IT Policy

INTRODUCTION

This document sets out the measures to be taken by all employees of Rolf Berryman (the “Company”) and by the Company as a whole in order to protect the Company’s computer systems, devices, infrastructure, computing environment and any and all other relevant equipment (collectively, “IT Systems”) from damage and threats whether internal, external, deliberate or accidental.

 

KEY PRINCIPLES

  • All IT Systems are to be protected against unauthorised access.
  • All IT Systems are to be used only in compliance with relevant Company Policies.
  • All data stored on IT Systems are to be managed securely in compliance with all relevant parts of the Data Protection Act 1998 and all other laws governing data protection whether now or in the future in force.
  • All employees of the Company and any and all third parties authorised to use the IT Systems including, but not limited to, contractors and sub-contractors (collectively, “Users”), must ensure that they are familiar with this Policy and must adhere to and comply with it at all times.
  • All line managers must ensure that all Users under their control and direction must adhere to and comply with this Policy at all times as required under paragraph 2.4.
  • All IT Systems are to be installed, maintained, serviced, repaired and upgraded by Gareth Lautenberg (the “IT Department”) or by such third party/parties as the IT Department may from time to time authorise.
  • The responsibility for the security and integrity of all IT Systems and the data stored thereon (including, but not limited to, the security, integrity and confidentiality of that data) lies with the IT Department unless expressly stated otherwise.
  • All breaches of security pertaining to the IT Systems or any data stored thereon shall be reported and subsequently investigated by the IT Department.
  • All Users must report any and all security concerns relating to the IT Systems or to the data stored thereon immediately to the IT Department.

 

IT DEPARTMENT RESPONSIBILITIES

THE IT MANAGER, GARETH LAUTENBERG, SHALL BE RESPONSIBLE FOR THE FOLLOWING:

  • ensuring that all IT Systems are assessed and deemed suitable for compliance with the Company’s security requirements;
  • ensuring that IT security standards within the Company are effectively implemented and regularly reviewed; and
  • ensuring that all Users are kept aware of the requirements of this Policy and of all related legislation, regulations and other relevant rules whether now or in the future in force including, but not limited to, the Data Protection Act 1998 and the Computer Misuse Act 1990.

THE IT STAFF SHALL BE RESPONSIBLE FOR THE FOLLOWING:

  • assisting all Users in understanding and complying with this Policy;
  • providing all Users with appropriate support and training in IT security matters and use of IT Systems;
  • ensuring that all Users are granted levels of access to IT Systems that are appropriate for each User, taking into account their job role, responsibilities and any special security requirements;
  • receiving and handling all reports relating to IT security matters and taking appropriate action in response;
  • taking proactive action, where possible, to establish and implement IT security procedures and raise User awareness;
  • assisting the IT Manager in monitoring all IT security within the Company and taking all necessary action to implement this Policy and any changes made to this Policy in the future; and
  • ensuring that regular backups are taken of all data stored within the IT Systems at intervals no less than monthly and that such backups are stored at a suitable location off the Company premises.

 

USERS’ RESPONSIBILITIES:

  • All Users must comply with all relevant parts of this Policy at all times when using the IT Systems.
  • All Users must use the IT Systems only within the bounds of UK law and must not use the IT Systems for any purpose or activity which is likely to contravene any UK law whether now or in the future in force.
  • Users must immediately inform the IT Department of any and all security concerns relating to the IT Systems.
  • Users must immediately inform the IT Department of any other technical problems (including, but not limited to, hardware failures and software errors) which may occur on the IT Systems.
  • Any and all deliberate or negligent breaches of this Policy by Users will be handled as appropriate under the Company’s disciplinary procedures.

