SIGNATORY RECORD

NeverHack

Date of signature : 11/09/2024

  • Signatory of the Sustainable IT Charter

Digital Services Companies

IT, telecoms

1000 contributors

GUYANCOURT, France

information@seela.io

https://neverhack.com

Presentation

NEVERHACK est un acteur du conseil et des services en cybersécurité, d’origine française né il y a 41 ans. En 2014, Arthur Bataille, l’actuel PDG du groupe, reprend le cabinet de conseil en cyber créé par ses parents « Silicom » avec pour ambition de développer l’entreprise à l’international. Après plusieurs achats d’entreprises et une première levée de fond en 2021, contribuant à son développement externe, la société nommée alors Pr0ph3cy (née de l’union entre 2 sociétés Silicom et Seela) change de nom en 2023 et lève 100 millions d’euros avec le fonds d’investissement Carlyle et se donne ainsi les moyens de faire davantage d’acquisitions pour devenir le leader mondial de la cybersécurité. Actuellement la société NEVERHACK reste en partie détenue par son patron-fondateur Arthur Bataille et les fonds européen IK Partners & Carlyle. La société emploie plus de 500 collaborateurs en France et 500 à l"étranger est implantée dans plusieurs villes françaises et aussi au Canada, en Belgique, Allemagne, Estonie, Italie, Espagne, Mexique et Singapour.
Alors que ses clients actuels sont surtout des grands groupes, issus du CAC 40, la société s’adresse également aux PME et ETI, devenues des cibles de choix des cyberattaquants.Son offre de valeur est complète avec de l’expertise, de la formation, du cyber entrainement et une solution de cotation de risques cyber.

Planned commitments and actions

  • Raise awareness on Sustainable IT (e.g. information workshop, MOOC, dissemination of good practice guides)
  • Enter a Sustainable IT labelling initiative
  • Organise a Digital Cleanup Day
  • Communicate to its stakeholders on the actions taken
  • Implementing data governance of your organisation and GDPR compliance or by following the principles of the GDPR in compliance with locally applicable data protection rules locally applicable data protection rules for other countries
  • Deployment of a security plan for its digital environments (antivirus, VPN, supplier audits, permanent monitoring)
  • Evaluate the robustness of its infrastructures (regular tests) and prioritise European infrastructures
  • Measure the lifespan of my equipment by type
  • Favour the purchase of sustainable equipment (reparability and durability criteria)
  • Engage with actors in the reuse sector and/or the social and solidarity economy in the management of the end-of-life of my equipment
  • Integrate environmental requirements in my calls for tender and establish a dialogue and measurement elements over the duration of the service with my suppliers
  • Ensuring that its suppliers and service providers comply with their GDPR requirements or follow the principles of the GDPR in compliance with locally applicable data protection rules for other countries, environmental, social and diversity
  • Encourage diversity among my service providers, particularly in relation to disability issues
  • Use start-ups, associations and sustainable innovation projects to meet my needs for products and services, and participate in the structuring and improvement of these sustainable offers and services
  • Measure the energy consumption and impact of my Information System (multi-criteria analysis)
  • Avoid unnecessary energy consumption e.g. by switching off at night, weekends and holidays
  • Favouring low-impact energy sources
  • Plan the archiving and cleaning of data with its teams to reduce their environmental footprint
  • Measure the impact of its digital services (e.g. frequency of use or energy consumption) using a multi-criteria and global approach to the entire service (equipment, servers, networks, etc.)
  • Reduce the environmental impact of its services: weight of images, videos, plugins, by favouring simpler or less energy-consuming solutions
  • Make its digital services accessible to as many people as possible (even in the event of poor connection quality, disability, etc.)
  • Facilitate the proper semantic understanding of its digital services in a clear and educational language
  • Ensure diversity in the recruitment of IS teams (initial and continuing training, diversity of training, origins, disability status)
  • Encourage gender diversity in the digital field at all levels
  • Promote work-life balance by, for example, respecting the right to disconnect and arranging for teleworking measures
  • Making anonymised data available to enable the development of innovative services that can benefit users and citizens
  • Favour the use of local and European tools in order to encourage the consolidation of players who respect the sovereignty of European data
  • Encouraging territorial innovations by testing and deploying social and environmental digital products and services

Actions started

  • Raise awareness on Sustainable IT (e.g. information workshop, MOOC, dissemination of good practice guides)
  • Enter a Sustainable IT labelling initiative
  • Organise a Digital Cleanup Day
  • Communicate to its stakeholders on the actions taken
  • Implementing data governance of your organisation and GDPR compliance or by following the principles of the GDPR in compliance with locally applicable data protection rules locally applicable data protection rules for other countries
  • Deployment of a security plan for its digital environments (antivirus, VPN, supplier audits, permanent monitoring)
  • Evaluate the robustness of its infrastructures (regular tests) and prioritise European infrastructures
  • Manage my fleet with an inventory by category
  • Favour the purchase of sustainable equipment (reparability and durability criteria)
  • Engage with actors in the reuse sector and/or the social and solidarity economy in the management of the end-of-life of my equipment
  • Integrate environmental requirements in my calls for tender and establish a dialogue and measurement elements over the duration of the service with my suppliers
  • Ensuring that its suppliers and service providers comply with their GDPR requirements or follow the principles of the GDPR in compliance with locally applicable data protection rules for other countries, environmental, social and diversity
  • Encourage diversity among my service providers, particularly in relation to disability issues
  • Measure the energy consumption and impact of my Information System (multi-criteria analysis)
  • Avoid unnecessary energy consumption e.g. by switching off at night, weekends and holidays
  • Favouring low-impact energy sources
  • Plan the archiving and cleaning of data with its teams to reduce their environmental footprint
  • Measure the impact of its digital services (e.g. frequency of use or energy consumption) using a multi-criteria and global approach to the entire service (equipment, servers, networks, etc.)
  • Ensure the development of useful and efficient digital services
  • Reduce the environmental impact of its services: weight of images, videos, plugins, by favouring simpler or less energy-consuming solutions
  • Make its digital services accessible to as many people as possible (even in the event of poor connection quality, disability, etc.)
  • Facilitate the proper semantic understanding of its digital services in a clear and educational language
  • Ensure diversity in the recruitment of IS teams (initial and continuing training, diversity of training, origins, disability status)
  • Encourage gender diversity in the digital field at all levels
  • Promote work-life balance by, for example, respecting the right to disconnect and arranging for teleworking measures
  • Favour the use of local and European tools in order to encourage the consolidation of players who respect the sovereignty of European data
  • Develop in open source to enable virtuous emulation of its ecosystem