OVHcloud Information System Security Policy
Learn how OVHcloud structures its Information System Security Policy (ISSP), from cybersecurity governance and risk management to data protection and datacentre security.
Purpose of this document
At OVHcloud, we use a detailed global management system for cybersecurity. This document explains how that system is structured and how it works. It includes the following:
-
A summary of OVHcloud’s operating environment. This helps identify the main cybersecurity risks, key concerns, and challenges.
-
Our security commitments to stakeholders. It also describes the main principles we follow to protect and manage our information systems.
-
The structure we use to connect strategy, daily operations, and future improvements. This ensures our approach to cybersecurity is both consistent and effective.
This document shall be referred to as the "Information System Security Policy". It is reviewed and updated on a yearly basis and in case of events with major impact. It supersedes a broad set of security policies and implementation guides, which are managed through individual lifecycles.
This text is intentionally written in plain English to make it easier to understand for non-experts.
Context of the cybersecurity governance
As a major alternative in a well-established market, OVHcloud faces a complex challenge. Our customers expect our cloud services to meet industry standards. At the same time, they want to benefit from our unique competitive strengths. In cybersecurity, we work to find the right balance. We aim to follow industry standards while also applying risk mitigation strategies that fit our specific business model.
OVHcloud operates in a fast-changing environment. Threats, technology, and customer expectations are always evolving. We must therefore remain flexible and able to adapt quickly.
What is information security?
Security means protecting our information systems and services from potential threats. The goal is to ensure the confidentiality, integrity, and availability of our customers' data and cloud services.
As a cloud service provider, OVHcloud must always ensure that systems remain available and data stays protected. This is a core responsibility shared by every OVHcloud employee.
Cybersecurity governance focuses mainly on risks that come from malicious actions. It also ensures strong coordination with all teams involved in delivering services. This coordination helps create a complete and consistent approach to managing risks.
OVHcloud’s security approach also includes clear rules for data protection and traceability. This is especially important when it comes to privacy. These commitments are formally included in our security policies.
The Information System Security Policy (ISSP) covers the following five security criteria:
-
Availability (A)
-
Integrity (I)
-
Confidentiality (C)
-
Traceability (T)
-
Privacy (P)
These criteria help define the security requirements for protected assets. They are also used to assess the impact of a security risk or incident.
What assets do we protect?
Infrastructure, platforms, applications
OVHcloud operates a global, high-quality infrastructure. This includes multiple datacentres, hardware, and servers. These components are connected by a high-performance network. The network allows for secure and reliable communication between services, as well as with public or private networks.
This infrastructure is essential to our business. It supports all OVHcloud products and services.
Our information system is also managed by OVHcloud. It includes customer-facing services, internal operations, automation tools, and collaboration platforms. It also includes the tools and interfaces that customers use to manage their services and communicate with OVHcloud teams.
Our service portfolio is broad. It includes Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS), and telecommunications services. These services are built on our strong infrastructure and information systems. They are also supported by additional services provided either by OVHcloud or by our partners.
This integrated setup allows us to offer a consistent and scalable range of services. It helps us meet the changing needs of our customers.
Information
OVHcloud treats client data as the most sensitive and critical type of information. This data is hosted as part of the services we provide. In this case, the client is the data controller and is responsible for how the data is used. OVHcloud acts as a subprocessor.
As a subprocessor, OVHcloud works under the client’s instructions. We follow the terms set out in the service contract and respect the client’s policies and guidelines.
OVHcloud also protects its own internal data. This data is needed to support our operations. For this type of data, OVHcloud is the data controller.
Internal data includes technical and administrative information. It is used to deliver services, manage business relationships, and meet legal requirements.
Who are the cybersecurity stakeholders?
Customers and partners
OVHcloud plays a key role in running and managing the infrastructure, platforms, and software that support digital operations.
These services are critical for the information systems and business activities of our clients. Many of our clients also provide services to other parties, creating a complex and constantly changing environment.
As a trusted cloud provider, OVHcloud is expected to show strong technical knowledge and control over how our services are delivered.
