Information Security
Ensuring cybersecurity in the digital age: the Fund’s role and responsibility
Information security is an integral part of stable operation of the information network, protection of national interests and maintenance of trust on the part of society and partners. With the development of digital technologies, Samruk-Kazyna JSC constantly increases the level of information security to prevent cyber threats, as well as brings information security requirements in line with legislative norms.
The Fund's key strategic objectives in this area are to ensure accessibility, integrity, confidentiality and sustainability.
Creating a culture of safety
As part of strengthening information security in accordance with the requirements of the international standard ISO 27001, work was carried out to analyse and optimise the IT infrastructure.
In addition, an assessment of the level of protection was conducted in accordance with the above‑mentioned standard.
Based on the maturity assessment performed, the information security management system complies with the established maturity level.
The Fund implements best practices, defines processes, policies, procedures, and documents key actions in the field of information security. Responsibility and accountability are defined, process owners are appointed. There is formalised and structured communication of information to the Fund's management.
Physical Infrastructure
In 2025, an assessment of the Fund’s IT infrastructure was conducted, during which potential single points of failure and vulnerabilities were identified.
Detailed documentation on the changes implemented was prepared, and recommendations were developed to ensure a smooth transition to the updated architecture with minimal operational risks. External web resources were optimised using OSINT analysis tools.
As a result of the work performed, the reliability, security and efficiency of the IT infrastructure were significantly enhanced, ensuring its stable operation and compliance with modern requirements.
Training
Training sessions and testing using specialised software are conducted to develop cyber hygiene skills among the Fund's employees.
Shaping effective information security policies
The Fund's Group of Companies implemented the Corporate Information Security Standard regulating the general set of rules for ensuring information security and managing the process of coordination of activities. The Fund implemented the requirements of the "Basic Rules of Information Security" and the relevant rules and regulations.
As part of effective information security management and improvement of ISMS processes, and in order to establish requirements for ensuring information protection and assigning access levels to employees, the development of a set of regulatory and administrative documents was initiated. This set includes risk and threat registers, risk management procedures, internal audit regulations, controls over security measures, and other documents aimed at establishing and further developing the information security management system.
Protecting critical infrastructure
In 2025, a security assessment (penetration testing) of the Fund’s information systems was conducted. The scope of the assessment included testing the security of the internal infrastructure and related information systems, evaluating employees’ resilience to social engineering attacks, as well as external testing of the Fund’s web resources using a “black box” model.
As a result of the testing, a number of medium‑severity vulnerabilities were identified and promptly remediated. No significant compromise scenarios leading to takeover of infrastructure or critical consequences were identified. In addition, no scenarios capable of disrupting the operation of the infrastructure or causing critical impacts were detected.
In the same year, optimisation of the placement of server and network equipment was carried out to enhance performance and improve ease of maintenance.
To ensure the fault tolerance of the Fund’s information systems, geo‑redundancy of critical infrastructure is being implemented.
Furthermore, modern software solutions were implemented for monitoring, data loss prevention, vulnerability scanning and the timely receipt of information on identified vulnerabilities.
Countering cyberattacks
To counter cyberattacks targeting the Fund’s infrastructure, the “CyberShield” project of the Fund Group was implemented based on its subsidiary QazCloud LLP, which provides round‑the‑clock (24/7) monitoring of incidents affecting the systems of the Fund and its portfolio companies.
In accordance with internal regulations and applicable information security standards, regular infrastructure scanning is carried out using specialised licensed software.
To identify cybersecurity risks, a register of risk sources and risk events is compiled, enabling assessment of potential negative impacts on the Fund’s operations. In addition, quarterly risk reports are prepared.
Pursuant to the Corporate Information Security Standard of Samruk‑Kazyna JSC, portfolio companies submit quarterly information on information security incidents. These incidents are analysed and remediated on an ongoing basis by responsible parties. In turn, the Fund performs analysis and oversight of incidents that may potentially pose threats to the confidentiality, integrity and availability of information systems.