Information Security Policy

Information Security Policy (not certified translation)

1. APPROVAL AND ENTRY INTO FORCE

This Information Security Policy was approved on 11 February 2026 by the Board of Directors of LEXMOR 2015, S.L. (hereinafter, “MBE Legal”).This Information Security Policy (hereinafter, the Policy) becomes effective as of the date of approval and shall remain in effect until a new Policy replaces it.

2. INTRODUCTION

MBE Legal greatly depends on ICT systems (Information and Communication Technologies) to achieve its objectives. MBE Legal acknowledges that digital transformation has increased the risks affecting information systems that support the provision of services, particularly those related to the public sector, and as a provider to the public sector, it shall appropriately manage these risks.

Risk management aims to protect ICT systems against accidental or intentional events that may compromise the availability, integrity, confidentiality, authenticity, or traceability of information processed by MBE Legal within the services provided to clients in general, and the public sector in particular.

ICT systems shall be protected against rapidly evolving threats that may affect confidentiality, integrity, availability, intended use, and the value of information and services. To defend against these threats, a strategy adaptable to environmental changes is required to ensure continuous service delivery. This includes implementing minimum security measures required under the National Security Framework (ENS), continuously monitoring service levels, tracking vulnerabilities, and preparing effective incident responses.

MBE Legal’s departments shall ensure that ICT security is integrated into every stage of the information system lifecycle —from initial design through to decommissioning— covering development/acquisition decisions and operational activities. Security requirements and budgetary requirements shall be identified and incorporated into planning, requests for proposals, and procurement of ICT projects.

Departments shall be prepared to prevent, detect, respond to, and recover from incidents, in compliance with ENS Article 8.

3. SCOPE

3.1. Subjective Scope

This Policy applies to all MBE Legal personnel and to any third party who, whether on-site or remotely, provides services to or on behalf of MBE Legal, either onsite or remotely.

3.2. Objective Scope

The objective scope of the information security management system under ENS is as follows: “Information systems supporting legal defence services, legal advice, and management of claims and incident reporting”.

4. MINIMUM SECURITY REQUIREMENTS

MBE Legal Security Policy governs the ongoing management of the security process. This Policy has been established in accordance with the principles established in Chapter II of the ENS and Article 21 of Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the EU (NIS 2 Directive), and has been developed taking into account the application of the following minimum security requirements:
a) Security process organization and implementation (Art. 13 ENS)
b) Risk analysis and management (Art. 14 ENS and Art. 21a NIS2)
c) Personnel management and cybersecurity training (Art. 15 ENS and Art. 21g NIS2)
d) Professionalism (Art. 16 ENS and Art. 21j NIS2)
e) Access authorization and control (Art. 17 ENS and Art. 21j NIS2)
f) Facility protection (Art. 18 ENS)
g) Acquisition of security products and contracting of security services (Art. 19 ENS and Art. 21e NIS2)
h) Minimum privilege (Art. 20 ENS)
i) System integrity and updating (Art. 21 ENS)
j) Protection of information at rest and in transit (Art. 22 ENS)
k) Prevention related to interconnected systems (Art. 23 ENS)
l) Activity logging and malware detection (Art. 24 ENS)
m) Security incidents (Art. 25 ENS)
n) Business continuity (Art. 26 ENS and Art. 21c NIS2)
o) Continuous improvement (Art. 27 ENS).
To meet these requirements, MBE Legal applies the security measures of ENS Annex II, considering:
● Assets comprising MBE Legal’s information system.
● The system security category (Art. 40 ENS).
● Risk management decisions.

