays a vital role in overseeing and enhancing our cybersecurity framework. Its responsibilities include:
At APSEZ, we recognise the threat faced to organisational integrity and operational continuity by the various cybersecurity risks in the fast-evolving digital landscape. Our Risk Management Committee plays a vital role in mitigation of these risks through continuous monitoring and review of the company’s risk management strategies. The committee is focussed on identifying, assessing (both qualitatively and quantitatively), analysing, and effectively managing current and anticipated cybersecurity risks.
The cyber risk assessment framework at APSEZ is intricately aligned with the Information Security Management System (ISO 27001) standards, ensuring seamless integration with our broader enterprise risk management initiatives.
To minimise the various cybersecurity risks, we have adopted a comprehensive IT security plan, encompassing business continuity strategies that include redundancy and high availability across various levels. As part of this plan, we have adopted and implemented ISO 27001:2013 – Information Security Management System (ISMS) across all our operational sites, inline with our security policy. We have also set up a 24/7 Cyber Defence Centre, designed to proactively identify and mitigate cybersecurity incidents.
We engage with independent auditing agencies to ensure compliance with cybersecurity standards. The internal and external annual IT General Controls (ITGC) and ISO/IEC 27001:2013 audits are part of this exercise. We are also covered by the various assessments conducted by the Adani Group Management Assurance Team. Besides ensuring our cybersecurity compliance, this provides an insight into our position with respect to cybersecurity.
Our approach to incident management is proactive and comprehensive.
A robust consequence management protocol is followed by APSEZ for effectively addressing any cases of cybersecurity non-compliance and breaches effectively.
We have deployed Endpoint Detection and Response (EDR) solutions to monitor and isolate compromised systems in real time. Based on the lessons learnt, we have integrated tools such as SIEM (Security Information and Event Management) for better threat correlation and analysis.
The cornerstone of our resilience strategy, our Business Continuity Plan (BCP) is designed to ensure uninterrupted operations in the face of natural disasters, cyber threats, and other disruptions affecting our Port and Special Economic Zone (SEZ) operations. The plan specifically addresses scenarios where critical aspects such as personnel availability, facilities, and technology are compromised, impacting the delivery of essential IT services vital for our business functions and customer service commitments.
The BCP framework:
Core Elements of the BCP
Activation – The BCP is activated on the direction of the APSEZ management in the event of a BCP-defined crisis. This comprehensive system:
To ensure the plan's effectiveness and readiness, we conduct semi-annual tests of all procedures and protocols.
Oversight and Cybersecurity Measures – The Chief Information Security Officer (CISO) plays a pivotal role in overseeing the Business Continuity and Disaster Management Plan. The CISO:
Cybersecurity Awareness and Capability Enhancement – Recognising the importance of cybersecurity in our overall business continuity strategy, APSEZ mandates annual cybersecurity training for all employees.
The IT team at APSEZ has deployed a series of systems to further enhance the company’s operational efficiencies.
Each implementation is targeted at streamlining operations, enhancing security, and improving service delivery across the organisation.
Through comprehensive BCP, rigorous cybersecurity initiatives, and continuous operational improvements, APSEZ maintains resilience, upholding the safety and security of its operations, and providing uninterrupted service to its customers, even in the face of unforeseen challenges.
Beyond training, we have implemented several advanced cybersecurity measures at APSEZ. These include:
| Cybersecurity/ Operational Initiative | Description | Purpose/Impact |
|---|---|---|
| Privileged Access Management (PAM) | Manages and monitors access to privileged accounts | Strengthens security by controlling access to critical systems and data |
| Security Orchestration, Automation and Response (SOAR) | Automates security operations to efficiently respond to incidents | Enhances incident response times, and minimises manual intervention in threat detection and response |
| Cloud Security Posture Management (CSPM) | Manages risks associated with cloud environments, and automates compliance monitoring | Ensures security of cloud environments and their compliance with relevant regulations, minimising the risk of data breaches |
| Multi-Factor Authentication (MFA) | Strengthens the authentication process by requiring multiple forms of verification | Augments user account security, reducing the possibility of unauthorised access |
| Web Application Firewall (WAF) | Secures websites from cyber-attacks by filtering and monitoring HTTP traffic | Protects the APSEZ website against various web-based threats, ensuring website integrity and user data |
| Grievance Management System (GMS) | Collects grievance-related information from internal and external stakeholders | Enables efficient handling and resolution of grievances, enhancing stakeholder satisfaction and operational transparency |
| Ransomware Protected Back-up Solution | Ensures data protection against ransomware threats or attacks | Ensures data recovery in the event of a ransomware attack, minimising operational disruption and data loss |
| Gate Operating Systems (GOS) at Mundra Port | Automates gate operations and enables online fee collection | Streamlines vehicle entry processes at Mundra Port, boosting efficiency and reducing wait times |
| SIEM (Security Information & Event Management) | SIEM collects, aggregates, and analyses data from various sources within an organization's IT infrastructure. This data includes logs from applications, devices, servers, and users, providing a comprehensive view of the organisation's security posture | SIEM ensures threat detection, efficient incident response, and regulatory compliance by centralising and analysing security data, thereby enhancing security posture, operational efficiency, and proactive threat management |
| EDR (End Point Detection & Response) | Continuously monitors end-user devices to detect and respond to cyber threats like ransomware and malware | Enhances security by providing real-time threat detection and automated response, improving incident response efficiency and reducing the impact of cyberattacks |
| DLP (Data Leak Prevention) | To prevent unauthorised access, sharing, or exfiltration of sensitive data | Protect confidential information, ensuring regulatory compliance and reducing the risk of data breaches |
| Deep and Darkweb Monitoring | Regular web monitoring focusses on the surface web, which includes publicly accessible websites indexed by search engines. In contrast, deep and dark web monitoring targets hidden parts of the internet not indexed by search engines, requiring special access methods | Continuous monitoring, Detect illicit activities such as data breaches, stolen credentials, and cyber threats, providing early warnings and actionable insight along with Brand Protection |
| Proxy, Network Admission Control | A proxy server acts as an intermediary between a user's device and the
internet. NAC manages and enforces policies regarding the access of devices and users to a network |
Proxy ensures better control over internet usage, improved privacy, and protection against malicious websites whereas NAC ensure that only authorised and compliant devices can access the network |
| Identity and Access Management | Manages Digital Identities and control user access to resources | Enhances security by ensuring only authorised users can access sensitive data |
These initiatives significantly strengthen our defence against cyber threats by providing real-time threat detection, log analysis, and incident response capabilities. They help in quick identification and mitigation of potential security threats, thereby reducing the risk of data breaches and other cyber incidents.
We have prioritised data protection and privacy at APSEZ, not merely as a compliance requirement but as a core value that drives our commitment to excellence and integrity in all our operations. We are committed to upholding the highest standards of data protection and privacy. Our business model is built on a foundation of trust, transparency, and ethical practices, ensuring that all personal and sensitive information is handled with the utmost care and confidentiality.
Data Privacy Governance
Our commitment to safeguarding the privacy and security of the data of our various stakeholders is unwavering. To uphold this commitment, we have formulated a comprehensive Data Privacy Policy, covering all individuals and entities associated with the organisation, including employees, contractors, partners and third-party vendors. The policy will help manage personal and sensitive data responsibly. It will comply with current regulations and will incorporate the best global practices, underscoring our belief that privacy is a fundamental right.
We implement robust measures to protect Personally Identifiable Information (PII), ensuring our processes meet regulatory standards. We also encourage our stakeholders, including customers and business partners, to contact us via email or phone with any questions about their personal data. These initiatives are designed to promote transparency and open communication regarding data collection and use.
We have integrated a detailed privacy policy system into our group-wide risk and compliance management framework. This system ensures the protection of stakeholders' privacy rights, regulatory compliance in data handling practices, and effective risk mitigation strategies. By embedding privacy policies throughout the organisation, we prioritise data security and build trust with our customers and partners.
Note: The organisation currently processes Personally Identifiable Information (PII) predominantly in digital form.
The Head - Cybersecurity is responsible for ensuring compliance of the Privacy Policy at APSEZ.
Given the threat posed by data privacy issues to the company’s integrity and operational continuity, we have aligned our framework for data privacy risk assessment with the Digital Personal Data Protection (DPDP) Act. Our efforts are focussed on ensuring compliance with legal requirements and industry’s best practices as per the Act.
Detection Mechanisms
Reporting Procedures
Our Data Privacy Protocols
We have instituted a comprehensive privacy impact assessment (PIA) for various projects at APSEZ. The assessment is designed to evaluate how a project, system or process affects the privacy of individuals whose data is being collected, stored, or processed. It ensures compliance with data protection laws like the GDPR and DPDP Act and helps mitigate potential privacy risks.
At APSEZ, we have established elaborate mechanisms to detect and report data breaches as part of our cybersecurity framework. The framework is also being extended to include privacy considerations. We employ a combination of technical and procedural measures to ensure timely detection and reporting of breaches.
| Key steps in conducting a PIA | |
|---|---|
| Identify the need for a PIA | Determine if the project involves high-risk data processing activities, such as handling sensitive personal information |
| Describe the Information Flows | Document the process of collection, usage, storage, and sharing of the collected |
| Identify Privacy Risks | Assess potential risks to individuals' privacy, including data breaches or misuse |
| Consult Stakeholders | Engage with stakeholders, including data subjects, to gather their input and concerns |
| Evaluate Privacy Solutions | Identify measures to mitigate identified risks, such as data encryption or access controls |
| Document the PIA | Record the findings and decisions made during the assessment |
| Review and Update | Regularly review and update the PIA to reflect changes in the project or regulatory environment |
We follow elaborate practices designed to ensure the integrity and security of data sharing and protection. These include:
Back-up and secure storage for 5 years for all essential applications, including IPOS Container and IPOS Non-Container systems; Protection and safe retention for 7 years for all financial documents
Adani Microsoft SharePoint solution Information used to enable sharing with third parties, when necessary; Approvals needed for this from relevant business and cybersecurity teams, ensuring compliance with strict security protocols
Individual’s opt-in consent obtained, where required under relevant Data Protection Laws, before processing activities on customer data / personal information are undertaken
Identification and secure deletion of data that is no longer needed, ensuring that it cannot be recovered. Deletion process, including details of what was deleted and when, clearly documented
Data identified for anonymisation and for application of techniques like generalisation, suppression, or pseudonymisation, to protect privacy while retaining its analytical value.
Restriction on use of personal data of all stakeholders to essential business operations, such as invoice generation and payment processing; Such data includes key identifiers like names, addresses, email, mobile numbers, and financial details; All such data securely blocked in the system after completion of process/service
Strict regulation of disclosure of customer information to third parties; Linked to legal obligations with government agencies; May include sharing of specific fields, such as customer PAN and GST numbers, for tax filing purposes
Privacy-by-design principles being adopted to embed data privacy into IT systems, in line with DPDP Act; To include features like data minimisation, encryption, and role-based access controls
Emphasis on protection of personal data or information of all the stakeholders, including customers, employees, third-party vendors, partners, suppliers, etc.; DPDP Act 2023 acts as regulation on data privacy and control; Our stakeholder data privacy measures include authorisation, encryption, verification, data back-up and recovery; We adopt the best business practices to protect all private data, including restrictions on data collection and access, regular audits, employee training on privacy practices, and regular reviews of compliance with the data protection laws
As a B2B enterprise, with our primary focus on commercial activities rather than marketing, we don’t necessitate an opt-out option for our customers regarding the handling of their personal information. In the broader context, given that the personal data is predominantly used for commercial purposes, the application of such data for secondary purposes is not relevant.
A robust Incident Response Plan (IRP) is in place with respect to cybersecurity & data privacy at APSEZ. The plan ensures effective management of data breaches involving personal data and is aligned with the organisation’s overall cybersecurity strategy as well as the requirements of privacy regulations like the DPDP Act.
We are now in the process of establishing dedicated communication channels, such as an email helpdesk and a grievance cell, to enable data principals to seamlessly lodge complaints. These mechanisms will be backed by defined timelines to address concerns efficiently.
Training & Awareness
Information Security and Data Privacy training and awareness help employees identify and avoid cyber threats, protect sensitive information reducing the risk of data breaches and cyberattacks. These training fosters a culture of security compliance, ensuring that everyone in the organisation understands their role in protecting sensitive information and maintaining regulatory standards.
Key Topics of these trainings focus on phishing awareness, password best practices, and data protection. Additionally, it covers safe internet practice, social engineering, mobile device security, two-factor authentication, data classification and secure handling, and privacy principles such as consent, minimisation, retention, and accountability. Training should also address access control and least privilege, device and endpoint protection, secure use of networks and cloud services, social engineering and physical security, incident reporting and initial response, backup and recovery, and third-party risk management.
We empower all our employees through concise e-learning modules, instructor-led sessions, role-based tracks, simulated phishing campaigns, tabletop exercises, hands on labs, and microlearning tips to reinforce secure behaviours.
The effectiveness of data privacy and cybersecurity training is measured through several methods:
Maintaining Confidentiality
We follow a zero-tolerance policy against any violations to the privacy policy. We have embedded the principle of confidentiality of personal information into our code of conduct. Any violation of the privacy policy, or involvement in privacy breaches, by an employee invites strict disciplinary action. We have an excellent track record in terms of customer privacy protection and have not reported any cases of information security breaches, data breaches, or cybersecurity incidents in the past three fiscal years. APSEZ has the distinction of ZERO substantiated incidents related to breach of customer privacy, data theft, leaks, or loss for FY 2025-26. This underlines our strong commitment to data protection and implementation of cybersecurity measures. No fines or penalties levied have been imposed on APSEZ with respect to data security breaches or cybersecurity incidents.