F Secure
Material Topics
Sustainability statement, in full
The complete text of F Secure’s FY2025 sustainability statement is held here – 93 pages, captured from the published report. Every disclosure below also links to its own passage.
Value chain diagram – from the 2024 report (click to enlarge)
ESRS 2 – General Disclosures
GOV-1The role of the administrative, management and supervisory bodiesReported
The role of the administrative, management and supervisory bodies
Reference: pages 31-33. Listed in the ESRS content index (Table 12) at pages 31-33 and, for Business conduct, again at pages 31-33.
In this statement "supervisory bodies" means the F-Secure Board of Directors, its Audit Committee and Personnel and Nomination Committee, and "management body" means the F-Secure Leadership Team, including the CEO (page 31).
Composition (page 31). As of 31 December 2025 F-Secure had 9 executive members in its management body and 7 non-executive members in its supervisory body. Board gender diversity moved from Female 33.3% (2) / Male 66.7% (4) in 2024 to Female 42.8% (3) / Male 57.2% (4) in 2025. Independence rose from ~67% (4 of 6) to ~85.7% (6 of 7 members independent from company and major shareholders). One Board member is elected from personnel, with a term ending at the next AGM. Board members are aged 44-68 with five different nationalities represented.
Expertise (page 31). The Board received ESG training in 2024 covering EU regulation, the double materiality assessment and third-party assurance. The Audit Committee Chair has prior expertise in sustainability reporting, and the Chief People Officer has prior ESRS reporting experience.
Oversight layers (page 33). Board of Directors; Audit Committee; Leadership Team; Sustainability Council (meets monthly, includes CFO, CPO, Legal Counsel, SVP of Corporate Development and the Sustainability function lead); Sustainability Function; and ESG Committees for DEI, Wellbeing and Environment, each reporting to the Council at least twice a year.
GOV-2Information provided to and sustainability matters addressed by the undertaking's administrative, management and supervisory bodiesReported
Information provided to and sustainability matters addressed by the administrative, management and supervisory bodies
Reference: pages 33-35 (ESRS content index, Table 12, page 50).
Frequency (page 33). "The F-Secure Board reviews ESG annually, while the Audit Committee discussed ESG in 2 of 5 meetings during 2025." Updates are presented by the SVP of Corporate Development based on input from the monthly Sustainability Council meetings, which include the CFO, CPO and Legal Counsel. Updates cover ESG plans and actions, policies and targets, progress reports and the implementation of due diligence.
Matters addressed (pages 34-35). Table 2 lists the material topics addressed by management and supervisory bodies, with a column for each. Examples flagged as reaching the supervisory body include the climate-mitigation target risk to channel business, protection of consumers' digital moments, learning and development, inclusive culture, the evolving threat landscape opportunity, AI in security applications and workforce development, talent acquisition and retention, supplier and partner security vulnerabilities, cybersecurity attacks, the whistleblower channel and partnership-related bribery risk. Two items are marked as not addressed by the supervisory body (M&A-related anti-bribery risk is marked "No" for both bodies).
2025 specifics (page 35). "Any changes in the DMA and/or IROs, and updates to targets have been reviewed by the Audit Committee during 2025", and the decision to commit to SBTi was reviewed by the Audit Committee.
Consideration of IROs (page 33). Operational risks are reviewed by each function including bi-annual reviews with the CEO, Leadership Team and Audit Committee; trade-offs between IROs are evaluated during strategy development.
GOV-2(was GOV-3)Integration of sustainability-related performance in incentive schemesReported
Integration of sustainability-related performance in incentive schemes
Reference: pages 35-36 (listed in Table 12 under both General disclosure and Climate change, pages 35-36).
The Leadership Team is eligible for a non-sales Short-Term Incentive (STI) Plan and for share-based long-term incentives (LTI). Similar LTI plans apply to certain members of the administrative and supervisory bodies (page 35).
Weightings (page 36). The non-sales STI consists of:
- Business Results (combined growth % and profitability %): 60-80% weight
- Function-specific targets (may include sustainability-related targets): 0-20% weight
- Company Employee Engagement (eNPS): 20% weight
F-Secure connects these to material sustainability drivers: "growth indicates consumers are protected globally (building trust in digitality), while eNPS reflects employee well-being and satisfaction" (page 35).
Climate link (page 36). The statement is explicit that "STI or LTI plans do not currently contain climate-related targets." The Long-Term Incentive criteria "are based on strategic financial targets".
Approval (page 36). The Board of Directors approves annual STI designs and company-level targets on Leadership Team proposals, and determines LTI terms, conditions, performance criteria and objectives for each performance and vesting period. The non-sales STI Plan is included in the remuneration policy, with goals approved annually by the Board.
GOV-3(was GOV-4)Statement on due diligenceReported
Statement on due diligence
Reference: page 36 (Table 12 index entry 36-36).
F-Secure maps the five core elements of due diligence to locations in the statement (page 36):
- a) Embedding due diligence in governance, strategy and business model - ESG governance is described under GOV-1 and GOV-2; the Leadership Team and Board oversee due diligence, with the Sustainability Council driving implementation.
- b) Engaging with affected stakeholders in all key steps - through stakeholder mapping covering employees, customers, suppliers, investors and government bodies; the map is reviewed when the business model or strategy changes significantly or new impacts emerge in IRO reviews.
- c) Identifying and assessing adverse impacts - through the IRO assessment process in IRO-1, with risk management aligned to ISO 31000:2018. The company states: "No adverse impacts as described under 'F-Secure impacts on people and the environment' have been identified."
- d) Taking actions to address those adverse impacts - risks are addressed under the risk management policy with designated owners, risk modelling and quantification, and proactive monitoring.
- e) Tracking effectiveness and communicating - each function tracks mitigation effectiveness; the Leadership Team and Audit Committee review risks biannually; progress is communicated through the annual group sustainability report and stakeholder updates.
GOV-4(was GOV-5)Risk management and internal controls over sustainability reportingReported
Risk management and internal controls over sustainability reporting
Reference: pages 36-37 (Table 12 index entry 36-37).
Controls over sustainability matters are developed by the sustainability function with the Sustainability Council and relevant functions, and approved by supervisory and management levels. The Audit Committee reviews Board-level policies and the preparation process, and the Code of Conduct and the annual group sustainability report are approved by the Board of Directors (page 36).
Framework (page 37). The internal control framework follows the Finnish Corporate Governance Code. ESG is identified as a key process with specific internal controls for material topics. Internal control monitoring includes an annual risk assessment, catalogue updates and gap follow-up, internal control self-assessments and internal control reporting.
Main risk (Table 3, page 37). The main identified risk is "Risk of reporting errors, especially related to data points." Mitigation: "We have developed more detailed internal descriptions of datapoints for Own workforce in 2025 to mitigate risks of error." Controls and tracking: "Comprehensive internal controls for metrics and targets, which have been updated in 2025 from lessons learned last year."
Named data-management risk areas include climate change model updates aligned with accounting policy changes, talent acquisition and retention data validation, business approvals outside of Workday, validation of reported vulnerabilities data accuracy, and assessing the number of security breaches involving AI tools. Each data point has a defined responsible person, control and testing mechanism. "The scope of reported data points has not changed since 2024." The CFO office reports control findings to the Audit Committee.
SBM-1Strategy, business model and value chainReported
Strategy, business model and value chain
Reference: pages 38-40 (Table 12 index entry 36).
Offering (page 38). F-Secure provides consumer cybersecurity: a Security Suite (F-Secure Total) with endpoint security, scam protection, privacy protection, password management and identity protection, plus an Embedded Security offering placed inside partners' apps. Scam protection capabilities were expanded during the reporting period.
Markets (page 38). End-customers are consumers, served directly and through approximately 200+ Service Provider partners (communication service providers, retailers, banks and insurance companies). Revenue in 2025 was 82% through partners and 18% direct. Revenue by region (Table 4, EUR million, 2024 to 2025): Nordic countries 42.0 to 44.8; Rest of Europe 48.1 to 45.4; North America 45.5 to 44.3; Rest of the world 10.6 to 11.3; total 146.3 to 145.7.
