XML 458 R45.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Cyber security is crucial to the Group’s business operations, as the Group relies on information and digital technology (IDT) systems and networks to conduct core activities, such as manufacturing, distribution, marketing, customer service, R&D and financial and management reporting, amongst other core activities.
The Board acknowledges that cyber security threats present significant risks to the Group’s business, reputation, financial condition and competitive position, and to the security and privacy of our consumers, employees and other stakeholders. This is particularly relevant as the Group transforms its business and introduces new technologies, such as loyalty programmes, connected technologies and other interactive platforms, which may alter its risk profile and are likely to increase the Group’s exposure to such threats.
The Group implements processes to identify, assess and manage material cyber security risks. These processes are integrated into the Group’s overall risk management systems and processes, overseen by the Board and implemented by management. The Group implements various processes to manage and mitigate the material risks from cyber security threats, including:
implementing appropriate technical and organisational security measures, such as defensive technologies, encryption, authentication, and backup and recovery systems, to protect the confidentiality, integrity and availability of IDT systems and networks, and the data stored on or transmitted through them;
providing regular training and awareness programmes to Group company employees and contractors on cyber security best practices and procedures, adherence to our SoBC (including cyber security and information security requirements) and other relevant standards;
maintaining vendor management processes for key vendors, including conducting due diligence and incorporating contractual obligations, intended to ensure that third-party service providers with access to Group IDT systems and networks, or that process or store Group data, adhere to our cyber security requirements and standards;
developing, maintaining and testing thorough incident response and business continuity procedures designed to enable the Group to promptly detect, contain, analyse, report and recover from any potential or actual incidents and minimise their impact on our operations and stakeholders;
engaging external assessors, consultants and other third parties as appropriate, to support cyber security risk assessment, identification and management processes and to provide independent assurance and recommendations; and
engaging with relevant internal and external stakeholders, such as regulators, law enforcement authorities, customers and other industry stakeholders, on cyber security matters and being prepared to disclose any material cyber security risks or incidents in a timely and transparent manner.
Our SoBC and Supplier Code of Conduct (discussed on page 116) both include requirements for cyber security risk management.
The Group regularly reviews and updates its cyber security risk processes to support alignment with business objectives, regulatory requirements and industry standards. In view of the continued transformation of the Group’s business and evolution of the Group’s product portfolio, the Group is enhancing its digital risk management programme, including by revising its cyber security controls and incident response plan, augmenting its cyber security team, increasing engagement across the business and extending coverage to a broadening range of solutions and technologies to improve the identification, management, monitoring and reporting of cyber risks. Feedback and learnings from audits, assessments and incident reports are reviewed and used on a regular basis to enhance the Group’s cyber resilience programme and awareness.
Cyber security risk management is integrated into, and follows, the Group’s risk identification process (see page 198). Cyber security risks are integrated into the Group risk register and assessed by defined impact and likelihood categories (set out on page 198).

For additional information on cyber security threats and how these could materially affect our business strategy, results of operations or financial condition, refer to the Group Principal Risk 'Cyber Security' on page 162 and Group risk factor 'Disruption to the Group's data and information technology systems' on page 416
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
The Group implements processes to identify, assess and manage material cyber security risks. These processes are integrated into the Group’s overall risk management systems and processes, overseen by the Board and implemented by management. The Group implements various processes to manage and mitigate the material risks from cyber security threats, including:
implementing appropriate technical and organisational security measures, such as defensive technologies, encryption, authentication, and backup and recovery systems, to protect the confidentiality, integrity and availability of IDT systems and networks, and the data stored on or transmitted through them;
providing regular training and awareness programmes to Group company employees and contractors on cyber security best practices and procedures, adherence to our SoBC (including cyber security and information security requirements) and other relevant standards;
maintaining vendor management processes for key vendors, including conducting due diligence and incorporating contractual obligations, intended to ensure that third-party service providers with access to Group IDT systems and networks, or that process or store Group data, adhere to our cyber security requirements and standards;
developing, maintaining and testing thorough incident response and business continuity procedures designed to enable the Group to promptly detect, contain, analyse, report and recover from any potential or actual incidents and minimise their impact on our operations and stakeholders;
engaging external assessors, consultants and other third parties as appropriate, to support cyber security risk assessment, identification and management processes and to provide independent assurance and recommendations; and
engaging with relevant internal and external stakeholders, such as regulators, law enforcement authorities, customers and other industry stakeholders, on cyber security matters and being prepared to disclose any material cyber security risks or incidents in a timely and transparent manner.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
The Board is responsible for the Group's strategy, including oversight of the Group’s IDT and cyber security strategy, and for reviewing the effectiveness of its risk management and internal control systems. On an annual basis, the Board reviews the Group risk register, which incorporates cyber security risks (discussed on pages 162, 198 to 199 and 416). Through the Audit Committee’s terms of reference, the Board has delegated certain responsibilities to the Audit Committee, including the review of the Group's risk management and internal control framework to ensure there is due process for risk identification and management, monitoring the effectiveness of material controls, reviewing the Group risk register and emerging risks, and monitoring procedures and controls for safeguarding assets including cyber security controls.
The Audit Committee reviews the Group risk register twice annually and is briefed periodically on the cyber risk landscape and Group cyber resilience by the Group Chief Information Security Officer (CISO) (reporting to the Director, Digital & Information). In 2024, all Directors were briefed at an Audit Committee meeting on the cyber risk landscape and the Group’s cyber security resilience programme by the Director, Digital & Information and the Group CISO. The Audit Committee receives reports from the Corporate Audit Committee, which monitors the effectiveness of risk management and internal controls across the Group’s functions and oversees the Group’s cyber security risk management framework. The Corporate Audit Committee receives half-yearly reports from the Group CISO on current and emerging cyber security threats to the Group, measures taken to prevent, detect and respond to those threats and efficacy of cyber security controls and incident response plans.
