Do you have documented information security policies and procedures in place?
Who within your organisation is responsible for information security?
Are your security policies regularly reviewed and updated?
Do you maintain an up-to-date inventory of all information assets (including hardware and software)?
How do you protect data and devices when no longer in use or being disposed of?
What measures are in place to control removable media (e.g., USB drives)?
Do all employees and contractors undergo background checks before being given access to sensitive information?
How are staff trained and made aware of cyber security responsibilities?
How do you manage and remove access for leavers or role changes?
Do you have procedures to handle and respond to cyber security incidents?
How are cyber incidents reported, escalated, and investigated?
How do you ensure compliance with applicable data protection laws (e.g., GDPR, Data Protection Act 2018)?
Have you had any security breaches in the past three years? If so, how were they handled?