Workforce (Table 5, page 38). Employees by region 2024 to 2025: Nordic 280 to 274; Rest of Europe 67 to 58; North America 33 to 30; Rest of the world 149 to 187; total 529 to 549.
Sector (page 38). "F-Secure belongs to the Technology - Software & IT Services ESRS sector", reported as a single operating segment.
Value chain (pages 39-40). Upstream: human resources and talent, technology suppliers, IT and cloud suppliers, partnerships, financial access and regulatory compliance. Core operations: product development, partner sales, direct consumer sales, services, trust foundation, talent development, business support and governance. Downstream: the partner channel and direct distribution through the F-Secure e-commerce platform and third-party app stores (Apple and Google). Figure 2 on page 40 sets out the value chain and actors.
SBM-2Interests and views of stakeholdersReported
Interests and views of stakeholders
Reference: pages 41-42 (Table 12 index entries 41 for General disclosure and 42-42 for Own workforce, 96-106 for Consumers and end-users).
Stakeholder map (Table 6, page 41). Six stakeholder groups with their expectations, how engagement is organised and the outcome: investors and financial institutions (ESG surveys, calls, ratings, capital market day, meetings with banks and analysts); employees (Fellows) (employee surveys, personal development dialogues, DEI and Wellbeing Committees, employee-elected board member, townhalls); partners (partner survey and discussions, engagement with sales, ESG ratings); consumers (customer support, surveys); policymakers and regulators (answering public consultations, participating in feedback rounds); and suppliers (cybersecurity examination by the CISO office, supplier onboarding, review of main suppliers' ESG priorities).
Named outcomes include organising the first Sustainability day, launching a weekly wellbeing hour, developing the F-Secure sustainable AI framework, the SBTi commitment, ESG training of sales, development of a Procurement policy of conduct and launching a supplier environmental data gathering programme.
DMA engagement (page 42). "As part of our Double Materiality Assessment review, we engaged key stakeholders, including financial institutions, our workforce, end-customers, the Board, and sales providing channel partners". "While the DMA review didn't result in material changes to our strategy or business model", stronger stakeholder relationships are expected through regular dialogue.
Consumers (page 42). Regular consumer and market surveys inform product roadmaps, with 81% of consumers expecting security services from internet providers.
SBM-3Material impacts, risks and opportunities and their interaction with strategy and business modelReported
Material impacts, risks and opportunities and their interaction with strategy and business model
Reference: pages 43-46 (Table 12 index entry 43-46; repeated for Climate change, Own workforce and Consumers and end-users).
Impacts (Table 7, page 43). Ten impacts across Environment (green coding principles, potential positive, long-term), Social (protecting consumers' digital moments; cybercrime awareness; family leaves; gender equality; learning and development; inclusive culture; critical strategic competences) and Governance (whistleblower channel; culture strengthening).
Risks and opportunities (Table 8, page 44). Fourteen items: Environment - failure to meet climate change mitigation targets may negatively impact channel business (risk, DVC/OO, mid and long term); Social - four opportunities (evolving threat landscape; data and AI in security applications; employer reputation through DEI; AI in workforce development) and seven risks (channel strategy; consumer willingness to pay; talent acquisition and retention; supplier and partner security vulnerabilities; cybersecurity attacks; mental health related absences; AI raising breach risk); Governance - two risks (partnership business use of intermediaries; M&A-related anti-bribery risk).
Financial position (page 45). "Management has not recognized that F-Secure's material risks and opportunities have affected the undertaking's most recently reported financial performance, financial position and cash flow".
Resilience (page 45). "F-Secure's strategy and business model are considered resilient to address material impacts and risks", assessed for the 2026-2028 strategy period using qualitative and quantitative analysis, expert assessments and external consultation.
Changes (Table 9, page 46). Removals include DEI partner retention risk and Tier 1 partnership risk; additions include AI-related security breach risk and culture strengthening.
Omission (page 30). F-Secure "has chosen to omit the information prescribed by ESRS 2 SBM-3 paragraph 48(e) anticipated financial effects" under the ESRS quick-fix delegated act of 11 July 2025.
IRO-1Description of the processes to identify and assess material impacts, risks and opportunitiesReported
Description of the processes to identify and assess material impacts, risks and opportunities
Reference: pages 47-49 (Table 12 index entry 47; also listed under Business conduct at 47 and under Climate change at 49-50).
Process (page 47). "F-Secure completed its first Double Materiality Assessment (DMA) in 2022 and refined it in 2023-2024, aligning with the final European Sustainability Reporting Standards and EFRAG guidance." Principles include quantitative and qualitative thresholds, engagement with affected stakeholders, assessment of sector and entity-specific topics particularly for cybersecurity, and reporting cross-cutting matters regardless of the outcome.
Sub-topic materiality (page 47). Material: climate change mitigation; working conditions; equal treatment and opportunities for all; information-related impacts for consumers and/or end-users; personal safety of consumers and/or end-users; corporate culture; protection of whistleblowers; corruption and bribery. Not material: climate change adaptation; energy; other work-related rights; social inclusion of consumers and/or end users; animal welfare; political engagement; management of relationships with suppliers including payment practices.
Thresholds (page 48). Scale, scope and financial impact are scored 1-3, with financial thresholds of 5% of revenue, 3% of business costs and a 2% EBIT margin. "A topic was considered material if it scored '3' in any category or met the financial impact threshold." Impacts are tagged own operations (OO), downstream (DVC) or upstream (UVC).
Governance (page 48). The DMA "has been reviewed by the Sustainability Council and the Audit Committee and approved by the Board of Directors. The assessment process and methodology have not changed since the last reporting period." "As a result of the analysis, no adverse impacts have been recognized."
Climate-specific IRO identification is described on pages 49-50 and cross-referenced under E1-2 (2025 ESRS numbering).
IRO-2Disclosure requirements in ESRS covered by the undertaking's sustainability statementReported
Disclosure requirements in ESRS covered by the undertaking's sustainability statement
Reference: pages 50-57. This is a genuine ESRS content index.
Table 12 (pages 50-51) lists, by topic, every disclosure requirement covered with a page index:
- General disclosure: BP-1 (29), BP-2 (29-30), GOV-1 (31-33), GOV-2 (33-35), GOV-3 (35-36), GOV-4 (36-36), GOV-5 (36-37), SBM-1 (36), SBM-2 (41), SBM-3 (43-46), IRO-1 (47), IRO-2 (50-57).
- Climate change: GOV-3 (35-36), E1-1 (70), SBM-3 (43-46), IRO-1 (49-50), E1-2 Policies (72), E1-3 Actions (73-74), E1-4 Targets (75-76), E1-6 Gross Scopes 1, 2, 3 and Total GHG emissions (76).
- Own workforce: SBM-2 (42-42), SBM-3 (43-46), S1-1 (83-85), S1-2 (85-86), S1-3 (86), S1-4 (86-89), S1-5 (89-90), S1-6 (91-91), S1-9 (93), S1-13 (94), S1-14 (94), S1-15 (94), S1-16 (95), S1-17 (95).
- Consumers and end-users: SBM-2 (96-106), SBM-3 (96), S4-1 and S4-2 (98), S4-3 (100), S4-4 (101-104), S4-5 (104-106).
- Business conduct: GOV-1 (31-33), IRO-1 (47), G1-1 (110-111), G1-3 (111-112), G1-4 (112-112).
Table 13 (pages 52-57) is the ESRS 2 Appendix B list of datapoints derived from other EU legislation, with SFDR, Pillar 3, Benchmark Regulation and EU Climate Law references. Entries are marked with a page index, "Not material", "Not applicable to F-Secure" or "Omitted 2025". E1-9 datapoints are marked Omitted 2025; E1-5, E1-7, E2-4, E3-1, E3-4, E4, E5-5, S2 and S3 datapoints are marked Not material; S1-14 paragraph 88(e) days lost is marked Omitted 2025.