 

SOFTWARE SECURITY MEASURES

  • All software in use on the IT Systems (including, but not limited to, operating systems and individual software applications) will be kept up-to-date and any and all relevant software updates, patches, fixes and other intermediate releases will be applied at the sole discretion of the IT Department.  This provision does not extend to upgrading software to new ‘major releases’ (e.g. from version 1.0 to version 2.0), only to updates within a particular major release (e.g. from version 1.0 to version 1.0.1 etc.).  Unless a software update is available free of charge it will be classed as a major release and thus falls within the remit of new software procurement and outside the scope of this provision.
  • Where any security flaw is identified in any software that flaw will be either fixed immediately or the software may be withdrawn from the IT Systems until such time as the security flaw can be effectively remedied.
  • No Users may install any software of their own, whether that software is supplied on physical media (e.g. DVD-Rom) or whether it is downloaded, without the approval of the IT Manager.  Any software belonging to Users must be approved by the IT Manager and may only be installed where that installation poses no security risk to the IT Systems and where the installation would not breach any licence agreements to which that software may be subject.
  • All software will be installed onto the IT Systems by the IT Department unless an individual User is given written permission to do so by the IT Manager.  Such written permission must clearly state which software may be installed and onto which computer(s) or device(s) it may be installed.

 

ANTI-VIRUS SECURITY MEASURES:

  • Most IT Systems (including all computers and servers) will be protected with suitable anti-virus, firewall and internet security software.  All such anti-virus, firewall and internet security software will be kept up-to-date with the latest software updates and definitions.
  • All IT Systems protected by anti-virus software will be subject to a full system scan at least annually.
  • All storage media (e.g. USB memory sticks or disks of any kind) used by Users for transferring files must be virus-scanned before any files may be transferred.  Such virus scans shall be performed automatically upon connection.
  • Users shall not be permitted to transfer files using cloud storage systems.
  • Any files being sent to third parties outside the Company, whether by email, on physical media or by other means (e.g. FTP or shared cloud storage) must be scanned for viruses before being sent or as part of the sending process, as appropriate.
  • Where any virus is detected by a User this must be reported immediately to the IT Department (this rule shall apply even where the anti-virus software automatically fixes the problem).  The IT Department shall promptly take any and all necessary action to remedy the problem.  In limited circumstances this may involve the temporary removal of the affected computer or device.  Wherever possible a suitable replacement computer or device will be provided immediately to limit disruption to the User.
  • Where any User deliberately introduces any malicious software or virus to the IT Systems this will constitute a criminal offence under the Computer Misuse Act 1990 and will be handled as appropriate under the Company’s disciplinary procedures.

 

HARDWARE SECURITY MEASURES:

  • Wherever practical, IT Systems will be located in rooms which may be securely locked when not in use or, in appropriate cases, at all times whether in use or not (with authorised Users being granted access by means of a key, smart card, door code or similar).  Where access to such locations is restricted, Users must not allow any unauthorised individual access to such locations for any reason.
  • All IT Systems not intended for normal use by Users (including, but not limited to, servers, networking equipment and network infrastructure) shall be located, wherever possible and practical, in secured, climate-controlled rooms and/or in locked cabinets which may be accessed only by designated members of the IT Department.
  • No Users shall have access to any IT Systems not intended for normal use by Users (including such devices mentioned above) without the express permission of the IT Manager.  Under normal circumstances whenever a problem with such IT Systems is identified by a User, that problem must be reported to the IT Department.  Under no circumstances should a User attempt to rectify any such problems without the express permission (and, in most cases, instruction and/or supervision) of the IT Manager.
  • All non-mobile devices (including, but not limited to, desktop computers, workstations and monitors) shall, wherever possible and practical, be physically secured in place with a suitable locking mechanism.  Where the design of the hardware allows, computer cases shall be locked to prevent tampering with or theft of internal components.
  • All mobile devices (including, but not limited to, laptops, netbooks, tablets, PDAs and mobile telephones) provided by the Company should always be transported securely and handled with care.  In circumstances where such mobile devices are to be left unattended they should be placed inside a lockable case or other suitable container.  Users should make all reasonable efforts to avoid such mobile devices from being left unattended at any location other than their private homes or Company premises.  If any such mobile device is to be left in a vehicle it must be stored out of sight.
  • The IT Department shall maintain a complete asset register of all IT Systems.  All IT Systems shall be labelled and the corresponding data shall be kept on the asset register.

