Corporate Security
Corporate security is vital to protect our assets, including its data, intellectual property, and personnel, from various threats such as cyberattacks, data breaches, and physical intrusions.
HR Security
Coherent employees undergo an extensive third-party background check before formal employment offers. In particular, employment, education, and criminal checks are performed for potential employees.
Upon hire, all employees must read and acknowledge Coherent’s Corporate Acceptable Use Policy (AUP), Code of Conduct, Non-Disclosure agreement on IP, and Annual Infosec Training, which helps to define employee's security responsibilities in protecting company assets and data.
Security Awareness Program
We consider employees to be our first line of defense, and we ensure that our employees are trained for their roles.
Coherent employees must complete security awareness training as part of their onboarding, and training is made available annually thereafter. In addition to general awareness training, Coherent conducts phishing awareness simulations at least annually, and provides additional role-based training for certain roles.
Vendor Management
We leverage several third-party service providers to support the development, maintenance, and support of our product as well as internal operations.
We maintain a vendor management program to ensure that appropriate security and privacy controls are in place. The program includes inventorying, tracking, and reviewing the security programs of the vendors.
Comprehensive due diligence is performed before finalizing a vendor that covers security, privacy, and compliance with the applicable laws.
Security Operation Center (SOC)
Coherent’s Security Operations Center (SOC) team provides 24x7x365 coverage to respond quickly to critical security and privacy events.
Coherent’s incident management policy and procedures are designed to Identify, investigate, respond to, mitigate, and notify of events related to Coherent’s technology and information assets.
Employees shall use the internal support portal or email soc-coherent@coherent.global to report security incidents.
Our customers and external parties can submit security incidents via the Spark Support Portal or email soc-coherent@coherent.global.
Our security leadership team reviews all security-related incidents, either suspected or proven, and we coordinate with affected customers using the most appropriate means, depending on the nature of the incident.
Last updated