E1 – Climate Change
E1-1Transition plan for climate change mitigationReported
Transition plan for climate change mitigation
Reference: pages 70-71 (Table 12 index entry 70).
"During 2025, F-Secure has continued to develop the details of the transition plan for climate change mitigation covering Scope 1, 2 and 3. The transition plan implementation is in the initial phase, with the four decarbonization levers disclosed under section E1-3 and E1-4 and key actions planned" (page 70).
Targets (page 70). "We've adopted the Greenhouse Gas Protocol and CSRD as our framework... targeting 42% absolute reduction across Scope 1, 2, and 52% emission intensity reduction of Scope 3, between 2024 and 2030, with 2024 as our base year. These targets align with IPCC 1.5C Pathways. Sectoral decarbonization standards are not yet available for IT and Software companies."
Levers and milestones (Table 18, page 70). Four levers with 2025, 2026-2027 and 2028-2030 actions and expected impact by 2030: fuel switching (55% reduction in fleet emissions, 17 tCO2e); renewable energy and energy efficiency (40% reduction from the 2024 baseline, 75 tCO2e); supply chain decarbonization (52% reduction in Scope 3 emission intensity); green coding principles (keep 2024 emission levels).
Investment (page 70). "F-Secure transition plan does not necessitate material dedicated investments or funding beyond normal business operations."
Taxonomy and lock-in (page 71). "As per disclosure requirement E1-3, F-Secure does not have taxonomy-compliant activities, and therefore, no linked investments and financing that would support its transition plan." Carbon lock-in "is not considered material for F-Secure as the impacts are small". "F-Secure is not excluded from the EU Paris-aligned Benchmarks."
Governance (pages 70-71). Oversight through the Environment Committee (operational Q3 2024), bi-annual Sustainability Council reviews and annual Board reporting. "In 2026, it will be reviewed by the Audit Committee and approved by the Board of Directors."
E1-2(was covered under ESRS 2 IRO-1)Identification of climate-related risks and scenario analysisReported
Identification of climate-related risks and scenario analysis
Back-filled from ESRS 2 IRO-1 (pages 49-50) and the E1 climate SBM-3 and scenario section (pages 66-70), where this content is disclosed in the FY2025 report. This disclosure requirement did not exist under the 2023 ESRS the report was prepared against.
Classification (pages 66-68). Physical and transition risks are treated separately. "Physical risks were not found to be significant as F-Secure has no assets in high-risk regions... while some limited exposure exists in India and Malaysia." "The only material transition risk identified is reputational risk from failing to meet mitigation targets aligned with the Paris Agreement", significant "because 97% of F-Secure's emissions come from Scope 3 categories".
Methodology and scope (pages 49, 66). Screening of climate hazards against the operational footprint; Table 16 (page 67) marks the hazards included - changing temperature, heat wave, heat stress, cold wave/frost, temperature variability, changing precipitation patterns, precipitation and hydrological variability, drought, ocean acidification, soil degradation, soil erosion, wildfire, storm and flood. "Physical risks in locations with fewer than 20 employees have been excluded from the analysis" (page 66). Transition screening used the STEEP framework across social, technological, economic, environmental and political driving forces (Table 17, page 68).
Scenarios (page 68). Three scenarios "aligned with IPCC AR6 pathways", following TCFD methodology, with a 2030 time horizon: Orderly Transition (SSP1-2.6), Disorderly Transition (SSP2-4.5) and Hot House World (SSP5-8.5). A high-emission scenario is therefore covered. F-Secure states the assessment is "aligned with limiting global warming to 1.5C in accordance with the Paris Agreement" (page 66), but no global average temperature projection is stated per scenario beyond the SSP labels.
Timing (page 70). "This scenario analysis will be reviewed annually".
E1-3(was covered under ESRS 2 SBM-3)Resilience in relation to climate changeReported
Resilience in relation to climate change
Back-filled from ESRS 2 SBM-3 (page 45) and the E1 resilience section (pages 66, 69-70), where this content is disclosed in the FY2025 report. This disclosure requirement did not exist under the 2023 ESRS the report was prepared against.
Scope (page 66). "F-Secure's climate resilience analysis covers its own operations, upstream and downstream value chain activities. The resilience analysis covers transition risks, including policy and regulatory developments, technology changes, market requirements, and reputational risks related to climate mitigation targets."
Results (page 69). "F-Secure is considered climate resilient due to our business nature as a software company." Performance is set out scenario by scenario: under an Orderly Transition "our current strategy aligns well"; under a Disorderly Transition the strategy "would face challenges... due to the abrupt policy changes and rapidly evolving partner requirements"; under a Hot House World the strategy "would likely not meet its targets due to limited transition pressure in the supply chain, and would face increasing physical impacts, particularly in vulnerable locations."
Strengths and uncertainties (page 69). "Key strengths include our current emissions tracking approach and early work on emissions inventory. Vulnerabilities include heavy supply chain dependency in reaching the scope 3 target."
Capacity to adapt (page 69). Seven strategic measures: enhanced supplier emissions data collection; climate governance strengthening through the Environment Committee; formal SBTi commitment; low-carbon service differentiation through green coding and a sustainable AI framework; climate transition contingency planning with "financial reserves for climate initiatives"; partner requirement anticipation through sales surveys; and distributed work enhancement. These are phased near-term (0-2 years, 2024-2026) and medium-term (2-5 years, 2026-2029).
Wider business-model resilience for the 2026-2028 strategy period is stated at page 45.
E1-4(was E1-2)Policies related to climate change mitigation and adaptationReported
Policies related to climate change mitigation and adaptation
Reference: page 72 (Table 12 index entry 72).
Three policies are disclosed in Table 20 with key contents, scope, responsibility and link to IROs:
- Climate Change Policy - targets across Scopes 1, 2 and 3; alignment with the Paris Agreement and IPCC 1.5C pathways; a process for identifying climate impacts, risks and opportunities; renewable energy deployment in offices and operations (excluding energy efficiency); climate change mitigation and adaptation. Scope: all employees, operations and value chain across all relevant geographies. Responsibility: CEO, with implementation by the Sustainability Council and Environment Committee.
- Supplier Code of Conduct - sustainable usage of natural resources, increasing energy efficiency and renewable energy use, reducing the environmental impact of global operations. Scope: suppliers, "only apply where included or referenced in agreement". Responsibility: Procurement with monitoring by F-Secure.
- Procurement policy - standards for all procurement activities, vendor evaluation, compliance with listed F-Secure policies, counterparty screening, regulatory and industry compliance, and promoting environmental, social and governance responsibilities. Scope: suppliers and employees. Approved by the CEO with monitoring by the Procurement function.
All three are linked to the same material IRO: "Failure to meet climate change mitigation targets may negatively impact channel business."
"The Climate Change Policy is based on the values and principles defined in F-Secure's Code of Conduct and informed by stakeholder input from our materiality assessment. Our Supplier Code of Conduct explicitly requires suppliers to commit to working in an environmentally responsible and efficient manner" (page 72).
E1-5(was E1-3)Actions and resources in relation to climate change policiesReported
Actions and resources in relation to climate change policies
Reference: pages 73-74 (Table 12 index entry 73-74).
Four decarbonisation levers linked to the environmental IROs (page 73):
- Fuel switching - "several cars have already been replaced with hybrid or electric models, and this transition will continue as leasing contracts are renewed. In the future, we aim to update our car policy to ensure that by 2030, all leased cars are electric."
- Renewable energy and energy efficiency - "In 2025, F-Secure's headquarters in Helsinki moved to new office spaces. In the process, renewable energy was considered, and the electricity used in the new Helsinki office is 100% renewable. Our plan is to ensure all large offices, as well as smaller facilities where energy contracts can be controlled, use 100% renewable energy by 2030."
