Information Security Policy

Policy ownerSuperSubBetting (sole trader)
Effective date1 January 2025
Version1.0
Review frequencyAnnually or following a significant security incident or change in technology

1. Purpose

This policy sets out the information security controls applied by SuperSubBetting to protect business data, visitor personal data and website integrity from unauthorised access, loss, alteration or disclosure. It supports compliance with UK GDPR Article 32 (security of processing).

2. Legal context

  • Legal requirement: UK GDPR Article 32 requires data controllers to implement appropriate technical and organisational security measures, taking into account the nature and risks of the processing. The standard required is proportionate to the size and risk profile of the business.
  • Not applicable: SuperSubBetting is not subject to mandatory regulatory information security reviews (e.g. FCA CBEST, NCSC Cyber Essentials mandates for government supply chains). An annual self-review of this policy is conducted as best practice.
  • Best practice: The controls below are aligned with NCSC's Cyber Essentials guidance for small organisations, which is not a regulatory obligation for this business but is the UK government's recommended baseline.

3. Scope

All information assets used in the operation of SuperSubBetting, including:

  • The supersubbetting.com website and hosting infrastructure.
  • Business devices (laptop, phone) used to manage the website, communications and finances.
  • Cloud services used for email, file storage and analytics.
  • Commercial service accounts and outbound-link systems.
  • Personal data of website visitors processed via analytics, cookies and contact forms.

4. Responsibilities

The sole trader is personally responsible for implementing and maintaining all information security controls. There are no employees or separate IT function.

5. Practical controls

5.1 Access controls

  • All admin accounts for the website, hosting, email and commercial services are protected by strong unique passwords managed via a password manager (e.g. 1Password, Bitwarden).
  • Two-factor authentication (2FA) is enabled on all admin accounts, email, hosting and financial services where available.
  • Default or shared credentials are never used.
  • Access to admin areas is restricted to the sole trader only. Any freelancer requiring access is given the minimum necessary permissions and access is removed immediately on completion of engagement.

5.2 Device security

  • Business devices use current, fully patched operating systems.
  • Automatic software updates are enabled.
  • Devices are protected by anti-malware software.
  • Full-disk encryption is enabled on laptops and mobile devices.
  • Devices are locked when unattended.

5.3 Network and web security

  • The website is served exclusively over HTTPS with a valid TLS certificate.
  • The website platform and all plugins/dependencies are kept up to date.
  • Business activity on public or untrusted Wi-Fi networks is conducted via a VPN.
  • The website hosting provider is a reputable commercial provider with documented security practices.

5.4 Data handling

  • Personal data is not stored on unencrypted USB drives or portable media.
  • Email containing personal data (e.g. contact-form submissions) is handled carefully and deleted when no longer needed.
  • Personal data is not shared with third parties except as described in the Privacy / Cookie Policy and Data Protection Policy.

5.5 Backups

  • The website and critical business files are backed up regularly (at minimum weekly) to a secondary location (e.g. encrypted cloud storage or external drive kept separate from the primary device).
  • Backups are tested periodically to confirm they can be restored.

5.6 Third-party and supply chain security

  • Third-party tools for analytics, outbound links and contact forms are reviewed at onboarding and periodically thereafter for their security and privacy practices.
  • Software is sourced from official, reputable providers only.

6. Security incident response

  1. Identify: On detecting a suspected security incident (e.g. unauthorised access, data leak, malware, phishing), document the date, time and nature immediately.
  2. Contain: Change affected passwords immediately, revoke compromised access tokens, take affected systems offline if necessary.
  3. Assess: Determine whether personal data has been accessed or exposed. If so, follow the personal-data breach procedure in the Data Protection Policy.
  4. Notify: If the incident involves a hosted service or third-party platform, notify that provider. If personal data has been compromised and the risk threshold is met, notify the ICO within 72 hours.
  5. Remediate: Implement fixes to prevent recurrence. Update passwords, patches and configurations as appropriate.
  6. Record: Log the incident, its impact, and the remedial actions taken in the breach/incident register.

7. Annual review

This policy is reviewed annually. The review considers:

  • Any security incidents during the preceding year.
  • Changes in the tools, platforms or services used by the business.
  • Updates to NCSC guidance or relevant threats to small publishers.
  • Any new personal data processing activities.

Note: No mandatory regulatory information security review applies to SuperSubBetting. The annual self-review is conducted as best practice and to maintain the standard required by UK GDPR Article 32.

8. Record-keeping

  • Security incident register — three years minimum.
  • Backup test records — two years.
  • This policy document with version history — retained indefinitely.