# IT AND CYBERSECURITY POLICY
Date: 10 November 2031
Parties: Merewood Surveying Limited and all personnel with access to its systems
## 1. Purpose and parties
Merewood Surveying Limited, company number 08421639, issues this policy for employees, agency workers, contractors and third parties with logical or physical access to its systems. It takes effect on Monday 10 November 2031 and is owned by IT Director Marcus Green, with Data Protection Officer Sophie Patel responsible for privacy escalation. It applies to company laptops, phones, cloud accounts, networks, paper data and approved home working.
## 2. Facts, scope and terms
Business use is permitted and incidental personal use is allowed during breaks if it is lawful, reasonable and does not disrupt work. Users must not access illegal or abusive content, install unlicensed software, gamble excessively, use peer-to-peer file sharing, bypass security controls, share credentials, or process Merewood data on an unmanaged personal device. Bring-your-own-device access requires enrolment in Merewood's mobile-device management profile and consent to a security wipe of company data.
## 3. Process and responsibilities
Each user must have a unique password of at least 16 characters, use the approved password manager and never reuse a company password elsewhere. Multi-factor authentication is mandatory for email, remote access, administrator accounts and financial systems. Laptops must use full-disk encryption, removable media must be encrypted and pre-approved, and critical security patches must be applied within 24 hours, high-risk patches within seven days and other patches within 30 days.
## 4. Evidence, records and safeguards
Users must lock screens when unattended, verify unexpected payment or access requests through a second channel, and report suspected phishing, lost equipment, malware or unauthorised disclosure to security@merewood.example and the service desk within one hour of discovery. Marcus will preserve evidence, contain access, reset credentials where necessary, assess affected personal data and coordinate recovery. Sophie will decide whether the UK GDPR Article 33 72-hour supervisory-authority notification window is engaged; staff must not contact the regulator or affected customers without authorisation.
## 5. Review, escalation and outcome
Network traffic, access events, email headers and security metadata may be logged and reviewed for security, legal compliance and service management. Monitoring will be proportionate, communicated through this policy and limited to what is necessary; content inspection or covert monitoring requires Sophie to document the purpose, necessity and authorisation. Merewood retains security logs for twelve months unless a live incident or legal hold requires longer, and access is limited to authorised IT, security, HR and legal personnel.
## 6. Reservations and practical protections
A minor breach, such as a late patch or careless screen exposure, may lead to retraining or a written warning. A significant breach, such as sending personal data to the wrong recipient or losing an unencrypted device, may lead to investigation, disciplinary action and regulatory assessment. Deliberate theft, credential sharing, disabling controls or knowingly exfiltrating data may be gross misconduct and may lead to summary dismissal and a law-enforcement referral, subject to a fair process and the Employment Rights Act 1996.
## 7. England and Wales law and completion
This completed fictional policy requires annual review and an immediate review after a material incident, major technology change or legal guidance change. It supports, but does not replace, the UK GDPR, Data Protection Act 2018, contractual duties and Cyber Essentials controls; it does not guarantee that an attack will be prevented. It is governed by England and Wales law, and every user must complete acknowledgement and training by 17:00 on 24 November 2031. Acknowledgement records will be retained with HR records, and access rights will be disabled immediately when a person leaves or a contract ends.