We must ensure that our services meet high standards for reliability, security, and performance. These standards are required by both our customers and their own end users.
Industry specific authorities and regulators
Regulatory authorities create rules to protect citizens and businesses in their regions. These rules include requirements for securing data and controlling how it is processed.
OVHcloud follows these rules in every region where we operate. We make sure our services match the specific needs and conditions of each local environment.
In addition, some regulators set extra rules for certain industries. These rules apply to specific types of data and processing activities that carry higher risks.
To meet these needs, OVHcloud offers services designed to comply with industry-specific rules. We are committed to meeting these standards and addressing the related risks.
Employees, management of OVHcloud and shareholders
OVHcloud employees are responsible for designing, maintaining, and operating the systems and processes that support our services.
Any security incident can cause direct harm to our operations. It can also reduce the value of our services and damage the reputation and professionalism of our teams.
On the other hand, running secure information systems strengthens OVHcloud’s ability to innovate. It also supports a culture of teamwork and dedication, which leads to better service quality.
OVHcloud operates in a highly competitive market. To succeed, we must grow rapidly to support innovation and expand internationally. At the same time, we must continue building our credibility.
Customer trust is the main factor behind this growth. That trust depends on our ability to protect their data and workloads.
Because of this, cybersecurity is a key part of OVHcloud’s growth strategy. It is fully supported by our management and shareholders.
By making cybersecurity a priority, we can protect customer trust and loyalty. This is essential for reaching our business goals and keeping our place as a leading cloud provider.
Subcontractors and outsourcing
OVHcloud works with subcontractors to manage different processes and projects. These subcontractors may have access to OVHcloud’s information systems and physical locations.
In addition, OVHcloud uses external applications and systems that are integrated into its main infrastructure. These outsourced systems support key parts of OVHcloud’s operations. They are an important part of the company’s overall security setup.
OVHcloud extends its security measures to cover these subcontractors and outsourced systems. Since they are essential to our operations, it is important that they follow the same security standards and rules.
Risks and opportunities related to cybersecurity
Risk management / Compliance
Effective risk management requires a formal method to choose the best security measures for each situation. When done properly, this method can be effective. However, it also comes with challenges.
One security measure can reduce several risks at the same time. Likewise, each risk often requires multiple measures to be fully addressed.
Using a detailed, structured assessment for every security decision can be inefficient. It may also create unnecessary complexity.
For many situations, a simpler approach is more practical. OVHcloud often uses a compliance-based method, following a set of security rules built on 25 years of experience in cloud services. It is also informed by international standards, industry regulations, and customer expectations. The security team carefully oversees this process.
To strengthen this foundation, our cybersecurity risk management process includes three main goals:
-
Identifying and managing top cyber risks This helps explain our risk mitigation strategies to stakeholders. It also tracks changes in risk levels across the company and within specific product lines. This approach gives a clear overview of our key concerns and shows that our priorities and actions are appropriate.
-
Supporting operational activities through risk-based assessments The security team provides tools, methods, and metrics to help business teams make better decisions. These resources help teams set priorities, resolve day-to-day issues, and explain any differences from established standards. This makes security decisions more consistent, relevant, and accountable.
-
Guiding complex decisions with in-depth analysis When facing more difficult decisions, we use a structured process to identify, assess, and reduce security risks. This improves the fairness, depth, transparency, and consistency of decisions made for specific projects or business situations.
Risk context
As a major infrastructure operator
As a leading cloud provider, OVHcloud is a high-profile company. We operate a large-scale, global infrastructure and serve millions of direct and indirect customers.
Because of this visibility, our systems are exposed to a wide range of risks. These risks often come from advanced threat actors, including:
-
nation-state sponsored groups
-
intelligence agencies
-
organised cybercriminal groups
-
activist groups
-
their related supply chains
These threat actors have several key goals:
-
Causing widespread disruption that affects OVHcloud and all of its customers
-
Undermining cloud infrastructure that supports a particular economic or political region
-
Attacking customers from specific sectors or geographic areas
-
Gaining long-term access for further malicious actions, such as supply chain attacks or data theft
-
Testing their tools and techniques against strong, modern systems that use advanced technologies
As a cloud services provider
As a cloud provider hosting millions of systems and services, OVHcloud is exposed to many types of attacks. These attacks often target our customers and are driven by a variety of motivations.
