Proportionate controls for protecting company, client and personal information.
Document owner: Max Pocock, Lead Consultant Operational role: Accountable information-security owner Version: 1.0 Issued: 25 July 2026 Review due: 25 July 2027, or earlier after a material incident, threat, system or contractual change Applies to: Managed Services Ltd and every person or supplier given access to its systems or information
Information is accessed only for authorised work, protected according to risk and recovered or securely disposed of through controlled processes.
1. Purpose and scope
This policy establishes minimum controls for devices, accounts, software, cloud services, paper records and communications used for company work. Contract, client, sector or jurisdiction requirements may impose stronger controls and take priority where applicable.
2. Accountability and risk
Max Pocock is accountable for proportionate security governance, supplier decisions and incident coordination. Every authorised user must protect credentials, follow instructions, report concerns promptly and stop work where continued activity may increase harm.
Before sensitive or high-impact work begins, the company will record the information involved, threats, access needs, client requirements, suppliers, recovery needs and residual risk. Unsupported systems or uncontrolled personal accounts must not be used for client information.
3. Access and authentication
Access will be limited to the least privilege needed and removed promptly when work or a relationship ends. Unique accounts, strong passwords and multi-factor authentication will be used where supported. Credentials, recovery codes and client access must not be shared informally.
Privileged access and material supplier permissions will be reviewed proportionately. Access by a separately engaged specialist requires confirmed need, confidentiality terms, suitable security and any required client approval.
4. Devices, software and communications
Company work must use supported, security-updated devices and software with appropriate malware protection, device locking and encryption. Sensitive information must be transferred using an approved route and recipients checked before sending.
Public or shared devices must not be used for confidential work. Public networks require proportionate protection. Paper and screen information must be protected from unauthorised viewing, loss and disposal.
5. Information lifecycle and resilience
Information will be classified informally or formally according to sensitivity and impact. Collection and copying will be minimised. Working files will use controlled naming and versions, and critical records will have recoverable copies appropriate to the engagement.
Retention, return and secure deletion will follow the contract, legal requirements and the Privacy and Data Protection Policy. Backup restoration will be tested proportionately. Deletion must be suspended where a lawful hold applies.
6. Suppliers and development
Security, privacy, location, availability, exit and subcontracting risks will be considered before a material technology supplier is used. Required contractual protections and client approvals must be in place.
Website and software changes will avoid embedded secrets, unnecessary data collection and unapproved third-party code. Material changes will be checked before release, with dependencies and access kept current.
7. Incidents and vulnerabilities
Suspected phishing, malware, lost devices, unauthorised access, misdirected information, service compromise or other security weakness must be reported immediately to Max Pocock. The company will:
- protect people and contain further harm;
- preserve relevant evidence and open an incident record;
- identify affected systems, information, clients and obligations;
- remove compromised access and recover from trusted sources;
- notify clients, insurers, regulators or affected people where required;
- validate security before normal operation; and
- record learning and corrective action.
Good-faith vulnerability reports can be sent to max.pocock@managed-group.co.uk. Reporters should not access unnecessary data, disrupt services or publicly disclose a weakness before a reasonable opportunity to respond.
8. Monitoring and review
The company will review material access, updates, backups, incidents, suppliers, emerging threats and contract requirements. Proportionate briefing will be provided before access is granted and after significant changes.
9. Document control
This policy provides proportionate company controls; it is not a claim of certification. Engagement-specific security schedules, client instructions and risk assessments must be applied where stronger or more detailed controls are needed.
