Cybersecurity Policy
1. Purpose
This policy establishes the company’s minimum expectations for protecting its systems, accounts, devices, data, services, and business operations from cybersecurity threats.
Cybersecurity is a shared business responsibility. All employees, contractors, managers, administrators, and third parties with access to company systems or data are expected to follow the requirements that apply to them.
The objective is to reduce cyber risk while allowing the company to operate effectively.
2. Scope
This policy applies to:
- Company employees
- Contractors and temporary workers
- Directors and managers
- Company-owned and company-managed devices
- Personal devices approved for company use
- Company networks
- Email and collaboration systems
- Cloud and SaaS services
- Business applications
- Websites and domains
- Company data
- Customer and employee data
- Third parties with access to company systems or information
3. Cybersecurity Ownership
The company will assign an individual responsible for coordinating cybersecurity activities.
Leadership remains responsible for ensuring appropriate resources, priorities, and authority are provided.
System, data, and business process owners are responsible for the security of the assets under their control.
Employees are responsible for following company security requirements and reporting suspicious activity or mistakes promptly.
4. Identity and Access
Access to company systems must be based on business need.
The company should:
- Use individual user accounts wherever practical.
- Apply least privilege.
- Require MFA for important systems and high-risk accounts.
- Control administrator and privileged access.
- Avoid unnecessary shared accounts.
- Review access regularly.
- Remove access promptly when employees, contractors, or vendors leave or no longer require it.
Passwords and authentication credentials must not be shared unless an approved business process specifically requires controlled credential sharing.
5. Devices and Systems
Company systems and devices should be securely configured and maintained.
The company should:
- Use supported operating systems and applications.
- Apply security updates within appropriate timeframes.
- Use endpoint protection where appropriate.
- Restrict unnecessary administrator rights.
- Enable device locking.
- Use encryption where appropriate.
- Remove or replace unsupported systems where practical.
- Employees must not disable security controls without authorization.
6. Data Protection
Company and customer information must be handled according to its sensitivity.
Employees should:
- Use approved systems for storing and sharing company data.
- Avoid personal email or personal cloud storage for company information.
- Check recipients before sending sensitive information.
- Restrict public sharing.
- Report accidental disclosure quickly.
- Sensitive information should only be accessible to people who require it.
7. Email, Internet, and SaaS Use
Employees should use company-approved email, cloud, SaaS, messaging, and collaboration services.
Suspicious messages, unexpected attachments, fake login pages, unexpected MFA prompts, and unusual requests should be reported promptly.
New software, SaaS services, browser extensions, or AI tools that will handle company information should be approved before use where required by company procedure.
8. Backup and Recovery
Important company data and systems must be backed up according to business need.
Backups should:
- Run on an appropriate schedule
- Be monitored for failures
- Be protected from unauthorized deletion or modification
- Be retained for an appropriate period
- Be tested periodically through restoration
- Recovery priorities should be documented for critical business systems
9. Logging and Monitoring
The company should maintain sufficient security visibility for important systems.
This may include:
- Account sign-ins
- Administrator activity
- Endpoint security alerts
- Email security alerts
- Remote access
- Cloud activity
- Backup failures
- Critical configuration changes
- Internet-facing systems
Security alerts must be directed to someone responsible for reviewing and escalating them.
10. Vendor and Third-Party Security
Third-party access should be limited to what is required.
Where practical:
- Vendors should use named accounts.
- MFA should be required.
- Access should be reviewed.
- Unused access should be removed.
- High-risk vendor access should be approved.
- Third-party cybersecurity responsibilities should be documented.
11. Cybersecurity Incident Reporting
Employees must report suspected cybersecurity incidents or mistakes promptly.
Examples include:
- Suspicious emails
- Unexpected MFA prompts
- Lost devices
- Malware warnings
- Password compromise
- Data sent to the wrong person
- Payment fraud attempts
- Unusual system behavior
Employees should not hide security mistakes or attempt their own investigation unless instructed to do so.
12. Incident Response
The company will maintain a basic incident response process covering:
- Incident ownership
- Triage
- Evidence preservation
- Containment
- Communication
- Escalation
- Eradication
- Recovery
- Review
Serious incidents should be escalated to appropriate technical, legal, insurance, management, or external response support.
13. Security Awareness
Employees should receive practical cybersecurity training appropriate to their role.
Training should include:
- Phishing
- Passwords and MFA
- Data handling
- Fraud and impersonation
- Device security
- Incident reporting
Higher-risk teams should receive additional training relevant to their responsibilities.
14. Exceptions
Exceptions to this policy should be documented and approved by an appropriate owner.
Significant exceptions should include:
- Reason for the exception
- Risk created
- Temporary controls
- Risk owner
- Approval
- Review or expiry date
15. Review
This policy should be reviewed at least annually and after significant changes, major incidents, or material changes in business risk.
Practical Rule
Cybersecurity controls should be proportionate to the risk, but important risks should never remain unowned or ignored.