- Supply chain decarbonization - "In 2025, we set up our supplier climate mitigation program... The program focuses on supplier engagement and climate data gathering from suppliers. We've also implemented our Procurement policy". "No quantitative emission reductions are available for these actions in 2025, but we expect a 52% emission intensity reduction by 2030."
- Efficient coding principles - during 2025 F-Secure developed and launched a company-wide framework for Sustainable AI use and trained the organisation on it, and organised a panel discussion on AI innovation and sustainability in software development with external experts. "By 2030, we do not expect emission reductions as the number of sold products is projected to grow, while we optimize energy consumption."
SBTi (page 73). "F-Secure has committed to set near-term, company-wide greenhouse gas emission reduction targets in line with climate science through the Science Based Targets initiative (SBTi)."
Resources (page 73). "No significant monetary amounts of Capex and Opex have been required to implement these actions." Management of these IROs sits with the F-Secure Environment Committee.
E1-6(was E1-4)Targets related to climate change mitigation and adaptationReported
Targets related to climate change mitigation and adaptation
Reference: pages 74-76 (Table 12 index entry 75-76).
Targets and progress (Table 21, page 75). 2024 base year, 2025 outcome, 2030 target value and 2030 target:
| Metric | 2024 base | 2025 | 2030 value | 2030 target |
|---|---|---|---|---|
| Gross Scope 1 and Scope 2 (market-based), tCO2eq | 220 | 195 | 127 | 42% emission reduction |
| Scope 3 emission intensity, tCO2eq/MEUR | 57 | 57 | 27 | 52% emission intensity reduction |
Change of target (pages 29, 74). "F-Secure has chosen to change the E1 scope 3 related target of absolute emission reduction of 42% to emission intensity reduction of 52% between 2024 and 2030. The change has been made due to business growth compatibility, and it allows for better comparisons between different companies."
Framework (page 76). "F-Secure has established GHG emission reduction targets compatible with limiting global warming to 1.5C by 2030... The GHG Protocol and IPCC's cross-sector pathway serve as our framework." Targets are defined by the Sustainability Council and approved by the Board of Directors. Base year 2024 was chosen "to ensure an accurate view and to avoid external influences. After 2030, the base year is set every five years."
Lever contributions (page 76). Fuel switching: "In 2025, the emissions of Scope 1 were 33 tCO2eq. Emissions will be within the 42% decrease target by 2027." Renewable energy: "The Scope 2 emissions have decreased 14% during 2025, mostly due to removal of Poland office and the decrease of Helsinki office heating." Supply chain: Scope 3 category 1 "represented over 80% of our Scope 3 emissions in 2025... 6610 tCO2eq". Efficient coding: "No material reduction expected as customer base growth will likely cancel out energy efficiency improvements."
"Our targets align with GHG inventory boundaries and don't include GHG removals, carbon credits or avoided emissions" (page 74). No baseline recalculation was performed in 2025.
E1-8(was E1-6)Gross Scopes 1, 2, 3 and Total GHG emissionsReported
Gross Scopes 1, 2, 3 and Total GHG emissions
Reference: pages 76-79 (Table 12 index entry 76).
Consolidation follows the operational control method; primary data is used where available, "currently only from AWS, representing <1% of total Scope 3 emissions" (page 76).
Inventory (Table 22, page 77), tCO2eq, 2024 base year to 2025:
- Gross Scope 1: 31 to 33 (+6%); 0% from regulated emission trading schemes.
- Gross location-based Scope 2: 233 to 198 (-15%); gross market-based Scope 2: 189 to 162 (-14%).
- Total gross indirect Scope 3: 8,330 to 8,282 (-1%). Category 1 purchased goods and services excluding data centres 6,466 to 6,610 (+2%); sub-category cloud computing and data centre services 43 to 318 (+640%); category 3 fuel and energy-related 49 to 43; category 5 waste 2 to 3; category 6 business travel 1,675 to 1,211 (-28%); category 7 employee commuting 23 to 22; category 8 upstream leased assets 11 to 15; category 11 use of sold products 61 to 61.
- Total GHG emissions (location-based): 8,594 to 8,513 (-1%). Total (market-based): 8,550 to 8,477 (-1%).
Intensity (Table 24, page 79). Location-based per net revenue 58.76 to 58.41 tCO2eq/MEUR; market-based 58.46 to 58.17. Net revenue used: 146.30 MEUR (2024) and 146 MEUR (2025).
Scope 3 boundary (Table 23, page 78). Categories 1, 3, 5, 6, 7, 8 and 11 are included; categories 2, 4, 9, 10, 12, 13, 14 and 15 are stated as not relevant with reasons (for example "no physical products are sold by F-Secure").
Methodology (pages 78-79). Scope 1 from fuel consumption in company vehicles using Statistics Finland factors; no biogenic Scope 1 emissions. Scope 2 from five sites, with heating and cooling calculated from office area. Scope 3 primarily spend-based, with named emission factor sources per category. Scope 3 uncertainty is acknowledged at page 29.
S1 – Own Workforce
S1-1Policies related to own workforceReported
Policies related to own workforce
Reference: pages 83-85 (Table 12 index entry 83-85).
Five workforce policies are disclosed in Table 26 (pages 83-84) with key contents, scope, responsibility and link to IROs, all owned by the Chief People Officer:
- DEI Policy - diversity, equity and inclusion aligned with values and the Code of Conduct; anti-harassment and non-discrimination guidelines; targets for talent acquisition and accountability mechanisms; training, targeted recruitment, programmes supporting vulnerable groups, leadership development; DEI Committee. Scope: all employees, employee-like contractors, leadership.
- Recruitment Policy - fair and transparent hiring, non-discrimination laws, background checks, employer branding and metrics; "aligned with ILO principles on non-discrimination and equal opportunity".
- Health and Wellbeing Policy - health and well-being principles, healthy work culture, local health compliance, flexible work environments; "addresses work-life balance, health and safety (ILO standards)".
- Learning and Development Policy - continuous learning, structured learning frameworks, measuring effectiveness.
- Rewards and Recognition Policy - job architecture, base salary, benefits, incentive plans, recognition and pensions; "aligned with OECD and ILO principles".
Human rights (page 84). Policies align with the OECD Guidelines for Multinational Enterprises, UN Global Compact, UN Guiding Principles on Business and Human Rights, the ILO Declaration on Fundamental Principles and Rights at Work and the International Bill of Human Rights, across three areas: respect for human rights; labour rights and safety with "zero tolerance for child labor, forced labor, or trafficking"; and application of standards, where "If local laws are less restrictive than the Code of Conduct, the Code of Conduct prevails."
Risk context (page 85). "F-Secure does not operate in industries/sectors where the risk of forced, compulsory, or child labour is significant. F-Secure has an office in Malaysia and employees in India, which are considered countries with higher risks", mitigated by hiring educated specialists and background checks.
Workplace accident prevention (page 85). Accidents are tracked in HR systems; occupational healthcare is provided.
S1-2Processes for engaging with own workforce and workers' representatives about impactsReported
Processes for engaging with own workforce and workers' representatives about impacts
Reference: pages 85-86 (Table 12 index entry 85-86).
"Senior leadership - comprising the CEO, Chief People Officer, and Leadership Team - leads employee engagement through regular Townhalls and monthly Leadership Forums" (page 85).
Five systematic methods are listed (page 85):
- Employee Engagement - monthly Townhalls with Q&A, function-specific all-hands meetings, Leadership Lab for Team Leaders, and a digital suggestion channel.
- Employee Feedback - "Biannual anonymous personnel surveys are conducted to gather feedback from all employees. The results are analyzed and presented at company, function, and team levels (where at least five responses are available)." Other mechanisms include the whistleblowing channel, exit interviews and HR consultations.
- Project-Based Engagement - employees participate in people processes and cultural initiatives.
