Cybersecurity and Data Protection

As cyber threats become increasingly sophisticated and widespread, Daher continuously strengthens the security of its information systems to protect its operations, data and stakeholders. Cybersecurity is a strategic priority for the Group, which relies on dedicated governance, recognized standards and a continuous improvement approach to ensure its cyber resilience.
Daher’s Information Security Policy is built around three fundamental principles: confidentiality, integrity and availability of data. To meet the growing requirements of its markets and strengthen the trust of customers and partners, the Group relies on several recognized frameworks:
- ISO 27001, the international standard for information security management, obtained in 2025 for IT services in France.
- AirCyber, the cybersecurity framework dedicated to the aerospace industry, for which Daher achieved the Silver level in 2025.
- Cyber Essentials in the United Kingdom and CMMC in the United States, supporting the specific requirements of defense activities and international markets.
This approach is supported by an ambitious awareness and training program designed to make every employee an active contributor to data protection and digital security.

Actions
Strengthening Cyber Governance
Cybersecurity is a strategic priority for Daher. A dedicated team of 12 cybersecurity experts based in France and the United States oversees the Group’s information security framework. Roadmaps, action plans and performance indicators are regularly reviewed by the Executive Committee and the Board of Directors to ensure a high level of digital resilience.
Deploying Recognized Standards
To strengthen the protection of its information systems, Daher continues to deploy internationally recognized cybersecurity standards and certifications. In 2025, the Group obtained ISO 27001 certification for its IT operations in France and achieved the AirCyber Silver label, following the Bronze level obtained in 2023. Daher is also certified Cyber Essentials in the United Kingdom and continues to strengthen its cybersecurity maturity in the United States through the CMMC framework for the defense sector.
Raising Awareness and Training Employees
Cybersecurity relies on the commitment of every employee. Since 2023, mandatory cybersecurity training has been deployed for all employees with access to IT resources. In 2025, 80% of eligible employees completed this training. Daher also launched a dedicated data protection and information classification training program (CODA), completed by 5,778 employees, as well as a cybersecurity serious gaming module for managers. The Group aims to train 95% of the relevant employee population by 2026.
Testing and Strengthening Digital Resilience
To prepare its teams for cyber threats, Daher regularly conducts crisis management exercises. In 2025, the Group participated in the national REMPAR25 exercise, enabling it to test its incident response capabilities, improve coordination among stakeholders and validate the effectiveness of its procedures under real-life conditions. During the year, two information security incidents were recorded, with no significant impact on the Group’s systems or data.
Our Ambition
Daher aims to ensure the cyber resilience of its information systems and to strengthen cybersecurity awareness across the Group on a lasting basis. In 2025, 80% of eligible employees completed mandatory cybersecurity training, while 5,778 employees received data protection training through the CODA program. The Group’s objective is to reach 95% training coverage of the relevant employee population by 2026.




