Management System Policies

v1 dated 12/01/2026

Commitment and objectives of the management system

MAGIC S.P.A., through its Top Management, undertakes the following commitments and pursues the related objectives for the Information Security Management System.

Management commitment

The Board of Directors and the CEO actively promote a culture of information security as an integral part of corporate governance. The organization is committed to allocating the human, technological and financial resources necessary to ensure that the ISMS remains effective and aligned with the operating context and the company’s growth strategy in its target markets.

Top Management acknowledges that protecting information assets is a shared responsibility at every level – from the Board of Directors to individual employees – and promotes the active involvement of all personnel, ensuring that security duties are integrated into everyday tasks.

Fundamental principles

The organization bases the ISMS on the following principles:

  • Risk-based approach: protection measures are sized proportionately to the level of risk, determined through structured assessments that combine likelihood and impact and are reviewed at least once a year.
  • Confidentiality: production, commercial and personal information is accessible exclusively on a need-to-know basis; access is granted only to those with a legitimate operational need.
  • Integrity: data is protected against unauthorized alteration throughout its entire life cycle, through appropriate technical and organizational controls.
  • Availability: information systems are maintained at service levels suitable to ensure the operational continuity of production and management processes.
  • Classification and proportionate protection: information is classified according to three levels – Confidential, Restricted, Public – each associated with differentiated protection requirements for processing, transmission and storage.
  • Shared responsibility and defined roles: security duties are formally assigned to each corporate function, consistently with the organization chart and job descriptions.
  • Compliance: the organization is committed to meeting applicable legal, regulatory and contractual requirements, including the protection of personal data and cybersecurity obligations.

Information security objectives

This policy provides the framework for defining specific security objectives, which are established periodically during management review and set according to:

  • maintaining the confidentiality of production and commercial information, preventing unauthorized access and improper disclosure;
  • ensuring the integrity of data across process chains, from research and development to logistics;
  • ensuring the availability of critical information systems at levels compatible with the continuity of services provided to customers in the food, medical and personal care sectors;
  • systematic management of information security risks, with timely treatment of vulnerabilities and emerging threats;
  • development of personnel skills and awareness in information security;
  • continuous improvement of the effectiveness of the ISMS through internal audits, risk assessments, incident analysis and management reviews.

Policy communication

This policy is made available as documented information with a public classification. The Management System Manager activates its distribution within the organization, ensuring that all personnel understand its content and the implications for their role. Policies classified as restricted or confidential are distributed only to the functions directly involved, according to the need-to-know principle.

Externally, the CEO authorizes the policy to be made available to customers, suppliers, certification bodies and other interested parties, upon request or whenever deemed appropriate to maintain trust in business relationships.

Continuous improvement

MAGIC S.P.A. pursues continuous improvement of the ISMS as part of its operational excellence strategy. The effectiveness of security measures is assessed through internal audits, management reviews, incident analysis and monitoring of performance indicators. The results of these assessments feed the cycle for updating the policy and related objectives, so that the system remains appropriate to the evolution of the context, threats and applicable requirements.

POL Information Security Policy

v1 dated 12/01/2026

Information security objectives

Magic S.P.A. pursues security objectives that are consistent with its industrial mission and with the risk context in which it operates, and is committed to reviewing their adequacy during each management review. The objectives promoted by this policy are as follows:

  • Preserve the confidentiality of production, commercial and personal information processed within the company, ensuring that access is granted exclusively on the basis of a proven operational need and prior formal authorization.
  • Ensure the integrity of data throughout its entire life cycle – from generation to storage – by preventing unauthorized alterations and protecting the reliability of the information on which business decisions are based.
  • Maintain the availability of information systems and networks at levels appropriate to production continuity needs, reducing the risk of unplanned interruptions and supporting operational resilience.
  • Manage information security risks through a structured and systematic approach, based on the assessment of the likelihood and impact of threats, so that protection resources are allocated according to the criticality of the assets.
  • Ensure compliance with applicable legal, regulatory and contractual requirements, with particular attention to the protection of personal data and cybersecurity obligations.
  • Develop personnel awareness and competence in information security, so that every employee recognizes their role in protecting company assets and acts accordingly.
  • Pursue continuous improvement of the effectiveness of the ISMS by identifying corrective actions and adjustment plans through internal audits, risk assessments and periodic reviews, and by informing the governing and management bodies of the outcomes of these activities.

