Cybersecurity & Data Breach Policy

Version 1.0 · Last Updated:

1. Introduction

Murzo Group recognises that cybersecurity is fundamental to business continuity, data protection, and trust.

This policy sets out Murzo Group’s approach to protecting digital systems, networks, information assets, and services against unauthorised access, disruption, loss, or misuse.

This policy applies across all Murzo Group operations, platforms, systems, and digital infrastructure.

2. Scope

This policy applies to:

  • All Murzo Group information systems and networks
  • Websites, cloud services, and internal platforms
  • Client platforms and collaboration tools
  • Devices, servers, and data storage environments
  • Employees, contractors, and authorised users

Cybersecurity obligations apply regardless of geographic location or access method.

3. Cybersecurity Governance

Murzo Group maintains governance controls to manage cybersecurity risks proportionately and responsibly.

Key principles include:

  • Risk-based security management
  • Defence-in-depth architecture
  • Least-privilege access
  • Continuous monitoring and review
  • Alignment with recognised standards

Cybersecurity oversight is integrated into Murzo Group’s broader Legal & Governance framework.

4. Standards & Guidance Alignment

Murzo Group’s cybersecurity practices are informed by recognised frameworks, including:

  • UK National Cyber Security Centre (NCSC) guidance
  • ISO/IEC 27001 – Information Security Management
  • ISO/IEC 27002 – Security Controls
  • ISO/IEC 27035 – Incident Management
  • ISO/IEC 22301 – Business Continuity
  • UK Data Protection Act 2018 and UK GDPR
  • Cyber Essentials principles (where applicable)

These standards guide Murzo Group’s controls without implying formal certification unless explicitly stated.

5. Security Measures

Murzo Group implements appropriate technical and organisational measures, which may include:

  • Network security controls and firewalls
  • Encryption of data in transit and at rest
  • Authentication and access control mechanisms
  • Logging, monitoring, and intrusion detection
  • Segregation of systems and environments
  • Secure configuration and patch management
  • Physical security controls for infrastructure

Security controls are reviewed and updated as risks evolve.

6. User Responsibilities

All users of Murzo Group systems must:

  • Protect login credentials and access tokens
  • Use systems only for authorised purposes
  • Follow security guidance and acceptable use rules
  • Report suspected security incidents promptly

Failure to comply may result in access suspension or disciplinary action.

7. Third-Party & Supply Chain Security

Murzo Group may engage third parties for hosting, infrastructure, or specialist services.

Where appropriate, Murzo Group:

  • Assesses third-party security practices
  • Applies contractual security requirements
  • Limits access to the minimum necessary

Murzo Group is not responsible for independent security failures of third-party platforms beyond its legal obligations.

8. Data Breach Management

Murzo Group maintains procedures to identify, assess, and respond to security incidents and data breaches.

In the event of a breach:

  • The incident is assessed promptly to determine impact and risk
  • Containment and remediation measures are applied
  • Regulatory notification is made where legally required
  • Affected parties are informed where required by law

Murzo Group does not guarantee that all incidents can be prevented.

9. Limitation of Liability

Despite robust security controls, no system is immune from attack.

To the fullest extent permitted by law:

  • Murzo Group shall not be liable for losses caused by sophisticated cyber attacks, malware, ransomware, or force majeure
  • Murzo Group is not responsible for breaches arising from user actions, weak client-side security, or third-party systems
  • Liability is limited in accordance with Murzo Group’s Terms & Conditions

10. International Access & Jurisdiction

Murzo Group systems may be accessed globally.

Users acknowledge that:

  • Cybersecurity and surveillance laws vary by jurisdiction
  • Murzo Group applies UK legal standards as its baseline
  • Users remain responsible for compliance with local laws
  • Murzo Group makes no guarantee that systems are lawful or accessible in all jurisdictions.

11. Monitoring & Enforcement

Murzo Group reserves the right to:

  • Monitor system activity for security purposes
  • Suspend or terminate access where threats are detected
  • Block IP addresses or networks posing security risk
  • Investigate suspected misuse or intrusion

Actions may be taken without notice where security requires.

12. Training & Awareness

Murzo Group promotes cybersecurity awareness appropriate to role and risk, including:

  • Secure system use
  • Incident recognition and reporting
  • Data protection responsibilities

Training is proportionate and ongoing.

13. Review & Updates

This policy is reviewed periodically and updated to reflect:

  • Emerging cyber threats
  • Legal and regulatory developments
  • Changes in systems or operations

Revised versions will be published on Murzo Group platforms.

Murzo Group signature