Because our customer base is highly diverse, it is difficult to clearly identify the exact types of attackers or their goals. Instead, we classify threats based on how the attacks are carried out. This helps us adjust our security approach.
We group the main attack paths into three categories:
-
Direct attacks on customer cloud assets. These occur through public network exposure.
-
Use of legitimate customer access. In this case, attackers try to bypass isolation mechanisms and reach systems belonging to other customers.
-
Targeting OVHcloud's shared infrastructure. This includes systems like customer management interfaces or internal tools. The goal is often to move laterally and indirectly access customer systems.
Attacks can start from several sources. These include external networks, a compromised customer system, or a system that has been subscribed to OVHcloud or one of our partners.
As a company
Like any organisation, OVHcloud faces many types of cyber threats. These include data breaches, misuse of resources, ransomware, phishing, and other forms of malicious activity.
Such attacks can harm the security of our systems and data. They can also disrupt our operations or be used as part of more complex attacks against our customers or infrastructure.
Most of the threats OVHcloud faces come from outside the company. However, the size and fast growth of our international teams also create risks from within. These include human errors and insider threats. For this reason, our risk management approach must address insider threats. This is in addition to managing external threats and normal operational risks.
Major operational risks
Although our security risk mitigation strategy mainly follows industry best practices, certain risks are given special attention in our security management process. These include:
-
Compromise of an employee's workstation with high-level system access
-
Vulnerability exploitation on product control planes or shared infrastructure assets
-
Leakage of authentication credentials, such as passwords, tokens, or private keys
-
Use of supplier access to leverage an attack (supply chain attack)
-
Exploitation of known vulnerabilities on systems exposed to the Internet
-
Malicious actions carried out using valid user credentials (insider threat)
-
Physical access to data through compromised datacentre operations
-
Exploitation of unknown vulnerabilities (zero-day) in production systems
-
Denial of Service (DoS) attacks at infrastructure level
-
Denial of Service (DoS) attacks at applicative level on administration interface
-
System isolation failure leading to illegitimate access to customer data
-
Exploitation of a weakness in network or applicative access controls
-
Employee or supplier abuse by social engineering attack
-
Late detection of security events because of faulty security controls
-
A service or application is out of control and not managed according to policies, leading to data exposure
-
Abuse of concentrated roles to bypass security rules
-
Human error or misconfiguration leading to unintended data exposure
-
Breach of physical security or access control in our datacentres
Material impacts related to cybersecurity
Negative impacts (risks)
Cybersecurity events and incidents can lead to several negative consequences for OVHcloud. These include:
-
Loss of customer trust in OVHcloud services
-
Financial responsibility for any business impacts experienced by customers
-
Failure to meet contractual obligations
-
Legal or regulatory consequences resulting from a security breach
-
Harm to OVHcloud's reputation as a reliable and trusted provider
-
Increased operational costs needed to handle the incident and restore normal service
-
Indirect financial effects, such as reduced revenue, higher insurance costs, and lower market value
Positive impacts (opportunities)
Implementing a consistent security approach that is fully aligned with OVHcloud’s strategy, daily operations, and product development brings several benefits:
-
Reduction in the number of security incidents
-
Ability to meet strict customer security requirements and prove compliance
-
Increased value of the products and services offered to customers
-
Stronger customer trust in OVHcloud’s service portfolio
-
Lower operational impact of security incidents due to faster detection and better response processes
-
Positive financial effects, such as lower costs for handling incidents, higher revenue, and stronger customer loyalty
OVHcloud Security Commitments to build trustable cloud services
Consistent foundations managed with an industrial approach
Our approach is based on standardised building blocks, secure architectures, and formal, proven, and highly automated processes. The goal is to make security a driver of efficiency and consistency within the Information System.
