Cybersecurity and information management
We believe that a strong security culture complements our cybersecurity objectives by reducing enterprise risk. The Infosys Cybersecurity Program ensures that necessary controls and processes are implemented, monitored, measured, and continuously improved to mitigate cyber risks across domains.
Recognized by top advisory and analyst firms
Our commitment
Protecting the confidentiality, availability and integrity of information assets from internal and external threats
Ensuring and maintaining stakeholders trust and confidence about cybersecurity
SEED
Infosys' cybersecurity framework is built on leading global security standards and frameworks such as the National Institute of Standards Technology (NIST) Cybersecurity framework and ISO 27001, which is structured around the below four key areas:
Governance tier to manage the cybersecurity program for successful orchestration of different domains of the cybersecurity framework
'Defense in depth' approach to secure information and information assets
Set of domains to evolve and transform within the Infosys cybersecurity framework
Capability to identify a cybersecurity event, execute appropriate response actions, and restore impaired services
Objectives of the strong governance framework:
- Proactive business security and employee experience
- Continuous improvement of security posture and compliance
- Effective management of cyber events
- Building a security culture
Our approach
Cybersecurity management
Cybersecurity requires participation from all spheres of the organization. Senior management, information security practitioners, IT professionals, and users have a pivotal role to play in securing the assets of an organization.
There was no material cybersecurity incident reported in fiscal 2026.
Infosys’ own Cybersecurity program is managed by the Information Security Group (ISG), which upholds the organization’s security posture, empowers internal teams with a culture of democratized cybersecurity, and delivers assurance and trust to all customers and stakeholders. Our practices look beyond compliance and include:
- Metrics program – Evaluates compliance, suggests improvements, and drives integration with business processes
- Standardized policies and guidelines aligned with the organization’s culture, business, and operational practices
- Internal audits
- External attestations and audits (e.g. SSAE-18 SOC 1 &SOC 2 Type II, ISO 27001)
- Client account audits
- AI governance reviews aligned with ISO 42001 and the NIST AI Risk Management Framework, addressing the agentic AI risk landscape
- Board-level oversight through periodic cybersecurity reviews
Thought leadership
In this era of rapid technology disruptions and digital transformations, Infosys enables businesses to embrace innovations and adapt to new technologies. We focus on strengthening cyber resiliency through platform-led convergence and consolidation of security capabilities and deliver AI-first service offerings via Infosys Cyber Next Platform.
We promote cybersecurity through:
- Social media messaging
- Tie-ups with analysts (eg. PAC Group) and industry bodies (such as Data Security Council of India and Information Security Forum) to create relevant joint thought leadership
- Participation in public cybersecurity awareness initiatives led by non profits such as NASSCOM and DSCI
- Publishing a tech-centric report that provides insights into emerging technology trends such as agentic AI, post-quantum cryptography, etc. and how they can be applied to businesses
- Sessions with global chapters within Infosys and customer CISO councils
Vulnerability management
The vulnerability management program at Infosys follows best-in-class industry practices coupled with top-notch processes that have been evolving over the years. We have strengthened this domain by the acquisition of The Missing Link, a leading cybersecurity company in Australia that brings expertise in Offensive Security and Global SOC in Sydney strengthening data sovereignty and localization aspects.
- Real-time asset discovery, instantaneous identification of vulnerabilities and misconfigurations, and timely remediation across hybrid, multi-cloud, and SaaS environments
- Automation of processes, configuration compliance, security assessments and review for assets, applications, network devices, data, and identities in real time
- Close coupling of detection and remediation processes, with AI assisted triage through the Cyber Advisory – a GenAI assistant that ingests SOC telemetry, threat intelligence, and SOPs to accelerate incident response, alert prioritization, and threat hunting
- Continuous monitoring of public facing sites and assets, including external attack surface management
- Penetration testing, red teaming exercises, and production application testing for detection and remediation Continuous vulnerability operations with Infosys Cyber Next Harness AI to enable prioritized identification and remediation of novel and chained vulnerabilities. This facilitates enterprise readiness to adopt frontier AI models.
