Information Security & Acceptable Use
The security discipline we live by — because we are the security company.
CHAPTER
HB-04
OWNER
Chief Information Security Officer
EFFECTIVE
January 1, 2026
REVIEWED
June 1, 2026
We hold ourselves to the highest standard
As a cybersecurity company, our own security posture is non-negotiable. Every member of the Team is a defender of company and client data. Failure to follow these controls puts our clients — and the people they serve — at risk.
Acceptable use
- 01Use company systems and data only for legitimate business purposes.
- 02Never share credentials; use the company password manager and enable multi-factor authentication.
- 03Encrypt devices, keep software patched, and lock screens when away.
- 04Do not install unapproved software or connect unapproved devices to company systems.
- 05Handle client data strictly according to its classification and the client agreement.
Access & least privilege
Access is granted on a least-privilege, need-to-know basis. Do not attempt to access systems or data you are not authorised to use, and report any access you no longer need so it can be revoked.
Report incidents immediately
If you suspect a security incident — a lost device, a phishing attempt, a suspected breach, or a mistaken disclosure — report it immediately to the security team. Prompt, honest reporting is always the right call; we never penalise good-faith reporting of incidents.
Mandatory training
All Team members must complete assigned security awareness training within the deadlines set by the security team. Detailed controls are published in our Corporate Standards.
/COMPANY_HANDBOOK
This is the official, controlled version of HB-04 — Information Security & Acceptable Use. Printed or downloaded copies are uncontrolled. This handbook is not an employment contract; where local law requires a different standard, local law prevails. Questions should be directed to people@alexasecurity.net.
VERSION
2026.1
REVIEWED
June 1, 2026
SCOPE
Global

