Trustworthy email communication at acib
- Legal framework and mandatory information (signature)
- Protection of sender identity (authentication).
- Threat defence (anti-malware & fraud)
- Classification and information labelling
- Encryption and data security
- Secure data transfer instead of email attachments
- Mass mailings and newsletters
- Handling external information and forwarding requests
- Central contact points and availability
- Legally secure delivery and signature
- Security information for recipients (precautionary measures)
- Security awareness and training
- Joint security responsibility in the research network (NISG)
- Archiving and data protection
Legal framework and mandatory information (signature)
- Exclusive use of the official domain: All official and legally valid email communication from acib GmbH is sent exclusively from addresses ending in @acib.at. Messages from other domains (e.g. freemail providers) on behalf of acib GmbH should be considered potentially fraudulent.
- Project-specific domains: In the context of specific collaborations, research consortia or funding projects, separate, project-specific domains may also be used. An overview of domains managed or used by acib can be found under section 1
- Legal validity: Conventional emails do not constitute legally binding obligations for acib GmbH unless they have been digitally signed (QES) or transmitted via dedicated, secure channels.
- Legal requirements (UGB & GDPR): In accordance with Section 14 of the Austrian Commercial Code (UGB) and the information requirements of the EU General Data Protection Regulation (GDPR), every business email sent by acib GmbH must contain a standardised signature disclaimer. This reads as follows: This email is sent on behalf of acib GmbH, Krenngasse 37, 8010 Graz, AUSTRIA. acib GmbH is incorporated under Austrian law and registered at LG für ZRS Graz, company register no. 224687y, VAT no. ATU 54545504. acib uses personal data (contact data, data about professional qualifications) for current and future business collaborations, and will retain such data for the duration of our business relationship and beyond as far as necessary for documentation purposes. Legal basis: Article 6 (1) b) and f) EU GDPR. Further information about acib and its legal status can be found at www.acib.at/imprint/. General information about privacy protection at acib can be found at www.acib.at/data_protection/.
Protection of sender identity (authentication).
- SPF (Sender Policy Framework): We specify which servers are authorised to send emails on our behalf.
- DKIM (DomainKeys Identified Mail): Every outgoing email receives a digital signature that ensures its integrity during transport.
- DMARC (Domain-based Message Authentication): We use a strict DMARC policy to prevent unauthorised use of our domain (spoofing) and to give recipient systems clear instructions on how to handle suspicious emails.
Threat defence (anti-malware & fraud)
- Spam & phishing protection: Incoming messages are automatically scanned for malicious links, attachments and phishing attempts.
- Fraud prevention (anti-fraud): We use mechanisms to detect identity theft (e.g. CEO fraud) to protect our employees and partners from targeted social engineering attacks.
- Safe Links & Safe Attachments: Incoming file attachments are checked for malicious code in a secure, isolated cloud environment (sandbox) before they are delivered. Similarly, URLs contained in emails are dynamically checked for malicious targets at the time of clicking (time-of-click protection).
- Zero-day threat protection: By using AI-powered threat analysis within the Microsoft infrastructure, we also identify and block new, as yet unknown attack patterns in real time before they reach our systems.
- Automated quarantine and incident response: Suspicious messages that indicate advanced threats are automatically isolated. Our IT security team receives immediate alerts to proactively analyse potential security incidents and initiate company-wide countermeasures.
Note on document transmission: To prevent the introduction of malware through malicious macros (e.g. ransomware), our email gateway blocks the receipt of outdated Office file formats (especially .doc and .xls) on the server side. We urge our communication partners to use only current, secure file formats (such as .docx, .xlsx or .pdf) for document exchangecontrols or complex patent disputes.
Regardless of this, we would like to point out that confidential documents should never be sent as email attachments. On request, we are happy to provide upload options to our system. An upload box can be requested at short.acib.at/secureupload.
Classification and information labelling
- Email labels (Traffic Light Protocol): Outgoing messages are assigned specific confidentiality labels (TLP:CLEAR, GREEN, AMBER, AMBER+, RED) by our employees depending on the criticality of the content. This labelling is not to be understood as a mere recommendation, but defines the strict limits of information disclosure. A detailed overview and binding definition of the labels used and the associated rules of use can be found at “Encryption and data security“.
- Automated disclaimers and protection of trade secrets: Based on the selected label, our system automatically adds legal notices and confidentiality clauses (disclaimers) to messages. We expressly point out that these disclaimers are legally binding. They serve to actively protect our trade secrets and the intellectual property of our research partners.
Encryption and data security
- Transport encryption (TLS): By default, every email is transmitted via an encrypted connection (TLS 1.2 or higher).
- Increased protection (TLP:AMBER+STRICT): For highly sensitive data, we enforce the AMBER+STRICT encryption level. In these cases, delivery is only carried out if a highly secure, verified connection to the recipient is guaranteed. Furthermore, only authenticated recipients can receive the message. To open classified documents of this confidentiality level, authentication with acib is required. If a document cannot be opened, please request authentication from acib in the acib tenant.
- Highest protection (TLP:RED): For the TOP SECRET confidentiality level, emails are encrypted and can only be opened by the recipient. Forwarding, even within the recipient’s organisation, is not possible.
