![]() |
People Group Services Limited Company Number: 11570329 |
Cyber Security Policy
Purpose
People Group Services Ltd recognises that cyber security is fundamental to protecting personal data, financial information, payroll systems, and the integrity of services provided to agencies, contractors, MSPs and end clients.
This Cyber Security Policy establishes the framework for protecting company systems, data, infrastructure and digital services from cyber threats, unauthorised access, and data breaches.
The policy supports compliance with:
- UK GDPR
- Data Protection Act 2018
- Computer Misuse Act 1990
- NCSC Cyber Security Principles
- ISO 27001 Information Security best practices
Scope
This policy applies to:
- All employees, directors and contractors
- All IT systems owned or operated by People Group Services Ltd
- All company devices and networks
- Third-party systems processing company data
- Cloud services and hosted platforms
- Remote working environments
- All personal data and commercially sensitive information
Cyber Security Objectives
People Group Services Ltd aims to:
• Protect sensitive payroll, financial and personal data
• Prevent unauthorised system access
• Maintain system availability and resilience
• Detect and respond to cyber threats quickly
• Ensure secure digital services for agencies and contractors
• Maintain full regulatory compliance
Governance and Responsibilities
Board of Directors
The Board has ultimate responsibility for cyber security governance and risk management.
Compliance Department
Responsible for:
- Policy management
- Security monitoring
- Incident response coordination
- Regulatory reporting
IT & Systems Administrators
Responsible for:
- Network security
- Access controls
- System updates and patching
- Security monitoring tools
Employees
All employees must:
- Follow cyber security procedures
- Protect passwords and devices
- Report suspicious activity immediately
- Complete security awareness training
Access Control
Access to systems and data is controlled through the following principles:
Least Privilege
Users only receive access necessary to perform their role.
Authentication Controls
People Group Services Ltd enforces:
- Strong password policies
- Multi-Factor Authentication (MFA)
- Unique user accounts
- Secure password storage
Passwords must:
- Be at least 12 characters long
- Include letters, numbers and symbols
- Not be reused across systems
Shared accounts are strictly prohibited.
Network Security
The company protects its networks through:
• Enterprise-grade firewalls
• Secure network segmentation
• Intrusion detection systems
• Secure VPN access for remote workers
• Continuous monitoring of network activity
Public Wi-Fi networks must never be used for company system access without VPN protection.
Device Security
All company devices must:
- Use full disk encryption
- Have automatic screen locking
- Run approved anti-virus software
- Receive regular security updates
- Be centrally managed by IT
Lost or stolen devices must be reported immediately.
Remote device wipe capability is maintained where possible.
Software and System Security
To reduce cyber risk:
- Only authorised software may be installed
- Systems are patched regularly
- Vulnerability scans are conducted periodically
- Security updates are applied promptly
- Unsupported or end-of-life software is not permitted
Data Security and Protection
People Group Services Ltd handles large volumes of:
- Personal data
- Payroll data
- Financial information
- Identification documents
- Compliance documentation
Security controls include:
• Data encryption in transit and at rest
• Secure document storage systems
• Controlled file sharing
• Data access logging
• Regular backups
Sensitive data must never be stored on personal devices.
Email Security
Email remains a primary cyber attack vector.
Controls include:
- Phishing detection systems
- Spam filtering
- Attachment scanning
- Secure email gateways
Employees must:
• Verify unusual requests for payment or data
• Avoid opening suspicious attachments
• Report suspected phishing immediately
Cyber Incident Management
A cyber incident includes:
- Data breach
- Ransomware attack
- Unauthorised system access
- Malware infection
- System compromise
If an incident occurs:
- Notify the Compliance or IT team immediately
- Disconnect affected devices from the network
- Preserve evidence where possible
- Follow incident response procedures
Where required, incidents will be reported to:
- Information Commissioner’s Office (ICO)
- Relevant regulators
- Affected parties
within legally mandated timeframes.
Backup and Disaster Recovery
People Group Services Ltd maintains secure backups of critical systems to ensure service continuity.
Backup controls include:
• Automated scheduled backups
• Off-site or cloud storage redundancy
• Encrypted backup data
• Regular restoration testing
Third-Party Security
Third-party suppliers with access to systems or data must demonstrate appropriate cyber security standards.
Due diligence may include:
- Security questionnaires
- Data processing agreements
- Security certifications
- Compliance assessments
Third parties must comply with People Group Services Ltd security requirements.
Security Monitoring
The company uses monitoring systems to identify potential cyber threats, including:
- Unusual login activity
- System anomalies
- Failed access attempts
- Suspicious network traffic
Logs are retained for audit and investigation purposes.
Staff Cyber Security Training
Employees receive periodic training covering:
- Phishing awareness
- Password security
- Data protection
- Safe use of company systems
- Incident reporting
Security awareness is essential to preventing cyber attacks.
Remote Working Security
Remote working must comply with company security standards.
Employees must:
- Use company-approved devices
- Connect via secure VPN
- Avoid shared computers
- Protect screens from public viewing
- Maintain secure home Wi-Fi networks
Compliance and Enforcement
Failure to comply with this policy may result in:
- Disciplinary action
- Loss of system access
- Contract termination
- Legal action where appropriate
Cyber security is a shared responsibility across the organisation.
Policy Review
This policy will be reviewed:
- Annually
- Following major system changes
- Following any cyber incident
- When regulatory requirements change
Contact
For cyber security concerns or to report incidents:
Compliance Department
People Group Services Ltd
Email: compliance@peoplegroupservices.com
Website: www.peoplegroupservices.com
Declaration
This Policy is approved by the Board of Directors of: People Group Services Limited Company Number: 11570329
Last updated: 23rd March 2026

