Security Policy

Introduction

At Online Account Entry (OAE), a trading name of Outsource Professional Directors (OPD) Limited, we are committed to protecting our clients’ data, systems, and digital assets. Security is at the heart of everything we do. This policy outlines the measures and controls we maintain to ensure that all information handled by OAE remains secure, confidential, and protected from unauthorised access, disclosure, alteration, or destruction.

Scope

This policy applies to all employees, contractors, clients, partners, and third parties who have access to OAE’s systems, data, or infrastructure. It covers all platforms, whether on-site or cloud-based.

Information Security Objectives

  • To maintain the confidentiality, integrity, and availability of client and company data.

  • To prevent unauthorised access, modification, or misuse of data.

  • To ensure all systems are protected from cyber threats, malware, and other vulnerabilities.

  • To comply with the UK Data Protection Act 2018, UK GDPR, and applicable international standards.

  • To continually improve our security framework through reviews and audits.

Access Control

  • User access to systems is granted strictly on a need-to-know basis.

  • All access rights are reviewed periodically and revoked upon role change or termination.

  • Multi-factor authentication (MFA) is implemented for all authorised users accessing sensitive systems.

Network and System Security

  • All servers, cloud platforms, and communication channels are secured using SSL/TLS encryption.

  • Firewalls, antivirus software, and intrusion detection systems (IDS) are deployed and maintained.

  • Regular vulnerability assessments and penetration tests are conducted.

Data Storage and Protection

  • All client and company data are stored on encrypted servers within secure data centres located in compliance with jurisdictional requirements.

  • Backup and disaster recovery systems are in place to ensure business continuity.

  • Sensitive data transmission uses end-to-end encryption.

Incident Management

  • All employees are required to report any suspected or confirmed security incident immediately.

  • OAE maintains a formal incident response plan, which includes containment, investigation, notification, and remediation.

  • Clients will be informed of any data breaches affecting their information in accordance with legal requirements.

Physical Security

  • OAE offices and data facilities are secured by controlled access, CCTV monitoring, and alarm systems.

  • Visitors are registered and escorted when on-site.

Training and Awareness

  • Staff undergo regular cybersecurity awareness training.

  • Continuous updates and briefings ensure employees remain vigilant and informed.

Review and Monitoring

OAE continuously monitors and audits its security practices to ensure they meet evolving regulatory and technological standards.