- AI-powered Continuous Threat Exposure Management (CTEM) for identification, prioritization, remediation and risk mitigation of exposures
The vulnerability remediation strategy of Infosys focuses on threat-based prioritization, vulnerability ageing analysis and continuous tracking for timely closure. We have successfully eliminated the ticketing system for vulnerability tracking by establishing a continuous detection and remediation cycle, where the IT teams are enabled and onboarded onto the vulnerability management platform. A cybersecurity awareness culture is nurtured, and teams are encouraged to proactively remediate the vulnerabilities reported on their assets or applications.
Supply chain cyber risk management
A comprehensive supplier security risk management program at Infosys ensures effective management of potential security risks across the various stages of supplier engagement.
The process comprises:
- Categorization of suppliers and sensitivity of data involved
- Defining a standardized set of information security, data privacy, and AI controls as applicable
- Defining, maintaining, and amending relevant security clauses in supplier contracts
- Due diligence and security risk assessment, including fourth-party visibility
- Continuous monitoring through security ratings and threat intelligence feeds, with explicit focus on 'harvest now, decrypt later' exposure across long-lived data and certificates
- Leverage SCA to identify opensource libraries with known vulnerabilities impacting the business applications
Defining and monitoring of key security metrics for suppliers (e.g., background check, security awareness training completion, timely interventions with regard to information security incidents, vulnerability remediation SLAs etc.),threat intel tracking and governance further strengthen the Infosys supplier security risk management program.
Cybersecurity competency development
Cybersecurity team members undergo technical as well as behavioral training on an ongoing basis. Infosys leverages internal training programs, as well as external bodies / agencies with cybersecurity subject matter expertise, and academic collaboration with a strong focus on learning through the classroom as well as on-the-job training.
- 2,429 professionals were trained and 3,884 were certified across various cybersecurity domains
- Over 4,600 cybersecurity professionals were trained in AI specific trainings including AI Aware, AI Builder, AI for Leadership, Sentinel Copilot, and Simbian
- Cyber Aspire program for early-career talent
- NIIT's Cybersecurity Master's program
- Specialized tracks on zero trust, cloud security, OT/IoT security, agentic AI security, and post-quantum cryptography (PQC) aligned with NIST PQC standards
- Joint enablement with strategic partners (eg. Palo Alto Networks, Microsoft Purview, Zscaler, CrowdStrike, Sailpoint, etc.) covering the Cyber Next platform ecosystem
- Mandatory Information security and privacy awareness training for all employees
Cybersecurity culture
At Infosys, driving a positive and sustainable cybersecurity culture is one of the key constituents of our robust cybersecurity strategy.
The Information Security Council and the Board endorses this culture, and a wide set of measures are in place to nurture it:
- Secure by Design principles adopted at organizational level through trainings and awareness-building campaigns
- Awareness campaigns delivered through diverse channels – Posters, cyber comics, employee handbook, caselets, cybersecurity scorecard, newsletter, advisories, emailers, push messages, annual mandatory awareness quiz, gamification, SME Cyber Talks, information security courses on the internal training platform, sessions, videos, podcasts, fireside chats, blogs, panel discussions, focused social engineering awareness, thought leadership messages, role-based awareness tracks for developers, administrators, leaders, and high-risk functions, with continuous simulated phishing and vishing exercises
- Annual flagship event – Cybersecurity Week
- Video-based, animated and interactive e-learning certification program
Innovation for clients
- Cyber AI: Helps customers amplify their defender potential, build effective cyber defenses, and enable accurate decision-making through platform-centric GenAI capabilities
- Cyber Next Platform Powered Services: Helps customers stay ahead of threat actors and proactively protect against security risks, integrated with leading solutions from our strategic partners
- Zero Trust Security architecture and solutions: Navigate customers through Zero Trust adoption across identity, data, device, application, infrastructure, and governance, backed by maturity assessments, reference architectures, and managed services. Key innovations and offerings include Secure Access Service Edge (SASE) powered by Zscaler.
- Secure Cloud transformation with Cobalt assets drives accelerated cloud adoption.
- AI/Agentic-AI security: Governance, lifecycle controls, and runtime protection for LLM and agentic systems - aligned with ISO 42001 and the NIST AI RMF
- Cyber Next Harness AI: Leverages our partnership with Anthropic to deliver AI-powered security solutions for detection, contextual correlation, triage, and prioritization of vulnerabilities