| General disclosure |
| GRI 2‑1 | Organizational details | The main legal entity in the Russian Federation is the AO Kaspersky Lab. The organization's headquarters are located at: 39A/2 Leningradskoe Shosse, Moscow, 125212, Russian Federation Legal information: https://www.kaspersky.com/legal | |
| GRI 2‑2 | Entities included in the organization's sustainability reporting | | Appendix 1
Appendix 9 |
| GRI 2‑3 | Reporting period, frequency and contact point | Report publication date: June 23, 2026 | Appendix 1 |
| GRI 2‑4 | Restatement of information | Some employee data for 2023 was recalculated due to the updating of employees' personal data, the transition to new accounting systems, and the adjustment of calculation methods. In each such instance, a corresponding note is included in the text. | |
| GRI 2‑5 | External assurance | The report has not been certified by an external entity. | |
| GRI 2‑6 | Activities, value chain and other business relationships | | Business model
Products
Sustainable supply chain |
| GRI 2‑7 | Employees | | Human resources management
Appendix 4 |
| GRI 2‑8 | Workers who are not employees | All workers at Kaspersky the Company’s employees. | |
| GRI 2‑9 | Governance structure and composition | | Sustainable Development Management System
Corporate governance |
| GRI 2‑10 | Nomination and selection of the highest governance body | | Corporate governance |
| GRI 2‑11 | Chair of the highest governance body | | Corporate governance |
| GRI 2‑12 | Role of the highest governance body in overseeing the management of impacts | | Sustainable Development Management System |
| GRI 2‑13 | Delegation of responsibility for managing impacts | | Corporate governance |
| GRI 2‑14 | Role of the highest governance body in sustainability reporting | The information in the Sustainability Report is approved by representatives of the relevant departments, the legal department, and the public relations department. | |
| GRI 2‑15 | Conflicts of interest | | Business ethics and anti‑corruption measures |
| GRI 2‑16 | Communication of critical concerns | The board of directors is notified of critical issues by representatives of relevant departments via email or during emergency face‑to‑face meetings. | |
| GRI 2‑17 | Collective knowledge of the highest governance body | | Corporate governance |
| GRI 2‑18 | Evaluation of the performance of the highest governance body | | Corporate governance |
| GRI 2‑19 | Remuneration policies | At the time this report was prepared, Kaspersky's remuneration policy did not account for the effectiveness of managing Kaspersky's impact on the economy, society and the environment. | |
| GRI 2‑20 | Process to determine remuneration | The information is not disclosed due to limitations imposed by Kaspersky's internal confidentiality policy. | |
| GRI 2‑21 | Annual total compensation ratio | The information is not disclosed due to limitations imposed by Kaspersky's internal confidentiality policy. | |
| GRI 2‑22 | Statement on sustainable development strategy | | Statement from the CEO |
| GRI 2‑23 | Policy commitments | | Sustainable Development Management System
Respect for human rights |
| GRI 2‑24 | Embedding policy commitments | | Sustainable Development Management System
Respect for human rights
Business ethics and anti‑corruption measures |
| GRI 2‑25 | Processes to remediate negative impacts | | Sustainable Development Management System
Business ethics and anti‑corruption measures
Safeguarding users' trust |
| GRI 2‑26 | Mechanisms for seeking advice and raising concerns | | Business ethics and anti‑corruption measures |
| GRI 2‑27 | Compliance with laws and regulations | During the reporting period, Kaspersky identified no instances of non‑compliance with laws or regulations, and the Company did not incur any fines or other penalties for violations of the law. | |
| GRI 2‑28 | Membership associations | | Appendix 3 |
| GRI 2‑29 | Approach to stakeholder engagement | | Interaction with stakeholders |
| GRI 2‑30 | Collective bargaining agreements | Kaspersky does not have a collective bargaining agreement. | |
| Material topics |
| GRI 3‑1 | Process to determine material topics | | Appendix 3 |
| GRI 3‑2 | List of material topics | | Appendix 3 |
| Economic performance |
| GRI 201‑1 | Direct economic value generated and distributed | | Key results |
| Market presence |
| GRI 202‑2 | Proportion of senior management hired from the local community | | The proportion of senior management hired from among the local population is 100%. |
| Indirect economic impacts |
| GRI 203‑1 | Infrastructure investments and services supported | | Sustainable Development Management System
Support beyond the digital world |
| GRI 203‑2 | Significant indirect economic impacts | | Sustainable Development Management System
Support beyond the digital world |
| Procurement practices |
| GRI 204‑1 | Proportion of spending on local suppliers | | Sustainable supply chain |
| Anti‑corruption |
| GRI 205‑1 | Operations assessed for risks related to corruption | | Business ethics and anti‑corruption measures |
| GRI 205‑2 | Communication and training about anti‑corruption policies and procedures | | Business ethics and anti‑corruption measures |
| GRI 205‑3 | Confirmed incidents of corruption and actions taken | | Business ethics and anti‑corruption measures |
| Energy |
| GRI 302‑1 | Energy consumption within the organization | | We improve energy efficiency |
