Legal
Information Security Policy
Last updated: 26 April 2026
Legal
Last updated: 26 April 2026
Allied ESM takes the security of information seriously. This policy summarises our approach to protecting the confidentiality, integrity, and availability of information assets — including client data, company data, and third-party data — entrusted to us in the course of our business.
This is a public-facing summary. Allied ESM also maintains detailed internal information security procedures and standards that govern day-to-day operations.
Certification
Cyber Essentials Certified — whole organisation
Cyber Essentials is the UK Government-backed scheme, delivered by the IASME Consortium on behalf of the National Cyber Security Centre. It verifies the five technical controls that protect against the most common internet-based cyber attacks. Our certification covers the whole organisation, not a single system or department, and is renewed annually.
Certified
4 August 2026
Valid to
4 August 2027
Certification body
Shonsys Limited
Issued by
The IASME Consortium Ltd
Certificate number
2fd73cdf-3026-496e-a036-cb455d652f28
Allied ESM is committed to maintaining appropriate information security controls across all aspects of our business. We recognise that as a service management consultancy handling client data, service configurations, and sensitive business information, robust information security is not optional — it is fundamental to the trust our clients place in us.
Allied ESM holds Cyber Essentials certification, covering the whole organisation. Cyber Essentials is the UK Government-backed scheme that verifies an organisation has the five technical controls in place to defend against the most common internet-based cyber attacks. Our wider approach to information security is aligned to ISO/IEC 27001.
This policy applies to:
In the course of delivering our services, Allied ESM may hold or process the following categories of information:
We do not collect, process, or store payment card data. We do not handle special category personal data (as defined under UK GDPR) in the ordinary course of our business.
Allied ESM applies the principle of least privilege across all systems and data:
Allied ESM takes care in how information is stored, transmitted, and disposed of:
Allied ESM maintains a process for identifying, reporting, and responding to information security incidents:
To report a suspected security issue involving Allied ESM systems or data, please contact us immediately at info@alliedesm.com.
Allied ESM uses a small number of trusted third-party platforms in the delivery of our services and operation of our business. We assess the security posture of these providers before use and prefer providers that hold recognised security certifications.
We require third-party providers who process data on our behalf to do so only under our instruction and in accordance with applicable data protection law. Where required, we put appropriate contractual arrangements in place (such as Data Processing Agreements) to formalise these obligations.
Allied ESM takes reasonable steps to ensure the continuity of our services in the event of a disruptive incident. Our use of cloud-based platforms with built-in redundancy, combined with documented recovery procedures, supports our ability to respond to and recover from disruptions with minimal impact on clients.
Cyber Essentials certification. Allied ESM was certified against the Cyber Essentials scheme on 4 August 2026, with a scope of whole organisation. The certificate was issued by The IASME Consortium Ltd, the National Cyber Security Centre's delivery partner for the scheme, following assessment by Shonsys Limited. Certification is valid for twelve months and is renewed annually; ours is due for recertification on 4 August 2027. Our certificate can be verified independently on the IASME certificate registry, and a copy is available on request.
This policy is reviewed at least annually by Allied ESM's directors, or sooner following a significant security incident, a material change to the business, or changes in applicable law or regulation.
Allied ESM complies with applicable information security and data protection legislation, including the UK GDPR, the Data Protection Act 2018, and the Network and Information Systems (NIS) Regulations where applicable.
If you have questions about our information security practices, wish to report a security concern, or need to discuss our security posture as part of a due diligence process, please contact us: