Digitalisation & Cybersecurity

Harnessing technology to enhance cybersecurity

Line illustration of a port worker with a tablet connected to cloud, folder and secure-lock icons

The fast-paced digital transformation taking place across industries and businesses has triggered serious cybersecurity challenges, necessitating a holistic approach to countering the same. Cybersecurity challenges have marked an increase in incidents such as ransomware attacks.

With its growing focus on adopting advanced technologies to boost operational and cost efficiencies, Adani Ports and Special Economic Zone Limited (APSEZ) is also facing several cybersecurity challenges. To combat these concerns, we have adopted a comprehensive approach to digitalisation. Going beyond simple automation, we harness data simulation and manipulation to deliver superior outcomes.

Our investments in technology:
  • Seek to reduce operational costs, provide real-time data for informed decision-making, optimise workflows, and strengthen information security
This approach is designed to:
  • Boost our operational capabilities
  • Enhance our cybersecurity
  • Enable us to resiliently navigate the digital age challenges

Key Highlights

  • Implementation of Advanced Digital Logistics Systems
  • Deployment of IoT for Real-Time Monitoring
  • Implementation of Customer portal to enable customers to perform their transaction from their office and provide them more visibilities on their cargo
  • Enhanced Cybersecurity Measures for Operational Technology
  • Initiatives for Enhancing Digital Literacy and Skills Among Employees

Material Topics

M10Customer Satisfaction
M14Data Privacy and Security
M17Regulatory Compliance
M19Digital Inequality

Capitals Impacted

Financial Capital
Intellectual Capital
Human Capital

SDG Alignment

SDG 9

GRI Linkage:

GRI 416, GRI 418

We make continuous investments in technological innovation to anticipate and respond with agility to market changes, capitalise on opportunities, and effectively meet the evolving customer demands.

Focussed on Digital Transformation

Amid the evolving needs of our diverse stakeholders, we have adopted a well-crafted digital transformation strategy tailored to their unique aspirations. The strategy is designed to effectively cater to the needs of our employees, suppliers, vendors, and customers. The focus, at APSEZ, is on continuous technological and digital advancement and investment.

Empowering Operational Success through Digital Transformation

We pursue an integrated approach to transform our operations, catalysing new growth opportunities and ensuring sustained success. We consistently seek innovative methods to enhance our services and provide our customers with seamless and superior experience. Some key examples of such innovations are:

  • Successful transformation of port operations and enhanced customer service by integrating advanced technologies and sophisticated software with superior infrastructure
  • Enhanced operational capabilities through integration of Artificial Intelligence (AI) and the Internet of Things (IoT)

Enabling inventory assurance through multi-sensor yards via TLS, SLAM and aerial telemetry of ports.

Establishment of Automated Terminal at Vizinjham, OCR integration at gates and Ship-to-Shore (STS) cranes, and Position Detection Systems (PDS) for yard cranes have led to notable enhancement in real-time monitoring and operational efficiency.

We are continually harnessing advanced technologies to drive our efforts to scale up our ports into ‘smart’ ports.

RFID mesh

Implementation of RFID mesh technology has helped establish a wireless network for connecting sensor devices.

We have successfully piloted the tracking of high-value containers in real-time, monitoring and detection of air pollution, automatic energy management and vehicle movement control, among other applications.

3D Scanning Technique

3D mapping technique was explored to obtain real-time profiles of bulk piles in the stock yard, for use in effective yard planning. This enabled us to measure the area occupied/available for cargo weight at any given point

Algorithmic Optimisation

Algorithmic optimisation was tested to create dynamic vessel plans, which were then implemented through a central control room for optimal utilisation of port equipment.

Video Analytics

Use of advanced video analytics for test cases has helped in reducing human intervention errors. These include intrusion, tempering, over-speeding, trespassing, fire, smoke, colours, number plate identification, and crowd movement etc.

Comprehensive Integration of Technology Platforms Across Operations to become ‘Future-Ready’

Berth
Port ops management
Railways
Real-time rake tracking
Terminal
Automated container depot mgmt. (TOS)
Truck
Fleet management system
Last-mile delivery
Digital customer portal

Middleware Integrating All Our Systems

Command & Control (C&C)

(Central platform to plan & monitor end-to-end operations)

Port Community System (PCS)

(Gateway for all external stakeholders for track & trace bookings, payment etc.)

Command & Control (C&C)

The Command & Control (C&C) platform functions as a central hub for planning, monitoring, and managing end-to-end operations. It integrates with various systems to offer:

  • The Operations department at APSEZ has established a Strategic Command Centre to drive our logistics strategy
  • The centre serves as a central Information hub, enabling effective management of real-time expectations while adhering to a comprehensive set of decision-making rules
  • It enables optimisation of processes and delivery of exceptional service to our customers
  • It uses Data Analytics with the objective of standardising processes and workflows, with its primary goal focussed on improving turnaround time (TAT), addressing pilferage risk, enhancing asset utilisation, improving response time, ensuring SLA adherence, and maintaining overall operational safety standards
  • Critical alerts, such as Route Deviation, Risky Point Stoppage, Device Tampering, and Frequent Unwanted Stoppage, are logged as tickets in the system. These tickets are automatically assigned to the respective stakeholders for appropriate action and measures. The command centre deploys an advanced algorithm for performing risk assessments for each trip and generating exceptions for non-adherence. Key technology enablers include GPS, RFID, QR, Automatic Number Plate Reading, along with Biometric Integration with PCS and Government Database

Port Community System (PCS)

The Port Community System (PCS), also known as ITUP, acts as a gateway for all external stakeholders, offering services such as tracking and tracing, bookings, and payments. Key features include:

  • Track & Trace: Real-time shipment and container tracking
  • Bookings: Streamlined booking processes
  • Payments: Secure and efficient payment processing
  • Stakeholder Integration: Connecting shipping lines, freight forwarders, customs, and other stakeholders for efficient information exchange

Implementing Technology to Improve Efficiency

As we transition into an integrated transportation utility company, we recognise the importance of digitalisation and automation in driving efficiencies across our value chain. From customer interactions to port operations, storage, and real-time tracking of cargo, we have prioritised technology, and continue to invest in its adoption and implementation.

Efficiencies in our port operation are being driven by:

Navis Terminal Operating System – Efficiently manages port operations by:

  • Supporting a broad range of terminal operations: Optimises vessel, yard, and route planning for container movement
  • Providing real-time data access: Increases cargo visibility

IPOS (Integrated Port Operating System) –

Designed to manage operational activities within a port, IPOS handles transactions, marine operations, vessel operations, gate activities and documentation. Key features include:

  • Efficient resource allocation of equipment and labour
  • Comprehensive documentation management
  • Real-time monitoring of port operations

(Used across all our ports, IPOS assists in managing Dry, Bulk, Break Bulk, ODC and Liquid Cargo)

Efficient cargo management at terminals is enabled with:

Tracker – It is designed to provide comprehensive tracking and management of terminal operations. It offers real-time visibility of the location and status of containers, optimising yard and gate operations. The system integrates data from various sources, including GPS and vehicle tracking systems, to ensure smooth communication and decision-making.

CMS – A Cargo Management System (CMS) is a comprehensive platform designed to streamline logistics operations, from booking and tracking to inventory and revenue management. It enhances efficiency and provides real-time insights for optimised cargo handling.

Our port and logistics assets are seamlessly integrated through a comprehensive layer of technology, enabling us to anticipate and adapt promptly to market needs, competitive opportunities, and customer demands.

Real-time visibility of cargo in our first/last mile delivery is ensured by:

FarEye – Provides real-time cargo visibility across multiple modes (rail, road). Used in our command centres, it assists in centralised monitoring and control, proactively detecting and managing exceptions like delays and deviations

FOIS (Freight Operations Information System) – Developed by Indian Railways, FOIS provides real-time tracking of freight trains. It assists in planning and optimising rake movements for efficient operations, with timely updates on rake positions and schedules to improve reliability

LMS and facilitate logistics close-looping from order to delivery to invoicing, automating first mile to last mile, managing strategic decisions like capacity management, and operations management like shipping plans, loading receipts, cargo tracking, and exception management

FleetX – Fleet management software is aimed at improving safety and monitoring. A plug-and-play device is installed in the trucking fleet to detect route deviations (geofencing to prevent unauthorised movements), pilferage, long vehicle holds, and speed limit violations

Seamless customer interactions are managed by:

Adani Customer Portal – Our Adani Customer Portal ensures smooth digital experience, providing real-time access to cargo status, transactions, and operational updates

Other Major Tech Initiatives at APSEZ

We have successfully integrated cutting-edge technology into our hinterland connectivity strategy.

  • Our Virochannagar MMLP is the first terminal in the Adani portfolio to initiate a zero-touch customer experience programme
  • Our proprietary technology portal allows seamless customer and supplier interactions

We have established a state-of-the-art Strategic Command Centre in Ahmedabad.

  • It acts as a primary information hub for all logistics operations, including real-time tracking and centralised monitoring of cargo from a single location
  • It leverages advanced data analytics to improve turnaround time, increase asset utilisation, monitor SLA adherence, and maintain safety standards
  • It is interlinked with local command centres at our logistic parks, improving visibility of the entire supply chain and leading to improved customer satisfaction

We have launched the Trucking Management Solution (TMS) to further complement the enhancements delivered by our command centre.

  • The platform has been developed in-house, and acts as a transformational marketplace and fulfilment system
  • It seamlessly integrates with customer systems, offering comprehensive trucking solutions, including real-time tracking
  • It is supported by APSEZ’s SLA-based fulfilment assurance and presents a diverse range of fleet and commodity options to customers
  • It is currently in use across group volumes and external clients, and is focussed on trucking operations, but will eventually be extended across the entire value chain

Vizhinjam Port – A shining example of technological innovation

Our Vizhinjam Port is a remarkable example showcasing our continuous innovation in technology. High level of automation makes it one of the most technologically sophisticated global transshipment ports. With best-in-class efficiency, productivity, reduced vessel turnaround times, and remote handling of operations, Vizhinjam Port has set a new benchmark in port operations.