| GRI 302‑4 | Reduction of energy consumption | | We improve energy efficiency |
| Water and effluents |
| GRI 303‑1 | Interactions with water as a shared resource | | We optimize water use |
| GRI 303‑2 | Management of water discharge‑related impacts | Kaspersky does not have approved wastewater quality standards, because it does not discharge water into natural water bodies. | We optimize water use |
| GRI 303‑3 | Water withdrawal | | We optimize water use |
| Emissions |
| GRI 305‑1 | Direct (Scope 1) GHG emissions | We are developing a methodology for collecting data and calculating the total amount of direct (Scope 1) greenhouse gas emissions for all Kaspersky facilities. This data will be presented in subsequent reports. | |
| GRI 305‑2 | Energy indirect (Scope 2) GHG emissions | We are developing a methodology for collecting data and calculating total indirect (Scope 2) greenhouse gas emissions from energy use. This data will be presented in subsequent reports. | |
| GRI 305‑3 | Other indirect (Scope 3) GHG emissions | | We reduce our carbon footprint |
| GRI 305‑5 | Reduction of GHG emissions | | We reduce our carbon footprint |
| GRI 305‑6 | Emissions of ozone‑depleting substances (ODS) | Kaspersky does not emit ozone‑depleting substances. | |
| GRI 305‑7 | Nitrogen oxides (NOX), sulfur oxides (SOX), and other significant air emissions | Kaspersky does not emit the specified pollutants into the atmosphere. | |
| Waste |
| GRI 306‑1 | Waste generation and significant waste‑related impacts | | We manage waste generation |
| GRI 306‑2 | Management of significant waste‑related impacts | | We manage waste generation |
| GRI 306‑3 | Waste generated | | We manage waste generation |
| GRI 306‑4 | Waste diverted from disposal | | We manage waste generation |
| GRI 306‑5 | Waste directed to disposal | | We manage waste generation |
| Employment |
| GRI 401‑1 | New employee hires and employee turnover | | Human resources management
Appendix 4 |
| GRI 401‑2 | Benefits provided to full‑time employees that are not provided to temporary or part‑time employees | | Our incentive system |
|
401-3
| Parental leave | | Appendix 4 |
| Occupational health and safety |
| GRI 403‑1 | Occupational health and safety management system | Within the scope of disclosure in this report, the occupational health and safety management system at all Kaspersky offices complies with the requirements of current labor legislation in the territories where Kaspersky operates. It includes regular employee training and regular special assessments of workplaces in all departments, a risk management and accident investigation system, and the organization of events to improve working conditions. The key performance indicator is the absence of workplace injuries. | Occupational health and safety |
| GRI 403‑2 | Hazard identification, risk assessment, and incident investigation | | Occupational health and safety |
| GRI 403‑4 | Worker participation, consultation, and communication on occupational health and safety | | Occupational health and safety |
| GRI 403‑5 | Worker training on occupational health and safety | | Occupational health and safety |
| GRI 403‑6 | Promotion of worker health | | Occupational health and safety |
| GRI 403‑8 | Workers covered by an occupational health and safety management system | The occupational health and safety management system covers all Kaspersky employees. | |
| GRI 403‑9 | Work‑related injuries | | Occupational health and safety |
| GRI 403‑10 | Work‑related ill health | During the reporting period, no cases of work‑related illnesses were recorded at the Company. | |
| Training and education |
| GRI 404‑1 | Average hours of training per year per employee | | Employee development |
| GRI 404‑2 | Programs for upgrading employee skills and transition assistance programs | | Employee development |
| GRI 404‑3 | Percentage of employees receiving regular performance and career development reviews | | Employee development |
| Diversity and equal opportunity |
| GRI 405‑1 | Diversity of governance bodies and employees | | Equal opportunities
Appendix 4 |
| GRI 405‑2 | Ratio of basic salary and remuneration of women to men | | Equal opportunities |
| Non‑discrimination |
| GRI 406‑1 | Incidents of discrimination and corrective actions taken | No cases of discrimination were identified during the reporting period. | Respect for human rights |
| Child labor |
| GRI 408‑1 | Operations and suppliers at significant risk for incidents of child labor | Kaspersky does not use child labor. Kaspersky also does not have any suppliers that are at risk of using child labor. | |
| Forced or compulsory labor |
| GRI 409‑1 | Operations and suppliers at significant risk for incidents of forced or compulsory labor | The company does not use forced or compulsory labor. Kaspersky also does not have any suppliers at risk of using forced labor. | |
| Local communities |
| GRI 413‑1 | Operations with local community engagement, impact assessments, and development programs | During the reporting period, Kaspersky implemented community engagement programs in Russia, Spain, Italy, Japan, India, South Africa, Singapore and Malaysia. | Social and charitable projects |
| Customer privacy |
| GRI 418‑1 | Substantiated complaints concerning breaches of customer privacy and losses of customer data | | Safeguarding users' trust |