UtilityDeals policies

Cyber Security & Information Security Policy

UtilityDeals Pty Ltd · ACN 162 870 886 · Version 1.0 · Effective 8 March 2026

Document ownerManaging Director / Executive Management
Version1.0
Effective date8 March 2026
Next review8 March 2027 (reviewed annually)

This document provides UtilityDeals Pty Ltd with a formal cyber security and information security governance framework tailored to its website, lead-generation operations, customer information, CRM, cloud services, communications and third-party technology environment.

1.Purpose

This Policy establishes the principles, responsibilities, controls and minimum security requirements applicable to UtilityDeals Pty Ltd information, systems, technology infrastructure, employees, contractors and third-party providers. Its objectives are to protect personal and commercial information, prevent unauthorised access or disclosure, reduce cyber risk, and establish an effective incident-response framework.

2.Scope

This Policy applies to directors, officers, employees, contractors, agents and third-party providers with access to UtilityDeals systems or information. It covers the website, CRM and lead systems, cloud services, email, telephony, AI voice systems, marketing platforms, financial systems, APIs, endpoints, backups and physical records.

3.Information security principles

UtilityDeals applies confidentiality, integrity, availability, least privilege, defence in depth and privacy-by-design principles. Security controls will be proportionate to the sensitivity of information and the operational importance of systems.

4.Information classification

Information is classified as Public, Internal, Confidential, or Restricted/Sensitive. Restricted information includes customer and lead information, telephone numbers, email addresses, addresses, energy account information, consent records, IP addresses, call recordings, credentials, API keys and commercially sensitive information.

5.Personal information

UtilityDeals will take reasonable technical and organisational measures to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. Information no longer required for a legitimate business or legal purpose will be securely destroyed or de-identified, subject to applicable retention requirements. See our Privacy Policy for how we collect and use personal information.

Lead and consent records must be protected against unauthorised access or alteration. Where available, records should preserve the source, date/time, campaign, consent wording/version, contact details, IP address and relevant interaction evidence. Only information reasonably necessary for the intended purpose should be collected.

7.Access control & MFA

Access is granted on a business-need and least-privilege basis. Individual accounts are required; shared accounts should be avoided. MFA must be enabled for administrators, email, CRM, cloud administration, financial systems and other critical systems where supported. Access must be removed promptly when no longer required.

8.Password & credential security

Users must use unique passwords, avoid reuse, never share credentials and use an approved password manager where provided. API keys, tokens and secrets must not be stored in public code or unsecured documents.

9.Email security

UtilityDeals will use appropriate email security including MFA, spam/malware filtering and domain authentication such as SPF, DKIM and DMARC where supported. Requests involving credentials, payment changes, bank details or sensitive information must be independently verified.

10.Endpoint, patch & website security

Company devices must use supported operating systems, security updates, endpoint protection, screen locking and appropriate encryption. The website and web applications must use HTTPS/TLS, secure administrator authentication, timely CMS/plugin updates, backups and appropriate vulnerability protections.

11.Cloud & third-party security

Cloud and SaaS services must be approved before use for sensitive information. Security, MFA, data location, incident notification, retention, deletion, subcontractors and privacy implications should be assessed. Third-party contracts should address confidentiality, security, breach notification and secure deletion where appropriate.

12.AI & automated voice systems

AI voice agents, chatbots and other AI systems must only receive information necessary for their approved function. Customer information must not be uploaded to an AI provider without appropriate approval and security/privacy assessment. Call recordings must be handled according to applicable requirements, and API credentials must be securely managed.

13.Encryption

Sensitive information transmitted over public networks must use current industry-standard encryption. Sensitive information should be encrypted at rest where supported. Credentials and secrets must not be stored in plain text.

14.Backup & recovery

Critical information and systems must have regular backups appropriate to their importance. Backups should be protected against unauthorised access and ransomware, sufficiently separated from production systems, and tested periodically.

15.Logging & monitoring

Where practical, critical systems should maintain logs of authentication, administrator activity, permission changes, unusual data exports and security alerts. Logs should be protected against unauthorised alteration or deletion.