- Individual encryption (Microsoft Purview Message Encryption): We provide our employees with Microsoft encryption for the flexible and secure exchange of sensitive information at an individual level. By selecting the ‘Encrypt’ option in the email client, messages can be protected in such a way that the recipient must authenticate themselves before reading (e.g. via a one-time passcode or Microsoft account).
- End-to-end encryption (S/MIME): S/MIME offers certificate-based end-to-end encryption, in which emails are digitally signed and encrypted. This technology is only supported by acib GmbH in specific, highly regulated projects, as it requires the prior exchange of personal certificates between the communication partners.
Secure data transfer instead of email attachments
- Secure file sharing (SharePoint / OneDrive links): Instead of physical file attachments, we send secure, temporary access links from our SharePoint environment as standard. In order to verify external recipients beyond doubt, these links are usually protected by guest authentication (e.g. by means of a one-time passcode sent to the email address) and automatic expiry dates. This ensures that documents remain centrally located in one place (‘single source of truth’) and that we can control access rights (e.g. read or edit rights) at any time and revoke them immediately if necessary.
- Temporary upload boxes for partners: We provide dedicated upload boxes in our SharePoint environment for the secure receipt of large amounts of data or sensitive documents from external communication partners. This eliminates the risky detour via email inboxes.
- Requesting data transfers: If you, as an external partner, would like to send us confidential data, simply ask your acib contact person for a personalised upload link or request a secure file box yourself at short.acib.at/secureupload.
Mass mailings and newsletters
- Central newsletter dispatch (Mailchimp): We exclusively use the certified external service provider Mailchimp for our information services, event invitations and newsletters. This ensures that high technical delivery standards are maintained and that the server load of our own systems is not affected.
- Protection of domain reputation: By strictly separating regular project correspondence (via M365) and mass mailings (via Mailchimp), we preventively prevent our primary company domain (@acib.at) from ending up on global blacklists or our regular business emails from being incorrectly classified as spam by recipient systems.
- GDPR compliance (registration and objection): Marketing emails are only sent to recipients who have given their express prior consent (double opt-in) or with whom we have an existing business relationship. Every message sent via Mailchimp must contain a clearly visible link for immediate, automated unsubscription (opt-out).
- Privacy policy: All information on the processing of personal data in the context of our newsletter distribution, the legal basis and the right of withdrawal is transparently regulated in our dedicated privacy policy under reference to DSE Newsletter.
Handling external information and forwarding requests
- No forwarding of advertising and job offers: External advertising mailings, product placements, service offers and non-industry-specific or general job advertisements (job offers) from third-party companies are generally not distributed via our internal channels. We ask external senders to refrain from sending such mailings, as they will be filtered and discarded without exception.
- Targeted information sharing: However, we are happy to review incoming information on relevant research funding, subject-specific calls for proposals, scientific conferences or industry-related events. If these are of recognisable value to our research and project work, they will be curated by the relevant department and made available to interested employees via our internal dashboards (not via mass email).
Central contact points and availability
| General enquiries and information | office@acib.at |
| Legal Questions | legal@acib.at |
| Questions about invoices and accounting | accounting@acib.at |
| Billing and Controlling | controlling@acib.at |
| Questions about deliveries and orders | procurement@acib.at |
| Questions about projects and collaborations (scientific collaboration) | scico@acib.at |
| Questions about (new) project collaborations and solutions (business development) | bd@acib.at |
| Questions about publications and open access | publications@acib.at |
| Questions about the COMET program | comet@acib.at |
| Questions about esib - European Summit for Industrial Biotechnology | esib@acib.at |
| Questions about LifeIsScience - European Long Night of Research | lis@acib.at |
| Questions about events, webinars, and functions | events@acib.at |
| Personnel matters | personal@acib.at |
| Inquiries from applicants | jobs@acib.at |
| Occupational safety | safety@acib.at |
| Information and system security | security@acib.at |
| Data protection questions | privacy@acib.at |
| Inquiries under the Freedom of Information Act | ifg@acib.at |
| Press inquiries | pr@acib.at |
| Questions about newsletters and mailings | editorial@acib.at |
| Technical IT questions | it@acib.at |
| Technical questions email | postmaster@acib.at |
| Email abuse (spam, phishing) | abuse@acib.at |
| Technical questions about domain issues and DNS registration | hostmaster@acib.at |
| Homepage inquiries | webmaster@acib.at |
| Compliance questions, Compliance Board | compliance@acib.at |
| Ombudsman for Scientific Integetriy | research-integrity@acib.at |
| Equal Treatment Officer | equality@acib.at |
| CEO Bureau | gef@acib.at |
| Works Council | betriebsrat@acib.at |
| Contact for committee members | gremien@acib.at |
| Sender address for system information (no reply possible) | no-reply@acib.at |
Legally secure delivery and signature
- Communication with authorities (e-delivery / MeinPostkorb): We use the electronic delivery system for legally effective and timely exchanges with Austrian offices and authorities. This replaces traditional RSa and RSb letters. acib GmbH retrieves and sends these centrally via the Enterprise Service Portal (USP) using ID Austria.