- Workers' representatives - "People and Culture Operations Director organize monthly meetings with Shop Steward... HR Board meets monthly with Shop Steward and country-specific elected representatives (People & Culture Advisor)".
- Collective Bargaining Compliance - "F-Secure adheres to collective bargaining agreements in Finland, France, and Spain, maintaining alignment of policies and practices through the People & Culture Operations Director."
Accessibility (page 85). Accessible Learning Management Systems and survey tools with screen reader compatibility, text-to-speech and closed captioning; virtual Townhalls with real-time captions and recorded transcripts; wheelchair-accessible facilities.
Use of insights (page 86). "Insights from these channels are used to identify and reassess material workforce IROs, including topics such as well-being, workload, equal treatment, skills development, and workplace culture", informing updates to hybrid work practices, well-being initiatives, targeted training and career development frameworks.
S1-2(was S1-3)Processes to remediate negative impacts and channels for own workforce to raise concernsReported
Processes to remediate negative impacts and channels for own workforce to raise concerns
Reference: page 86 (Table 12 index entry 86; Appendix B datapoint "ESRS S1-3 grievance/complaints handling mechanisms paragraph 32 (c)" also indexed to page 86).
"Every employee at F-Secure has the right and obligation to raise concerns about Code of Conduct violations, including human rights" (page 86).
Primary reporting channels (page 86):
- Team leader, local People & Culture advisor, legal or personnel surveys
- Verbal or electronic communication methods
- The team leader's leader or People & Culture if the issue relates to the direct team leader
- Shop Steward or employee representatives
- Direct contact with the CEO or Board of Directors
Whistleblowing (page 86). "Our whistleblowing channel is operated through a third-party provider to ensure independence, confidentiality, and anonymity. The channel is made available and maintained by F-Secure, but the reporting mechanism itself is administered externally." "Retaliation against anyone raising a good-faith concern is strictly prohibited."
Remedy effectiveness (page 86). "We assess the effectiveness of the remedy provided through follow-up reviews with the affected individuals, monitoring for recurrence of the issue, and evaluating whether the corrective actions have addressed the root cause. Feedback from employees, case-closure criteria, and ongoing monitoring help us confirm that the remedy has achieved its intended outcome."
Awareness and trust (page 86). Assessed through biannual personnel surveys, 1-on-1 meetings and Townhalls, and trust metrics such as eNPS.
S1-3(was S1-4)Taking action on material impacts on own workforceReported
Taking action on material impacts on own workforce
Reference: pages 86-89 (Table 12 index entry 86-89). Scope: "All employees globally; targeted initiatives for underrepresented groups. Time Horizon: Ongoing; programs launched and maintained in 2025" (page 86).
Actions on positive impacts (pages 87-88). Family leaves and well-being: equal access to parental and caregiving leave, a Wellbeing Strategy with support across Finland, India, the US and Malaysia, and a Culture, Health & Well-being Committee. Learning and development: targeted training for R&D and leadership roles and centralised training via the LMS. Gender equality: targeted recruitment for underrepresented groups. Culture building: speak-up culture training. Secure employment: prioritising permanent over fixed-term contracts, plus remote and hybrid work.
Prevention of negative impacts (page 87). "F-Secure has assessed its practices and confirms that it does not cause or contribute to material negative impacts on its own workforce." Monitoring uses surveys, absence trend analysis, performance processes and grievance and whistleblowing channels. "No tensions were identified between preventing negative impacts and other business pressures during the reporting period."
Risk mitigation (Table 27, page 88). Two risks: Employee Workload and Well-being - well-being programmes, support resources, regular check-ins, occupational health care in Finland and comprehensive health coverage in India, US, France and Malaysia; measured by survey feedback and absence and mental-health tracking. Talent Acquisition and Retention - strategic workforce planning, strengthened pre/onboarding and development programmes, centralised learning; measured by time-to-hire, attrition and HiPo retention, review completion, talent density and succession pipeline.
Opportunities (Table 28, page 88). Employer Reputation - DEI development projects, DEI talks platform, Mothers in Business programme, Women in Tech initiatives. Use of AI - AI tools to enhance employee experience and processes.
Resources (page 88). The People and Culture function manages all workforce IROs globally. "These activities did not require any material operating (Opex) or capital expenditures (Capex) in 2025" (page 87).
S1-4(was S1-5)Targets related to own workforceReported
Targets related to own workforce
Reference: pages 89-91 (Table 12 index entry 89-90).
Targets and progress (Table 29, page 89), baseline 2023 unless stated, with 2024 and 2025 outcomes and 2030 targets:
| Target | Baseline 2023 | 2024 | 2025 | 2030 target |
|---|---|---|---|---|
| Gender diversity, directors including leadership team | F 23%, M 77% | F 23.5%, M 76.5% | F 25.81%, M 74.19% | F 33, M 67 |
| Gender diversity, all employees | F 30%, M 70% | M 69.19%, F 30.62% | F 30.29%, M 69.71%, ND 0.18% | No gender above 65% |
| Nationalities among senior management | 24 | 28 | 28 | >20 |
| Age groups (all employees) | largest 35.7% (30-40) | largest 36.7% | largest 36.98% (30-40) | none above 35% |
| eNPS | 2 | 40 | 33 | >50 |
| Performance and career review | baseline 2024 | 88% | 98.91% | 98% |
Commentary (page 90). The directors target is "that 33% of senior leaders at the director level should be female", measured on HR management system data and "aligning with the EU gender equality strategy 2020-2025 and the directive on gender balance in corporate boards". On age: "Our 2025 outcome shows one age group exceeding 35%, specifically the 30-40y group at 36,98%." On eNPS: target above 50 in 2030, "Our 2025 outcome is 33." On performance reviews: "Our 2025 outcome is 98.91%."
Restatements (page 30). The 2024 gender diversity figure for directors was corrected from F 25.1% / M 74.9% to F 23.5% / M 76.5%, and the 2024 performance and career review figure from 82% to 88%.
Target setting (page 91). Targets are defined by the CPO with Leadership Team members, the Sustainability Council and the CEO where part of incentive schemes, and approved by the Board of Directors (page 89). Employee input comes through surveys and function experts; progress is shared through monthly Townhalls.
S1-5(was S1-6)Characteristics of the undertaking's employeesReported
Characteristics of the undertaking's employees
Reference: pages 91-93 (Table 12 index entry 91-91). Data is sourced from the HR system (Workday), "the single source of truth for all workforce data", and reflects status at the end of the reporting period (page 91).
By gender (Table 30, page 91), headcount 2024 to 2025: Male 366 to 382; Female 162 to 166; Non-Binary 0; Not reported 1 to 1; Total 529 to 549.
By country (Table 31, page 92): Finland 270 to 266; India 70 to 105; Malaysia 74 to 76; total for these three 414 to 447.
By contract (Table 34, page 92), 2025: permanent 543 (F 164, M 378, Other 1); temporary 6 (F 2, M 4); non-guaranteed hours 0; full-time 533; part-time 16.
By region (Table 36, page 93), 2025: Europe 332, North America 30, Asia 187, total 549; permanent 543, temporary 6, full-time 533, part-time 16.
Turnover (Table 32, page 92). "Employee turnover is calculated as the number of employees who have left voluntarily or due to dismissal, retirement, or death in service, divided by the F-Secure headcount as of December 31, 2025." Total number 107 (2024) to 103 (2025); rate 20.23% to 18.76%.
Cross-reference (page 91). "The measures provided in the group sustainability report own workforce section are aligned with related data provided in other sections of the annual report noting that average annual number of personnel is used in the financial statement (Cross-reference to financial section 7. Personnel expenses)."
F-Secure measures full-time employees by FTE "with no 'non-guaranteed hours' employees" (page 82).
S1-8(was S1-9)Diversity metricsReported
Diversity metrics
Reference: page 93 (Table 12 index entry 93).
Methodology (page 93). "Data includes employees only and excludes contractors." The HR system allows employees to self-identify as female, male, other or not declared. "According to F-Secure's Job Architecture, employees in roles classified as F6 and above are considered part of top management."
