HBK’s commitment to security extends to our suppliers, vendors, and business partners. We maintain a structured Third-Party Risk Management (TPRM) process designed to evaluate and monitor the security posture of all external entities that process or access HBK data.
Before onboarding, suppliers undergo due diligence assessments covering security controls, data handling, and regulatory compliance. Our Supplier Security Questionnaire evaluates critical parameters such as encryption practices, vulnerability management, access control, and incident response capabilities.
All supplier contracts include mandatory information security, confidentiality, and data protection clauses, reflecting both HBK and Spectris Group’s compliance obligations. High-risk or critical suppliers are subject to periodic reassessments and evidence reviews, ensuring that they continue to meet our evolving standards.
Our policy framework — including the Third-Party Security Policy, Supplier Code of Conduct, and Data Protection Addendum — provides clear expectations for vendors on how information is to be protected throughout the relationship lifecycle.
By maintaining this structured oversight, HBK ensures that its extended ecosystem operates securely, transparently, and in alignment with customer and regulatory expectations.
Security awareness is a fundamental pillar of HBK’s information security culture. We recognize that our people play a critical role in defending against cyber threats, and we invest continuously in equipping them with the knowledge to do so.
All HBK employees and contractors complete mandatory Information Security and Privacy training during onboarding and through annual refreshers.
Specialized role-based training programs are delivered to IT administrators, developers, and other personnel with privileged access or sensitive responsibilities. HBK also runs regular phishing simulation campaigns, micro-learning modules, and interactive workshops designed to improve real-world readiness. Awareness metrics are tracked, reported to leadership, and used to identify areas for improvement.
The awareness program is complemented by clear internal policies — including the Acceptable Use Policy, Data Classification Policy, and Remote Work Security Guidelines — ensuring that every employee understands how to handle data securely, whether on-site, in the field, or working remotely.
Through continuous education and reinforcement, HBK fosters a proactive security culture where employees act as the first line of defence.
At HBK, safeguarding data, systems, and intellectual property is a core part of our mission to deliver precision measurement solutions that customers can trust.
Security is embedded at every layer — from product development and cloud infrastructure to supply chain and employee awareness.
Our security foundation is built on the CIA triad:
We apply a defense-in-depth strategy, combining technical, procedural, and organizational controls that evolve with the threat landscape.
Security at HBK is not a standalone function — it’s an organizational value.
Through this integrated approach, HBK ensures that every employee, system, and partner operates with security at the forefront — upholding the trust and reliability that our customers place in us every day.
HBK’s governance model ensures that information security is managed as a strategic, business-critical function - not merely a technical one.
Oversight for cybersecurity rests with executive leadership, supported by a structured governance framework that spans every region and function of our organization.
The Information Security & Compliance Office, led by designated officers and supported by the IT, Legal, HR, and Product Engineering teams, implements and monitors HBK’s security management system.
Responsibilities are clearly defined and documented through:
Our governance approach is harmonized under the Spectris Control Framework, which aligns with global regulations and standards such as:
This ensures a unified security posture across all Spectris companies, with HBK maintaining localized accountability for its operations.
Executive management reviews the effectiveness of HBK’s controls and risk mitigation on a quarterly basis, while internal audits and assurance activities provide independent validation.
This model enables a continuous cycle of governance, monitoring, and improvement — ensuring that cybersecurity remains a sustained organizational priority.
HBK’s security posture is validated through multiple independent certifications and external assessments, demonstrating our commitment to continuous improvement and transparency.
We have achieved:
Additionally, HBK has completed a comprehensive gap assessment against the ISO/IEC 27001:2022 standard.
The findings of this assessment have been integrated into our global ISMS Implementation Roadmap, supported by executive sponsorship and a cross-functional steering committee.
Certification to ISO/IEC 27001 is currently in progress across key business units.
Beyond formal certifications, HBK undergoes periodic customer security reviews, third-party audits, and internal assurance activities.
These continuous validations reinforce the strength of our controls and reflect our transparent approach to maintaining trust with customers and partners worldwide.
Risk management is deeply integrated into HBK’s business and operational processes.
Our enterprise-wide risk management framework ensures that security risks are systematically identified, evaluated, and addressed based on their likelihood and potential impact.
Risks are documented within a central risk register, which is reviewed periodically by security, compliance, and executive teams.
Controls and mitigations are prioritized according to HBK’s defined risk appetite and are subject to validation through:
We employ a combination of:
These mechanisms maintain visibility across our environment.
Findings from these assessments feed directly into our ISMS continuous improvement plan and inform targeted remediation initiatives.
This proactive approach enables HBK to maintain situational awareness, anticipate emerging threats, and ensure that our defenses evolve in line with technological and regulatory developments.
The integration of risk management into the enterprise governance model ensures that cybersecurity is treated as a core element of HBK’s overall business resilience strategy.
HBK’s Information Security Management System (ISMS) provides the foundation for our security program, integrating policies, controls, and governance across all business units and sites.
Our ISMS is aligned to the ISO/IEC 27001:2022 standard and mapped to the Spectris Control Framework, which incorporates elements from NIS2, GDPR, and Cyber Resilience Act requirements.
We embed security-by-design and privacy-by-design principles into all stages of our operations and product lifecycle — from concept and development to deployment and maintenance.
These practices are governed by a comprehensive Policy Suite covering areas such as:
Together, they form a resilient framework designed to protect data integrity, maintain compliance, and sustain operational resilience.