Security & trust

Endpoint Security

Protecting the devices our team uses to deliver and support Govform.

Encrypted staff devices

Our staff-device policy requires full disk encryption and automatic screen locking. These measures help protect organisational information when a laptop is lost, stolen or left unattended during work.

The policy covers device protection alongside secure storage and information handling. Staff are required to keep sensitive information in approved systems and follow the remote-working procedures when using devices away from the office.

  • Full disk encryption is required for staff computers.
  • Screens must lock automatically within five minutes of inactivity.
  • Devices must be stored securely and protected from unauthorised use.

Endpoint protection

Our device controls include antivirus and native operating-system protection, automatic security updates and malicious-site protection. Windows and macOS protections help reduce the risk from harmful files, untrusted software and everyday cyber threats.

Staff working practices reinforce those controls through approved software, cautious handling of unexpected links and attachments, and prompt reporting of suspicious activity. Device protection forms part of our organisational security arrangements.

  • Current endpoint protection and native firewalls support device security.
  • Approved software and security updates reduce avoidable exposure.
  • Staff report suspected malware or account compromise through the incident process.

Security updates

Our staff-device policy sets clear requirements for keeping operating systems and applications current. It requires updates within 14 days and priority handling for critical security patches within 48 hours.

These policy timeframes guide staff-device maintenance and the response to new security issues. They work alongside malware protection, secure configuration and staff awareness to reduce risks on the equipment used to deliver and support Govform.

  • Keep operating systems, browsers and applications supported and updated.
  • Give critical security patches priority over routine maintenance.
  • Report update problems so they can be addressed through the appropriate support route.

Responding to a lost or compromised device

Lost-device and cyber-incident scenarios are covered by our response and continuity procedures. Staff are required to report a concern promptly so the team can assess the affected equipment, accounts and information.

The response can include restricting account access, revoking credentials and arranging replacement equipment. Recovery and investigation are coordinated through the incident process, with device-security requirements carried into the restored working setup.

  • Escalate suspected loss, theft or compromise through the incident route.
  • Assess the information and accounts that could be affected.
  • Restore access and equipment through an authorised recovery process.
Explore incident response
Build with confidence

Secure services start with a conversation.

Talk to our team about your organisation’s security requirements, hosting choices and the services you want to deliver.