5. BASIC PRINCIPLES

MBE Legal’s Information Security Policy establishes the following principles:
  • Security as an integral process: security is a process that encompasses all human, material, technical, legal and organisational elements related to information systems.
  • Comprehensive risk-based management: risk analysis and risk treatment are an essential part of the security process and shall be a continuous and constantly updated activity. Risk management will enable the maintenance of a controlled environment, minimising acceptable risks.
  • Prevention, detection, response and recovery: Information system security shall include actions relating to prevention, detection and response.
  • Existence of lines of defence: MBE Legal's information system shall have a protection strategy consisting of multiple layers of security.
  • Continuous monitoring and periodic reassessment: Continuous monitoring will enable the detection of anomalous activities or behaviour and a timely response. Ongoing assessment will enable its evolution to be measured, and security measures will be periodically reassessed and updated, adapting their effectiveness to the evolution of risks and protection systems.

6. INFORMATION SECURITY OBJECTIVES

MBE Legal sets the following objectives in Security:
  • Ensuring information protection.
  • Physical security: MBE Legal locates information systems in secure areas, protected by physical access controls appropriate to their level of criticality.
  • Access control: MBE Legal limits access to information assets by users, processes and other information systems through the implementation of identification, authentication and authorisation mechanisms adapted to the criticality of each asset.
  • Acquisition, development and maintenance of information systems: MBE Legal considers security aspects in all phases of the information systems life cycle.
  • Ensuring the continued provision of services: MBE Legal implements appropriate procedures to ensure the availability of information systems and maintain the continuity of business processes.
  • Data protection: MBE Legal adopts the necessary technical and organisational measures to manage the risks arising from the processing of personal data.
  • Compliance: MBE Legal adopts the necessary technical and organisational measures to comply with current legal regulations on information security.

7. MISSION

The mission of MBE Legal (Moreno, Boj & Equipo Legal) is to provide claims management services (TPA), expert legal advice and robust, strategic defence, protecting its clients' interests with the utmost professional rigour, transparency and a clear focus on results. The firm relies on experience, specialisation and teamwork to offer a consistent, effective service that is aligned with the needs of each case.

For MBE Legal, excellence in the provision of legal services is based on a way of working that combines talent and commitment, fostering relationships of trust and continuity in the monitoring of cases, as a guarantee of quality and security for its clients.

8. COMPLIANCE WITH ARTICLES

To comply with the provisions of Royal Decree 311/2022, of 3 May, regulating the National Security Scheme, MBE Legal has implemented various security measures proportional to the nature of the information and services to be protected, considering the category of the systems affected.
Compliance with the provisions of the ENS is detailed in the document ‘Declaration of Applicability’.

9. POLICY DEVELOPMENT

The Information Security Committee has approved the implementation of an Information Security Management System (ISMS), which shall be established, maintained and continuously improved in accordance with the ENS and applicable security standards. This system will be adapted to and serve as a management tool for the controls of the National Security Scheme. The system will be documented and will enable evidence to be generated of the controls and compliance with the objectives set by the Committee. There will be a document management procedure that will establish guidelines for the structuring of the system's security documentation, its management and access.
The Information Security Committee is responsible for the annual review of this Policy, proposing, where necessary, improvements to it for approval by the Management of MBE Legal.
This Security Policy is mandatory and is structured at the documentary level, in the following hierarchical levels:
  • First level: Information Security Policy.
  • Second level: Security Regulations.
  • Third level: Security Procedures.
The Chief Information Security Officer (CISO) shall review these regulations at least once a year, proposing improvements where necessary.
In addition to this Security Policy, MBE Legal staff and third-party companies shall be familiar with all regulations, procedures, technical instructions, or other documentation that may affect the performance of their duties.

10. SECURITY ORGANIZATION

10.1. Security Roles

• Head of Information (HoI): Ignacio Boj Albarracín
• Head of Services (HoS): Ignacio Boj Albarracín
• Head of Security (CISO/RSF): Ignacio Boj Albarracín
• Head of System (HoSy): Javier Moreno Alemán

10.2. Information Security Committee (ISC)

Members:
  • Chair: Javier Moreno Alemán
    • Head of Services
    • Head of System
    • Head of Security

Optionally, other members of MBE Legal shall join the Committee's work, including specialised working groups, whether internal, external, or mixed.
The Information Security Committee shall hold its meetings at the premises of MBE Legal or remotely every six months, following a call to that effect by the Committee Chair. In any case, the Committee shall hold extraordinary meetings when circumstances so require.

