Skip to main content
NexusGroup Employee Portal

Policy · Information & security

Information Security

How we protect Nexus Group information assets — classifying, accessing, storing and sharing them safely.

Purpose

Information is one of our most important assets — staff and customer records, financial data, operational reports and more. This policy sets out how we keep that information accurate, available and protected. It works alongside the Privacy Policy (which covers personal information) and the IT Security & Acceptable Use Policy (which covers using our technology safely).

Know what you’re handling

Every information asset has a classification — Public, Internal, Confidential or Restricted — that tells you how to handle it. See the data classification guide and the information asset register.

Access on a need-to-know basis

  • Only access information you need for your work.
  • Access is granted to the right role, with manager approval, through an IT access request.
  • Don’t share your login, and don’t use someone else’s access.

Storing and sharing safely

  • Keep work information on approved systems — not personal devices, USB sticks or personal accounts.
  • Share with specific people, not “anyone with the link”, and give the least access needed.
  • Take extra care with Confidential and Restricted information; never copy Restricted information off approved systems.
  • Follow Saving and sharing files safely.

Protecting your access

  • Use multi-factor authentication and a strong passphrase.
  • Lock your screen when you step away.
  • Watch for phishing and report suspicious messages.

Reporting a problem

If a device is lost, information is shared with the wrong person, or you suspect a breach, report it to the Service Desk straight away. Acting quickly limits the harm — you won’t be in trouble for reporting honestly.

Everyone’s responsibility

Protecting information isn’t just IT’s job — it’s part of everyone’s. If you’re unsure how to handle something, check before you act.