 

ACCESS SECURITY:

  • All IT Systems (and in particular mobile devices including, but not limited to, laptops, netbooks, tablets, PDAs and mobile telephones) shall be protected with a secure password or such other form of secure log-in system as the IT Department may deem appropriate.  Such alternative forms of secure log-in may include fingerprint identification and facial recognition.
  • ALL PASSWORDS MUST, WHERE THE SOFTWARE, COMPUTER OR DEVICE ALLOWS:
    • be at least six characters long;
    • contain a combination of one upper case, one number and one symbol;
    • be changed at least every 45 days;
    • be different from the previous password;
    • not be obvious or easily guessed (e.g. birthdays or other memorable dates, memorable names, events or places etc.); and
    • be created by individual Users.
  • Passwords should be kept secret by each User.  Under no circumstances should a User share their password with anyone including the IT Manager and the IT Staff.  No User will be legitimately asked for their password by anyone at any time and any such request should be refused.  If a User has reason to believe that another individual has obtained their password they should change their password immediately [and report the suspected breach of security to the IT Department].
  • If a User forgets their password, this should be reported to the IT Department.  The IT Department will take the necessary steps to restore the User’s access to the IT Systems which may include the issuing of a temporary password which may be fully or partially known to the member of the IT Staff responsible for resolving the issue.  A new password must be set up by the User immediately upon the restoration of access to the IT Systems.
  • If set up by the company, all IT Systems with displays and user input devices (e.g. mouse, keyboard, touchscreen etc.) shall be protected, where possible, with a password protected screensaver that will activate after a given period of inactivity.  This time period cannot be changed by Users and Users may not disable the screensaver.  Activation of the screensaver will not interrupt or disrupt any other activities taking place on the computer (e.g. data processing).
  • Users may not use any software which may allow outside parties to access the IT Systems without the express consent of the IT Manager.  Any such software must be reasonably required by the User for the performance of their job role and must be fully inspected and cleared by the IT Manager.
  • Users may connect their own devices (including, but not limited to, mobile telephones, tablets and laptops) to the Company network subject to the approval of the IT Department.  Any and all instructions and requirements provided by the IT Department governing the use of Users’ own devices when connected to the Company network must be followed at all times.  Users’ use of their own devices shall be subject to, and governed by, all relevant Company Policies (including, but not limited to, this Policy) while those devices are connected to the Company network or to any other part of the IT Systems.  The IT Department shall reserve the right to request the immediate disconnection of any such devices without notice.

 

DATA PROTECTION:

  • All personal data (as defined in the Data Protection Act 1998) collected, held and processed by the Company will be collected, held and processed strictly in accordance with the eight Data Protection Principles of the Data Protection Act 1998, the provisions of the Data Protection Act 1998 and the Company’s Data Protection Policy.
  • All Users handling data for and on behalf of the Company shall be subject to, and must comply with, the provisions of the Company’s Data Protection Policy.

 

INTERNET AND EMAIL USE:

  • All Users shall be subject to, and must comply with, the provisions of the Company’s Communications, Email and Internet Policy when using the IT Systems.
  • Where provisions in this Policy require any additional steps to be taken to ensure IT security when using the internet or email over and above the requirements imposed by the Communications, Email and Internet Policy, Users must take such steps as required.

 

REPORTING IT SECURITY BREACHES:

  • All concerns, questions, suspected breaches or known breaches shall be referred immediately to Gareth Lautenberg.
  • Upon receiving a question or notification of a breach, the IT Department shall, within 24hours assess the issue including, but not limited to, the level of risk associated therewith, and shall take any and all such steps as the IT Department deems necessary to respond to the issue.
  • Under no circumstances should a User attempt to resolve an IT security breach on their own without first consulting the IT Department.  Users may only attempt to resolve IT security breaches under the instruction of, and with the express permission of, the IT Department.
  • All IT security breaches, whether remedied by the IT Department or by a User under the IT Department’s direction, shall be fully documented.

 

IMPLEMENTATION OF POLICY:

  • This Policy shall be deemed effective as of 25th May 2018.  No part of this Policy shall have retroactive effect and shall thus apply only to matters occurring on or after this date.

 

THIS POLICY HAS BEEN APPROVED AND AUTHORISED BY:

NAME: Gareth Lautenberg

POSITION: Partner

DATE: 4th May 2018

What people say

Have a look at what our clients have to say, they were sitting right where you are now before we helped them.

Eleanor Jones 2

“Peter has secured employment at a firm which ticks all of the boxes for me. I had not previously come across this firm before until he introduced me only a few weeks ago. Peter knew exactly what I was looking for (quality work, but with a focus on work-life balance) and helped me to secure an offer within only two weeks of applying. I am confident that this is a great move for me in the long term, and I probably would not have submitted an application if it weren’t for Peter’s knowledge and relationship with my new employer.”

