Cybersecurity is crucial for ensuring business continuity, protecting digital assets, and maintaining the stability and trust of our stakeholders. We have an Information Security Policy that outlines conduct and behavior guidelines for all employees, contractors, consultants, temporary staff, and affiliated personnel.
Canacol’s IT Manager is responsible for the implementation of the IT security and Cybersecurity strategy, who reports directly to the CEO. Furthermore, the Audit Committee is responsible for overseeing IT security and regularly receives security updates, including detailed discussions on key topics.
Since 2022 Canacol has established an information Security management system implementing effective cyber security measures based on ISO 27,001.
Multiple layers of protection spread across the company has let IT team keep the company’s data safe and no major incidents have occurred.
Cyber Security Risk assessment is performed in regular basis to manage the current risks and to identify new ones since attackers rapidly evolve and are becoming more innovative. Accompanied by the technology and the security awareness program Canacol has set the tone cybersecurity culture led by the executive level, in this way, information security/cybersecurity is linked of the annual employee performance evaluation.
Responsible Approach to Artificial Intelligence
At Canacol Energy, we recognize the potential benefits that Artificial Intelligence (AI) may bring to business efficiency and innovation. As AI technologies continue to evolve, the Company is taking a cautious and risk-based approach to their evaluation and future adoption.
Given the early stage of AI adoption within the organization, Canacol has established interim guidelines governing the use of AI technologies to help protect corporate, customer, and employee information while reducing legal, security, and reputational risks.
Our current approach is guided by the following principles:
Information Protection
Corporate, confidential, personal, operational, and financial information must not be processed through unapproved AI tools.
Cybersecurity and Risk Management
Potential AI-related risks, including information leakage, inaccurate outputs, and regulatory exposure, are considered as part of our information security and risk management processes.
Human Oversight
AI-generated outputs must be treated as unverified and may not replace human judgment, review, or accountability.
Responsible Evaluation and Governance
The Company is evaluating future AI opportunities through a structured approach focused on business value, risk assessment, governance, and controlled adoption.
Compliance and Ethical Use
Any future AI adoption will be aligned with applicable laws, information security requirements, privacy obligations, and the Company's Code of Conduct.
Canacol remains committed to evaluating emerging technologies responsibly while protecting the interests of its employees, stakeholders, customers, and shareholders.