Cyber Security & Information Security Policy
| Document owner | Managing Director / Executive Management |
|---|---|
| Version | 1.0 |
| Effective date | 8 March 2026 |
| Next review | 8 March 2027 (reviewed annually) |
This document provides UtilityDeals Pty Ltd with a formal cyber security and information security governance framework tailored to its website, lead-generation operations, customer information, CRM, cloud services, communications and third-party technology environment.
1.Purpose
This Policy establishes the principles, responsibilities, controls and minimum security requirements applicable to UtilityDeals Pty Ltd information, systems, technology infrastructure, employees, contractors and third-party providers. Its objectives are to protect personal and commercial information, prevent unauthorised access or disclosure, reduce cyber risk, and establish an effective incident-response framework.
2.Scope
This Policy applies to directors, officers, employees, contractors, agents and third-party providers with access to UtilityDeals systems or information. It covers the website, CRM and lead systems, cloud services, email, telephony, AI voice systems, marketing platforms, financial systems, APIs, endpoints, backups and physical records.
3.Information security principles
UtilityDeals applies confidentiality, integrity, availability, least privilege, defence in depth and privacy-by-design principles. Security controls will be proportionate to the sensitivity of information and the operational importance of systems.
4.Information classification
Information is classified as Public, Internal, Confidential, or Restricted/Sensitive. Restricted information includes customer and lead information, telephone numbers, email addresses, addresses, energy account information, consent records, IP addresses, call recordings, credentials, API keys and commercially sensitive information.
5.Personal information
UtilityDeals will take reasonable technical and organisational measures to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. Information no longer required for a legitimate business or legal purpose will be securely destroyed or de-identified, subject to applicable retention requirements. See our Privacy Policy for how we collect and use personal information.
6.Lead generation & consent records
Lead and consent records must be protected against unauthorised access or alteration. Where available, records should preserve the source, date/time, campaign, consent wording/version, contact details, IP address and relevant interaction evidence. Only information reasonably necessary for the intended purpose should be collected.
7.Access control & MFA
Access is granted on a business-need and least-privilege basis. Individual accounts are required; shared accounts should be avoided. MFA must be enabled for administrators, email, CRM, cloud administration, financial systems and other critical systems where supported. Access must be removed promptly when no longer required.
8.Password & credential security
Users must use unique passwords, avoid reuse, never share credentials and use an approved password manager where provided. API keys, tokens and secrets must not be stored in public code or unsecured documents.
9.Email security
UtilityDeals will use appropriate email security including MFA, spam/malware filtering and domain authentication such as SPF, DKIM and DMARC where supported. Requests involving credentials, payment changes, bank details or sensitive information must be independently verified.
10.Endpoint, patch & website security
Company devices must use supported operating systems, security updates, endpoint protection, screen locking and appropriate encryption. The website and web applications must use HTTPS/TLS, secure administrator authentication, timely CMS/plugin updates, backups and appropriate vulnerability protections.
11.Cloud & third-party security
Cloud and SaaS services must be approved before use for sensitive information. Security, MFA, data location, incident notification, retention, deletion, subcontractors and privacy implications should be assessed. Third-party contracts should address confidentiality, security, breach notification and secure deletion where appropriate.
12.AI & automated voice systems
AI voice agents, chatbots and other AI systems must only receive information necessary for their approved function. Customer information must not be uploaded to an AI provider without appropriate approval and security/privacy assessment. Call recordings must be handled according to applicable requirements, and API credentials must be securely managed.
13.Encryption
Sensitive information transmitted over public networks must use current industry-standard encryption. Sensitive information should be encrypted at rest where supported. Credentials and secrets must not be stored in plain text.
14.Backup & recovery
Critical information and systems must have regular backups appropriate to their importance. Backups should be protected against unauthorised access and ransomware, sufficiently separated from production systems, and tested periodically.
15.Logging & monitoring
Where practical, critical systems should maintain logs of authentication, administrator activity, permission changes, unusual data exports and security alerts. Logs should be protected against unauthorised alteration or deletion.
16.Human security & remote work
Employees and contractors must complete appropriate security awareness training, protect credentials, report incidents, use approved devices and systems, and secure information when working remotely. Lost or stolen devices must be reported immediately.
17.Incident response
Suspected incidents include unauthorised access, credential compromise, malware, ransomware, phishing, data leakage, device loss, website compromise and suspicious exports. UtilityDeals will identify, contain, investigate, remediate, notify where legally required, and conduct lessons-learned reviews.
18.Data breach response
Potential breaches must be assessed promptly to determine whether notification obligations arise under applicable law, including the Notifiable Data Breaches scheme. Management should maintain an incident owner, privacy/legal escalation pathway, technology-provider contacts and communication procedures.
19.Data retention & secure destruction
Information will be retained only for legitimate business, contractual, legal, compliance or dispute-resolution purposes (see our Dispute Resolution Policy). When no longer required, it should be securely deleted or de-identified, subject to applicable retention requirements.
20.Business continuity
UtilityDeals will maintain reasonable measures to continue critical operations following cyber attacks, system failures, cloud outages, loss of access, data corruption, ransomware or telecommunications outages.
21.Essential Eight alignment
UtilityDeals will use the Australian Signals Directorate Essential Eight as a baseline reference: patch applications; patch operating systems; configure MFA; restrict administrative privileges; application control; restrict Microsoft Office macros; user application hardening; and regular backups.
22.Governance, audit & review
Management is responsible for maintaining this Policy, identifying material cyber risks, implementing appropriate controls and escalating significant incidents. The Policy will be reviewed at least annually and after material incidents or significant technology changes.
23.Non-compliance
Failure to comply may result in withdrawal of access, disciplinary action, termination of contractor access or employment where appropriate, contractual remedies, or legal action where warranted.
Appendix A — Minimum control checklist
| Control | Minimum requirement | Priority |
|---|---|---|
| MFA | Email, admin, CRM and critical systems | Critical |
| Passwords | Unique credentials / password manager | Critical |
| Admin access | Restricted and reviewed | Critical |
| Website | HTTPS, current software, secure admin | Critical |
| Backups | Regular, protected and tested | Critical |
| Endpoint security | Supported OS and endpoint protection | High |
| Patching | Security updates maintained | High |
| SPF, DKIM and DMARC where supported | High | |
| Lead database | Role-based access and controlled exports | Critical |
| Consent records | Protected from unauthorised alteration | Critical |
| Third parties | Security/privacy assessment | High |
| AI systems | Approved providers and secure API credentials | High |
| Incident response | Documented process and escalation | Critical |
| Staff training | Periodic cyber awareness training | High |
| Data destruction | Secure deletion/de-identification | High |
Approval
Approved by the IT Manager, 8 March 2026.
