Minimum controls
Participating Businesses implement, where relevant:
- named responsibility for security;
- individual accounts and least-privilege access;
- multi-factor authentication for supported important services;
- strong credential management and secure recovery;
- supported software, security updates and malware protection;
- encryption and secure configuration appropriate to the device and data;
- controlled backups and proportionate restoration checks;
- secure sharing, storage and disposal;
- supplier and cloud-service assessment;
- logging or monitoring proportionate to risk; and
- prompt incident reporting and response.
People
Users protect credentials, verify unusual requests, avoid unauthorised software or sharing, secure devices and report suspected phishing, loss or compromise immediately.
Suppliers
Suppliers with access to systems or information must meet appropriate security requirements and report incidents without undue delay. Access is limited to the authorised purpose and removed when no longer required.
Incidents
The Black & White business applying this policy contains the incident, preserves evidence, assesses operational and privacy impact, restores services safely and meets notification duties. Lessons learned are converted into corrective action.
Public detail
Minimum control baseline
Access is granted on least-privilege and need-to-know principles, approved by an accountable person and removed promptly when no longer required. Unique accounts, strong authentication and multi-factor authentication are used where supported and proportionate. Privileged activity, shared access and service accounts receive additional control.
Supported software, secure configuration, timely security updates, malware protection, encryption, backups and recovery testing are applied according to risk. Business information is classified sufficiently to determine sharing, storage and disposal. Portable devices and removable media are restricted and protected. Sensitive information is not placed in unapproved personal accounts or consumer services.
Suppliers with system or data access are assessed before appointment and governed by written security and incident duties. Changes, integrations and automations are tested before production. Logs and alerts are retained proportionately to detect misuse and investigate incidents, without excessive monitoring.
People receive practical awareness covering phishing, payment diversion, password safety, suspicious links, device security and rapid reporting. Changes to bank details or payment instructions are verified through an independent trusted channel.
Incidents are contained, evidence preserved, affected credentials and systems protected, recovery prioritised and required notifications coordinated with privacy, contractual, insurance and legal duties. Lessons and corrective actions are tracked to closure.
Sensitive technical configurations, credentials, recovery material and security weaknesses are not published. This policy states the control standard without exposing protective arrangements.
Approval
Approved by David Swaddle, Founder, on 30 August 2026.