Information Security Policy

Published: December 15, 2023

25+ Reviews

Last Updated: May 2026

We Do Your Group Limited (the ‘Organisation’) aims to provide a high level of Information Security.

 

The organisation operates an information security management system that has gained ISO 27001:2022 certification, including aspects specific to its scope of certification, which covers all organisational processes.

 

The management is committed to:

  • Setting Information Security Objectives.
  • Identify and regularly assess threats to business operations and manage associated risks.
  • Define and implement specific controls and procedures to ensure confidentiality, availability and integrity of all forms of business and personal data.
  • Develop and maintain effective Information Security management processes to mitigate or minimise identified risks.
  • Protect all the organisation’s assets, including personnel, corporate reputation, business information and systems, physical property and key business processes from harm.
  • Record, analyse and investigate all reported security and quality incidents and irregularities to develop improvements to prevent their recurrence.
  • Consider security in all aspects of business operation and planning.
  • Expect a positive commitment to security by all levels of management and provide sufficient resources commensurate to the assessed risks.
  • Conduct security operations that comply with business principles, national legal requirements, and international standards. Where practical, we will improve on the performance standards specified.
  • Produce and test response, contingency and business interruption plans to cover all foreseeable events to minimise the impact of any incident or emergency and train personnel in their effective and efficient implementation.
  • Introduce and maintain active programmes to develop security awareness and responsibility among all employees and contractors.
  • Ensure compliance with this policy through education, training, review, and audit.
  • Continual improvement to satisfy the applicable requirements and improve the integrated management system.

 

Dual-Logging for Customer-Affecting Information Security Events

Where an information security event is also a customer complaint — including but not limited to data disclosure to an unauthorised party, customer-side credential exposure, service changes deployed without customer consent that affect how their information is processed, customer-reported phishing or impersonation events, and backup or business-continuity failures that prevent customers from accessing their own data — the event is logged in both the Complaint and Feedback Register and the Information Security Incident Register. Each entry cross-references the paired entry by ID. The full trigger criteria and procedural detail are set out in the Logging an Incident or Non-Conformance via Claude SOP and the Logging a Complaint or Feedback Entry via Claude SOP.

 

Where an event affects only customer satisfaction (for example, a service-quality complaint with no information security dimension), it is logged only in the Complaint and Feedback Register. Where an event affects only the Information Security Management System (for example, internal data exposure between Organisation staff, near-miss or averted incidents, or technical control failures with no customer impact), it is logged only in the Information Security Incident Register.

 

From June 2026 onwards, this dual-logging is enforced at logging time by the Claude-driven register skills (wdyg-incident-register and wdyg-feedback-register). When a customer-affecting information security event is logged via the wdyg-incident-register skill, Claude offers to also create the matching Complaint and Feedback Register entry via the wdyg-feedback-register skill and maintains the cross-reference between the two. The Microsoft Form route previously used for new entries is retired. This Claude-driven mechanism supersedes the previously-planned Halo Quality and Compliance Log redesign as the OFI04 systemic fix.

 

This Information Security Policy is regularly reviewed to ensure its continuing suitability.

Copies of the Information Security Policy are made available to all members of staff and relevant interested parties on our website and may be updated from time to time.

 

JJMorrow

Director

26th May 2026