Trevian Asset Management Oy – Information Security Policy
Trevian Asset Management Oy is one of Finland’s leading investment and asset management companies specializing in commercial real estate. In our operations, we comply with applicable legislation, regulatory requirements, and industry best practices. Information security is an essential part of our responsibility framework.
In the course of our business, we process important and sensitive information belonging to our clients, and our personnel handle such data in their daily work. Our clients place their trust in us when it comes to the processing of their information, and we aim to be worthy of that trust. Ensuring information security is therefore one of the fundamental pillars of our operations.
The double materiality assessment conducted in autumn 2025 confirmed that our stakeholders (tenants, owners, financiers) expect high-quality, transparent, and securely shared data from us. This policy defines the principles by which we ensure an adequate level of information security and data protection, lawful processing of personal data, risk management, incident handling, responsible operations, and the delivery of high-quality services.
1. Objectives of Information Security
The objective of information security is to ensure:
– the confidentiality, integrity, and availability of information and information systems,
– lawful processing of personal data,
– business continuity and resilience,
– controlled adoption of new technologies and operating models, and
– risk-based and proactive development of information security.
2. Organization and Responsibilities
Overall responsibility for information security lies with the Chief Executive Officer of Trevian Asset Management Oy.
The CEO ensures that the organization has sufficient capabilities and resources to implement and develop information security.
Compliance Team:
– maintains principles and guidelines related to information security, data protection, and risk management,
– monitors compliance with these principles and guidelines,
– coordinates the handling of incidents,
– supports the business in information security–related matters, and
– ensures that instructions and policies remain up to date.
Each employee and Business Partner:
– complies with this policy and issued instructions,
– appropriately protects the information they process,
– reports any observed incidents without delay, and
– observes confidentiality regarding information handled in their work.
3. Information Security Controls
We implement and develop information security through administrative, technical, and physical measures. Our approach is risk-based.
a. Business Continuity and Preparedness
– We maintain business continuity and preparedness plans,
– regularly test backups and recovery capabilities, and
– define clear availability requirements for critical services.
b. Supply Chain Security
– We assess the information security practices of external service providers,
– include clear information security obligations in contracts, and
– monitor the implementation of suppliers’ information security measures.
c. Device, Identity, and Access Management
– We define information security requirements for devices and systems,
– apply the principle of least privilege in access rights, and
– ensure that access rights are based on job responsibilities and are removed in a timely manner.
d. Encryption and Data Protection
– We use appropriate encryption methods to protect information, and
– safeguard personal data and confidential information throughout all processing stages.
e. Monitoring and Log Management
– We collect and retain log data for areas required by risk management,
– monitor system security and potential incidents, and
– use automated alerting methods where appropriate.
f. Personnel Competence and Awareness
– We regularly train personnel on information security and data protection,
– strengthen awareness through guidelines and internal communications, and
– require everyone to take an active role in maintaining information security
4. Information Security Incident Management
We have defined clear procedures for reporting, handling, and reporting information security incidents and suspected misuse.
Incidents:
– are handled without delay,
– are documented and analyzed, and
– lead to necessary corrective and preventive actions.
The Compliance Team coordinates incident management and ensures, where necessary, that statutory notification obligations to authorities are fulfilled.
5. Review and Approval
The Information Security Policy is reviewed regularly and updated when:
– legislation or regulatory requirements change,
– significant changes occur in the organization’s operations or technical environment, or
– risk management activities, audits, or incidents indicate a need for updates.
The Compliance Team is responsible for updating this policy.
Approved by the Board of Directors of Trevian Asset Management Oy on 23 February 2026