- Verifiable business mail (eBrief): Digital letter delivery (e.g. eBrief from Austrian Post) is used for the certified dispatch of important documents to partners or companies that are not connected to the official e-delivery system. This ensures a high level of security and traceability during transport.
- Contract signing (DocuSign & PDF signatures): A secure transport route does not replace a legally binding signature. For contracts and legally binding documents, acib GmbH uses dedicated electronic signature workflows (such as DocuSign or certified Adobe signatures). Such documents may only be sent for digital signature after mandatory prior review and approval by the legal department (legal@acib.at).
Strict adherence to these specified delivery and signature methods is essential to ensure the legal validity of our contracts and our correspondence with authorities beyond any doubt. This effectively protects acib GmbH from legal disadvantages, missed deadlines or invalid agreements due to formal errors. The use of private or non-IT-approved signature and delivery services (so-called shadow IT) for business purposes is strictly prohibited for compliance and data protection reasons. If you are unsure about the correct transmission method or the formal requirements for a signature, you must consult the legal department (legal@acib.at) in advance.
Security information for recipients (precautionary measures)
- Reinsurance in case of suspicion: If in doubt, contact your contact person at acib GmbH via a second channel (e.g. telephone) to verify the authenticity of a request.
No password requests: We will never ask you to disclose passwords or access data via email. We use secure systems such as 1Password or encrypted messages to communicate or share passwords. - Confidentiality in subject lines: We take care not to include sensitive information in the subject line of an email, as for technical reasons this can often be transmitted unencrypted or stored in logs.
- No last-minute changes to bank details by email: acib GmbH will never ask you exclusively by email (without prior personal consultation) to make transfers to changed or new bank accounts. If you receive such payment requests, please contact our finance department at accounting@acib.at or by telephone, or compare the details with those published on our homepage under Reference to accounting.
- Be wary of unexpected links and requests: Be suspicious of emails that appear to come from acib GmbH but create unusually high time pressure (e.g. ‘Urgent review required’) or unexpectedly ask you to click on external links or enter login details on a website.
- Check the sender’s address: Do not rely solely on the name of the sender displayed. For unexpected messages, always check the actual email address (behind the name) to ensure that the message actually originates from an @acib.at domain and not from a similar-looking fake (e.g. @acib.com or @aclb.at).
Security awareness and training
- Mandatory employee training: All employees (including guest researchers and administrative staff) participate in mandatory security awareness training upon joining the company and as part of regular refresher courses. These courses impart essential knowledge for the early detection of phishing, spear phishing, ransomware attacks and social engineering tactics (such as CEO fraud).
- Active phishing simulations: To continuously review and sharpen our security awareness, we conduct internal, unannounced phishing simulations at irregular intervals. These serve purely as training exercises and help us to identify weaknesses in the detection process and provide targeted retraining.
- Reporting culture (phishing button): We promote a proactive reporting culture (see something, say something). Every email client in our Microsoft tenant is equipped with a special ‘phishing report button’. Employees are encouraged to immediately forward suspicious messages to the IT security team for analysis at the touch of a button, rather than simply deleting or ignoring them.
- Incident response management: Should a security incident nevertheless occur (e.g. a malicious link clicked or compromised access data), our clearly defined incident response processes come into effect. Affected employees are obliged to report incidents immediately and without fear of sanctions to security@acib.at <security@acib.at> in order to ensure rapid containment, isolation of affected systems and transparent information for any partners.
Joint security responsibility in the research network (NISG)
Rejection of insufficiently secured messages (DMARC/SPF/DKIM): In order to protect our systems from spoofing and phishing, acib GmbH strictly checks incoming emails for compliance with current email authentication standards (SPF, DKIM and DMARC). We do not guarantee delivery of messages sent from mail servers with no or insufficiently configured authentication entries. Such emails may be automatically rejected (Rejected) or moved to quarantine by our security systems.
We ask our communication partners to secure their email infrastructure in accordance with current best practices in order to ensure smooth communication.
Archiving and data protection
- Audit-proof and unalterable archiving: In accordance with the provisions of the Austrian Commercial Code (UGB § 212) and the Federal Tax Code (BAO), all incoming and outgoing business emails (including attachments) are archived automatically, completely and in an audit-proof manner. The archiving solution used ensures that messages cannot be manipulated retrospectively or deleted before the expiry of the statutory retention periods (usually 7 years, often longer for specific research projects).
- Data protection (GDPR) and data subject rights: In the course of email communication, acib GmbH inevitably processes personal data (e.g. names, contact details, communication content). This processing is carried out on the basis of our legitimate interest and for the purpose of fulfilling contracts (Art. 6 (1) (b) and (f) GDPR). For detailed information on data processing, storage periods and your rights as a data subject (such as information, deletion or restriction), please refer to our comprehensive privacy policy at reference to DSE email.
- Exclusion of private use: In order to avoid conflicts between the company’s archiving obligations and telecommunications secrecy or the privacy of employees, the use of work acib email addresses for private purposes is prohibited. Incoming messages are always treated as business correspondence and processed and archived in accordance with the above guidelines.