Insider Threat, Enhanced Vetting & Sensitive Roles Policy

Version 1.0 · Last Updated:

1. Purpose

This policy sets out Murzo Group's approach to insider threat risk, enhanced vetting, sensitive roles, role-based access, aftercare, protective monitoring, conflict management, and reporting of security concerns.

The purpose is to protect people, confidential information, systems, cultural objects, high-value goods, food safety, financial assets, property, controlled items, client data, intellectual property, and public trust from intentional or negligent misuse by trusted insiders.

2. Scope

This policy applies to directors, workers, contractors, consultants, suppliers, temporary staff, agency workers, advisers, security providers, system administrators, finance contacts, asset custodians, food safety leads, property managers, and anyone with access to sensitive Murzo Group assets.

It applies before appointment, during engagement, after role changes, during offboarding, and where concerns arise.

3. Sensitive Roles

A sensitive role is any role that could cause material harm if misused, compromised, coerced, negligent, or conflicted.

  • Access to banking, payment, payroll, procurement, high-value goods, property transactions, or corporate filings
  • Access to administrator accounts, cybersecurity tools, confidential data, client systems, source code, domains, or cloud services
  • Access to cultural property, human remains, controlled items, weapons, explosives, security-sensitive projects, or defence-adjacent activity
  • Access to food safety controls, product release, recall decisions, allergen data, batch records, or laboratory results
  • Authority to sign contracts, approve suppliers, move assets, instruct lawyers, speak publicly, or represent Murzo Group internationally

4. Risk-Based Vetting

Murzo Group will apply vetting that is proportionate to role risk, jurisdiction, legal limits, data protection requirements, and business need.

Baseline checks may include identity, right to work, employment history, qualifications, references, conflict declarations, sanctions checks, and role suitability. Enhanced checks may include criminal record checks where lawful, financial integrity checks, directorship checks, adverse media checks, security interviews, overseas police certificates, or specialist clearance where appropriate.

5. Aftercare & Change of Circumstances

Sensitive-role holders may be required to report relevant changes that could affect trust, security, conflicts, availability, or legal risk.

Reportable changes may include criminal investigation, serious financial difficulty, new conflicts of interest, outside business interests, unusual foreign contacts, coercion attempts, unauthorised disclosures, loss of credentials, unexplained access requests, or pressure from third parties.

6. Access Control & Segregation of Duties

Sensitive access must be granted on a least-privilege and need-to-know basis. High-risk activity should not rely on a single person where segregation of duties, dual approval, or independent review is practicable.

Access should be reviewed when a person changes role, project, location, supplier relationship, employment status, or risk profile.

7. Insider Threat Indicators

No single behaviour proves insider threat. However, concerns should be escalated where patterns suggest unacceptable risk.

  • Unusual access, bulk downloads, unauthorised copying, unexplained data movement, or attempts to bypass controls
  • Resistance to oversight, secrecy around suppliers, unusual payment requests, conflicts, unexplained wealth, or undeclared outside interests
  • Attempts to access cultural objects, high-value goods, controlled items, client data, or food records without business need
  • Threats, coercion, blackmail concerns, extremist interest, serious grievance escalation, or hostile communications
  • Repeated policy breaches, poor security judgement, concealment of mistakes, or tampering with records

8. Monitoring, Privacy & Fairness

Murzo Group may monitor systems, access logs, CCTV, communications metadata, asset movement, financial approvals, and security events where lawful and proportionate.

Monitoring must respect data protection, employment, human rights, and local legal requirements. Concerns must be assessed fairly and must not be based on protected characteristics or unsupported assumptions.

9. Reporting, Investigation & Response

Security concerns must be reported promptly to an authorised representative. Murzo Group may restrict access, preserve evidence, suspend activity, conduct an investigation, involve HR, obtain legal advice, notify authorities, or terminate access where required.

Whistleblowers and good-faith reporters must be protected from retaliation.

10. Records, Review & Responsibilities

Murzo Group will keep appropriate records of sensitive-role designations, vetting decisions, access approvals, reviews, concerns, investigations, restrictions, and offboarding.

Managers, security leads, HR contacts, system owners, asset custodians, finance contacts, and authorised representatives are responsible for applying this policy. It will be reviewed periodically and after significant incidents, role changes, legal changes, or threat changes.

Murzo Group signature