Cyber Security Policy

Public summary version: 1.3
Effective date: 6 Sep 2026
Next review: 6 Sep 2027
Owner: CTO
Executive accountability: Chief Executive

1. Purpose and scope

SpotDev Services Ltd protects the confidentiality, integrity and availability of information used in our business and client delivery. This summary describes our security policy framework for employees, directors, contractors and authorised third parties.

Our controls cover company information, devices, business services and the work we are authorised to perform in client systems. Clients procure and retain control of their own infrastructure; our responsibilities depend on the agreed service and delegated authority. Stricter client requirements apply to the relevant engagement.

2. Governance and assurance

The Chief Executive retains executive accountability for information security. The CTO owns the security framework, supported by the COO and relevant control owners. We use documented risk assessment, controlled policies and accountable treatment of findings. Exceptions require authorised approval, proportionate safeguards and a defined review or expiry.

SpotDev holds Cyber Essentials Plus certification, subject to its stated scope and validity. The certificate record provides the verification details.

We are developing our information security management system using ISO/IEC 27001:2022 as a reference. We are not ISO/IEC 27001 certified. A policy commitment or control mapping is not proof of certification or of every control's effectiveness.

3. Identity, access and people

Our access policy requires individual authorisation, least privilege, strong authentication and MFA for human access to in-scope services, subject to controlled exceptions. Client approval defines the permitted scope of our access to client systems.

Access is reviewed and adjusted when responsibilities change and removed when no longer authorised. Credentials and service identities are protected through controlled management. Personnel are required to maintain confidentiality, follow relevant security requirements and report suspected incidents promptly.

4. Devices, information and encryption

Company-owned work devices are managed and protected through encryption, endpoint protection, supported software and security configuration. Access from other devices requires an approved protection arrangement.

Our policies require approved storage and transfer methods, data minimisation, encryption appropriate to the information and service, and controlled retention and disposal. Provider protection is assessed for the relevant service; it is not assumed from a general supplier claim. Encryption does not replace access control or responsible data handling.

5. Secure development and change

Our secure development policy requires security requirements to be considered during design and delivery, appropriate separation of environments, protected test information and documented change control.

Production releases require authorised human approval, Head of Quality Assurance sign-off and a passing dedicated automated PR review, with the evidence recorded under the controlled release process. Testing, vulnerability checks and rollback or recovery planning are applied to the relevant change and risk. Client systems remain subject to the client's access and change restrictions.

6. Vulnerability management and service security

Our vulnerability policy defines assessment, acknowledgement, containment and remediation requirements according to severity, exposure and exploitation risk. It covers relevant code, dependencies, images, deployed applications, public services and managed devices within our responsibility.

Required testing and monitoring are proportionate to the service and risk. Code review does not replace assessment of deployed services. Findings require an owner, treatment and closure evidence; exceptions are controlled. Detailed deadlines and assurance information can be supplied through an authorised client review.

Remote and cloud access is governed by authentication, device protection and least privilege. Additional private-access or network restrictions apply where required by a client, provider or risk assessment.

7. Suppliers and incidents

Suppliers handling company or client information are subject to risk-based assessment, appropriate contractual requirements and review. Responsibilities for provider-managed services and client-controlled systems are recorded for the engagement.

Our Incident Response Plan defines assessment, containment, evidence preservation, communication and recovery responsibilities. Client notifications follow the applicable agreement and legal obligations. Security and continuity exercises are policy requirements; claims about completed tests are supported by the relevant records.

8. Contact and supporting information

Report suspected security issues to security@spotdev.co.uk. Send an initial description without credentials, unnecessary personal data or intrusive testing. Further information can be exchanged through an agreed appropriate channel. Reporting an issue does not authorise access to systems or disruptive testing.

Relevant controlled policies and verified supporting evidence may be supplied through an authorised assurance process, with appropriate confidentiality and security restrictions. This page is a public summary, not a disclosure of operating procedures or a replacement for agreed contractual obligations. We review it annually and after material policy changes.