To support this, we have developed tools, processes, and production-ready components that all teams can use to apply security best practices.
Security is not the only benefit of this structured approach, but it is essential. It enables "security by design" and helps maintain consistent security over time. By integrating security from the start, we avoid treating it as an afterthought.
Formal security checks are performed in project and change management. These checks ensure that security principles are respected from the design phase through the entire lifecycle of each system or application.
Every team is responsible for the security of the systems they manage. We work continuously to balance two goals:
-
Enforcing OVHcloud’s common security rules
-
Giving system owners the freedom to apply their technical expertise
This balance is essential to our security approach. We work closely with business teams to make sure security principles are consistently applied across the company.
Support every type of customers in their growth in the cloud
OVHcloud’s products are built using open-source technologies and established technology standards. This makes it easier for customers to adopt and manage their systems in the cloud.
Security is a key part of our product development process. The security team is involved in every decision that may affect security. This ensures that security is considered from the beginning.
Our approach to product security is based on risk. We take into account:
-
The scale and speed of deployment
-
The security culture of our customers
-
The specific use cases and technologies for each product
This allows us to adapt our security measures to meet the needs of different customer groups.
Applying best practices for configuration and managing the full security lifecycle is essential. It adds value for our customers and is a major reason why they choose to move to the cloud. This responsibility is fully integrated into the product lifecycle.
Even though the security posture may differ by product, we manage all security events, incidents, vulnerabilities, threats, and security-related information in a unified and consistent way.
Support every customer to manage their own specific risks
OVHcloud offers its solutions to a wide range of customers across many industries. These include:
-
Startups
-
Small and medium-sized enterprises (SMEs)
-
Large companies
-
Government agencies
-
Multinational corporations
Each customer has a different approach to security. This is based on their business needs and operational context, and OVHcloud takes this into account.
In cloud computing, security is a shared responsibility. OVHcloud and its customers each have defined roles. Customers are ultimately responsible for the security of their information systems in the cloud. To avoid risks caused by confusion, we clearly explain what each party is responsible for.
To help customers secure their systems, OVHcloud provides:
-
A set of tools and features to improve security
-
Standard security features available to all customers
-
Optional features for managing specific risks
Customers also have the freedom to add their own security tools and solutions. Our platform is designed to support this flexibility.
We offer a wide range of built-in security services. These are available through our solutions catalogue and are supported by technologies and services from our partners. Our products also support third-party and community solutions. This allows customers to build their own security strategies and adapt them to their specific needs.
Cybersecurity governance
OVHcloud's leadership is committed to cybersecurity for the long term. This is shown through the creation of clear rules for managing risks. It also includes assigning responsibilities, providing the necessary resources, and monitoring performance.
The Chief Information Security Officer (CISO) defines and implements cybersecurity governance. This work is overseen by the Chief Information Officer (CIO), who acts as the executive sponsor on this topic within the Executive Committee. This governance is reviewed and updated every year to align with OVHcloud’s strategic objectives and its company-wide risk management.
Ownership of systems is a key principle in defining security responsibilities at OVHcloud. Each team is responsible for the security of the systems they build and manage based on three core principles:
-
Team accountability
-
Industrialisation
-
In-depth technical expertise
The security team maintains strong relationships with all system-operating teams. This helps ensure a consistent approach to security across OVHcloud.
This governance applies to all companies in the OVHcloud group. It also includes employees, suppliers, service providers, subcontractors, and users of the information system.
OVHcloud's services are built on a cybersecurity framework that is designed to:
-
Balance long-term strategy with efficient day-to-day operations
-
Keep our security efforts focused
-
Ensure we respond effectively to new threats and vulnerabilities
The OVHcloud security team operates a unified and comprehensive set of security controls within its Information System Management System, internally known as OneISMS. The OneISMS program is structured around three main layers, all managed by the security team:
-
Requirements management layer This layer consolidates and organises all security requirements from various sources. It standardises them into a consistent framework and defines clear applicability criteria.
