People Group Services
CIS
POLICY DOCUMENT LIBRARY
Company Policy Documents
People Group Services Limited
Company Number: 11570329

Cyber Security Policy

Purpose

People Group Services Ltd recognises that cyber security is fundamental to protecting personal data, financial information, payroll systems, and the integrity of services provided to agencies, contractors, MSPs and end clients.

This Cyber Security Policy establishes the framework for protecting company systems, data, infrastructure and digital services from cyber threats, unauthorised access, and data breaches.

The policy supports compliance with:

  • UK GDPR
  • Data Protection Act 2018
  • Computer Misuse Act 1990
  • NCSC Cyber Security Principles
  • ISO 27001 Information Security best practices

Scope

This policy applies to:

  • All employees, directors and contractors
  • All IT systems owned or operated by People Group Services Ltd
  • All company devices and networks
  • Third-party systems processing company data
  • Cloud services and hosted platforms
  • Remote working environments
  • All personal data and commercially sensitive information

Cyber Security Objectives

People Group Services Ltd aims to:

• Protect sensitive payroll, financial and personal data
• Prevent unauthorised system access
• Maintain system availability and resilience
• Detect and respond to cyber threats quickly
• Ensure secure digital services for agencies and contractors
• Maintain full regulatory compliance

Governance and Responsibilities

Board of Directors

The Board has ultimate responsibility for cyber security governance and risk management.

Compliance Department

Responsible for:

  • Policy management
  • Security monitoring
  • Incident response coordination
  • Regulatory reporting

IT & Systems Administrators

Responsible for:

  • Network security
  • Access controls
  • System updates and patching
  • Security monitoring tools

Employees

All employees must:

  • Follow cyber security procedures
  • Protect passwords and devices
  • Report suspicious activity immediately
  • Complete security awareness training

Access Control

Access to systems and data is controlled through the following principles:

Least Privilege

Users only receive access necessary to perform their role.

Authentication Controls

People Group Services Ltd enforces:

  • Strong password policies
  • Multi-Factor Authentication (MFA)
  • Unique user accounts
  • Secure password storage

Passwords must:

  • Be at least 12 characters long
  • Include letters, numbers and symbols
  • Not be reused across systems

Shared accounts are strictly prohibited.

Network Security

The company protects its networks through:

• Enterprise-grade firewalls
• Secure network segmentation
• Intrusion detection systems
• Secure VPN access for remote workers
• Continuous monitoring of network activity

Public Wi-Fi networks must never be used for company system access without VPN protection.

Device Security

All company devices must:

  • Use full disk encryption
  • Have automatic screen locking
  • Run approved anti-virus software
  • Receive regular security updates
  • Be centrally managed by IT

Lost or stolen devices must be reported immediately.

Remote device wipe capability is maintained where possible.

Software and System Security

To reduce cyber risk:

  • Only authorised software may be installed
  • Systems are patched regularly
  • Vulnerability scans are conducted periodically
  • Security updates are applied promptly
  • Unsupported or end-of-life software is not permitted

Data Security and Protection

People Group Services Ltd handles large volumes of:

  • Personal data
  • Payroll data
  • Financial information
  • Identification documents
  • Compliance documentation

Security controls include:

• Data encryption in transit and at rest
• Secure document storage systems
• Controlled file sharing
• Data access logging
• Regular backups

Sensitive data must never be stored on personal devices.

Email Security

Email remains a primary cyber attack vector.

Controls include:

  • Phishing detection systems
  • Spam filtering
  • Attachment scanning
  • Secure email gateways

Employees must:

• Verify unusual requests for payment or data
• Avoid opening suspicious attachments
• Report suspected phishing immediately

Cyber Incident Management

A cyber incident includes:

  • Data breach
  • Ransomware attack
  • Unauthorised system access
  • Malware infection
  • System compromise

If an incident occurs:

  1. Notify the Compliance or IT team immediately
  2. Disconnect affected devices from the network
  3. Preserve evidence where possible
  4. Follow incident response procedures

Where required, incidents will be reported to:

  • Information Commissioner’s Office (ICO)
  • Relevant regulators
  • Affected parties

within legally mandated timeframes.

Backup and Disaster Recovery

People Group Services Ltd maintains secure backups of critical systems to ensure service continuity.

Backup controls include:

• Automated scheduled backups
• Off-site or cloud storage redundancy
• Encrypted backup data
• Regular restoration testing

Third-Party Security

Third-party suppliers with access to systems or data must demonstrate appropriate cyber security standards.

Due diligence may include:

  • Security questionnaires
  • Data processing agreements
  • Security certifications
  • Compliance assessments

Third parties must comply with People Group Services Ltd security requirements.

Security Monitoring

The company uses monitoring systems to identify potential cyber threats, including:

  • Unusual login activity
  • System anomalies
  • Failed access attempts
  • Suspicious network traffic

Logs are retained for audit and investigation purposes.

Staff Cyber Security Training

Employees receive periodic training covering:

  • Phishing awareness
  • Password security
  • Data protection
  • Safe use of company systems
  • Incident reporting

Security awareness is essential to preventing cyber attacks.

Remote Working Security

Remote working must comply with company security standards.

Employees must:

  • Use company-approved devices
  • Connect via secure VPN
  • Avoid shared computers
  • Protect screens from public viewing
  • Maintain secure home Wi-Fi networks

Compliance and Enforcement

Failure to comply with this policy may result in:

  • Disciplinary action
  • Loss of system access
  • Contract termination
  • Legal action where appropriate

Cyber security is a shared responsibility across the organisation.

Policy Review

This policy will be reviewed:

  • Annually
  • Following major system changes
  • Following any cyber incident
  • When regulatory requirements change

Contact

For cyber security concerns or to report incidents:

Compliance Department
People Group Services Ltd
Email: compliance@peoplegroupservices.com
Website: www.peoplegroupservices.com

 

Declaration

This Policy is approved by the Board of Directors of: People Group Services Limited Company Number: 11570329

Last updated: 23rd March 2026