Security Policy
1. Purpose
This Security Policy establishes the framework, standards, and practices that Damhills Technologies Limited ("Damhills") follows to protect the confidentiality, integrity, and availability of all information assets — including client data, company intellectual property, employee records, and operational systems.
As an IT solutions company delivering software development, cybersecurity, and network infrastructure services, information security is foundational to our business operations and client trust. This policy applies to all employees, contractors, vendors, and third parties who access Damhills systems or data.
2. Information Security Principles
Confidentiality
Ensuring information is accessible only to authorised individuals with a legitimate business need.
Integrity
Safeguarding the accuracy and completeness of information and processing methods.
Availability
Ensuring that authorised users have reliable and timely access to information and associated assets.
3. Access Control
Access to information systems is governed by the Principle of Least Privilege — users are granted only the minimum access necessary to perform their job functions. Specific controls include:
- Role-Based Access Control (RBAC): All systems enforce role-based permissions, ensuring employees can only access data relevant to their department and function.
- Multi-Factor Authentication (MFA): MFA is mandatory for all internal systems, client portals, cloud dashboards, and administrative interfaces.
- Password Policy: Minimum 12-character passwords with complexity requirements, rotated every 90 days. Password managers are encouraged and provided.
- Access Reviews: Quarterly access reviews are conducted to ensure former employees, expired contractors, and unnecessary privileges are promptly revoked.
- Privileged Access Management: Administrative and root access is tightly controlled through a Privileged Access Management (PAM) solution with session logging and approval workflows.
4. Network & Infrastructure Security
Our infrastructure is designed with security at every layer:
- Firewall & IDS/IPS: Enterprise-grade firewalls and intrusion detection/prevention systems protect all network perimeters.
- Network Segmentation: Production, staging, development, and corporate networks are logically isolated to contain potential breaches.
- DDoS Protection: Cloud-based DDoS mitigation services protect client-facing applications from volumetric and application-layer attacks.
- VPN & Encryption: All remote access is tunnelled through encrypted VPN connections. Data at rest is encrypted using AES-256.
- Patch Management: Critical security patches are applied within 24–72 hours of release. All systems undergo regular vulnerability scanning.
5. Application Security
All software developed by Damhills follows secure coding practices:
- OWASP Top 10 vulnerabilities are addressed in every development sprint
- Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) are integrated into our CI/CD pipelines
- Third-party dependencies are scanned for known vulnerabilities using tools like Dependabot and Snyk
- Code reviews with security checklists are mandatory before any production deployment
- Penetration testing is conducted by independent security assessors for all client-facing applications
6. Incident Response
Damhills maintains a formal Incident Response Plan (IRP) with the following phases:
1. Detection & Analysis
Security events are monitored 24/7 through SIEM tools. Anomalies trigger immediate investigation by the security team.
2. Containment
Affected systems are isolated to prevent lateral movement. Short-term and long-term containment strategies are deployed.
3. Eradication & Recovery
Root causes are identified and eliminated. Systems are restored from verified clean backups and validated before reconnection.
4. Post-Incident Review
A thorough post-mortem is conducted. Lessons learned are documented and incorporated into improved security controls.
7. Employee Security Awareness
Human error remains the leading cause of security breaches. To mitigate this risk, Damhills implements:
- Mandatory Onboarding Training: All new employees complete a security induction programme covering data handling, phishing awareness, and acceptable use policies.
- Quarterly Simulations: Simulated phishing campaigns and social engineering tests are conducted to reinforce security vigilance.
- Clean Desk Policy: Sensitive information must not be left unattended on desks, screens, or in unsecured areas.
- Device Security: All company devices are encrypted, password-protected, and equipped with remote wipe capabilities.
8. Third-Party & Vendor Security
Before engaging any third-party vendor or cloud provider, Damhills conducts a security assessment to evaluate their data handling practices, compliance certifications, and incident response capabilities. All vendor agreements include data protection clauses, non-disclosure obligations, and the right to audit.
9. Policy Compliance & Enforcement
Compliance with this Security Policy is mandatory for all personnel. Violations may result in disciplinary action, including termination of employment or contract, and may lead to legal proceedings where applicable. The Chief Technology Officer (CTO) is responsible for overseeing policy compliance, conducting periodic audits, and recommending updates to this policy.
10. Contact
For security-related inquiries, vulnerability reports, or to report a suspected incident, please contact:
Damhills Technologies Limited
Security Operations
Email: info@damhillstechnologieslimited.com
WhatsApp: +234 807 314 0735