-
Implementation layer This layer provides a formal approach to managing and operating security controls. It ensures alignment between controls and security objectives, manages control documentation and operational follow-up, and coordinates risk management within a unified framework.
-
Security assessment layer This layer handles both internal and external control mechanisms. It focuses on verifying the achievement of security objectives and assessing the effectiveness of resources allocated to security. It also covers third-party audits, whether for certification purposes or at the request of customers.
Together, these layers ensure that OVHcloud maintains a consistent, effective, and transparent security posture across its information systems.
Key performance indicators:
-
Ratio of products covered in OneISMS
-
Number of man-days spent on security assessments
Relations with external security experts
Our security team and technical experts maintain strong working relationships with external security communities, public authorities, software publishers, and hardware manufacturers. These collaborations help us stay informed about emerging threats and vulnerabilities, and allow us to take early action to reduce the associated risks.
We actively contribute to the security community by sharing our knowledge and innovations. We also support responsible disclosure practices to encourage open and ethical handling of security findings.
To further strengthen our security posture, we operate a public bug bounty program. This program allows external security researchers to report vulnerabilities, helping us continuously improve the security of our systems.
Key performance indicators:
- Bug bounty rewards paid out
Compliance program
OVHcloud’s commitment to its customers and partners is defined through a formal contractual relationship. This contract clearly outlines our obligations.
We provide a detailed and easy-to-understand matrix of security roles and responsibilities. This ensures that all parties understand their respective duties.
OVHcloud complies with all applicable laws and regulations in every country where we operate. We also follow industry-specific regulations, such as those for healthcare and financial information systems.
Our security management system is based on international standards, including ISO/IEC 27001. This standard highlights the importance of security principles.
We regularly evaluate our security features through:
-
Independent third-party audits
-
Recognised audit benchmarks
-
Compliance reports and certificates shared with customers when relevant
The OVHcloud security team runs a structured program that includes:
-
Internal and external reviews
-
Security controls
-
Regular audits
This program helps us test our security posture and ensures that we continue to meet our commitments.
We compare our practices to widely used security compliance frameworks. A dedicated team is responsible for driving continuous improvement. This team works closely with system owners to:
-
Apply improvements
-
Increase the overall security level
-
Reduce risk
-
Stay aligned with our security commitments
Beyond our legal and contractual obligations, OVHcloud actively engages with its ecosystem. This includes customers, partners, and prospects.
We prioritise clarity and transparency in all communications. Our goal is to build open and honest relationships with our stakeholders. We provide accurate and timely information about our security practices, so that stakeholders can fully understand our security posture and make informed decisions.
Key performance indicators:
- Number of man-days spent on security assessments
Security by design
We design and build our production systems using the following principles:
-
Production-grade requirements Each system is designed to support high traffic and to scale quickly.
-
Secure interfaces and gateways Systems are designed to be exposed to external threats. Limiting exposure is treated as an additional security layer.
-
Robust and proven technologies We use both open-source and proprietary technologies that meet strict standards for performance and resilience.
-
Deterministic behaviour Systems are configured for consistent and secure operation. We build strong expertise through gradual adoption, detailed testing, and high levels of automation. This includes using an "as-code" model and managing each system through its full lifecycle.
-
Internally developed software Custom software is developed using strict processes to meet specific needs, such as high performance or advanced security controls.
Data protection
OVHcloud applies a strict rule: customer data is never used for business purposes.
Employees do not know the nature of the data hosted by customers and are not allowed to access it. However, during technical operations on systems that store customer data, employees may technically be in a position to access this data. Such access is strictly forbidden. OVHcloud has implemented strong security controls to detect any unauthorised access, ensure traceability of actions, and guarantee that this rule is respected at all times.
In addition to customer data, OVHcloud manages internal data, which may relate to customers, employees, service providers, or partners. When legally permitted, this data may be shared with third parties. OVHcloud acts as the data controller for this internal data and applies appropriate security measures based on the type of data, its sensitivity, and the phase of its lifecycle—whether it is being stored, used, transmitted, or deleted.