Gender distribution of top management (Table 37, page 93):
| Year | Female | Male | Other |
|---|---|---|---|
| 2024 | 12 (23.5%) | 39 (76.5%) | 0 |
| 2025 | 16 (25.81%) | 46 (74.19%) | 0 |
Age distribution of employees (Table 38, page 93):
| Year | Under 30 | 30-50 | Over 50 |
|---|---|---|---|
| 2024 | 109 (20.60%) | 353 (66.73%) | 67 (12.67%) |
| 2025 | 114 (20.77%) | 363 (66.12%) | 72 (13.11%) |
Restatement (page 30). The calculation method for the S1-9 gender distribution table "was updated based on approved targets"; the 2024 figures for directors including leadership team were corrected from female 25.1% / male 74.9% to female 23.5% / male 76.5%.
The company also reports age distribution against its own five-band target in S1-5 (under 30 20.77%, under 40 36.98%, under 50 29.14%, under 60 11.66%, above 60 1.46%; page 89).
S1-12(was S1-13)Training and skills development metricsReported
Training and skills development metrics
Reference: page 94 (Table 12 index entry 94).
Methodology (page 94). "Data is available on e-learning completions and global training session participation since August 2023 in our Learning Management System (LMS). Each employee undergoes two performance reviews per year: mid-year and end-of-year reviews".
2025 (Table 40, page 94):
| Metric | Female | Male | Other | Total |
|---|---|---|---|---|
| Employees participating in regular performance and career development reviews | 98.78% | 98.95% | 100% | 98.91% |
| Number of performance reviews per employee | 2.79 | 2.70 | 3.00 | 2.72 |
| Average training hours per employee | 1.48 |
2024 comparative (Table 39, page 94): participation Female 85.8%, Male 88.2%, total 88%; reviews per employee 1.68, 1.70, total 1.7; average training hours per employee 1.84. The total participation figures exclude "a single employee who has not reported gender".
Calculation basis (page 94). "Performance and career development review percentage is calculated based on all employees as of December 31, 2025, counting each employee once regardless of whether they had 1 or 2 reviews during the year, excluding employees terminated during 2025."
Restatement (page 30). "The nature of the error was that calculation method for disclosure S1-13 Training was updated. In prior period section S1-5 Own workforce targets and career review target percentage was 82%. That was were corrected this reporting period and corrected figure is 88%."
Average training hours fell from 1.84 to 1.48 hours per employee year on year, while review participation rose from 88% to 98.91%.
S1-13(was S1-14)Health and safety metricsReported
Health and safety metrics
Reference: page 94 (Table 12 index entry 94). This disclosure is partially omitted under the ESRS 1 Appendix C phase-in provisions.
Metrics (Table 41, page 94), 2024 to 2025:
| Data point | 2024 | 2025 |
|---|---|---|
| Percentage of own workforce covered by the health and safety management system based on legal requirements and/or recognised standards or guidelines | 100% | 100% |
| Number of fatalities as a result of work-related injuries and work-related ill health | 0 | 0 |
| Number and share of recordable work-related accidents | 0 | 0 |
Omission stated by the company (page 94). "Health and safety data include only employees. F-Secure has chosen to omit the number of cases of recordable work-related ill health and the number of days lost to work-related injuries, subject to legal restrictions on data collection." This is flagged in the phase-in section as well: "'S1-14 Health and safety metrics' partially" omitted (page 30). The Appendix B datapoint table marks "ESRS S1-14 Number of days lost to injuries, accidents, fatalities or illness paragraph 88 (e)" as "Omitted 2025", while paragraph 88(b) and (c) fatalities and accident rate are indexed to page 94 (Table 13, page 55).
Data collection (page 94). "During autumn 2024, we introduced a dedicated form within our HR system to systematically track work-related accidents and resulting absences... Beginning in 2025, all accident reports are expected to be submitted promptly following incident occurrence." In Finland "all health-related data is managed by our occupational health care provider".
S1-14(was S1-15)Work-life balance metricsReported
Work-life balance metrics
Reference: page 95 (Table 12 index entry 94).
Metrics (Table 42, page 95), 2024 to 2025:
| Data point | 2024 | 2025 |
|---|---|---|
| Percentage of employees entitled to family leave | 100% | 100% |
| Percentage of employed personnel who took family leave, by gender | Male 3.2%, Female 2.6%, Total 5.86% | Female 3.46%, Male 4.55%, Total 8.01% |
Context (page 95). "All employees are entitled to take family leave as outlined by applicable laws of the countries, company policies, and collective agreements where relevant. F-Secure supports work-life balance culture, maintaining that employees can access and utilize family leave without barriers. F-Secure actively monitors these metrics to ensure equitable access to family leave across all genders. We remain committed to addressing any gaps in usage or access to support our broader objectives of work-life balance and inclusion."
Family leaves are one of the material own workforce IROs, described as an actual positive impact: "Family leaves for F-Secure employees exceeding local requirements in some countries" (Table 25, page 81). The related action is equal access to parental and caregiving leave "so that no one is disadvantaged for prioritizing family" (page 87). Take-up rose from 5.86% to 8.01% of employees year on year, with the male rate overtaking the female rate.
S1-15(was S1-16)Compensation metrics (pay gap and total compensation)Reported
Compensation metrics (pay gap and total compensation)
Reference: page 95 (Table 12 index entry 95).
Metrics (Table 43, page 95), 2024 to 2025:
| Remuneration | 2024 | 2025 |
|---|---|---|
| Gender pay gap, % | 12.74% | 8.15% |
| Annual total remuneration ratio of the highest paid individual to the median annual total remuneration for all employees | 5.11 | 7.17 |
Methodology (page 95). "The main data source is our HR system from where we extract the annual base salary, and the annual total of allowances and benefits paid on top of the base salary valid at the end of the year. We also extract the total amount of one-time payments (including incentives), and overtime compensation (where available) paid during the year. The annual payout amounts from the LTI programs are also obtained."
The pay gap formula is "(Average annual total compensation of male employees - average annual total compensation of female employees) divided by the average annual total compensation of male employees", and "The CEO is excluded from pay gap calculation."
For the total remuneration ratio, "we first calculate the median annual total compensation amount excluding the highest amount. Then we calculate the ratio using the following formula: (The highest annual total compensation amount) divided by (the median annual total compensation amount)."
"F-Secure measures the pay gap as part of our annual global salary increase process" (page 95), and pay gap analyses are conducted "before and after salary reviews" (page 88). The gap narrowed by 4.59 percentage points year on year, while the total remuneration ratio widened from 5.11 to 7.17.
S1-16(was S1-17)Incidents, complaints and severe human rights impactsReported
Incidents, complaints and severe human rights impacts
Reference: page 95 (Table 12 index entry 95; Appendix B datapoints for paragraph 103(a) indexed to 95 and paragraph 104(a) to 95-95).
Metrics (Table 44, page 95), 2024 to 2025:
| Data point | 2024 | 2025 |
|---|---|---|
| Total number of incidents of discrimination, including harassment, reported | 0 | 0 |
| Number of complaints made through channels available to own employees (including grievance mechanisms) | 0 | 0 |
| Total amount of material fines, penalties and compensation for damages as a result of those incidents and complaints | 0 | 0 |
| Number of severe human rights incidents connected to the undertaking's workforce | 0 | 0 |
| Total amount of fines, penalties and compensation for damages for those incidents | 0 | 0 |
Context (page 95). "F-Secure provides a confidential Whistleblowing Channel, accessible 24/7 to all employees and stakeholders. This platform supports transparent and ethical business conduct by enabling the safe reporting of concerns related to discrimination, harassment, or unfair treatment."
"In alignment with our zero-tolerance policy, we closely monitor and address any incidents of discrimination or harassment across all operations. During the reporting period, there have been no reported work-related incidents of discrimination based on gender, racial or ethnic origin, nationality, religion or belief, disability, age, sexual orientation, or other forms of discrimination involving internal or external stakeholders."