Key Automation Features:

  • 8 semi-automated and remotely-operated rail-mounted quay cranes (RMQCs)
  • 24 fully automated cantilever rail-mounted gantry cranes (CRMGs) in the yard, with operators required only for managing exceptions
  • Quayside processes, including capturing containers and internal transfer vehicle (ITV) details, automated with optical character recognition (OCR) powered cameras
  • Terminal gates automated with AI-powered OCRs and passive RFIDs
  • ITVs equipped with real-time location systems (RTLS), machine learning technology (MLT), and passive RFID systems

Key Automation Benefits:

  • Reduction in manual handling and improvement in overall port operations
  • Greater ability to handle increased cargo throughput with enhanced safety and reliability
  • Way paved for drawing transshipment cargo from traditional hubs like Singapore and the Middle East, significantly enhancing India’s position within the global supply chain

Recognising the need for technology-leading innovation to achieve end-to-end supply chain efficiency, we will continue to prioritise investments in technology as we transform into an integrated transport utility company, offering unmatched waterfront to last-mile connectivity solutions.

APSEZ Digital Transformation Operational Roadmap (2023-2028)

FY 2023-24NextGen Foundation

NextGen - TOS (Navis)

  • Process standardisation
  • Establishing capability (10 MTeUs per terminal)

PCS Foundation

  • Paperless & Cashless port entry
  • Axle-based billing
  • Customer enablement of Marine module
FY 2024-25Scaling Digitalisation

NextGen - TOS (Navis)

  • Digital expansion
  • Crane operation digitalisation
  • Gate operation automation
  • Data lake

PCS Scaling

  • Elevating customer experience
  • Efficient information exchange
  • Onboarding all ports
FY 2025-26Transformation

NextGen-TOS (Navis)

  • Transformation of planning thru central C&C
  • Data-driven action prompts
  • Optimisation of inventory (Yard) and resources (EITV, RTGS, Manpower) - Expert Decking

PCS Transformation

  • Enabling smart platform ecosystem
  • Embed data intelligence
  • Enable smart solutions
  • Tailormade solutions for customers

Logistics super app

FY 2026-27Reimagination
  • Digital innovations
  • Digital twin
  • Embed mobility
  • AI/ML driven operation
  • Zero touch ITUP
FY 2027-28Smart Operations
  • Automated operations
  • Auto planning
  • AGV-based operation
  • Connected integrated assets
  • Operate from anywhere

Strategic Command Centre
Digitised Data for Decision-Making

  • Serves as a central information hub
  • Leverages data analytics to standardise processes and workflows, reduce TAT, address pilferage risk, increase asset utilisation, improve response time, ensure SLA adherence and maintain safety standards for overall operations
  • Advanced algorithm performs risk assessment for each trip and generates exception reporting (route deviation, risky point stoppage, device tampering, frequent unwanted stoppage)
  • Key technology enablers include GPS, RFID, QR, automatic number plate reading, biometric, integration with PCS and Government database
APSEZ Strategic Command Centre control roomOperators at the APSEZ command centre console
Applications
Track & TraceTOSRod TMSContainer Management SystemERPSalesforce
Date Storage and Transformation
Users

Using Technology to Drive Customer Satisfaction

At APSEZ, we prioritise customer relationships and satisfaction through sustained investments in cutting-edge technologies. Besides enhancing consumer experience, these investments are designed to integrate a forward-thinking approach into our services. They lend a strong competitive and market leading edge to the company in terms of customer service. They also enable us to reduce operational costs, augmenting productivity and efficiency, while effectively helping us steer our sustainability goals.

FY 2025-26 Update

Technology
Superior Information Access

Our IT system provided the following information – Cargo status report: SMS-based VCN status: Vessel declaration and auto PPA: auto alerts on compliance: vessel closure and NOC: weather reports on SMS

Auto-Steering for RTG

We installed a laser-based feedback system that minimised the zig-zag movement of RTGs. The stack profiling system analysed the height of the stack and prevented collision with RTGs through automatic immobilisation, enhancing safety and equipment efficiency.

Remotely Operated Robotic e-RTG

We employed cranes in our ports, and these could be operated remotely, enhancing our technological capability.

Dredger Technology Modification

When maintenance dredgers became critical, we converted CSD to WID without external fabrication, saving crores of rupees in capital expenditure.

Container Position Detection System

We modified existing e-RTGs to account for 50,000 possibilities of a container in our yard and relayed to the TOS, avoiding delays and errors.

Relevance
Complex Cargo Management

We developed expertise in handling special cargo, ranging from metro rail bogies to helicopters, cranes and wind turbines, among other applications.

Berthing Capacity

We developed a robust capability to address futuristics vessels – especially large – at the design stage, thereby future-proofing our ports.

Neem Oil Urea Coating Facility

We developed a facility to handle 35,00 MT of coated urea per day, capable of filling 11 rakes of 52 wagons each, in line with the national priority for the fertiliser sector.