Key performance indicators:
- Number of violations reported to authorities
People
Teamwork, segregation of duties, individual accountability, and progressive trust are key principles in OVHcloud's security model. Our teams are collectively responsible for managing thousands of customer environments. Everyone’s active involvement is necessary to maintain end-to-end security across all services.
All OVHcloud employees follow a formal cybersecurity awareness and training program. This process begins even before hiring, through background checks adapted to the responsibilities of the role. These checks help identify potential risks, such as the possibility of malicious behaviour or exposure to external pressures.
On their first day, new employees receive cybersecurity onboarding. This introduction explains the importance of cybersecurity in our service delivery and emphasises how individual responsibility is applied throughout the organisation. This initial awareness is reinforced through regular internal communication, sharing operational feedback and current cybersecurity concerns to keep all staff alert and engaged. For sensitive positions, additional training is provided on a regular basis.
We also test our teams’ ability to recognise and respond to cybersecurity risks. Regular exercises and incident response simulations are conducted to ensure that employees are well prepared to handle real security events quickly and effectively.
Key performance indicators:
-
Number of employees trained in cybersecurity
-
Phishing test results
-
Respect of offboarding procedures
Work environment
Most operational activities at OVHcloud are carried out using centralised services such as ticketing, documentation, system design, automation, code management, software building, and service operations. Employees use their workstations to access these services.
Maintaining a high level of control over workstations is essential to prevent them from becoming an entry point for attacks. At the same time, OVHcloud employees often need access to a wide range of tools, low-level system interactions, and broad connectivity to open networks. These capabilities are important for experimentation, development, and troubleshooting.
Balancing these operational needs with strict security requirements is a continuous challenge.
To address this, we implement:
-
Strict access control to internal networks, systems, and applications. Access is based on business roles and managed through secure gateways or bastions to ensure traceability
-
Monitoring of internal networks, access to external resources, communication tools, and internal applications to detect unusual or unauthorised activity
-
Strict control over workstation configuration, including system hardening, automated configuration management, removal of local administrator rights, centralised monitoring with EDR and malware protection, and incident investigation tools
-
Dedicated workstations with custom configurations for sensitive roles and critical environments
-
Strict control of application access through mobile devices
Key performance indicators:
-
Number of security alerts related to misbehaviours
-
Number of technical misbehaviours
Identity and access management
OVHcloud's internal Identity and Access Management (IAM) system is designed to manage the entire lifecycle of user identities, from creation to termination.
Access requests follow a structured process, including formal review and approval steps. Access is granted only to authorised individuals, based on business needs. We support both individual and service accounts, and maintain a strict separation between standard user accounts and administrative accounts to reduce the risk of unauthorised access.
Authentication credentials are managed throughout their lifecycle—creation, updates, and deletion. We use various authentication methods, including passwords, digital certificates, physical tokens, and biometric authentication. We also support Single Sign-On (SSO) to simplify user access and use bastion hosts to secure administrative actions.
To ensure individual accountability, we conduct regular access reviews and monitor account usage to verify that access rights are aligned with internal policies and procedures. Our Role-Based Access Control (RBAC) system defines access levels based on the user's role, and we maintain a wide range of roles to suit different operational contexts.
Access to network services is protected by secure authentication mechanisms. We strongly recommend the use of multifactor authentication to add an additional layer of security. Our password policies enforce complexity requirements, and all passwords are stored securely using encryption.
We also monitor the status of credentials belonging to former users to ensure that no unauthorised access remains after termination. Overall, our IAM system follows the principle of least privilege, granting access only to users who genuinely need it.
Key performance indicators:
-
Accuracy of access rights
-
Ratio of applications using SSO
Secure continuous delivery
At OVHcloud, our development teams include over a thousand developers working across multiple technology stacks. This diversity makes it difficult to apply a single, uniform development process.
To address this, we have defined a set of development archetypes. These serve as foundational models for different types of projects. We also centralise all source code in a shared repository to ensure consistent access and enable effective collaboration across teams.