This is a nil return across every S1-17 datapoint for both years.
S4 – Consumers and End-users
S4-1Policies related to consumers and end-usersReported
Policies related to consumers and end-users
Reference: page 98 (Table 12 lists "S4-1 Policies related to consumers and end-users S4-2 - Processes for engaging with consumers and end-users about impacts" at page 98).
Three policies are disclosed in Table 46 (page 98):
- Personal Data Policy - controls and principles for protecting customer privacy, privacy organisation and roles, key privacy principles and processes, privacy training and monitoring, "Based on EU GDPR and relevant privacy regulations". Scope: all employees, leadership, employee-like contractors and suppliers. Responsibility: CEO and leadership team. Linked IROs: evolving threat landscape, cybersecurity, protecting digital moments.
- Cyber Security Policy - objectives for strategic cybersecurity activities, governance practices, information security, privacy and software security management, "Based on ISO 27001 standard". Responsibility: CEO accountable, Chief Information Security Officer for implementation.
- AI Policy - "Encourages innovation with AI applications... Adherence to high standards in privacy, cybersecurity, intellectual property rights, and business integrity". Linked IROs: use of AI in security applications, AI increases risk of security breach.
IROs without a policy (page 98). "The following IROs do not have policies inked to them but are managed as part of F-Secure's business operations: Create awareness about cybercrimes; Channel strategy; Consumer willingness to pay." For cybercrime awareness "Externally reported targets have not been set", but effectiveness is tracked through audience reach, click-through rates, web session volumes, media readership and social following.
Standards (page 99). "F-Secure is certified to ISO 27001:2022 Standard for Information Security Management across all operations", with reference controls including ISO 27001 Annex A, NIST CSF and 800-63B, OWASP Top10, MASV and MASG, ISO 3001:2018 and ISO 22301:2019. "No reported cases of non-respect of UN Guiding Principles on Business and Human Rights, ILO Declaration on Fundamental Principles and Rights at Work, or OECD Guidelines for Multinational Enterprises involving consumers and/or end-users."
S4-2Processes for engaging with consumers and end-users about impactsReported
Processes for engaging with consumers and end-users about impacts
Reference: pages 99-100 (Table 12 index entry 98, combined with S4-1).
Methods (page 99). "The majority of engagements are direct with dialog between F-Secure and consumers, including customer care contacts, app store feedback, and social media feedback. F-Secure requests formal feedback through a continuous product survey process." Partner feedback about their end-users is processed similarly, through "joint customer need surveys, generic feedback from partners' market and consumer surveys, or feedback from their customer care teams".
Stage and frequency (page 99). "The majority of consumer engagement happens after onboarding, once consumers have installed and activated protection services. Daily engagement occurs through the protection app working in the background." "All consumer feedback is consolidated, analyzed, and processed monthly."
Accountability (page 99). "F-Secure's Chief Product Business Officer, part of the Leadership Team reporting directly to the CEO, has operational responsibility for engagement and integration of results into F-Secure's strategy, business model, and daily activities."
Effectiveness (page 99). Tracked through "the number of support cases, NPS (Net Promoter Score), CES (Customer Effort Score), and app store ratings", measured with partners in the Apple App Store and Google Play. "Significant changes in metrics or feedback are investigated with corrective actions taken regardless of channel."
Vulnerable consumers (pages 99-100). "We strive for demographic representation in testing processes to provide a multitude of cultural perspectives"; "No consumer group is excluded in design". "By complying with the European Accessibility Act and W3C accessibility recommendations, F-Secure strives for ease of use for users with various disabilities." A beta community is used "to verify design decisions before product availability to larger audiences".
S4-2(was S4-3)Processes to remediate negative impacts and channels for consumers and end-users to raise concernsReported
Processes to remediate negative impacts and channels for consumers and end-users to raise concerns
Reference: page 100 (Table 12 index entry 100).
Channels (page 100). End-users reach F-Secure through self-help (community forum and chatbot) and assisted (chat and phone) channels, with Customer Care active on social media and app stores:
- Phone support in multiple languages during business hours, English for extended business hours
- Chat support in multiple languages including chatbot, English 24/7
- Email support, with a dedicated address for GDPR requests
- Feedback forms integrated into customer contact cases
- Community and social media channels
"These channels are managed internally by the undertaking to ensure timely and consistent responses." Where channel partners are the first point of contact, "we provide help desk training and maintain open support channels for partner assistance".
Effectiveness (page 100). "F-Secure logs all customer contacts (inquiries and support requests) within a ticketing system to identify trends, track performance metrics, and make data-driven decisions", tracking "ticket volume, resolution time, and customer satisfaction (post-ticket survey) per contact channel". "For common issues, we have monthly internal review and verification processes through the customer experience council with action points to remediate issues and follow up on progress."
Trustworthiness (page 100). All contact channels are publicly available on the web; "Consumers may provide feedback under the whistleblowing policy through a publicly available whistleblowing channel without fear of retaliation". "F-Secure has a complaint process triggered by low post-ticket survey scores and customer requests for contact... Post-complaint surveys measure complaint handling effectiveness." End-users can also report concerns through the whistleblowing channel, which "allows anonymous reporting of Code of Conduct violations including human rights violations" (page 99).
S4-3(was S4-4)Taking action on material impacts on consumers and end-users, and approaches to managing material risks and pursuing material opportunities related to consumers and end-users, and effectiveness of those actionsReported
Taking action on material impacts on consumers and end-users, and approaches to managing material risks and pursuing material opportunities
Reference: pages 101-103 (Table 12 index entry 101-104).
Actions on positive impacts (page 101). Protecting digital moments: "During 2025, we continued to expand our scam protection capabilities and launched a dedicated Scam Protection offering in our Direct Business in May 2025." Creating awareness about cybercrimes: free tools including an identity theft checker, messaging scam analysis and online scanners; an annual Cyber Threats Guide for partners; an annual Cybersecurity Awareness Month Campaign with ready-to-use partner materials; year-round white-labelled content and monthly F-Alert bulletins.
Avoiding negative impacts (page 101). "F-Secure has not identified material negative impacts on consumers and end-users... Our software-based products... are not targeted at children or financially vulnerable individuals." Reviews of support channel effectiveness, whistleblowing reports and product NPS surveys "serve as a further sensor to gauge, if our product would start to have material negative impact(s)". "These activities did not require any material operating expenditures (Opex) and/or capital expenditures 2025."
Opportunities (Table 47, page 102). Evolving threat landscape - redirecting resourcing into research, innovation and product creation around scam protection, upgrading channel partners to versions with scam protection.
Risks (Table 48, page 102). Five risks with 2025 mitigations: consumer willingness to pay decline; channel strategy risks; security of suppliers and partners ("Security review gateways in procurement process, contractual security requirements enforcement, regular security audits of critical vendors", expected outcome 100% coverage for critical suppliers); cybersecurity attacks (ISO 27001 implementation, proactive monitoring, vulnerability management, crisis rehearsals; expected outcome 0 critical security incidents).
Human rights (page 103). "F-Secure has zero (0) human rights issues or incidents connected to consumers during 2025."
Resources (page 103). Product Management and Technology, and Marketing and Content Creation, with the Product Board governing prioritisation.
S4-4(was S4-5)Targets related to managing material negative impacts, advancing positive impacts, and managing material risks and opportunitiesReported
Targets related to managing material negative impacts, advancing positive impacts, and managing material risks and opportunities
Reference: pages 104-106 (Table 12 index entry 104-106).