10.3. ENS Responsibilities

The duties and responsibilities of each ENS security role are detailed and established below:
.
Duties of the Head of Information and Services

● Establish and approve the security requirements applicable to the service and information within the framework set out in Annex II of the ENS, following a proposal to the ENS Security Officer and/or Information Security Committee.
● Accept the residual risk levels affecting the Service and Information.

Duties of Head of Security (CISO/ RSF)

● Maintain and verify the appropriate level of security for the information handled and the electronic services provided by the information systems.
● Manage, supervise, and maintain the physical security of MBE Legal's facilities.
● Promote training and awareness in security matters.
● Appoint those responsible for carrying out risk analysis, the statement of applicability, identifying security measures, determining necessary configurations and preparing system documentation.
● Provide advice on determining the category of the system, in collaboration with the Head of System and/or Information Security Committee.
● Participate in the development and implementation of security improvement plans and, where appropriate, continuity plans, proceeding with their validation.
● Manage external or internal reviews of the system.
● Manage certification processes.
● Submit changes and other system requirements to the Security Committee for approval.

Duties of Head of System

● Restrict or suspend access to information or service provision if it becomes aware that these present serious security deficiencies.
● Implement and manage MBE Legal's Information Systems throughout their life cycle, including the implementation of cybersecurity controls, as well as their operation and verification of their correct functioning.
● Define the topology and management of the Information System, establishing the criteria for use and the services available therein.
● Ensure that specific security measures are properly integrated into the overall security framework.
● Collaborate with the Security Manager to investigate and resolve cyber incidents affecting MBE Legal's Information Systems and apply the knowledge gained from the analysis of cyber incidents that have occurred to reduce the likelihood or impact of future incidents.
● Perform the duties of system security administrator:

✔ Manage, configurate and update, where appropriate, of the hardware and software on which the security mechanisms and services are based.
✔ Manage authorisations granted to system users, in particular the privileges granted, including the monitoring of activity carried out on the system and its correspondence with what has been authorised.
✔ Approve changes to the current configuration of the Information System.
✔ Ensure that established security controls are strictly complied with.
✔ Ensure that approved procedures for handling the Information System are applied.
✔ Supervise hardware and software installations, modifications and upgrades to ensure that security is not compromised and that they always comply with the relevant authorisations.
✔ Monitor the security status provided by security event management tools and technical audit mechanisms.
✔ When justified by the complexity of the system, the Head of System shall appoint as many deputy system managers as they deem necessary, who will report directly to them and be responsible within their area for all actions delegated to them. Similarly, they shall also delegate specific functions of their responsibilities to others.
.
Duties of Information Security Committee

The Security Committee shall have the following functions:

● Respond to requests regarding Information Security from the Administration and the various security roles and/or areas, reporting regularly on the status of Information Security.
● Advise on information security matters.
● Resolve conflicts of responsibility that may arise between the different administrative units.
● Promote the continuous improvement of the information security management system. To this end, it shall be responsible to:

✔ Coordinate the efforts of different areas in the field of Information Security to ensure that they are consistent, aligned with the strategy decided upon in this area, and avoid duplication.
✔ Propose plans to improve Information Security, with the corresponding budget allocation, prioritising security measures when resources are limited.
✔ Ensure that information security is considered in all projects from their initial specification to their implementation. It shall ensure the creation and use of horizontal services that reduce duplication and support the uniform operation of all ICT systems.
✔ Monitor the main residual risks assumed by the Administration and recommend possible actions in relation to them.
✔ Monitor the management of security incidents and recommend possible actions to be taken in relation to them.
✔ Develop and regularly review the Information Security Policy for approval by the competent body.
✔ Develop Information Security regulations for approval in coordination with the General Management.
✔ Verify information security procedures and other documentation for approval.
✔ Develop training programmes to educate and raise awareness among staff on Information Security and on the protection of personal data.
✔ Develop and approve training and qualification requirements for administrators, operators and users from an information security perspective.
✔ Promote the performance of periodic ENS and data protection audits to verify compliance with the Administration's information security obligations.

