IT Security Policy¶
Effective from 30th July 2026
Introduction¶
The security of WOW Media UK Ltd's IT systems and data is a priority for the Company. This policy applies to all employees, contractors, and third-party suppliers ("Users") with access to Company systems, data, or devices.
Responsibilities¶
Matt Lovett is responsible for IT security across the Company, including third-party suppliers, investigating security incidents, and keeping this policy up to date.
Users are responsible for: - Following this policy and applicable law (including UK GDPR and the Computer Misuse Act 1990). - Reporting any actual or suspected security issue immediately — do not attempt to resolve a suspected breach yourself. - Only using the access and systems needed for their role.
Passwords & Access¶
- All Users are provided a 1Password account and must use it to generate and store unique, strong passwords for all work-related accounts.
- Your 1Password Master Password must never be shared, written down, or stored elsewhere.
- Two-factor authentication must be enabled wherever available.
- Passwords must be changed immediately if 1Password flags a security concern, a breach is suspected, or there is any other indication of compromise.
- Access to systems is granted on a need-to-use basis and reviewed when someone's role changes or they leave the Company.
Devices & Physical Security¶
- Screens must be locked whenever you step away from your device, whether at home, in the office, or in a public space (e.g. a café or co-working space).
- Devices must have a passcode/biometric lock enabled at all times.
- Keep firewalls enabled and run up-to-date anti-virus software on any device used for work.
- Enable automatic OS and software updates wherever possible.
- Take reasonable care to keep devices secure when working in public — don't leave a laptop or phone unattended, and be mindful of who can see your screen.
- Personal devices (phones, tablets, laptops) may be used to access Company accounts and cloud-based systems (e.g. email, Slack, Google Drive), provided they are passcode-protected, kept up to date, and capable of being remotely wiped if lost or stolen.
- Personal storage devices (e.g. USB drives) must not be physically connected to Company-owned hardware without prior approval.
Software¶
- Only Matt Lovett may approve installation of new software onto Company systems.
- All software must be kept up to date to maintain security.
Data Protection¶
- All personal data is handled in accordance with UK GDPR and the Data Protection Act 2018, and the Company's Data Protection Policy.
- Personal data must be encrypted in transit (e.g. TLS) and at rest (e.g. on laptops, USB drives, backups).
- Personal data must never be transferred to an employee's personal device. Transfers to contractor/agent devices are only permitted where that party has agreed to comply with this policy and UK GDPR.
- International transfers of personal data outside the UK must use an approved safeguard — currently the International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses — unless the destination country has UK adequacy status.
- Secure disposal: shred physical documents containing personal data; securely delete electronic copies using appropriate tools. Do not place sensitive paperwork in general waste.
- Users may download files from the Company's cloud storage supplier, Google, without approval. Google automatically scans most files for viruses on download; larger files (and some file types, such as zip archives) may not be scanned, and Google will show a warning if this is the case. Files that cannot be automatically scanned should not be downloaded without prior approval from Matt Lovett. Downloads from any other cloud storage system require prior approval.
Acceptable Use¶
Company systems, email, and communication tools must be used in a manner consistent with professional conduct. You must not use them to access, send, or store material that is illegal, discriminatory, harassing, defamatory, or obscene, or to attempt unauthorised access to any system, account, or data.
Reasonable personal use of company email and communication tools is permitted, provided it doesn't interfere with your work or breach this policy. When sending emails on behalf of the Company, take care with tone and content — emails can carry the same legal weight as other correspondence and may be disclosable in legal proceedings. If in doubt, check with Matt Lovett before sending.
Client or customer information should only be shared where appropriate and should never be sent in a way that puts it at risk (see Data Protection, above).
Monitoring¶
The Company monitors activity within internal tools and email systems to help maintain security, investigate suspected misuse, and ensure systems are working correctly. Some monitoring is actively reviewed on an ongoing basis to improve processes and security. General internet browsing is not monitored.
Backups¶
All data is backed up regularly, with backups stored securely off-site with reputable third-party providers, encrypted where applicable.
Business Continuity¶
The Company maintains reasonable measures to recover systems and data in the event of an incident or disaster.
Training¶
Users are expected to complete Company-provided security awareness training and keep up to date with any ongoing training requirements.
Reporting Issues¶
Report any suspected breach, lost/stolen device, or technical issue to Matt Lovett immediately.
Review¶
This is a live policy document maintained in the wiki portal — always refer to the current version.