We maintain transparency through regular internal and external/third-party audits and assessments.
At Koch, we comply with a wide range of internationally recognized security standards. Proactive, risk-based controls protect the confidentiality, integrity, and availability of our customer and user data. Koch’s security program aligns with the following leading industry standards to support effective risk management, continuous improvement, and regulatory compliance across the enterprise: ISO/IEC 27001:2022 and NIST Cybersecurity Framework (CSF) 2.0. Alignment reflects adherence to industry best practices and principles. Each Koch company may pursue formal certification based on their specific business, customer, or regulatory requirements. Certifications with key regulatory agencies that are specific to their operations are maintained at the sub-company level.
Koch maintains a cyber security framework designed to support cyber security, compliance, and risk management. The basis of our security framework is a standard known as International Standards Organization (ISO) 27001/2: Information Technology Security Techniques, Information Security Management Systems (ISMS); commonly referred to as ISO27001/2. Though the basis of the Framework is ISO27001/2, principles also reflect requirements influenced by the National Institute of Standards and Technology (NIST) Cyber Security Framework (CSF). ISO27001/2 was chosen as the authoritative source due to its widespread applicability across industries and developed countries world-wide, including the United States. Our cyber security framework provides a foundation for managing security and risk across the organization while supporting the operational autonomy of Koch companies. This security framework is reviewed and refined on an ongoing basis to adapt to changes in business operations, technology, and the evolving threat landscape. The framework is built on the following principles:
Koch is committed to protecting its employees, partners, clients, and Koch from damaging acts that are intentional or unintentional. Effective security is a team effort involving the participation and support of every entity that interacts with Koch data and systems, applications, and services. Therefore, it is the responsibility of both Koch personnel and third parties to be aware of and adhere to Koch cyber security requirements. Protecting Koch data and the systems that collect, process, and maintain this data is of critical importance. Commensurate with risk, security and privacy measures must be implemented to guard against unauthorized access to, alteration, disclosure or destruction of data and systems, applications, and services. This also includes protection against accidental loss or destruction. The security of systems, applications and services include controls and safeguards to offset possible threats, as well as controls to ensure confidentiality, integrity, availability, and safety.
Koch's Security Trust Center is a centralized location for key information and resources on Koch's security posture, compliance and security documentation. The Koch Security Trust Center is used by organizations in these distinct ways:
Powered By
Copyright © 2026