10.4. Designation Procedures

The creation of the Information Security Committee, the appointment of its members and the designation of those responsible identified in this Policy has been carried out by the MBE Legal Department and communicated to the interested parties.
The members of the Committee, as well as the security roles, will be reviewed every three years or when a vacancy arises.

10.5. RACI Matrix

Tasks CEO HoI HoR CISO/RSF ISC
Security Policy A C C R C
Determination of the System category C C A/R C
Risk Analysis I R A/R R
Statement of applicability I R A/R R
IS standards and procedures I A/R R
Security incident responses I I C A/R R
Security of the lifecycle of information services and systems C A/R
A: Accountable (makes the decision, authorises and approves)
R: Responsible (is responsible for carrying out the work)
C: Consulted (consulted before decisions are made)
I: Informed (informed of decisions made)

11. CONFLICT RESOLUTION

The Information Security Committee resolves conflicts between security roles.

12. PERSONAL DATA

MBE Legal will only process personal data when it is appropriate, relevant and not excessive, and when it is related to the scope and purposes for which it was obtained. Similarly, it will adopt the necessary technical and organisational measures to comply with the Data Protection regulations in force in each case, in accordance with the Personal Data Protection Policy approved by the MBE Legal Senior Management.
In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) and its transposition into Spanish law with Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights, the appropriate measures have been adapted, such as the analysis of the legal legitimacy of each piece of data, the data processing carried out, risk analysis, impact assessment if the risk is high, recording of activities and the appointment of the person who will perform the functions of Data Protection Officer.

13. THIRD PARTIES

When providing services to other organisations, or handling information from other organisations, they will be made aware of this Information Security Policy. MBE Legal will define and approve the channels for coordinating information and the procedures for responding to security incidents, as well as any other security-related coordination activities required with such organisations.
When MBE Legal uses third-party services or transfers information to third parties, they will be made aware of this Security Policy and the existing Security Regulations that apply to such services or information.
Such third parties shall be subject to the obligations set out in the aforementioned regulations and shall develop their own operating procedures to comply with them. Specific procedures for communication and incident resolution shall be established. It shall be ensured that third-party personnel are adequately aware of security matters, at least to the same level as that established in this Security Policy.
Similarly, taking into account the obligation to comply with the provisions of the Technical Safety Instructions established in the second additional provision of Royal Decree 311/2022, and in consideration of the Resolution of 13 October 2016, of the Secretary of State for Public Administration, approving the Technical Security Instruction in accordance with the National Security Scheme, which establishes that private sector operators providing services or solutions to public entities, which are required to comply with the National Security Scheme, shall be able to present the corresponding Declaration of Conformity with the National Security Scheme in the case of BASIC category systems, or the Certification of Conformity with the National Security Scheme in the case of MEDIUM or HIGH category systems.
When any aspect of this Security Policy cannot be satisfied by a third party as required in the preceding paragraphs, a report from the ENS Security Officer will be required, specifying the risks involved and how to address them. This report shall be approved by those responsible for the information and services affected before proceeding.

14. CONTINUOUS IMPROVEMENT

Information security management is a process that is subject to constant updating. Accordingly, MBE Legal shall implement a continuous improvement process, which includes:
  • Review of the Information Security Policy.
  • Review of services and information and their categorisation.
  • Annual risk analysis.
  • Conducting internal and external audits.
  • Reviewing security measures.
  • Reviewing and updating rules and procedures..
For MBE Legal, the proper management of information security is an ongoing and collective challenge, necessary for the continuity of the Entity.