Our development toolchain supports a wide range of technologies and workflows. It includes a continuous delivery system that automates building and testing. Developers also have access to dedicated environments and labs for testing and validation. Code signing is used to guarantee the authenticity and integrity of software.
To support secure and efficient development, we provide low-level primitives such as logging, secret management, and container execution. Our APIs are designed to be RESTful and secure, and are protected by reverse proxies that act as secure gateways.
Access to systems and data is managed through internally developed Identity and Access Management tools. These tools provide a high level of access control and auditability. We also use dependency management tools to ensure that external components are up to date and free of known vulnerabilities.
By offering a flexible and scalable framework, OVHcloud is able to meet the diverse needs of its development teams while maintaining a strong security posture.
Secure state management
Hardening is a key part of OVHcloud’s security posture. It involves systematically removing unnecessary features, configuring systems with secure settings, and applying the latest security patches to reduce vulnerabilities.
Cryptographic configuration management is also essential. OVHcloud follows industry best practices for secure encryption, using recommended algorithms and protocols to protect the confidentiality and integrity of data.
System and application configurations are tightly controlled. Any changes are carefully tracked and managed. Inventory control is strictly enforced. All IT assets—including hardware, software, and data—are registered and monitored to maintain visibility and control.
Exposure management is another important component of our approach. OVHcloud regularly identifies and addresses security risks through:
-
Vulnerability assessments
-
Remediation activities
-
Continuous improvement of system configurations
These combined efforts ensure that our infrastructure remains secure, well-managed, and aligned with industry standards.
Key performance indicators:
- CMDB coverage
Monitoring, detection and incident response
We operate a continuous threat analysis framework that is directly connected to our monitoring systems. This allows us to adjust our operational practices in real time to address current risks and respond quickly and effectively to security incidents.
Our security team structure enables the rapid mobilisation of experts when needed. This ensures that incidents are investigated and resolved efficiently, with corrective actions implemented quickly and in a sustainable way to reduce future risk.
Operational monitoring and event logging are the responsibility of each system owner. In addition, our Security Information and Event Management (SIEM) system provides real-time monitoring, event correlation, and threat detection capabilities. We collect and analyse relevant log data, along with external threat intelligence, to identify potential security risks.
Our incident management process includes clear definitions of incident types, severity levels, and response procedures. An established escalation process ensures that incidents are handled by the appropriate teams at each stage.
We have a dedicated Computer Emergency Response Team (CERT) trained to manage security incidents. The incident response process covers full incident analysis, containment, eradication, and recovery. A post-incident review is conducted to capture lessons learned and improve future response efforts.
We also maintain a clear communication plan to ensure that stakeholders are informed and updated during security incidents. Regular drills and simulations are conducted to test and strengthen our incident response capabilities.
Key performance indicators:
-
Coverage of SIEM
-
Number of incidents with impact on customer data
-
Number of incidents with impact on financial statements
Datacentre security
OVHcloud datacentres are designed and operated as industrial-grade facilities. Each site is planned based on a risk analysis that considers geographical, technical, and societal factors. These factors influence the way each datacentre is managed and operated.
All operations within datacentres follow formal procedures to minimise human error and ensure traceability and accountability. Any change is handled through a structured and centrally coordinated process, which helps anticipate risks and assess potential impacts.
Routine operations are also subject to strict, formal procedures. These procedures are supported by datacentre management tools and automated data collection systems connected to the infrastructure. This ensures operational consistency and reduces risks, especially during handling of media containing customer data.
Access to OVHcloud datacentres is restricted and based on individual identification and a strict business need. Access control is defined by a zoning model, in which each zone has specific access rules based on its criticality and business function.
To support this access policy, OVHcloud relies on:
-
Advanced video surveillance systems
-
Dedicated datacentre information systems
-
Centralised coordination and monitoring of security and operational activities
These systems help ensure that local operations are secure and aligned with OVHcloud’s global security and monitoring framework.
Key performance indicators:
-
Number of datacentres audited within the last 12 months
-
Number of datacentres not audited within the last 36 months