The Group maintains a dedicated cyber security team, led by the Group CISO, responsible for developing and implementing the Group’s cyber security strategy, standards and procedures, including to address any material incident that might arise. The Group's cyber security team has appropriate professional expertise, knowledge and experience in the field, including to identify, assess and manage cyber security risks,
maintain appropriate security monitoring, incident response and business continuity procedures, and to implement those should an incident arise. Senior cyber security team members, including the Group CISO, all have prior relevant industry experience. The Group CISO has over 20 years of information security experience, previously serving as CISO for GSK’s Pharmaceutical, Supply Chain, and R&D divisions before joining the Group. Relevant industry certifications are also held within the cyber security team, for example, Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Controls (CRISC), Certified Incident Handler, Certified Forensic Analyst and Certified Information Systems Security Professional. The team leverages professional memberships from ISACA and SANS Institute for continuous professional development.
The Group's cyber security team actively monitors and evaluates the evolving cyber security threat landscape. It assesses the security posture of the Group’s IDT landscape using various tools, including vulnerability scans, penetration tests and control assessments. Specialists are engaged on an annual basis to assess the Group’s cyber security programme and identify and prioritise cyber security risks and vulnerabilities. Key findings from these assessments and incident summaries are reported periodically to the Director, Digital & Information and to the Audit Committee, accompanied by recommendations for mitigating or addressing any identified risks. Any significant cyber security incidents would be reported as soon as reasonably practicable to the Audit Committee and the Board in accordance with the Group’s incident response procedures.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Board is responsible for the Group's strategy, including oversight of the Group’s IDT and cyber security strategy, and for reviewing the effectiveness of its risk management and internal control systems. On an annual basis, the Board reviews the Group risk register, which incorporates cyber security risks (discussed on pages 162, 198 to 199 and 416). Through the Audit Committee’s terms of reference, the Board has delegated certain responsibilities to the Audit Committee, including the review of the Group's risk management and internal control framework to ensure there is due process for risk identification and management, monitoring the effectiveness of material controls, reviewing the Group risk register and emerging risks, and monitoring procedures and controls for safeguarding assets including cyber security controls.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee receives reports from the Corporate Audit Committee, which monitors the effectiveness of risk management and internal controls across the Group’s functions and oversees the Group’s cyber security risk management framework. The Corporate Audit Committee receives half-yearly reports from the Group CISO on current and emerging cyber security threats to the Group, measures taken to prevent, detect and respond to those threats and efficacy of cyber security controls and incident response plans.
Cybersecurity Risk Role of Management [Text Block]
The Group maintains a dedicated cyber security team, led by the Group CISO, responsible for developing and implementing the Group’s cyber security strategy, standards and procedures, including to address any material incident that might arise. The Group's cyber security team has appropriate professional expertise, knowledge and experience in the field, including to identify, assess and manage cyber security risks,
maintain appropriate security monitoring, incident response and business continuity procedures, and to implement those should an incident arise. Senior cyber security team members, including the Group CISO, all have prior relevant industry experience. The Group CISO has over 20 years of information security experience, previously serving as CISO for GSK’s Pharmaceutical, Supply Chain, and R&D divisions before joining the Group. Relevant industry certifications are also held within the cyber security team, for example, Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Controls (CRISC), Certified Incident Handler, Certified Forensic Analyst and Certified Information Systems Security Professional. The team leverages professional memberships from ISACA and SANS Institute for continuous professional development.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The Group maintains a dedicated cyber security team, led by the Group CISO, responsible for developing and implementing the Group’s cyber security strategy, standards and procedures, including to address any material incident that might arise.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The Group's cyber security team has appropriate professional expertise, knowledge and experience in the field, including to identify, assess and manage cyber security risks, maintain appropriate security monitoring, incident response and business continuity procedures, and to implement those should an incident arise.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
The Group maintains a dedicated cyber security team, led by the Group CISO, responsible for developing and implementing the Group’s cyber security strategy, standards and procedures, including to address any material incident that might arise. The Group's cyber security team has appropriate professional expertise, knowledge and experience in the field, including to identify, assess and manage cyber security risks,
maintain appropriate security monitoring, incident response and business continuity procedures, and to implement those should an incident arise. Senior cyber security team members, including the Group CISO, all have prior relevant industry experience. The Group CISO has over 20 years of information security experience, previously serving as CISO for GSK’s Pharmaceutical, Supply Chain, and R&D divisions before joining the Group. Relevant industry certifications are also held within the cyber security team, for example, Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Controls (CRISC), Certified Incident Handler, Certified Forensic Analyst and Certified Information Systems Security Professional. The team leverages professional memberships from ISACA and SANS Institute for continuous professional development.
The Group's cyber security team actively monitors and evaluates the evolving cyber security threat landscape. It assesses the security posture of the Group’s IDT landscape using various tools, including vulnerability scans, penetration tests and control assessments. Specialists are engaged on an annual basis to assess the Group’s cyber security programme and identify and prioritise cyber security risks and vulnerabilities. Key findings from these assessments and incident summaries are reported periodically to the Director, Digital & Information and to the Audit Committee, accompanied by recommendations for mitigating or addressing any identified risks. Any significant cyber security incidents would be reported as soon as reasonably practicable to the Audit Committee and the Board in accordance with the Group’s incident response procedures.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true