Cybersecurity Policy

1. Purpose

This policy establishes the company’s minimum expectations for protecting its systems, accounts, devices, data, services, and business operations from cybersecurity threats.

Cybersecurity is a shared business responsibility. All employees, contractors, managers, administrators, and third parties with access to company systems or data are expected to follow the requirements that apply to them.

The objective is to reduce cyber risk while allowing the company to operate effectively.

2. Scope

This policy applies to:

  • Company employees
  • Contractors and temporary workers
  • Directors and managers
  • Company-owned and company-managed devices
  • Personal devices approved for company use
  • Company networks
  • Email and collaboration systems
  • Cloud and SaaS services
  • Business applications
  • Websites and domains
  • Company data
  • Customer and employee data
  • Third parties with access to company systems or information

3. Cybersecurity Ownership

The company will assign an individual responsible for coordinating cybersecurity activities.

Leadership remains responsible for ensuring appropriate resources, priorities, and authority are provided.

System, data, and business process owners are responsible for the security of the assets under their control.

Employees are responsible for following company security requirements and reporting suspicious activity or mistakes promptly.

4. Identity and Access

Access to company systems must be based on business need.

The company should:

  • Use individual user accounts wherever practical.
  • Apply least privilege.
  • Require MFA for important systems and high-risk accounts.
  • Control administrator and privileged access.
  • Avoid unnecessary shared accounts.
  • Review access regularly.
  • Remove access promptly when employees, contractors, or vendors leave or no longer require it.

Passwords and authentication credentials must not be shared unless an approved business process specifically requires controlled credential sharing.

5. Devices and Systems

Company systems and devices should be securely configured and maintained.

The company should:

  • Use supported operating systems and applications.
  • Apply security updates within appropriate timeframes.
  • Use endpoint protection where appropriate.
  • Restrict unnecessary administrator rights.
  • Enable device locking.
  • Use encryption where appropriate.
  • Remove or replace unsupported systems where practical.
  • Employees must not disable security controls without authorization.

6. Data Protection

Company and customer information must be handled according to its sensitivity.

Employees should:

  • Use approved systems for storing and sharing company data.
  • Avoid personal email or personal cloud storage for company information.
  • Check recipients before sending sensitive information.
  • Restrict public sharing.
  • Report accidental disclosure quickly.
  • Sensitive information should only be accessible to people who require it.

7. Email, Internet, and SaaS Use

Employees should use company-approved email, cloud, SaaS, messaging, and collaboration services.

Suspicious messages, unexpected attachments, fake login pages, unexpected MFA prompts, and unusual requests should be reported promptly.

New software, SaaS services, browser extensions, or AI tools that will handle company information should be approved before use where required by company procedure.

8. Backup and Recovery

Important company data and systems must be backed up according to business need.

Backups should:

  • Run on an appropriate schedule
  • Be monitored for failures
  • Be protected from unauthorized deletion or modification
  • Be retained for an appropriate period
  • Be tested periodically through restoration
  • Recovery priorities should be documented for critical business systems

9. Logging and Monitoring

The company should maintain sufficient security visibility for important systems.

This may include:

  • Account sign-ins
  • Administrator activity
  • Endpoint security alerts
  • Email security alerts
  • Remote access
  • Cloud activity
  • Backup failures
  • Critical configuration changes
  • Internet-facing systems

Security alerts must be directed to someone responsible for reviewing and escalating them.

10. Vendor and Third-Party Security

Third-party access should be limited to what is required.

Where practical:

  • Vendors should use named accounts.
  • MFA should be required.
  • Access should be reviewed.
  • Unused access should be removed.
  • High-risk vendor access should be approved.
  • Third-party cybersecurity responsibilities should be documented.

11. Cybersecurity Incident Reporting

Employees must report suspected cybersecurity incidents or mistakes promptly.

Examples include:

  • Suspicious emails
  • Unexpected MFA prompts
  • Lost devices
  • Malware warnings
  • Password compromise
  • Data sent to the wrong person
  • Payment fraud attempts
  • Unusual system behavior

Employees should not hide security mistakes or attempt their own investigation unless instructed to do so.

12. Incident Response

The company will maintain a basic incident response process covering:

  • Incident ownership
  • Triage
  • Evidence preservation
  • Containment
  • Communication
  • Escalation
  • Eradication
  • Recovery
  • Review

Serious incidents should be escalated to appropriate technical, legal, insurance, management, or external response support.

13. Security Awareness

Employees should receive practical cybersecurity training appropriate to their role.

Training should include:

  • Phishing
  • Passwords and MFA
  • Data handling
  • Fraud and impersonation
  • Device security
  • Incident reporting

Higher-risk teams should receive additional training relevant to their responsibilities.

14. Exceptions

Exceptions to this policy should be documented and approved by an appropriate owner.

Significant exceptions should include:

  • Reason for the exception
  • Risk created
  • Temporary controls
  • Risk owner
  • Approval
  • Review or expiry date

15. Review

This policy should be reviewed at least annually and after significant changes, major incidents, or material changes in business risk.

Practical Rule

Cybersecurity controls should be proportionate to the risk, but important risks should never remain unowned or ignored.