Anti-Lift Mechanism for Twin 20 ft Container

We introduced a photo sensor in the management of RTGs, equipped to lift two 20 feet containers in one go, enhancing judgement calls and safety.

Innovative and Ground-Breaking Technology
First Floating Ro-Ro Terminal

We launched India’s first Ro-Ro terminal that could be operated 24*7, even with a sea level variation as high as 6 metres.

Scale
Largest Dredging Capability

We developed the largest dredging capacity, by size, in India (equivalent to 80 times the Vatican City ).

Environmental Friendliness
Berthing Aid System

We created a laser sensor system to provide graphical information using customised software (developed at a quarter of the prevailing cost), to provide information (berthing velocity, distance and approach angle) and maintain low berthing velocity (less than 0.1m/s) to avoid collision.

Automatic Hydrocarbon Gas Detectors

We designed a system to detect the number of gaseous hydrocarbons in the ambient air, integrated with the SCADA system to provide real-time information and raise automatic alarms when necessary.

Zero Vessel Waste Dump

We completely (100%) treated and recycled solid and liquid waste generated by incoming vessels.

Customer Value Proposition Model

We have developed a robust customer-centric model rooted in our deep understanding of the evolving customer needs. We use world-class infrastructure, cutting-edge technology, and service excellence to not just meet but exceed customer expectations. This gives us a distinctive leadership edge in the competitive market and aids our growth trajectory.

Diverse Customer Base

Serving wide range of customer categories, such as exporters, importers, shipping lines, refineries, etc.

Value Proposition

Providing extensive portfolio of services, including handling, storage, transportation, and value-added services like customs clearance, warehousing, and container repair

Differentiated,
End-To-End Solutions

Offering efficient end-to-end logistics solutions by capitalising on our vertically integrated business model and strategic coastal locations, enabling faster transit times and lower transportation costs

The model is designed to drive our sustained, long-term growth and give us a strong competitive advantage.

Nurturing Long-Term Customer Relationships

Our efforts to build long-term relationships with our customers are steered by our commitment to deliver reliable, efficient and cost-effective logistics solutions. We use advanced technologies, such as APMS, SAP, Data Lake and Realtime dashboards, and web-based mobile applications, to provide real-time visibility into the cargo value chain, and help in precise tracking of port-based vessels and cargo. Our ‘smart port’ initiative boosts service delivery via IoT devices and data analytics, ensuring seamless customer experience and convenience.

Customer Satisfaction Surveys

We conduct surveys to get customer feedback and strengthen our customer service proposition. Our goal is to achieve a customer satisfaction score of 4.5/5 by 2026.

APSEZ conducts an annual Customer Satisfaction Survey to understand customer needs, evaluate service performance, and identify improvement opportunities. The survey is hosted on a web-based platform and includes a comprehensive set of questions covering service quality, customer experience, and sustainability aspects such as environment, health & safety, and governance. All responses are recorded on a 1–5 rating scale for objective assessment.

Under the updated survey methodology, the recent survey was carried out across multiple business verticals. This enhanced approach focusses on evaluating ESG compliance, tracking alignment with sustainability goals, and highlighting areas requiring attention. Insights from the survey support continuous improvement, strengthen customer engagement, and reinforce APSEZ’s commitment to responsible and sustainable business practices.

Survey Topics and Key Findings

The following questionnaire was sent to customers as part of the survey.

Customer’s ESG Credentials and Alignment to APSEZ’s Sustainability Goal
  • Customer’s policy on quality control, health & safety, and respect for human rights at the workplace includes due diligence, risk identification, and management
  • Carbon emissions, water use, other environmental indicators, and the corresponding targets
  • Certification on environment, safety, and annual ESG parameter reporting
Infrastructure, Operations, and Allied Services
  • Availability of various dredging equipment
  • Condition of the dredging equipment, environmental consciousness, delivering time and accuracy
  • IT and Hydrographic survey capabilities
Performance and Practices
  • OHS (Occupational Health and Safety) Practices, risk management and evaluation, community engagement. Minimum age and wages of workers, suppliers audit and evaluation of ESG practice
Value Enhancement
  • Environment management system, evaluation of biodiversity-related impacts. Pricing, easiness, environmental and social practices, customer feedback, target for performance improvement etc.
Policy Awareness
  • Whistle-blower policy, Code of conduct, Human Rights guidelines, anti-discrimination, diversity and equal opportunity policy, Supplier code of conduct, Occupational Health and Safety Policy
  • Environmental Policy, Energy and Emission Policy, Water Stewardship Policy, Water Reuse or Recycle Policy, etc.
Other Processes
  • Parameters influencing service usage, suggestions for improvement, and scope of improvement

Customer Satisfaction Survey Results

FY 2022-23 FY 2023-24 FY 2024-25 FY 2025-26
Customers Satisfaction Score 4.3/5 4.5/5 4.3/5 4.5/5
% of Satisfied Customers 86 90 86 90
Coverage (%) 100 100 100 100

Focus on Cybersecurity

To ensure the protection of our systems and data against potential cyber threats during the adoption of advanced technologies and digital processes, we have integrated cybersecurity with digitisation. This helps in protecting the integrity and confidentiality of our critical infrastructure, besides enabling its seamless availability for delivery of secure logistics solutions.

