Cyber Security Policy
Roles and Responsibilities
All Team Members
All team members are responsible for:
- Protecting company and client information from unauthorised access, loss, or misuse
- Using systems and devices in line with this policy and related procedures
- Keeping their devices up to date with the latest operating systems and security updates
- Reporting suspected security incidents or weaknesses as soon as possible
Management
Management is responsible for:
- Maintaining appropriate cyber security governance and oversight
- Ensuring proportionate controls are in place given the size and risk profile of the organisation
- Reviewing and updating this policy regularly
Device and BYOD Security
To support flexible working while managing risk:
- Personal devices used for work must be protected with strong passwords, PINs, or biometric authentication
- Devices must be configured to lock automatically when not in use
- Operating systems, applications, and security updates must be installed promptly
- Lost or stolen devices that contain or can access company data must be reported immediately
Cloud Services and Access Control
- Approved cloud-based tools are used for collaboration, data storage, and communication
- Access to systems and data is limited to what is necessary for each role
- Strong, unique passwords must be used for all work-related accounts
- Multi-factor authentication (MFA) is used where available
Data Protection and Handling
- Client and company data must be stored only in approved cloud systems
- Sensitive information must not be stored locally on devices unless necessary
- Data should be shared securely and only with authorised individuals
3rd Party Software & Tools
TerraVerde has implemented procedures to evaluate and monitor third-party tools; however, such procedures are based on available information and representations and do not constitute a guarantee of third-party compliance or security performance.
Incident Management
- Any suspected cyber security incident, including data loss, unauthorised access, or phishing attempts, must be reported as soon as possible.
- Incidents will be assessed and managed promptly to minimise impact
- Lessons learned from incidents will be used to improve controls and awareness
Awareness and Good Practice
All team members are expected to:
- Remain vigilant to common cyber threats such as phishing and social engineering
- Use good judgement when handling data and accessing systems
- Seek guidance if unsure about security requirements
Policy Acknowledgement and Acceptance
All team members and contractors must formally acknowledge and agree to comply with this Cyber Security Policy before being granted access to company systems, data, or client information.
Acceptance of this policy is a condition of:
- Employment or engagement
- Continued access to company and client systems
- Participation in client work where company or client data is processed
Records of policy acknowledgement will be maintained by Management.
Review Cycle
- The policy will be reviewed:
- At least annually
- Following a significant incident
- Following material changes to technology or operating model
If you have any questions or concerns about this policy, please contact our Compliance Manager at [email protected]


