Strategy&Consult

Information Security Statement

Public overview of our risk-based security approach

Effective: 4 August 2026 | Version: 1.0

This statement describes objectives and governance expectations. It does not claim ISO 27001, SOC 2, Cyber Essentials or other certification unless a current certificate is expressly identified and made available.

Our approach

Strategy&Consult applies risk-based measures intended to preserve confidentiality, integrity, availability and resilience in proportion to the data, service, threat and legal obligations. Controls are reviewed as systems, providers and risks change.

Control areas

  • Governance and asset/data ownership; policies, risk assessment and staff responsibilities.
  • Least-privilege access, joiner/mover/leaver processes, strong authentication and periodic access review.
  • Secure configuration, patching, malware protection, vulnerability management and change control.
  • Encryption in transit and at rest where appropriate; approved collaboration and transfer channels.
  • Supplier due diligence and contractual security, confidentiality, breach and subprocessor obligations.
  • Logging, monitoring, incident triage, evidence preservation, notification assessment and lessons learned.
  • Backups, restoration testing, continuity and disaster-recovery planning proportionate to service criticality.
  • Privacy by design, data minimisation, retention/deletion and secure disposal.
  • Security and privacy training, phishing awareness and confidential reporting routes.

Website-specific controls

We maintain supported WordPress, theme and plugin versions; minimise plugins; protect administration with strong authentication; restrict uploads and forms; scan files; rate-limit abuse; back up securely; test restoration; use HTTPS and appropriate HTTP security headers; and monitor changes and incidents.

Client information

Engagement security requirements are agreed according to scope and sensitivity. Clients should use designated secure channels and avoid emailing sensitive data unless encryption and recipients are confirmed. We segregate access by engagement and use client data only for authorised purposes.

Incident reporting

Report suspected loss, unauthorised access, phishing, malicious content or misdirected information promptly to info@strategyandconsult.com with ‘Security Incident’ in the subject. Do not include passwords or unnecessary sensitive data. We triage reports, contain and investigate proportionately, and assess notification duties.

Responsible disclosure

Do not exploit, persist, exfiltrate, alter data, disrupt service or access other users’ information. Provide reproducible details and allow reasonable time for investigation. This statement is not permission to test systems; a formal vulnerability-disclosure policy should be adopted before inviting research.

Review

This public statement is reviewed at least annually and after a material security, legal or service change.