Eleanor Jones

“I have worked with Peter in the past, but had secured positions via direct applications to employers. I decided to engage Peter to help with my recent search because of his positive ‘can do’ attitude and honest approach. Peter is not a ‘needy’ recruiter and gives you the space and respect to make careful decisions. He does not pressure you into the interview room or waste time applying to numerous employers.”

Sam 3

“Sam is an absolutely brilliant recruiter and I would be very happy to recommend him to anyone looking to move firms. I have worked with several recruiters in the past, and Sam was the one to help me secure my dream position. Sam has great recruiter qualities – he is very proactive, honest, takes time to listen and to truly understand your career goals, and importantly not pushing you into any direction that would suit the current list of vacancies.Sam really understands the legal market and firms he works with and is not afraid to take on challenging mandates such as changing practice areas. Throughout the process, Sam always remained very engaged and quickly answered any queries that I had and helped me with interview preparation. Sam is very friendly and an absolute pleasure to work with and I would not hesitate to recommend him to any candidate.”

Adam 3

“First time moving firms as a 3 year PQE solicitor – keen for a new challenge in a supported, yet demanding, environment.Someone who was willing to understand my situation, listen to me and help guide me by identifying appropriate roles to develop my career.The initial persistence to speak with me (and catching me on the right day) paid off.Adam’s service was top class, from start to finish. He identified appropriate firms and built/maintained good rapport with those involved in the hiring process. Adam is a recruiter of his word – if he says he will do something, he does. He was responsive throughout my engagement and got the balance right by being encouraging and confidence promoting, without being overbearing.Adam succeeded in getting me interviews with top quality firms and a very reasonable offer of employment, in a quality firm, that would be a good move for me. I would recommend Adam without hesitation. He was a pleasure to work with and is a real credit to the recruitment industry.”

Regional Sales Director

I have known Toby for over ten years. Throughout the years, he has been extremely helpful in assisting me to find new roles, irrespective of the geographical location and seniority. In addition to this, he assisted me with locating and placing candidates when I was involved in an office setup in London.

Toby has a honest, no nonsense approach and he truly seeks to find the best fit for the advertised roles. He is well connected and unlike a large majority of recruiters in our space, very commercially aware of the eDiscovery industry.

Toby is a pleasure to work with and I highly recommend engaging with him and his company.

Regional Sales Director

Sam 2

“At a key juncture in my career, I started working with Sam after he approached me with some opportunities that were of interest. Sam is knowledgeable and was communicative throughout my process. I felt informed and confident in my decision to change firms. Sam is honest, personable, informative, and well-connected in the market. Sam helped recruit me to a large, well-known international law firm, increasing my salary by over 30% in the process. Sam delivered a fantastic result, and I would not hesitate in recommending him to others.”

Adam 2

“Adam has been great and really helpful at every stage of the recruitment process. He provided information and guidance ahead of interviews and liaised effectively on my behalf with the firms. I have really valued his support throughout the process”

Mariann 1

“The Service from both Mariann and Toby has been ‘top notch’ great team to have in your corner! Dedicated and completely understand the sector”

Adam 1

“Adam called me personally and explained the opportunities that were available. This led me to pursue those live opportunities when I may not otherwise have had the confidence to do so at this stage given the pandemic. He reassured me about the job market which put my mind at ease, and so I decided to go for it and explore the possibilities”

Sam 1

“Sam was more akin to a consultant than a recruiter. He looked at what would be a good fit for my skill set and where there were potential opportunities for me to progress. Sam discounted good firms, explaining to me why he didn’t think they would fit my profile in the long-term, rather than pushing me into interviews which may have secured him a commission in the short-term, but wouldn’t have been right for me in the long-term. Sam was excellent. Very empathetic and understanding of my personal circumstances, dealing with any issues professionally and sensitively. We worked together to identify what was right for me. Sam helped me secure a position within a prestigious international law firm that will allow me to develop my experience within a growth sector, providing genuine scope for promotion in the future, and a significant salary increase.

I would unquestionably recommend Sam to anyone in the market.”

Get in touch

Whether you are looking for the next step in your career or to build your team, please get in touch...