Skip to main content
NexusGroup Employee Portal

Policy · Information & security

IT Security & Acceptable Use

How to use Nexus Group technology safely, securely and appropriately.

Purpose

This policy explains how to use Nexus Group’s technology — devices, accounts, networks, email and the internet — safely and appropriately. Following it protects you, our customers and the business from cyber threats and data loss.

Acceptable use

Nexus Group technology is provided for work. Reasonable, limited personal use is allowed if it’s lawful, doesn’t interfere with your work, and follows this policy and the Code of Conduct.

You must not use Nexus systems to:

  • access, store or share offensive, discriminatory or illegal material;
  • run a personal business or send spam;
  • install unapproved software or bypass security controls;
  • share confidential or personal information without authorisation.

Passwords and accounts

  • Use a strong, unique passphrase and never share it (see the Setting a strong passphrase guide).
  • Always use multi-factor authentication (MFA) where it’s offered.
  • Lock your screen (Windows + L) whenever you step away.
  • Your account is yours — don’t let others use it, and don’t use anyone else’s.

Email and phishing

Be alert to phishing — emails that try to trick you into clicking a link, opening an attachment or giving away information. If something looks off, don’t click — report it using the Spotting and reporting phishing guide. When in doubt, contact the Service Desk.

Devices and data

  • Keep devices updated and don’t disable security software.
  • Store work files in approved Nexus locations, not on personal drives or USBs.
  • Encrypt or password-protect sensitive information before sending it.
  • Report lost or stolen devices to the Service Desk immediately.

Monitoring

To keep systems secure and meet legal obligations, Nexus Group may log and monitor the use of its systems. Monitoring is proportionate and respects privacy.

Reporting security issues

Report any suspected security incident — a suspicious email, a possible data breach, malware or a lost device — to the IT Service Desk straight away (ext. 4357 or servicedesk@nexusgroup.example.com). Reporting early limits the damage.