Information Security Overview
Published: 23 July 2026 · Reviewed annually · Applies to: 3T Restoration Ltd
3T Restoration Ltd is committed to protecting the confidentiality, integrity and availability of all information it holds — whether relating to customers, employees, suppliers or business operations. This Information Security Overview sets out the principles, controls and responsibilities that govern how we manage and safeguard information across our organisation.
1. Scope and Purpose
This overview applies to all information assets owned, processed or managed by 3T Restoration Ltd, including customer records, survey reports, financial data, employee information, supplier contracts and any other data held in digital or physical form. It applies to all directors, employees, subcontractors and third parties who access or handle company information. The purpose of this document is to communicate our commitment to information security, outline the controls we have in place, and set clear expectations for everyone who interacts with our data. It should be read alongside our Privacy Policy, Cookies Policy and Ethical Code of Conduct.
2. Legal and Regulatory Framework
3T Restoration Ltd operates in full compliance with all applicable information security and data protection legislation, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Computer Misuse Act 1990, the Network and Information Systems (NIS) Regulations 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR). Where we process personal data on behalf of customers or third parties, we do so only on the basis of a lawful processing condition and in accordance with our documented data processing agreements. We maintain records of processing activities as required under Article 30 of the UK GDPR.
3. Information Classification
All information held by 3T Restoration Ltd is classified according to its sensitivity and the potential impact of unauthorised disclosure. We apply four classification levels: Public (information approved for external release), Internal (general business information not intended for public disclosure), Confidential (sensitive business, customer or employee information requiring restricted access), and Restricted (highly sensitive information accessible only to named individuals on a strict need-to-know basis). All personnel are responsible for correctly classifying information they create or handle and for applying the appropriate level of protection. Misclassification or improper handling of sensitive information is treated as a serious breach of this policy.
4. Access Control and Authentication
Access to company systems, applications and data is granted on the principle of least privilege — individuals are given only the minimum level of access required to perform their role. All system accounts are protected by strong, unique passwords and, where technically feasible, multi-factor authentication (MFA). Shared or generic accounts are not permitted. Access rights are reviewed regularly and revoked promptly upon change of role or termination of employment or contract. Remote access to company systems is permitted only through approved, encrypted connections. All access to sensitive or restricted information is logged and subject to periodic audit.
5. Device and Endpoint Security
All devices used to access company information — including laptops, mobile phones and tablets — must be protected by up-to-date operating system software, security patches and reputable anti-malware software. Devices must be encrypted at rest and must be configured to lock automatically after a period of inactivity. Lost or stolen devices must be reported immediately to a director so that remote wipe or account suspension can be initiated without delay. Personal devices used for business purposes (BYOD) must meet the same minimum security standards as company-issued equipment. The use of unmanaged or unsecured devices to access confidential or restricted information is prohibited.
6. Network and Communications Security
Company networks are protected by firewalls, intrusion detection controls and regular security monitoring. All data transmitted over public or untrusted networks — including email containing sensitive information, file transfers and remote system access — must be encrypted using industry-standard protocols (TLS 1.2 or higher). The use of public Wi-Fi networks to access confidential company systems or data is prohibited unless a secure, approved VPN connection is in use. Email communications containing personal data or commercially sensitive information must be sent only to verified recipients and, where appropriate, using encrypted or password-protected attachments.
7. Data Storage and Retention
Customer records, survey reports, photographic evidence and other business data are stored in secure, access-controlled systems. Physical documents containing sensitive information are stored in locked cabinets and disposed of securely by cross-cut shredding or certified destruction. We retain personal data only for as long as is necessary for the purpose for which it was collected, or as required by law. Our data retention schedule defines specific retention periods for each category of information, after which data is securely deleted or anonymised. We do not retain personal data indefinitely and do not use it for purposes incompatible with the original reason for collection.
8. Third-Party and Supply Chain Security
Where we engage third-party suppliers, subcontractors or service providers who may access, process or store company or customer information, we carry out appropriate due diligence to assess their information security practices before engagement. All third parties handling personal data on our behalf are required to enter into a Data Processing Agreement (DPA) that sets out their obligations under UK GDPR. We do not permit third parties to use customer data for their own purposes or to share it with further parties without our explicit written consent. Third-party access to our systems is time-limited, monitored and revoked immediately upon completion of the relevant engagement.
