Last updated: 10 October 2026
Information is at the heart of everything we do. Our clients trust us with access to their systems, data and people, and protecting that information is one of our highest priorities. This policy sets out LevelUp Networks’ commitment to information security and the principles behind our ISO/IEC 27001-certified Information Security Management System (ISMS).
1. Purpose
The purpose of this policy is to protect the confidentiality, integrity and availability of information belonging to LevelUp Networks, our clients and our partners, and to make sure we meet our legal, regulatory and contractual obligations.
- Confidentiality: information is only accessible to those authorised to see it.
- Integrity: information is accurate, complete and protected from unauthorised change.
- Availability: information and systems are available to authorised users when they need them.
2. Scope
This policy applies to all information, systems, services and premises used by LevelUp Networks, and to everyone who works for or on behalf of the company, including employees, contractors, subcontractors and suppliers with access to our information or our clients’ systems.
3. Our commitments
LevelUp Networks is committed to:
- maintaining and continually improving an ISMS certified to ISO/IEC 27001;
- maintaining Cyber Essentials certification as a baseline for technical controls;
- identifying, assessing and treating information security risks in a consistent, documented way;
- setting measurable information security objectives and reviewing them regularly;
- complying with applicable law, including the UK GDPR and Data Protection Act 2018, and with our contractual obligations to clients;
- providing the resources, training and leadership needed to make this policy effective; and
- making security a shared responsibility across the whole organisation.
4. Key controls
Our ISMS is supported by a framework of policies and controls aligned with ISO/IEC 27001 Annex A, including:
- Access control: named accounts, least-privilege access, multi-factor authentication and regular access reviews, with prompt removal of access for leavers.
- Client system access: remote access to client environments only through approved, encrypted and logged tools, by authorised personnel.
- Asset management: an up-to-date record of information assets, with appropriate handling and secure disposal.
- Endpoint and network security: managed anti-malware and endpoint detection, firewalls, secure configuration and timely patching.
- Cryptography: encryption of data in transit and, where appropriate, at rest.
- Logging and monitoring: centralised logging and monitoring of security events.
- Backup and continuity: tested backup, recovery and business continuity arrangements for our own critical systems.
- Supplier security: assessment of suppliers and sub-processors before engagement, with security and data-protection requirements built into contracts.
- Secure use of AI: AI and automation tools are assessed before use and operate under human oversight and our confidentiality obligations.
- People security: screening, confidentiality agreements, and security awareness training at induction and on an ongoing basis.
- Physical security: appropriate controls to protect our premises, equipment and information.
5. Incident management
All staff must report suspected or actual security incidents immediately. We maintain a documented incident response process to contain, investigate and learn from incidents, and we notify affected clients, the ICO and other parties where required, without undue delay. Our Privacy Policy explains how we handle personal data.
6. Roles and responsibilities
- Directors are accountable for information security, approve this policy and make sure the ISMS has the resources it needs.
- The ISMS lead manages the ISMS day to day, including risk assessments, internal audits and reporting on performance.
- All staff and contractors must follow this policy and related procedures, protect the information they handle and report any concerns or incidents.
7. Compliance and review
Compliance with this policy is checked through internal audits, independent certification audits and management reviews. Breaches of this policy may lead to disciplinary action or termination of contract.
This policy is reviewed at least once a year, and whenever significant changes occur, to make sure it remains suitable, adequate and effective. It is approved by the directors of LevelUp Networks Ltd.
8. Contact
If you have any questions about this policy, or wish to report a security concern relating to our services, please contact us at [email protected] or on +44 (0) 203 695 7554.