COGNIORA CONSULTING LTD is committed to protecting the confidentiality, integrity and availability of the information entrusted to us by our clients, suppliers, partners and employees.
This Information Security Policy sets out our commitment to maintaining appropriate security controls and reducing information security risks.
This policy applies to:
• All business activities carried out by COGNIORA CONSULTING LTD.
• All employees, directors and contractors.
• All information processed by the business, whether electronic or paper-based.
• All systems, devices and cloud services used to support our operations.
We aim to:
• Protect confidential information from unauthorised access.
• Maintain the accuracy and integrity of information.
• Ensure information is available when required.
• Comply with applicable legal and regulatory requirements.
• Continuously improve our information security practices.
Information is handled according to its sensitivity.
Information may be classified as:
• Public
• Internal
• Confidential
• Client Confidential
Appropriate safeguards are applied according to the classification.
Access to business information is restricted to authorised individuals who require access to perform their duties.
We aim to:
• Use strong passwords.
• Enable multi-factor authentication where available.
• Remove access promptly when no longer required.
• Apply the principle of least privilege.
Business devices should be protected through appropriate security measures, including:
• Password or biometric authentication.
• Device encryption where available.
• Automatic locking after periods of inactivity.
• Regular software updates.
• Anti-malware protection.
We use reputable cloud service providers where appropriate to support our business operations.
Cloud providers are selected based on reliability, security and compliance with applicable data protection legislation.
Personal data is processed in accordance with:
• UK GDPR.
• Data Protection Act 2018.
• Our Privacy Policy.
We only collect and retain personal information necessary for legitimate business purposes.
Any suspected information security incident should be investigated promptly.
Where appropriate we will:
• Assess the impact.
• Contain the incident.
• Restore affected services.
• Implement corrective actions.
• Notify affected parties where required by law.
Reasonable measures are maintained to reduce the impact of unexpected disruption.
These may include:
• Secure cloud storage.
• Backup procedures.
• Recovery planning.
• Alternative communication methods.
Anyone working on behalf of COGNIORA CONSULTING LTD is expected to:
• Protect confidential information.
• Use business systems responsibly.
• Report suspected security incidents promptly.
• Follow applicable security procedures.
Where third-party providers are used, we seek to work with organisations that maintain appropriate security standards.
Access to client information is limited to what is necessary for the provision of services.
Information security is reviewed periodically.
Security measures may be updated in response to:
• New threats.
• Changes in technology.
• Business growth.
• Legal or regulatory changes.
This policy will be reviewed periodically to ensure it remains appropriate for the business and reflects current legal and operational requirements.
COGNIORA CONSULTING LTD
Company Number: 16743129
Registered Office
65 Knowl Piece
Wilbury Way
Hitchin
Hertfordshire
SG4 0TY
United Kingdom
Cogniora Consulting
Copyright © 2026 Cogniora Consulting - All Rights Reserved.