Cybersecurity Governance Framework

Our Cybersecurity Policy (https://www.adaniports.com/investors/corporate-governance) is crafted to help us effectively address and manage the complexities of cyber risks. This ensures the protection of our IT and business operations against cyber threats.

We are continually investing in strengthening our cybersecurity framework and minimising our risk exposure through a structured governance framework, encompassing robust monitoring mechanisms and stringent reviews. This underlines our commitment to maintaining the highest standards of digital security and operational excellence in the face of evolving cyber threats.

Cybersecurity Governance Framework at APSEZ

Board-level Information Technology & Data Security (IT & DS) Committee
  • Comprises Independent Directors – As of March 31, 2026, the Committee was chaired by P.S. Jayakumar and comprises 3 distinguished Independent Directors
  • Responsible for overseeing and protecting the company’s information technology usage, and supervising the implementation of cybersecurity matters at Board level
  • Mandated with reviewing the policies, plans and programmes related to enterprise cybersecurity, privacy and data protection risks associated with the company and its IT infrastructure
  • Details of the committee’s charter are available on our https://www.adaniports.com/-/media/project/ports/investor/board-and-committee-charters/apsezl---it--ds-committee-charter.pdf
Chief Digital Officer (CDO)
  • Reports directly to CEO and is supported by a dedicated team collaborating across the Adani Group, ensuring a unified approach to cybersecurity governance and management
  • Responsible for operational oversight of IT, digitalisation, and cybersecurity
Chief Information Security Officer (CISO)
  • Responsible for ensuring compliance of the Information Security & Privacy Policy

Responsibilities of the Information Technology & Data Security Committee

The Information Technology & Data Security (IT & DS) Committee plays a vital role in overseeing and enhancing our cybersecurity framework. Its responsibilities include:

Reviewing the implementation of cutting-edge IT solutions across the organisation to automate key functions and processes
Ensuring the protection of critical data through regular oversight of IT and cybersecurity teams' actions
Developing forward-looking strategies to manage cyber risk exposure
Conducting annual reviews of the cybersecurity breach response and crisis management plans
Assessing the adequacy of resources for cybersecurity and recommending enhancements
Evaluating cyber risks associated with third-party and outsourced IT services
Annually reviewing the sufficiency of the Group's cyber insurance coverage

Cyber Risk Management Strategy

At APSEZ, we recognise the threat faced to organisational integrity and operational continuity by the various cybersecurity risks in the fast-evolving digital landscape. Our Risk Management Committee plays a vital role in mitigation of these risks through continuous monitoring and review of the company’s risk management strategies. The committee is focussed on identifying, assessing (both qualitatively and quantitatively), analysing, and effectively managing current and anticipated cybersecurity risks.

The cyber risk assessment framework at APSEZ is intricately aligned with the Information Security Management System (ISO 27001) standards, ensuring seamless integration with our broader enterprise risk management initiatives.

Cybersecurity Infrastructure and Processes

To minimise the various cybersecurity risks, we have adopted a comprehensive IT security plan, encompassing business continuity strategies that include redundancy and high availability across various levels. As part of this plan, we have adopted and implemented ISO 27001:2013 – Information Security Management System (ISMS) across all our operational sites, inline with our security policy. We have also set up a 24/7 Cyber Defence Centre, designed to proactively identify and mitigate cybersecurity incidents.

Audit and Compliance

We engage with independent auditing agencies to ensure compliance with cybersecurity standards. The internal and external annual IT General Controls (ITGC) and ISO/IEC 27001:2013 audits are part of this exercise. We are also covered by the various assessments conducted by the Adani Group Management Assurance Team. Besides ensuring our cybersecurity compliance, this provides an insight into our position with respect to cybersecurity.

Incident Management and Response

Our approach to incident management is proactive and comprehensive.

Conduct bi-annual 'Incident Response' testing and maintain a 24/7 Security Operation Centre for incident detection and management, in line with the NIST framework
Adopted a well-defined escalation process, enabling employees and contractors to report any actual / potential cybersecurity breaches via our internal digital platform
Dedicated telephone lines and email IDs for employees to register their concerns or issues. These are equipped with real-time tracking and resolution in accordance with the escalation matrix and defined timeline
APSEZ strengthened its cybersecurity posture by prioritising comprehensive vulnerability assessment and management across all critical IT systems. This included periodic third-party assessments, penetration testing, and simulated cyber attack exercises to proactively identify and remediate security gaps. These activities were supported by a robust High Availability and Disaster Recovery framework to ensure continuity in the event of disruptions. Additionally, a formal grievance reporting mechanism was made available to internal and external stakeholders for flagging suspected vulnerabilities or misuse, enabling swift investigation and corrective action. Together, these measures enhance system reliability and significantly reduce exposure to digital risks.

Consequence Management for Non-Compliance

A robust consequence management protocol is followed by APSEZ for effectively addressing any cases of cybersecurity non-compliance and breaches effectively.

