By adhering to these guidelines and building a culture of security awareness, we protect our creative work and sensitive data from potential threats.
To raise security awareness across the team, specifically around phishing and other cybersecurity threats, so we protect sensitive data, maintain the integrity of our work, and keep the digital environment safe for everyone.
All team members — full-time, part-time and freelance — as well as community members with access to company accounts and data.
Report suspected phishing to TechOps immediately. Do not click links, download attachments, or enter your credentials if prompted by a suspicious email.
docusign.net/.https://www.docusign.net and may include a regional subdomain such as na2, na3, na4, au, ca, eu or demo.Use strong passwords. Mix uppercase, lowercase, numbers and special characters, and use a password manager to generate and store them. Avoid anything guessable.
1Password is the password manager we use.
Enable multi-factor authentication on all accounts, and especially on anything with access to sensitive information. Use an authentication app for the second factor.
Use email filtering to reduce spam and phishing, and review your settings periodically. Be cautious opening attachments, particularly from unknown senders, and scan them before opening.
Meeting recordings. Make sure recordings have appropriate access restrictions. Avoid sharing sensitive information or client data in publicly accessible recordings. Always notify participants and obtain consent before recording — see the AI meeting notes policy.
Check the defaults. Review the default settings of recording tools periodically against our standards, and set recordings to private or restricted access wherever possible.
Migration note. Carried from Notion on 17 September 2026. Three points for the owner at the next review:
- Password rotation. The source mandates updating passwords every 3 months. Forced rotation has been advised against by NIST since 2017 on the grounds that it produces weaker, more predictable passwords. It has been left in place because it is the stated policy and not mine to change, but it is worth a decision.
- SMS as a second factor. The source offered "an authentication app or SMS". SMS is vulnerable to SIM-swap attacks; the recommendation here has been narrowed to an authentication app. Confirm this is the intent.
- Scope of the 1Password mandate. The source said "if you are a company director, please use 1Password". Generalised here, since a password manager is not a director perk. Confirm licensing covers everyone.
A phishing example screenshot in the source has not been carried across. Re-add it to
content/_assets/if it is still a useful example.
content/policies/security-policy.md. Change the content and bump reviewed in the same commit — that is the whole review process. Migrated from Notion: source page.