Security policy
We ask clients to hold themselves to a standard. This is the standard we hold ourselves to, and how to tell us if we have fallen short of it.
Last updated: to be set at launch
Why this page exists
A managed service provider is a concentration of risk. We hold privileged access to our clients' environments, which makes us a more attractive target than most of our clients individually. Supply chain compromise of an MSP is a recognised attack pattern, not a hypothetical one.
So we apply the same controls we recommend, to ourselves, and we publish them so you can hold us to them.
Our own environment
- Essential Eight. We assess our own environment against the ACSC maturity model on the same cycle we assess clients, and we will share our current position with clients on request.
- Phishing-resistant MFA on all staff accounts, with hardware security keys required for any account holding privileged client access.
- Privileged access separation. Administrative work is performed from dedicated accounts that cannot access email or browse the web.
- Managed devices only. Client environments are accessible exclusively from enrolled, encrypted, compliant company devices. No personal devices, ever.
- Application control and EDR deployed on all staff endpoints and monitored.
- Immutable, tested backups of our own systems and documentation, with restore testing on the same schedule we apply to clients.
Client access and credentials
- Least privilege. Access is scoped to what a role requires and reviewed when people change roles or leave.
- Individual accounts. Every engineer accesses your environment under their own named identity, so your audit logs show a person rather than a shared service account.
- Credential vaulting. Client credentials are held in a dedicated secrets platform with access logging, and never in documentation, email or chat.
- Just-in-time elevation for the highest-privilege operations, with approval recorded.
- Access is revoked on the day an engagement ends or a staff member departs — not at the next review.
People
- National police check for all personnel with client access. Confirm this is your actual practice.
- Reference and identity verification before commencement.
- Confidentiality obligations in every employment and contractor agreement.
- Security awareness training at induction and annually, plus regular internal phishing simulation.
- Australian Government security clearances where an engagement requires them. Delete if not applicable.
Data handling
- Client data is held in Australian data centres wherever practicable, with the specific location named in each service schedule.
- Encryption in transit and at rest across our platforms.
- Client environments are logically separated; we do not commingle client data.
- Data is returned or destroyed at the end of an engagement, in accordance with the service agreement.
Suppliers
We assess the security posture of the platforms we depend on, maintain a register of material sub-processors, and notify clients of changes that affect where or how their data is handled. Where a supplier suffers an incident that affects our clients, we will tell those clients directly rather than waiting for the supplier's public statement.
If we are compromised
We maintain an incident response plan covering compromise of our own environment. If an incident affects, or may affect, a client environment, we will:
- Contain first, and notify affected clients without unreasonable delay.
- Provide the technical facts as we establish them, including what remains unknown.
- Support each client's own assessment and any notification obligation they carry.
- Publish a post-incident summary to affected clients, including what we got wrong.
Reporting a vulnerability
If you believe you have found a security vulnerability in our systems or this website, we want to hear about it and we will not pursue action against anyone who reports in good faith.
Email security@nextcyber.com.au with enough detail to reproduce the issue. We will acknowledge within two business days and keep you updated until it is resolved. Please give us a reasonable period to remediate before disclosing publicly, and please do not access, modify or delete data belonging to anyone else.
Client questions
Clients and prospective clients may request our current Essential Eight position, our sub-processor register, our insurance certificates and our responses to a standard due-diligence questionnaire. Email security@nextcyber.com.au.