Legal
Security Policy
Last updated: 1 January 2026
1. Our Commitment
FIVE MELLON Single Member P.C. is committed to protecting the information and data of its clients, partners and employees. This policy sets out the information security principles and practices we follow, in line with the ISO 27001, ISO 9001 and ISO 22301 standards.
2. Scope
This policy applies to all IT systems, networks, applications and data owned or managed by the Company. It covers all employees, partners and third parties with access to our systems.
3. Information Security Principles
Our approach rests on the principles of confidentiality (access only for authorised individuals), integrity (ensuring data is accurate and complete) and availability (ensuring access when it is needed). We apply the principles of least privilege and need to know.
4. Technical Security Measures
We apply encryption of data in transit and at rest, access control with multi-factor authentication, regular backups and restore testing, 24/7 system monitoring, regular vulnerability assessments and penetration testing, and firewalls with advanced protection.
5. Incident Management
We maintain a documented security incident response procedure. Every incident is logged, assessed and handled according to its severity. In the event of a data breach we notify the competent authorities within 72 hours, as required by the GDPR.
6. Training & Awareness
All staff undergo regular information security training. We run annual phishing simulation exercises and issue regular updates on new threats. Security is every employee's responsibility.
7. Policy Review
This policy is reviewed at least annually, or after significant changes. For questions, contact security@fivemellon.com.