
Digital Security
Security is at the heart of everything we do. Geomatikk works proactively with cybersecurity, risk management, and preparedness to ensure that the data and systems of our customers, partners, and employees are always protected.
Our Commitment to Security and Compliance
As a key player in managing and protecting critical infrastructure, Geomatikk handles large volumes of data related to cables, utility networks, and other vital societal information.
That is why security is embedded in every part of our operations, from system development to daily processes. We work systematically to safeguard information, systems, and workflows, and we comply with all relevant laws, regulations, and standards for information security.
The NIS2 Directive
The NIS2 Directive is the EU’s framework for strengthening cybersecurity in critical sectors such as energy, water supply, transportation, and digital services. NIS2 sets clear requirements for security, risk management, and incident handling, for both organizations and their suppliers. NIS2 is about continuous control, every day, all year round.

Geomatikk is indirectly affected by NIS2 through our customers, who are directly subject to its requirements. As a responsible supplier, we have conducted risk assessments, established documented management systems, and implemented relevant measures to meet NIS2 expectations. This ensures that we support our customers in their compliance efforts while strengthening our own resilience and security.
This means our customers can be confident that:
- We comply with requirements for security management and risk handling
- We have processes for alerting, logging, and incident response
- We impose the same security requirements on our subcontractors
- We conduct regular audits and improvements of our routines
Certifications and Standards
By being certified according to leading standards, Geomatikk ensures high quality, environmental responsibility, information security, and a safe working environment, for customers, employees, and society.
ISO 9001
ISO 9001 is an international standard for quality management. It helps us establish and maintain effective processes that ensure our services meet customer requirements and expectations. The certification involves continuous improvement, risk management, and clear accountability, all to deliver quality at every stage.
ISO 14001
ISO 14001 provides a framework for identifying and reducing our environmental impact. The standard requires us to map environmental aspects, set improvement goals, and follow up systematically. This enables us to contribute to sustainable development while meeting regulatory requirements and societal expectations.
ISO 45001
ISO 45001 is a global standard for occupational health and safety that our group adheres to – though only some companies are certified. It helps us prevent accidents, reduce risks, and create a safe and inclusive work environment. At Geomatikk, this means actively working on both physical safety and psychosocial well-being, in line with our values and sustainability goals.
ISO/IEC 27001
ISO/IEC 27001 is a leading standard for information security management. It provides the tools to protect sensitive information, identify risks, and establish robust security routines. Certification
demonstrates that we take data security seriously, both for our own systems and for the customer data we manage.
Information Security in Practice
Physical Security
Geomatikk has established robust routines and technical measures to secure both physical premises and digital infrastructure. This is a key part of our work on information security and preparedness.
Access Control
Office spaces and server rooms are secured with access control systems including key cards, codes, and physical barriers. Only authorized personnel have access, and visitors must be escorted in secure zones. Additional technical measures such as screen locks, access restrictions, and encrypted network traffic protect information and systems.
Server Infrastructure
Our server infrastructure is hosted in multiple secure data centers with very high physical security. These centers mirror data and backups between locations and offer robust solutions for power supply, fire protection, and access control. This provides strong protection against both physical and digital threats.
Data in our datacenters is protected with strong encryption in transit and at rest on supported systems, using securely stored and access‑controlled encryption keys. Backups are taken daily and stored encrypted, ensuring data can be restored when needed.
Servers are automatically updated with security patches and regularly scanned for vulnerabilities. Secure protocols such as SFTP are used for data transfers, with IP filtering and options for customized encryption and certificate management.
Contingency plans are in place to ensure operations during power outages, fires, or network failures, including alternative locations and rapid system recovery.
Authentication
From early 2026, logins to IPS and selected systems will be handled through ID-porten (including MinID, BankID, and other secure identity solutions) or via Single Sign-On (SSO) through Microsoft Entra ID. This ensures a high level of security and guarantees that only authorized users can access our services and customer data.
By combining national authentication solutions with modern identity management, we provide simple, secure, and traceable logins, for both internal users and customers.
Penetration Testing
Geomatikk conducts several annual rounds of penetration testing performed by external, independent security firms on all our applications. These experts look for vulnerabilities in our systems and infrastructure to uncover weaknesses not detected by standard quality control.
As part of this process, we also test human security, including simulated phishing and social engineering tests to strengthen employee awareness.
Other Areas We Focus On
Information Security and Privacy
We comply with the EU General Data Protection Regulation (GDPR) and have strict routines for handling personal data and securing digital systems.
Ethics and Social Responsibility
We follow ethical guidelines and actively work for sustainability, diversity, and a responsible supply chain.
Internal Control and Risk Management
We systematically identify, assess, and manage risks, and we continuously work on improvements and learning.
Compliance with Laws and Regulations
We adhere to applicable regulations, including the NIS2 Directive, GDPR, and HSE requirements, with clear routines for audits and documentation.
Training and Competence
All employees receive regular training in security, ethics, and quality to maintain high awareness and competence.
Transparency and Reporting
We are open about how we work and share relevant security information with customers, partners, and authorities.
Monitoring and Incident Handling
Our systems are continuously monitored. We have established contingency plans and clear routines for rapid response to security incidents.