Cybersecurity Policy

The Cybersecurity and Incident Response Policy is designed to provide guidelines for The Wheel to respond quickly and effectively to a crisis involving a cyber-incident.

Overview

This policy aims to lay out the preparations and planning that will enable the organisation to respond effectively to any such threat, from the moment it is identified until the eventual return to normal operations, all while minimising the impact of such an event on the company’s operation.

This policy is based on understanding The Wheel’s business needs and the risks that are associated with our ongoing operations. Along with other mitigating factors (see Appendix 4), the policy seeks to address the following risks from The Wheel’s risk register: 

  • T1: Loss or misuse of database, files or key programmes due to viruses or other external factors
  • T2: Risk of harm to systems or information or misuse of systems by staff, e.g. GDPR breach
  • T3: Breach of security of internet banking
  • T4: Loss or breach of integrity or functionality of main website

This policy should be read in conjunction with the Business Continuity Policy, and the Media & Crisis Communication Policy. The policy is not a general IT policy.

Objective

To ensure the Organisation’s ability to continue or resume performing its business functions that support the organisation’s mission in a cyber-attack scenario. This is done while ensuring the Health and Safety of all concerned as much as possible and complying with legal requirements under all circumstances. 

Areas to be considered in any cybersecurity incident

Appendix 1: Holding Statement Template (for media and external dissemination)

Immediate Release: [date of issue]; [time of issue]

Statement Issued by The Wheel

The Wheel confirms that it has received a report of [nature of event/issue]. According to the information received [provide information without admitting liability]. 

Our immediate priority is to ensure [action to assist innocent parties negatively affected or next steps]. 

We are currently in the process of establishing the facts, and we will be providing further information as soon as it becomes available. 

For further information: 

Name [name of contact for the media]: 

Title [title of media contact]

Telephone: 

Mobile: 

Email:

Appendix 2: Template for Data Protection reporting (where risk is ongoing)

Immediate Release: [date of issue]; [time of issue]

Statement Issued by The Wheel

The Wheel confirms that it acts as data controller for a number of individuals and entities. The Wheel believes it has temporarily lost control of some of that data (optional) due to _________. 

We are currently implementing the company’s incident response plan and involving third parties where necessary. 

At this stage, we estimate the specific incident may take _____ hours/days/weeks to be resolved 

We have/will contact all individuals affected all individuals whose personal sensitive information was put at risk by the breach. We estimate the number of individuals affected to be ___. 

For further information: 

Name [name of contact for the Regulator]: 

Title [title of Regulator contact]

Telephone: 

Mobile: 

Email:

Appendix 3: Template for Data Protection reporting (where risk is contained)

Immediate Release: [date of issue]; [time of issue]

Statement Issued by The Wheel

The Wheel confirms that it acts as data controller for a number of individuals and entities. The Wheel believes it temporarily lost control of some of that data (optional) due to _________. 

We have implemented the company’s incident response plan involving third parties where necessary. 

At this stage, we assess the specific incident to be resolved. 

We have informed all individuals whose personal sensitive information was put at risk by the breach. We estimate the number of individuals affected to be ___. 

(optional if relevant) We have also informed the relevant authorities including _________. 

For further information: 

Name [name of contact for the Regulator]: 

Title [title of Regulator contact]

Telephone: 

Mobile: 

Email:

Appendix 4: Current Mitigations

  1. Regular monitoring by retained IT support and most up to date firewall and protections in place. 
  2. Best-in-class systems (Microsoft, Salesforce etc.) are used in the organisation and are cloud-based with passwords and two-factor authentication where feasible. No proprietary software is used, but trusted suppliers are identified & engaged. 
  3. Laptop are password protected and encrypted with BitLocker security.
  4. Cyber security insurance cover in place.
  5. Regular updates to all staff from IT Manager regarding cybersecurity threats.
  6. Dummy phishing attempts sent to staff at various times (last one January 2023; 0% click rate).
  7. Procedures in place to reduce risk of online meeting intrusions. 

Additional resources

Join The Wheel today and avail of membership deals

Find out how you can cut your costs, and maybe even avail of FREE membership, by joining The Wheel today.