16.Human security & remote work

Employees and contractors must complete appropriate security awareness training, protect credentials, report incidents, use approved devices and systems, and secure information when working remotely. Lost or stolen devices must be reported immediately.

17.Incident response

Suspected incidents include unauthorised access, credential compromise, malware, ransomware, phishing, data leakage, device loss, website compromise and suspicious exports. UtilityDeals will identify, contain, investigate, remediate, notify where legally required, and conduct lessons-learned reviews.

18.Data breach response

Potential breaches must be assessed promptly to determine whether notification obligations arise under applicable law, including the Notifiable Data Breaches scheme. Management should maintain an incident owner, privacy/legal escalation pathway, technology-provider contacts and communication procedures.

19.Data retention & secure destruction

Information will be retained only for legitimate business, contractual, legal, compliance or dispute-resolution purposes (see our Dispute Resolution Policy). When no longer required, it should be securely deleted or de-identified, subject to applicable retention requirements.

20.Business continuity

UtilityDeals will maintain reasonable measures to continue critical operations following cyber attacks, system failures, cloud outages, loss of access, data corruption, ransomware or telecommunications outages.

21.Essential Eight alignment

UtilityDeals will use the Australian Signals Directorate Essential Eight as a baseline reference: patch applications; patch operating systems; configure MFA; restrict administrative privileges; application control; restrict Microsoft Office macros; user application hardening; and regular backups.

22.Governance, audit & review

Management is responsible for maintaining this Policy, identifying material cyber risks, implementing appropriate controls and escalating significant incidents. The Policy will be reviewed at least annually and after material incidents or significant technology changes.

23.Non-compliance

Failure to comply may result in withdrawal of access, disciplinary action, termination of contractor access or employment where appropriate, contractual remedies, or legal action where warranted.

Appendix A — Minimum control checklist

ControlMinimum requirementPriority
MFAEmail, admin, CRM and critical systemsCritical
PasswordsUnique credentials / password managerCritical
Admin accessRestricted and reviewedCritical
WebsiteHTTPS, current software, secure adminCritical
BackupsRegular, protected and testedCritical
Endpoint securitySupported OS and endpoint protectionHigh
PatchingSecurity updates maintainedHigh
EmailSPF, DKIM and DMARC where supportedHigh
Lead databaseRole-based access and controlled exportsCritical
Consent recordsProtected from unauthorised alterationCritical
Third partiesSecurity/privacy assessmentHigh
AI systemsApproved providers and secure API credentialsHigh
Incident responseDocumented process and escalationCritical
Staff trainingPeriodic cyber awareness trainingHigh
Data destructionSecure deletion/de-identificationHigh

Approval

Approved by the IT Manager, 8 March 2026.

Implementation note: This Policy describes UtilityDeals’ intended governance framework. It must not be represented as evidence of Essential Eight maturity, ISO 27001 certification or independent security certification unless the relevant controls have actually been implemented and independently assessed.
UtilityDeals

Australian-owned comparison and switching service for homes and businesses in VIC, NSW, QLD and SA, with our head office in Melbourne. We compare a panel of retailers, and retailers pay us a commission if you switch — our service is free to you.

Services

Contact

© 2026 UtilityDeals Pty Ltd. All rights reserved.ABN : 67 162 870 886 · ACN : 162 870 886 · Registered address: 86 Skyline Way, Berwick VIC 3806, Australia

Disclaimer: UtilityDeals compares plans from a panel of retailers and providers it has commercial arrangements with — for electricity, gas, solar and battery, and internet and telecom. We do not compare against all retailers or providers in the market, and we do not claim to give you the best offer or rates available at any given time. UtilityDeals endeavours to match or better your current rates by comparing your bill with the offers available from retailers on our panel, and recommends the panel offer estimated to save you the most at that point in time. Retailers on our panel pay UtilityDeals a commission if you switch; our service is free to you. Your details are shared with a panel retailer only to arrange your service — see our Privacy Policy.

Scroll to Top