Information Security and Service Resilience Statement
1. Governance, Scope and Current Status
Information security and service resilience are governed according to risk, legal requirements, customer commitments and operational need. The framework applies to personnel, devices, systems, cloud services, websites, customer and supplier information, repair records, hosted-service information and authorised remote access.
Darren Waggott, Director, has overall accountability. System and information owners are responsible for appropriate access, maintenance, supplier oversight, backup and recovery requirements.
The company is not currently certified to ISO/IEC 27001 or Cyber Essentials and has not completed a SOC 2 examination. This statement describes the intended control framework and readiness work; it is not independent assurance or a guarantee that incidents or outages cannot occur.
2. Identity, Systems, Data and Supplier Controls
Controls are selected proportionately and may include asset ownership, supported software, secure configuration, security updates, firewalls, malware protection, encryption, logging, vulnerability management, backups and physical protection. Access follows least privilege, unique identities and multi-factor authentication where appropriate, with prompt removal when no longer required.
Personal data is governed through the Data Protection and UK GDPR Governance Policy. Payment-card information is handled through approved payment providers and must not be copied into unapproved systems. Seed phrases and private keys must never be requested or stored.
Material suppliers are assessed for security, privacy, location, subprocessors, incident support, continuity, deletion and exit risk. Contractual requirements and evidence are proportionate to the service and risk.
3. Vulnerabilities, Incidents and Communications
Suspected compromise, data loss, malware, unauthorised access, service disruption and material vulnerabilities must be reported without delay. The response process covers triage, containment, preservation of evidence, eradication, recovery, notification, lessons and corrective action.
External researchers must follow the Security and Vulnerability Disclosure Policy. It does not authorise access to customer data, disruption, social engineering or destructive testing.
Customers and authorities are informed where required by law, contract or the assessed risk. Communications must be accurate and coordinated; unverified claims, concealed incidents and premature attribution are prohibited.
4. Business Continuity, Recovery and Improvement
Critical activities and dependencies are assessed so that proportionate continuity and recovery arrangements can be maintained. Plans address people, premises, power, connectivity, suppliers, communications, data, ecommerce and service restoration. Recovery priorities and acceptable disruption are defined according to impact and contractual obligations.
Backups must be protected from the same event as primary data where practicable and restoration should be tested. Alternative working, supplier substitution and manual procedures are considered where appropriate. Hosting-site resilience and remedies remain governed by the relevant Hosting Terms and site schedule.
Incidents, exercises, vulnerabilities, supplier changes and failed recoveries generate lessons and assigned actions. Cyber Essentials is the first planned external cyber-security certification objective, but certification will be claimed only after award and with its scope stated accurately.
Review, Questions and Contact
This policy is reviewed at least annually and after a material legal, operational or service change.
The Mining Shop UK Limited · Company number 14666497 · VAT GB482035600
Registered office: Enterprise House, 202 to 206 Linthorpe Road, Middlesbrough, England, TS1 3QW
Shop and repair centre: 38 Church Street, Hartlepool, TS24 7DG, United Kingdom
Email: [email protected] · Phone: 01429 408034
View the complete policy set in our Legal, Policies and Terms index.