XML 190 R14.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
The cybersecurity governance and programme are defined in a charter approved by executive management, which is anchored in a risk-based approach based on industry standards to balance the level of cybersecurity against the risks to Novo Nordisk.

At Novo Nordisk, cybersecurity risk management is an integral part of our enterprise risk management framework defined in our information security framework. The framework aligns with industry best practice covering IT infrastructure, IT systems, and third-party service providers, and includes steps for identifying and assessing the severity of a cybersecurity threat, evaluating the potential business impact, implementing countermeasures and mitigation strategies, and informing executive management of material cybersecurity threats and incidents. Risks are consolidated across business areas and integrated into the enterprise risk management framework, where the likelihood and impact of cybersecurity risk scenarios are evaluated for risk treatment by executive management and reported to the Board of Directors. The cybersecurity risk management programme is validated through peer-benchmarked maturity assessments, external technical assessments of the core infrastructure, key applications and operational processes, as well as group internal audit evaluations of the cross-organisational controls implementation.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] At Novo Nordisk, cybersecurity risk management is an integral part of our enterprise risk management framework defined in our information security framework. The framework aligns with industry best practice covering IT infrastructure, IT systems, and third-party service providers, and includes steps for identifying and assessing the severity of a cybersecurity threat, evaluating the potential business impact, implementing countermeasures and mitigation strategies, and informing executive management of material cybersecurity threats and incidents. Risks are consolidated across business areas and integrated into the enterprise risk management framework, where the likelihood and impact of cybersecurity risk scenarios are evaluated for risk treatment by executive management and reported to the Board of Directors.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
The Board of Directors has overall oversight responsibility for our risk management, and is charged with oversight of our threat landscape, posture, performance, and strategy related to cybersecurity. The Audit Committee is charged with overseeing the cybersecurity incident trends and potentially significant incidents that have been handled. Executive management is responsible for identifying, considering and assessing material cybersecurity risks on an ongoing basis, establishing processes to ensure that such potential cybersecurity risk exposures are monitored, putting in place appropriate mitigation measures and maintaining cybersecurity programmes.

Novo Nordisk cybersecurity programmes and teams are under the direction of our Chief Information Security Officer (CISO) in alignment with the strategic direction set by executive management. Novo Nordisk CISO is an experienced information security officer, who holds multiple industry certifications such as Certified Information Systems Security Professional (CISSP) and Certified Information Security Manager® (CISM). Our teams are comprised of certified and experienced information systems security professionals and information security managers.

Novo Nordisk cybersecurity teams monitor, detect, contain, respond to and report upon cybersecurity threats, events, and incidents in collaboration with specialised third-party service providers. This covers processes for handling major cybersecurity incidents, which is integrated into the corporate crisis management framework for management of large-scale cyber events. Management, including the CISO and our cybersecurity teams, regularly reports on cybersecurity to various organisational levels including submitting regular reports to the Audit Committee and Board of Directors.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Board of Directors has overall oversight responsibility for our risk management, and is charged with oversight of our threat landscape, posture, performance, and strategy related to cybersecurity. The Audit Committee is charged with overseeing the cybersecurity incident trends and potentially significant incidents that have been handled.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Management, including the CISO and our cybersecurity teams, regularly reports on cybersecurity to various organisational levels including submitting regular reports to the Audit Committee and Board of Directors.
Cybersecurity Risk Role of Management [Text Block] Executive management is responsible for identifying, considering and assessing material cybersecurity risks on an ongoing basis, establishing processes to ensure that such potential cybersecurity risk exposures are monitored, putting in place appropriate mitigation measures and maintaining cybersecurity programmes.
Novo Nordisk cybersecurity programmes and teams are under the direction of our Chief Information Security Officer (CISO) in alignment with the strategic direction set by executive management. Novo Nordisk CISO is an experienced information security officer, who holds multiple industry certifications such as Certified Information Systems Security Professional (CISSP) and Certified Information Security Manager® (CISM). Our teams are comprised of certified and experienced information systems security professionals and information security managers.

Novo Nordisk cybersecurity teams monitor, detect, contain, respond to and report upon cybersecurity threats, events, and incidents in collaboration with specialised third-party service providers. This covers processes for handling major cybersecurity incidents, which is integrated into the corporate crisis management framework for management of large-scale cyber events. Management, including the CISO and our cybersecurity teams, regularly reports on cybersecurity to various organisational levels including submitting regular reports to the Audit Committee and Board of Directors.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Executive management is responsible for identifying, considering and assessing material cybersecurity risks on an ongoing basis, establishing processes to ensure that such potential cybersecurity risk exposures are monitored, putting in place appropriate mitigation measures and maintaining cybersecurity programmes.Novo Nordisk cybersecurity programmes and teams are under the direction of our Chief Information Security Officer (CISO) in alignment with the strategic direction set by executive management. Novo Nordisk CISO is an experienced information security officer, who holds multiple industry certifications such as Certified Information Systems Security Professional (CISSP) and Certified Information Security Manager® (CISM). Our teams are comprised of certified and experienced information systems security professionals and information security managers.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Novo Nordisk CISO is an experienced information security officer, who holds multiple industry certifications such as Certified Information Systems Security Professional (CISSP) and Certified Information Security Manager® (CISM). Our teams are comprised of certified and experienced information systems security professionals and information security managers.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] Novo Nordisk cybersecurity teams monitor, detect, contain, respond to and report upon cybersecurity threats, events, and incidents in collaboration with specialised third-party service providers. This covers processes for handling major cybersecurity incidents, which is integrated into the corporate crisis management framework for management of large-scale cyber events.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true