Rothian
CapabilitiesSolutionsApproachServicesUI4AIAgentsInsightsUpdatesAbout
Book a working session
CapabilitiesSolutionsApproachServicesUI4AIAgentsInsightsUpdatesAbout
Book a working session
← Policies
Governance

Information security policy

How Rothian protects its own and its clients’ information, the controls we apply to people, devices, suppliers and AI tools, and how we handle incidents.

Last updated
16 September 2026
Next review
16 September 2027

This is a public summary of our information security policy. The full policy and supporting standards are available to clients and prospective clients on request.

Purpose and scope

Clients trust us with access to their systems, data and plans. This policy sets out how we protect the confidentiality, integrity and availability of that information, and of our own. It applies to everyone who works for or with Rothian — employees, directors, associates and subcontractors — and to every system, device and service used for Rothian work.

Principles

  • Proportionate to risk. Controls reflect the sensitivity of the information and the threats we face, assessed and reviewed through a risk register.
  • Least privilege. People and systems get the minimum access needed, for the minimum time.
  • Client rules first. Where a client’s security requirements are stricter than ours, theirs apply on their engagement.
  • Secure by design. Security is part of how we design and build, not a review at the end.
  • Aligned to recognised standards. Our controls are aligned to ISO/IEC 27001:2022 and the NCSC Cyber Assessment Framework, and cover the Cyber Essentials technical controls.

Leadership and responsibility

A director is accountable for information security and reports on it to the board at least quarterly. Everyone is responsible for following this policy and reporting concerns.

Key controls

People. Background checks proportionate to the role; confidentiality obligations in every contract; security and data protection training at induction and annually; access removed on the day someone leaves an engagement.

Identity and access. Single sign-on and phishing-resistant multi-factor authentication on all business systems; no shared accounts; privileged access time-limited and logged; access reviewed quarterly.

Devices. Company-managed or enrolled devices only for client data; full-disk encryption, automatic updates, endpoint detection and response, and remote wipe; screens locked when unattended.

Data. Information classified and handled by classification; encryption in transit and at rest; client data kept in client-approved locations and deleted or returned at the end of an engagement; no client data on personal accounts or removable media.

Software development. Peer review on every change; automated security testing, dependency and secret scanning in pipelines; signed commits and software bills of materials; production access separated from development.

Suppliers. Security and data protection due diligence before onboarding any supplier that handles sensitive information, with contractual obligations and periodic review.

AI tools. Only approved AI tools may be used for client work, under enterprise terms that prevent training on our or our clients’ data. Client data is never entered into consumer AI services. See our responsible AI policy.

Resilience. Business-critical data backed up and restores tested; continuity plans for loss of key systems or people.

Incidents

Anyone who suspects a security incident must report it immediately. We contain, investigate and learn from every incident. Where client information is involved, we notify the client without undue delay and within any contractual timescale, and we meet our obligations to notify the Information Commissioner’s Office and affected individuals.

Compliance and review

Breaches of this policy may lead to disciplinary action or termination of contract. We review the policy at least annually, and after any significant incident or change in how we work.

Governance
  • Information security policy
  • Responsible AI policy
  • Anti-bribery and corruption policy
  • Whistleblowing policy
  • Supplier and associate code of conduct
All policies →
Rothian

Empowering Business.

Outcomes, not resources. An SME core, an associate network, and five capabilities across four services.

Follow us on LinkedIn ↗
Capabilities
ApplicationCloudCyberDataDigitalAll solutions
Services
StrategyDesignDevelopmentDeliveryDelivery framework
AI
UI4AIAgentic solutionsPartners
Company
AboutOur valuesInsightsUpdatesAssociate networkContactinfo@rothian.com
PrivacyCookiesTermsAccessibilityModern slaveryAll policies
© 2026 Rothian LtdRegistered in England and WalesCompany No. 11570066VAT Reg. 345 8483 68Empowering Business