Information Security. Cybersecurity is essential to Ingersoll Rand for protecting network integrity, intellectual property, customer data, and the smooth operation of our locations. It serves as a vital defense against disruptions and data breaches, supporting trust, and competitiveness in the digital age.

Cybersecurity program oversight

Program scope

Our cybersecurity program is overseen by our chief information security officer (CISO) and is designed to protect and preserve the confidentiality, integrity, and availability of our information technology (IT) assets.

Risk monitoring

Risks and controls are monitored by the CISO and chief information officer (CIO), and their evaluation of our overall program drives the nature and scope of our cybersecurity investments.

CISO experience

Our CISO reports directly to the CIO and has 20 years of IT experience, including leadership roles at various companies with enterprise IT infrastructure and cybersecurity.

NIST CSF reporting

The CISO reports directly to the CIO on the effectiveness of the company's cybersecurity program controls aligned to the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF).

Regulatory controls

We have implemented controls based on the NIST CSF and the Sarbanes-Oxley Act of 2002.

Enterprise risk ownership

Our IT organization is led by the CIO, who is responsible for cybersecurity risk management.

Audit committee & board reporting

The Audit Committee is tasked with oversight of our overall ERM, including cybersecurity, and receives recurring cybersecurity updates throughout the year, with at least two full cybersecurity reports to the Board of Directors each year.

Board-level expertise

Directors with experience in cybersecurity and technology play crucial oversight roles for our digital and cybersecurity strategies.

Reducing risks of cyberattacks

All employees, contractors, and partners are required to comply with the Ingersoll Rand IT Acceptable Use and Security Policy, which details our information security requirements.

Monthly awareness training

All employees are required to take monthly security awareness training that includes current security challenges and aligns with the company's risk management objectives.

Bimonthly phishing simulations

This training is updated dynamically based upon employee results of bimonthly phishing simulations.

Risks addressed

This training helps educate our user base on the various cybersecurity risks faced by Ingersoll Rand. These risks include disruptive cyber-attacks, fines and injunctions, unauthorized access to sensitive information, and fraud.

Higher-risk functions

To ensure our cyber training program is robust, we identify functions that exhibit higher potential risk, including operations, engineering, and sales. We then develop and deliver additional focused training to these functions designed to bolster their cybersecurity awareness and reduce cyber risk.

Audit Committee Risk Oversight

The Audit Committee oversees our general risk management strategy, including its technology security program, and guidelines and policies relating to appropriate risk mitigation and strategies; management's plan and execution of appropriate risk mitigation and strategies, which include risk monitoring and controls. We periodically engage external subject matter experts who provide independent qualitative and quantitative assessments of the cybersecurity program maturity and response readiness. We also use processes to oversee and identify material risks from cybersecurity threats associated with our use of third-party technology and systems.

banner

Have a security concern?

Ingersoll Rand takes security seriously, and is committed to promptly addressing vulnerabilities that may compromise our offerings. If you've discovered a security vulnerability in a product or service of any brand in the Ingersoll Rand portfolio, please report it to us.