Fundamental principles of information security

This policy is based on a set of principles that guide all decisions, controls and operating procedures concerning the protection of Magic S.P.A.’s information assets.

  • Risk-based approach. The organization adopts a structured risk assessment method – based on the combination of likelihood and impact – to identify, analyze and treat threats to information security. Protection measures are selected and sized in proportion to the assessed risk level, prioritizing mitigation, informed acceptance, transfer or elimination of the risk. Assessments are reviewed at least annually and whenever significant changes occur in the organizational context or in the threat landscape.
  • Shared responsibility and defined roles. Information security is a responsibility that spans all levels of the organization, from the Board of Directors to the individual employee. Cybersecurity roles and responsibilities are defined, formalized in the MOD Job Descriptions and in the MOD Organization Chart, communicated to the relevant units and reviewed periodically. Personnel authorized to access relevant information and network systems are identified after assessing their experience, skills and reliability and ensure full compliance with information security regulations; the same requirement applies to system administrators.
  • Reliability of human resources. The organization integrates information security into personnel management practices. Employment contracts include confidentiality clauses and security obligations that continue to apply even after termination or change of the employment relationship. Breaches of security obligations are treated as disciplinary offences under applicable law and the applicable collective bargaining agreement, with sanctions proportionate to the seriousness of the conduct. Personnel adherence to ISMS policies is an explicit requirement of the employment relationship.
  • Classification and proportionate protection. All company information is classified according to its sensitivity and business criticality, based on the three-level framework – Confidential, Restricted and Public – established in the POL Information Classification and Labelling Policy. The protection controls applied to data processing, transmission and storage are differentiated by classification level, ensuring protection proportionate to the value of the asset.
  • Acceptable use of resources. The information, systems and technological resources assigned to personnel remain company property and may be used exclusively for purposes consistent with the recipient’s role and duties. The organization prohibits the use of information resources for activities that could compromise the company’s security, reputation or regulatory compliance. The detailed rules are established in the POL Operational Security Policy.
  • Protection of off-site assets. Company assets used outside operating sites – laptops, mobile devices, storage media – are subject to specific protection measures, such as disk encryption, strong authentication and secure connections. Remote work is permitted in compliance with the security requirements defined in company procedures, which ensure the compliance of devices and access methods.
  • Clear desk and clear screen. The organization promotes the clear desk and clear screen rule as a preventive measure against the accidental disclosure of sensitive information. Confidential documents, removable media and credentials must not be left unattended on desks; every workstation applies automatic screen locking after a period of inactivity.
  • Reporting security events. The organization provides personnel with dedicated channels – e-mail to the IT department and the company ticketing platform – for the timely reporting of observed or suspected security events. Every employee is required to report without delay any anomaly, weakness or potential breach, thereby contributing to early detection and effective incident response.
  • Supply chain security. The organization assesses and monitors security risks associated with suppliers and third parties that access company information or systems, requiring adequate contractual safeguards and verifying compliance with its protection requirements.
  • Business continuity and crisis management. Magic S.P.A. adopts business continuity and disaster recovery plans designed to ensure the availability of critical processes even in adverse events, keeping interruption times within limits consistent with business needs.
  • Continuous improvement. The organization is committed to assessing the effectiveness of the security measures adopted through internal audits, management reviews and incident analysis, defining adjustment plans approved by management bodies and periodically informing the Board of Directors of the outcomes of assessments and progress made.