All company devices are equipped with data leak protection agents, and all outbound communications are scrutinised for potential data leaks
The Information Protection Group identifies breaches, which are escalated for immediate management attention
Unresolved incidents are further escalated to senior leadership
The IT Consequence Management Policy, managed by the HR Team, is invoked in cases of non-compliance, and appropriate actions are taken in line with procurement and legal terms for both in-house and consultant-level breaches

We have deployed Endpoint Detection and Response (EDR) solutions to monitor and isolate compromised systems in real time. Based on the lessons learnt, we have integrated tools such as SIEM (Security Information and Event Management) for better threat correlation and analysis.

Business Continuity Plan

The cornerstone of our resilience strategy, our Business Continuity Plan (BCP) is designed to ensure uninterrupted operations in the face of natural disasters, cyber threats, and other disruptions affecting our Port and Special Economic Zone (SEZ) operations. The plan specifically addresses scenarios where critical aspects such as personnel availability, facilities, and technology are compromised, impacting the delivery of essential IT services vital for our business functions and customer service commitments.

The BCP framework:

  • Delineates a clear crisis management organisation structure, detailing the roles, responsibilities and procedures for recovery and resumption
  • Activates when APSEZ management triggers the recovery protocols in response to a disaster or emergency, ensuring continuity, resilience, and a swift return to normal operations

Core Elements of the BCP

Activation – The BCP is activated on the direction of the APSEZ management in the event of a BCP-defined crisis. This comprehensive system:

  • Is designed to facilitate understanding of departmental responsibilities during resumption, recovery, restoration, and return phases
  • Outlines the essential resources and records needed by critical departments for effective business resumption

To ensure the plan's effectiveness and readiness, we conduct semi-annual tests of all procedures and protocols.

Oversight and Cybersecurity Measures – The Chief Information Security Officer (CISO) plays a pivotal role in overseeing the Business Continuity and Disaster Management Plan. The CISO:

  • Focusses on meeting the various technological and cybersecurity requirements
  • Is entrusted with responsibilities that extend to assessment of system upgrades, consultation with technology partners, and engagement with other stakeholders to strengthen the cybersecurity framework

Cybersecurity Awareness and Capability Enhancement – Recognising the importance of cybersecurity in our overall business continuity strategy, APSEZ mandates annual cybersecurity training for all employees.

  • The company emphasises rigorous adherence to all its protocols
  • In FY 2025-26, we successfully trained 3,471 employees, enhancing our cybersecurity awareness and preparedness

Operational Improvements and Systems Implementation

The IT team at APSEZ has deployed a series of systems to further enhance the company’s operational efficiencies.

  • Grievance Management System (GMS)
  • Integrated Transport Utility Platform (ITUP)
  • Ransomware Protected Backup solution (Commvault AirGap)
  • Gate Operating System (GOS)

Each implementation is targeted at streamlining operations, enhancing security, and improving service delivery across the organisation.

Through comprehensive BCP, rigorous cybersecurity initiatives, and continuous operational improvements, APSEZ maintains resilience, upholding the safety and security of its operations, and providing uninterrupted service to its customers, even in the face of unforeseen challenges.

Cybersecurity and Operational Improvement Initiatives

Beyond training, we have implemented several advanced cybersecurity measures at APSEZ. These include:

Cybersecurity/ Operational Initiative Description Purpose/Impact
Privileged Access Management (PAM) Manages and monitors access to privileged accounts Strengthens security by controlling access to critical systems and data
Security Orchestration, Automation and Response (SOAR) Automates security operations to efficiently respond to incidents Enhances incident response times, and minimises manual intervention in threat detection and response
Cloud Security Posture Management (CSPM) Manages risks associated with cloud environments, and automates compliance monitoring Ensures security of cloud environments and their compliance with relevant regulations, minimising the risk of data breaches
Multi-Factor Authentication (MFA) Strengthens the authentication process by requiring multiple forms of verification Augments user account security, reducing the possibility of unauthorised access
Web Application Firewall (WAF) Secures websites from cyber-attacks by filtering and monitoring HTTP traffic Protects the APSEZ website against various web-based threats, ensuring website integrity and user data
Grievance Management System (GMS) Collects grievance-related information from internal and external stakeholders Enables efficient handling and resolution of grievances, enhancing stakeholder satisfaction and operational transparency
Ransomware Protected Back-up Solution Ensures data protection against ransomware threats or attacks Ensures data recovery in the event of a ransomware attack, minimising operational disruption and data loss
Gate Operating Systems (GOS) at Mundra Port Automates gate operations and enables online fee collection Streamlines vehicle entry processes at Mundra Port, boosting efficiency and reducing wait times
SIEM (Security Information & Event Management) SIEM collects, aggregates, and analyses data from various sources within an organization's IT infrastructure. This data includes logs from applications, devices, servers, and users, providing a comprehensive view of the organisation's security posture SIEM ensures threat detection, efficient incident response, and regulatory compliance by centralising and analysing security data, thereby enhancing security posture, operational efficiency, and proactive threat management
EDR (End Point Detection & Response) Continuously monitors end-user devices to detect and respond to cyber threats like ransomware and malware Enhances security by providing real-time threat detection and automated response, improving incident response efficiency and reducing the impact of cyberattacks
DLP (Data Leak Prevention) To prevent unauthorised access, sharing, or exfiltration of sensitive data Protect confidential information, ensuring regulatory compliance and reducing the risk of data breaches
Deep and Darkweb Monitoring Regular web monitoring focusses on the surface web, which includes publicly accessible websites indexed by search engines. In contrast, deep and dark web monitoring targets hidden parts of the internet not indexed by search engines, requiring special access methods Continuous monitoring, Detect illicit activities such as data breaches, stolen credentials, and cyber threats, providing early warnings and actionable insight along with Brand Protection
Proxy, Network Admission Control A proxy server acts as an intermediary between a user's device and the internet.