Targets and progress (Table 49, page 104):
| Target | Baseline 2023 | 2024 | 2025 | 2030 target |
|---|---|---|---|---|
| F-Secure consumer product NPS (Total) | 49 | 49 | 52 | 55 |
| Partner Business NPS | 56 | 63 | 55 | Above 55 |
| Completion rate of internal cyber security training | baseline 2024 | 95% | 94% | 98% (all employees) |
| Number of major cyber security incidents | 2 (no customer data compromised) | 1 (no customer data compromised) | 0 | 0 incidents involving leaked customer personal data |
Commentary (pages 105-106). The consumer product NPS target applies to F-Secure Total in the Direct Business: "The F-Secure Total NPS target for 2027 is 50 and 55 for 2030. The 2025 outcome for product NPS is 52." On partner NPS: "F-Secure's global NPS survey outcome in 2025 was 55. We expect our NPS score to remain above 55." On training: "We have set a 2030 target of reaching a training completion rate of over 98%. For 2025, the training completion outcome was 94%." On incidents: "In 2023, F-Secure had two major incidents but neither of them impacted customer data. For 2024, our outcome was 1... In 2025 our outcome was 0."
Limitations acknowledged (pages 105-106). "The target measurement is not completely absolute since it is dependent on human assessment of the incident. This shortcoming is mitigated by having multiple security team members review all incidents."
Metric dropped (pages 29, 106). The "Ratio of externally reported vulnerabilities compared to internally reported vulnerabilities" was dropped from the S4 targets "due to data quality issues affecting annual comparability" and is now tracked internally only.
Restatement (page 29). "The 2024 cybersecurity training completion rate initially excluded employees on extended leave. This has been corrected in 2025, and the 2024 cybersecurity training completion rate has been updated to include all employees" (from 97% to 95%).
G1 – Business Conduct
G1-1Business conduct policies and corporate cultureReported
Business conduct policies and corporate culture
Reference: pages 109-111 (Table 12 index entry 110-111).
Culture (page 109). "Our culture is called 'Fellowship' and it includes four values: 1) Keep focus, 2) I make a difference, 3) Just do it, and 4) Dare to care." Key actions: a Leadership Academy launched in 2023, with "our goal is to strengthen our 'ready-now' leadership succession pipeline to 65% by the end of 2026"; a Leadership Lab for approximately 90 Team Leaders, organised quarterly in 2025; team performance dynamics work where "We expect Talent Density... to grow to 50% by the end of 2025 and the results will be available in March 2026"; and employee lifecycle process review, through which "voluntary attrition remained under 12%". Culture is tracked through biannual Fellow surveys with an eNPS goal of 50 by end of 2030.
Policies (Table 51, page 110). Three policies, all owned by the General Counsel and approved by the Board of Directors: the Code of Conduct (ethical principles, values, expected behaviours, anti-corruption standards and reporting procedures); the Anti-Bribery and Corruption Policy (prohibited conduct, gifts, conflicts of interest, third-party due diligence, compliance and enforcement, "Based on the UN Convention Against Corruption"); and the Whistleblowing Policy (reporting channels, investigation procedures, confidentiality and anti-retaliation).
Whistleblower protection (page 110). Protections are provided "in accordance with Directive (EU) 2019/1937", including identity protection, protection from retaliation with possible reversal of the burden of proof, compensation and remedies, and possible protection against civil, criminal and administrative liability.
Training (page 111). "Our Code of Conduct training is mandatory for all employees, including specific modules on anti-corruption and reporting procedures. New employees complete this during onboarding, with refresher training required every two years. This training covers 100% of high-risk functions, particularly sales and procurement teams."
The Code of Conduct and Whistleblowing Policy are publicly available on the F-Secure website.
G1-2(was G1-3)Prevention and detection of corruption and briberyReported
Prevention and detection of corruption and bribery
Reference: pages 111-112 (Table 12 index entry 111-112 under the heading "G1-3 Prevention and detection of corruption or bribery"; the report's own section heading is "G1-3 Procedures to address corruption and bribery").
Reporting routes (page 111). "Employees who suspect policy violations can report through multiple channels: speaking to managers, Legal, or HR; using our whistleblowing channel; or writing to the CEO or Board. We guarantee a confidential review of all reports and protect whistleblowers from retaliation."
Controls (page 111). "We require an accurate recording of all financial transactions involving F-Secure expenses or asset transfers. Our expense management systems maintain proper documentation and transparency. The effectiveness of our anti-corruption efforts is monitored through regular audits and reviews that identify and address risk areas or compliance issues." "No action plans require significant capital expenditure (CapEx) or operating expenditure (OpEx), and all actions are funded through normal business operations."
Independence of investigations (page 111). "When investigating suspected incidents, we ensure investigators are separate from the management chain involved in the matter. Substantiated investigations involving corruption or bribery are reported to the Audit Committee, with outcomes communicated to relevant management bodies and to authorities when legally required."
Training (page 111). "F-Secure's anti-corruption training is mandatory for all employees, with particular focus on high-risk functions. This comprehensive training ensures 100% coverage of functions at risk, particularly those in sales and procurement, as well as our executive management, including the Leadership Team."
The two material corruption and bribery IROs are the partnership business use of agents and intermediaries, and anti-bribery risk arising from M&A transactions (Table 50, page 108).
G1-3(part of MDR-T/GDR-T disclosures)Targets related to business conductReported
Targets related to business conduct (part of MDR-T/GDR-T disclosures)
Back-filled from the G1 metrics and targets section (page 112), where this content is disclosed in the FY2025 report. This disclosure requirement did not exist as a numbered DR under the 2023 ESRS the statement was prepared against; business conduct targets fell under MDR-T.
Targets (Table 52, page 112). "F-Secure has established two targets related to business conduct":
| Target | Baseline 2023 | 2024 | 2025 | 2030 target |
|---|---|---|---|---|
| Zero-tolerance on bribery and corruption | 0 incidents | 0 incidents | 0 incidents | 0 incidents |
| Code of conduct training target | baseline is 2024 | 96% | 96% | 98% (permanent and fixed-term employees) |
Zero-tolerance target (page 112). "Our zero-tolerance target is based on our Code of Conduct principles and Anti-Bribery and Corruption Policy. Both... have been approved by F-Secure's Board of Directors. The target applies to all F-Secure operations globally... The performance against this target is monitored by reviewing the number of corruption and/or bribery-related incidents reported through the whistleblowing channel or to line managers, the CEO, the HR team, the Legal team, or the Board of Directors. The target is absolute... With zero incidents since our 2023 baseline, we are on track to maintain this performance through 2030."
Training target (page 112). "With 2024 as our baseline year, we've achieved 96% completion, working toward our 2030 target of 98%. The General Counsel, together with the Leadership Team, has set this target. This target acknowledges practical limitations like recent hires and employees on extended leave. We monitor performance through our Learning Academy platform and implement targeted follow-up for non-completions. The reported Code of Conduct training target includes permanent and fixed-term employees and excludes individuals for whom employee status information is unavailable" (see also page 29).
G1-4Incidents of corruption or briberyReported
Incidents of corruption or bribery
Reference: page 112 (Table 12 index entry 112-112; Appendix B datapoints for paragraph 24(a) fines and paragraph 24(b) standards both indexed to page 112).
Metrics (Table 53, page 112):
| Data point | 2024 | 2025 |
|---|---|---|
| Number of convictions and amount of fines for violations of anti-corruption and anti-bribery laws | 0 | 0 |
Statement (page 112). "F-Secure reports zero convictions and zero fines for violations of anti-corruption and anti-bribery laws during 2025. As there have been no known breaches in anti-corruption procedures or standards, we have not needed to take remedial actions."
This is a nil return for both years, consistent with the zero-tolerance target which records 0 incidents at the 2023 baseline and in each of 2024 and 2025 (Table 52, page 112).
Compliance scope is stated with the target: "F-Secure is committed to complying with all laws and regulations that apply to our business activities around the world, including but not limited to the Foreign Corrupt Practices Act (FCPA) and the UK Bribery Act 2010" (page 112).
Investigation and escalation arrangements sit under G1-3: investigators are separate from the management chain involved, and substantiated corruption or bribery investigations are reported to the Audit Committee (page 111).