9. Security Awareness and Training
All personnel with access to company information receive security awareness guidance at the point of onboarding and on an ongoing basis. This includes instruction on recognising phishing and social engineering attacks, safe handling of sensitive data, password hygiene, device security, and the correct procedure for reporting suspected security incidents. Directors and senior personnel with access to restricted information receive additional role-specific guidance. We maintain a culture in which security is treated as a shared responsibility — not solely the concern of management — and in which personnel feel confident raising concerns without fear of blame or retaliation.
10. Incident Detection and Response
3T Restoration Ltd maintains a documented incident response process for identifying, containing, investigating and recovering from information security incidents. All personnel are required to report any actual or suspected security incident — including lost devices, unauthorised access, phishing attempts, data breaches or system anomalies — to a director immediately upon discovery. Where an incident involves a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware, as required under Article 33 of the UK GDPR. Affected individuals will be notified without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
11. Business Continuity and Disaster Recovery
We maintain business continuity arrangements to ensure that critical information and systems can be recovered promptly in the event of a significant disruption — including hardware failure, ransomware attack, fire, flood or other unforeseen event. Key business data is backed up regularly to secure, geographically separate locations. Backups are tested periodically to confirm that data can be successfully restored within an acceptable timeframe. Our continuity arrangements are reviewed annually and updated to reflect changes in our systems, data volumes and operational requirements. The objective is to minimise disruption to customers and to resume normal operations as quickly as possible following any incident.
12. Physical Security
Access to premises where sensitive information is processed or stored is restricted to authorised personnel. Visitors are required to sign in and are accompanied at all times in areas where confidential information may be visible. Clear desk and clear screen policies apply in all working environments — sensitive documents must not be left unattended, and screens must be locked when not in use. Physical media containing sensitive data — including USB drives, external hard drives and printed documents — must be stored securely and disposed of in accordance with our data retention and destruction procedures. The removal of physical media from company premises requires prior authorisation.
13. Vulnerability Management and Patching
We apply a risk-based approach to vulnerability management. Operating systems, applications and firmware on all company devices and systems are kept up to date with security patches and updates, which are applied promptly following release by the relevant vendor. Where a critical vulnerability is identified, remediation is prioritised and completed without delay. We conduct periodic reviews of our technology estate to identify outdated, unsupported or end-of-life software and hardware, and take appropriate action to mitigate the associated risks. Any system or application that cannot be patched to a secure state is isolated, replaced or decommissioned.
14. Governance, Review and Accountability
Overall responsibility for information security rests with the directors of 3T Restoration Ltd. This overview, together with our supporting security controls and procedures, is reviewed at least annually and following any significant security incident, material change to our systems or relevant change in legislation. Compliance with this overview is mandatory for all personnel and third parties with access to company information. Non-compliance is treated as a disciplinary matter and may result in termination of employment or contract. We are committed to continual improvement of our information security posture and to maintaining the trust that our customers, employees and partners place in us.
Useful Contacts & Resources
- Information Commissioner's Office (ICO): ico.org.uk — Report a data breach or make a complaint.
- National Cyber Security Centre (NCSC): www.ncsc.gov.uk — Guidance on cyber security for UK organisations.
- Action Fraud: www.actionfraud.police.uk — Report cyber crime or fraud to the UK's national reporting centre.
- GOV.UK — UK GDPR Guidance: www.gov.uk/data-protection
- Report a security concern to 3T Restoration Ltd: [email protected]
Related Policies
- Privacy Policy — How we collect, use and protect personal data under UK GDPR.
- Cookies Policy — How we use cookies and similar tracking technologies on our website.
- Ethical Code of Conduct — The principles of integrity and professionalism governing all business activities.
- ESG Report — Environmental, Social and Governance commitments across our business.
- Terms of Use — The terms governing use of our website and services.
This overview was approved by the directors of 3T Restoration Ltd and published on 23 July 2026. It will be reviewed and updated annually or following any significant security incident or material change in legislation. For any queries or to report a security concern, contact us at [email protected] or visit our contact page.