A family of businesses. A team that genuinely cares.
What makes We Do Your Group a great place to build a career.
What working here actually feels like, day to day.
Browse current vacancies across all group companies
Our process, step by step — so you know exactly what to expect.
How we invest in the people who join us.
What our culture looks like and how we use DISC profiling.
The story behind the group, the people who built it, and the standards we hold ourselves to.
From a single business to a family of companies — here’s how we got here and where we’re headed.
What we’re building, why we’re building it, and the principle that sits behind everything we do.
Six values that shape how we hire, how we work, and how we look after the people around us.
The people behind the group — from the leadership team to the faces you’ll work with every day.
verified accreditations that give our clients, partners, and team the assurance they deserve.
We Do Your Group Limited (the ‘Organisation’) aims to provide a high level of Information Security.
The organisation operates an information security management system that has gained ISO 27001:2022 certification, including aspects specific to its scope of certification, which covers all organisational processes.
The management is committed to:
Dual-Logging for Customer-Affecting Information Security Events
Where an information security event is also a customer complaint — including but not limited to data disclosure to an unauthorised party, customer-side credential exposure, service changes deployed without customer consent that affect how their information is processed, customer-reported phishing or impersonation events, and backup or business-continuity failures that prevent customers from accessing their own data — the event is logged in both the Complaint and Feedback Register and the Information Security Incident Register. Each entry cross-references the paired entry by ID. The full trigger criteria and procedural detail are set out in the Logging an Incident or Non-Conformance via Claude SOP and the Logging a Complaint or Feedback Entry via Claude SOP.
Where an event affects only customer satisfaction (for example, a service-quality complaint with no information security dimension), it is logged only in the Complaint and Feedback Register. Where an event affects only the Information Security Management System (for example, internal data exposure between Organisation staff, near-miss or averted incidents, or technical control failures with no customer impact), it is logged only in the Information Security Incident Register.
From June 2026 onwards, this dual-logging is enforced at logging time by the Claude-driven register skills (wdyg-incident-register and wdyg-feedback-register). When a customer-affecting information security event is logged via the wdyg-incident-register skill, Claude offers to also create the matching Complaint and Feedback Register entry via the wdyg-feedback-register skill and maintains the cross-reference between the two. The Microsoft Form route previously used for new entries is retired. This Claude-driven mechanism supersedes the previously-planned Halo Quality and Compliance Log redesign as the OFI04 systemic fix.
This Information Security Policy is regularly reviewed to ensure its continuing suitability.
Copies of the Information Security Policy are made available to all members of staff and relevant interested parties on our website and may be updated from time to time.
JJMorrow
Director
26th May 2026
This website uses cookies to improve your experience. Choose what you're happy with.
Required for the site to function and can't be switched off.
Help us improve the website. Turn on if you agree.
Used for ads and personalisation. Turn on if you agree.
This website uses cookies to improve your experience. Choose what you're happy with.
Required for the site to function and can't be switched off.
Help us improve the website. Turn on if you agree.
Used for ads and personalisation. Turn on if you agree.