Purpose
This policy explains how to use Nexus Group’s technology — devices, accounts, networks, email and the internet — safely and appropriately. Following it protects you, our customers and the business from cyber threats and data loss.
Acceptable use
Nexus Group technology is provided for work. Reasonable, limited personal use is allowed if it’s lawful, doesn’t interfere with your work, and follows this policy and the Code of Conduct.
You must not use Nexus systems to:
- access, store or share offensive, discriminatory or illegal material;
- run a personal business or send spam;
- install unapproved software or bypass security controls;
- share confidential or personal information without authorisation.
Passwords and accounts
- Use a strong, unique passphrase and never share it (see the Setting a strong passphrase guide).
- Always use multi-factor authentication (MFA) where it’s offered.
- Lock your screen (Windows + L) whenever you step away.
- Your account is yours — don’t let others use it, and don’t use anyone else’s.
Email and phishing
Be alert to phishing — emails that try to trick you into clicking a link, opening an attachment or giving away information. If something looks off, don’t click — report it using the Spotting and reporting phishing guide. When in doubt, contact the Service Desk.
Devices and data
- Keep devices updated and don’t disable security software.
- Store work files in approved Nexus locations, not on personal drives or USBs.
- Encrypt or password-protect sensitive information before sending it.
- Report lost or stolen devices to the Service Desk immediately.
Monitoring
To keep systems secure and meet legal obligations, Nexus Group may log and monitor the use of its systems. Monitoring is proportionate and respects privacy.
Reporting security issues
Report any suspected security incident — a suspicious email, a possible data breach, malware or a lost device — to the IT Service Desk straight away (ext. 4357 or servicedesk@nexusgroup.example.com). Reporting early limits the damage.