NAC manages and enforces policies regarding the access of devices and users to a network
Proxy ensures better control over internet usage, improved privacy, and protection against malicious websites whereas NAC ensure that only authorised and compliant devices can access the network
Identity and Access Management Manages Digital Identities and control user access to resources Enhances security by ensuring only authorised users can access sensitive data

These initiatives significantly strengthen our defence against cyber threats by providing real-time threat detection, log analysis, and incident response capabilities. They help in quick identification and mitigation of potential security threats, thereby reducing the risk of data breaches and other cyber incidents.

Protecting Data Privacy

We have prioritised data protection and privacy at APSEZ, not merely as a compliance requirement but as a core value that drives our commitment to excellence and integrity in all our operations. We are committed to upholding the highest standards of data protection and privacy. Our business model is built on a foundation of trust, transparency, and ethical practices, ensuring that all personal and sensitive information is handled with the utmost care and confidentiality.

Data Privacy Governance

Our commitment to safeguarding the privacy and security of the data of our various stakeholders is unwavering. To uphold this commitment, we have formulated a comprehensive Data Privacy Policy, covering all individuals and entities associated with the organisation, including employees, contractors, partners and third-party vendors. The policy will help manage personal and sensitive data responsibly. It will comply with current regulations and will incorporate the best global practices, underscoring our belief that privacy is a fundamental right.

We implement robust measures to protect Personally Identifiable Information (PII), ensuring our processes meet regulatory standards. We also encourage our stakeholders, including customers and business partners, to contact us via email or phone with any questions about their personal data. These initiatives are designed to promote transparency and open communication regarding data collection and use.

We have integrated a detailed privacy policy system into our group-wide risk and compliance management framework. This system ensures the protection of stakeholders' privacy rights, regulatory compliance in data handling practices, and effective risk mitigation strategies. By embedding privacy policies throughout the organisation, we prioritise data security and build trust with our customers and partners.

Note: The organisation currently processes Personally Identifiable Information (PII) predominantly in digital form.

The Head - Cybersecurity is responsible for ensuring compliance of the Privacy Policy at APSEZ.

Strategy for Data Privacy Protection & Risk Mitigation

Given the threat posed by data privacy issues to the company’s integrity and operational continuity, we have aligned our framework for data privacy risk assessment with the Digital Personal Data Protection (DPDP) Act. Our efforts are focussed on ensuring compliance with legal requirements and industry’s best practices as per the Act.

Detection Mechanisms

  • Monitoring Tools: Intrusion Detection Systems (IDS), Data Loss Prevention (DLP) solutions, and Security Information and Event Management (SIEM) platforms are utilised to monitor suspicious activities
  • Access Logs: Access logs are regularly reviewed to identify unauthorised access or anomalies
  • Incident Reporting Channels: Employees are trained to promptly report suspicious activities or potential breaches to the cybersecurity team

Reporting Procedures

  • Internal Reporting: Potential breaches are escalated to the Incident Response Team (IRT) for further investigation and containment
  • Regulatory Reporting: Timely notification to regulatory authorities is ensured for confirmed breaches involving personal data, as mandated by data privacy regulations
  • Stakeholder Notification: Detailed information about the breach and the measures taken is provided to affected individuals and stakeholders, along with guidance on how they can protect themselves

Our Data Privacy Protocols

We have instituted a comprehensive privacy impact assessment (PIA) for various projects at APSEZ. The assessment is designed to evaluate how a project, system or process affects the privacy of individuals whose data is being collected, stored, or processed. It ensures compliance with data protection laws like the GDPR and DPDP Act and helps mitigate potential privacy risks.

At APSEZ, we have established elaborate mechanisms to detect and report data breaches as part of our cybersecurity framework. The framework is also being extended to include privacy considerations. We employ a combination of technical and procedural measures to ensure timely detection and reporting of breaches.

