Information Security Policy
Bespoke Training & Development
71-75 Shelton Street, London
WC2H 9JQ
United Kingdom
Prepared for Bespoke Training & Development by
Professor Alan Gillies MA PhD FBCS CITP FAHE Doctor Honoris Causa
Version: 2.0
Dated: 1st May 2026
Review date: 1st May 2027
We undertake to take proportionate steps to protect the security of all the information we hold, including personal information. We follow the principles of the Government Cybersecurity Essentials Scheme.
Boundary firewall
We have a firewall configured to protect us against an intrusion from the internet.
Secure configuration
We configure new hardware and software where possible to provide the most effective protection.
We carry out reviews to periodically remove unused software and services from your devices to reduce the number of potential vulnerabilities.
We install updates to key applications and systems when notified by suppliers
We change any default passwords used by software or hardware to protect us against an intrusion from by attackers.
Access control
We restrict access to our system to users and sources we trust.
Each user has their own username and password.
Each user has an account that has permissions appropriate to the job they are carrying out at the time. We only use administrator accounts when strictly necessary (eg for installing known and trusted software).
We enforce strong passwords, limit the number of failed login attempts and enforce regular password changes.
When a staff member leaves the organisation or is absent for long periods, their passwords or other access should be cancelled immediately.
Malware protection
We use anti-malware products to protect our network in real time and to prevent or detect threats. They are kept up-to-date and we act upon any alerts issued by the malware protection.
Patch management and software updates
We keep our software up-to-date by checking regularly for updates and applying them. Where possible this is done automatically.
Physical security
We take steps through access control and alarm systems to protect the physical security of equipment. We ensure that personal data on your systems is protected against these types of threats, by access control measures, encryption and remote backups.
Personal information held on paper is stored securely and disposed of securely.
Asset registration
Details of all equipment holding personal information are recorded in our asset register along with an asset owner and location.
Mobile devices
Because we use cloud-based storage which creates local copies on devices which we use remotely, all such devices are subject to the following safeguards:
All staff are required to protect their devices with strong passwords in accordance with the password policy described below.
Where available, passkeys should be used in place of passwords.
Where fingerprint or facial identification eg on tablets is available this should be used for additional security.
When not in use, mobile devices with access to Bespoke servers are required to be stored securely.
When transported, devices should not be left visible, or left unattended in an insecure environment.
Password policy
The password policy applies to all directors, staff and contractors who use Bespoke systems.
Passwords should only be used as primary security when passkeys and biometric identification are not available.
All passwords should be reasonably complex and difficult for unauthorized people to guess.
Users must choose unique passwords for all of their company accounts and may not use a password that they are already using for a personal account.
All passwords must be changed regularly, with the frequency varying based on the sensitivity of the account in question. This requirement will be enforced using software when possible.
If the security of a password is in doubt - for example, if it appears that an unauthorized person has logged in to the account - the password will be changed immediately.
Default passwords - such as those created for new users when they start or those that protect new systems when they’re initially set up - will be changed as quickly as possible.
Users should never share their passwords with anyone else. Everyone who needs access to a system will be given their own unique password.
Users may never share their passwords with any outside parties, including those claiming to be representatives of a business partner with a legitimate need to access a system.
Users should take steps to avoid phishing scams and other attempts by hackers to steal passwords and other sensitive information. All staff will receive training on how to recognize these attacks.
Users must refrain from writing passwords down and keeping them at their workstations.
Use of Emails
Wherever possible, users are sent emails directing them to login to systems to view personal information, rather than sending out personal information in emails, which, although more secure than alternatives such as faxes are not encrypted.
Cloud processing
Bespoke uses Microsoft Cloud-based services.
The Microsoft Cloud consists of approximately 16 data centres across the world, all of which operate 24/7/365. The Microsoft Cloud powers everything from Azure hosted applications and websites to Microsoft 365 application licenses.
Microsoft has designed and built its data centres with various stringent security measures to ensure your data stays protected. These measures include user controls to prevent unauthorised access, active threat detection software to spot anomalies, and firewalls to block any unauthorised attempts to view data.
The strict security controls go both ways. Microsoft’s own staff cannot access the contents of customer files due to these controls and the encryption of data on its servers. Physical access to data is also blocked through further measures, including security guards and locked server rooms. In an attempt to maintain security online, Microsoft includes multi-factor authentication with all its licenses. This pushes the user to use a one-time security code or fingerprint ID when they go to login on an unrecognised device.
Microsoft operates end-to-end protection for cloud services, spanning from product development to delivery. A partnership with GitHub allows cloud apps to be built and deployed using its Advanced Security licence. Microsoft Defender for Cloud then helps to secure the cloud environment, with both passive and active threat identification. Azure network security and permissions management meanwhile allow for complete control over who accesses what within the cloud.
Microsoft’s physical data centres are also built to be risk averse, meaning that in the event of an interruption (be that floods or power outages), there can be confidence that customer data will be unaffected. Microsoft’s data centres feature fire suppression systems, water sensors, and early fire detection to keep all data safe and secure. In addition to this, the data is stored and cross-replicated to multiple locations, so there’s even a backup location to ensure peace of mind in the event of a disaster.
Cloud security services are a great way to provide your business with peace of mind.
Business continuity
We have a robust data backup strategy in place to protect against disasters but also malware, such as ransomware.
All of our data is either processed remotely or is backed up to the cloud on a regular basis.
Staff training
We recognise that staff can be the weakest link. We train our staff in basic cybersecurity, to recognise threats such as phishing emails and other malware and alerting them to the risks involved in posting information relating to your business activities on social networks.
We encourage general security awareness within our organisation, and actively encourage a security aware culture.
Organisational Learning
As a learning organisation, we encourage staff to report any security issues or concerns, seeking to establish a no-blame culture, to learn from experiences
We have an acceptable-use policy and training materials for staff so that they know their data protection responsibilities.
Asset disposal
We ensure that all information assets are disposed of in a responsible manner.
Where we use a contractor to erase data and dispose of or recycle our IT equipment, we ask for documentary evidence that they have done so adequately. Where we dispose of equipment, we record the disposal in our asset register.
