Effective: 4 August 2026 | Version: 1.0
This statement describes objectives and governance expectations. It does not claim ISO 27001, SOC 2, Cyber Essentials or other certification unless a current certificate is expressly identified and made available.
Strategy&Consult applies risk-based measures intended to preserve confidentiality, integrity, availability and resilience in proportion to the data, service, threat and legal obligations. Controls are reviewed as systems, providers and risks change.
We maintain supported WordPress, theme and plugin versions; minimise plugins; protect administration with strong authentication; restrict uploads and forms; scan files; rate-limit abuse; back up securely; test restoration; use HTTPS and appropriate HTTP security headers; and monitor changes and incidents.
Engagement security requirements are agreed according to scope and sensitivity. Clients should use designated secure channels and avoid emailing sensitive data unless encryption and recipients are confirmed. We segregate access by engagement and use client data only for authorised purposes.
Report suspected loss, unauthorised access, phishing, malicious content or misdirected information promptly to info@strategyandconsult.com with ‘Security Incident’ in the subject. Do not include passwords or unnecessary sensitive data. We triage reports, contain and investigate proportionately, and assess notification duties.
Do not exploit, persist, exfiltrate, alter data, disrupt service or access other users’ information. Provide reproducible details and allow reasonable time for investigation. This statement is not permission to test systems; a formal vulnerability-disclosure policy should be adopted before inviting research.
This public statement is reviewed at least annually and after a material security, legal or service change.