Key steps in conducting a PIA
Identify the need for a PIA Determine if the project involves high-risk data processing activities, such as handling sensitive personal information
Describe the Information Flows Document the process of collection, usage, storage, and sharing of the collected
Identify Privacy Risks Assess potential risks to individuals' privacy, including data breaches or misuse
Consult Stakeholders Engage with stakeholders, including data subjects, to gather their input and concerns
Evaluate Privacy Solutions Identify measures to mitigate identified risks, such as data encryption or access controls
Document the PIA Record the findings and decisions made during the assessment
Review and Update Regularly review and update the PIA to reflect changes in the project or regulatory environment

Data Protection and Information Sharing Practices

We follow elaborate practices designed to ensure the integrity and security of data sharing and protection. These include:

Safe Data Storage

Back-up and secure storage for 5 years for all essential applications, including IPOS Container and IPOS Non-Container systems; Protection and safe retention for 7 years for all financial documents

Controlled Information Sharing

Adani Microsoft SharePoint solution Information used to enable sharing with third parties, when necessary; Approvals needed for this from relevant business and cybersecurity teams, ensuring compliance with strict security protocols

Seeking Consent

Individual’s opt-in consent obtained, where required under relevant Data Protection Laws, before processing activities on customer data / personal information are undertaken

Data Deletion

Identification and secure deletion of data that is no longer needed, ensuring that it cannot be recovered. Deletion process, including details of what was deleted and when, clearly documented

Data Anonymisation

Data identified for anonymisation and for application of techniques like generalisation, suppression, or pseudonymisation, to protect privacy while retaining its analytical value.

Purpose-Specific Data Usage

Restriction on use of personal data of all stakeholders to essential business operations, such as invoice generation and payment processing; Such data includes key identifiers like names, addresses, email, mobile numbers, and financial details; All such data securely blocked in the system after completion of process/service

Regulatory Compliance

Strict regulation of disclosure of customer information to third parties; Linked to legal obligations with government agencies; May include sharing of specific fields, such as customer PAN and GST numbers, for tax filing purposes

Privacy by Design

Privacy-by-design principles being adopted to embed data privacy into IT systems, in line with DPDP Act; To include features like data minimisation, encryption, and role-based access controls

Protection of Personal Information

Emphasis on protection of personal data or information of all the stakeholders, including customers, employees, third-party vendors, partners, suppliers, etc.; DPDP Act 2023 acts as regulation on data privacy and control; Our stakeholder data privacy measures include authorisation, encryption, verification, data back-up and recovery; We adopt the best business practices to protect all private data, including restrictions on data collection and access, regular audits, employee training on privacy practices, and regular reviews of compliance with the data protection laws

As a B2B enterprise, with our primary focus on commercial activities rather than marketing, we don’t necessitate an opt-out option for our customers regarding the handling of their personal information. In the broader context, given that the personal data is predominantly used for commercial purposes, the application of such data for secondary purposes is not relevant.

Compliance

Robust Data Privacy Incident Response Management

A robust Incident Response Plan (IRP) is in place with respect to cybersecurity & data privacy at APSEZ. The plan ensures effective management of data breaches involving personal data and is aligned with the organisation’s overall cybersecurity strategy as well as the requirements of privacy regulations like the DPDP Act.

We are now in the process of establishing dedicated communication channels, such as an email helpdesk and a grievance cell, to enable data principals to seamlessly lodge complaints. These mechanisms will be backed by defined timelines to address concerns efficiently.

APSEZ command centre with operators monitoring a port-terminal visualisation on a large video wall

Training & Awareness

Information Security and Data Privacy training and awareness help employees identify and avoid cyber threats, protect sensitive information reducing the risk of data breaches and cyberattacks. These training fosters a culture of security compliance, ensuring that everyone in the organisation understands their role in protecting sensitive information and maintaining regulatory standards.

Key Topics of these trainings focus on phishing awareness, password best practices, and data protection. Additionally, it covers safe internet practice, social engineering, mobile device security, two-factor authentication, data classification and secure handling, and privacy principles such as consent, minimisation, retention, and accountability. Training should also address access control and least privilege, device and endpoint protection, secure use of networks and cloud services, social engineering and physical security, incident reporting and initial response, backup and recovery, and third-party risk management.

We empower all our employees through concise e-learning modules, instructor-led sessions, role-based tracks, simulated phishing campaigns, tabletop exercises, hands on labs, and microlearning tips to reinforce secure behaviours.

The effectiveness of data privacy and cybersecurity training is measured through several methods:

  1. Pre- and Post-Training Assessments: Comparing knowledge and skills before and after training to gauge improvement
  2. Phishing Simulations: Conducting simulated phishing attacks to see how well employees apply what they've learned
  3. Employee Feedback: Gathering feedback from participants to understand their perception of the training's relevance and effectiveness

Maintaining Confidentiality

We follow a zero-tolerance policy against any violations to the privacy policy. We have embedded the principle of confidentiality of personal information into our code of conduct. Any violation of the privacy policy, or involvement in privacy breaches, by an employee invites strict disciplinary action. We have an excellent track record in terms of customer privacy protection and have not reported any cases of information security breaches, data breaches, or cybersecurity incidents in the past three fiscal years. APSEZ has the distinction of ZERO substantiated incidents related to breach of customer privacy, data theft, leaks, or loss for FY 2025-26. This underlines our strong commitment to data protection and implementation of cybersecurity measures. No fines or penalties levied have been imposed on APSEZ with respect to data security breaches or cybersecurity incidents.