Summary
Every BeeTcore team member, contractor, and delivery partner with access to client systems is trained in information security before that access is granted, and the training continues for as long as they work with BeeTcore. Training is matched to each person’s role, led by BeeTcore’s leadership, and aligned to the principles of ISO 27001. Security is treated as everyone’s job, and anyone can raise a concern at any time.
1. Scope and ownership
The program covers every employee, contractor, and delivery partner who handles client systems or data. It is owned and led by BeeTcore’s leadership, who set the content, track completion, and keep it current.
2. Onboarding
No one receives access to client systems before completing a security briefing. Onboarding covers:
- Confidentiality agreements (NDAs), signed before any access is granted
- Individual accounts with multi-factor authentication, set up from day one
- Access to the approved team password manager, and how to use it
- BeeTcore’s rules for handling client data and credentials
3. Core training for everyone
- Credentials: passwords live only in the approved team password manager, and are never shared in email, chat, or documents.
- Multi-factor authentication: required on every account that supports it.
- Phishing and social engineering: how to recognise suspicious emails, messages, links, and requests, including those that appear to come from clients or colleagues.
- Device security: keeping devices updated, locked, and protected, and never leaving client data on shared or personal devices.
- Client data: collecting and keeping only what is needed, in line with the GDPR, the Nigeria Data Protection Act 2023, and other applicable laws.
- Reporting: what to report, and how, as set out in Section 7.
4. Role-specific training
- Developers: secure coding against the OWASP Top 10, managing secrets and keys, and keeping dependencies safe, as set out in the Secure Web Development Framework.
- Project managers: handling client data and access requests, and following the Change Management Framework.
- Designers and content teams: handling client assets and any personal data in content safely.
- Leadership: the evolving threat landscape, compliance obligations, and BeeTcore’s overall security posture.
5. Ongoing learning
Training is refreshed regularly, at planned intervals. The team is briefed when significant new threats or vulnerabilities emerge, and a shared library of security guidance is kept current. Lessons from real incidents are shared with the team through Continuous Service Improvement.
6. Practical exercises
The team works through realistic scenarios, such as a phishing attempt, a compromised account, or a suspected platform breach, to practise recognising threats and following the Incident Management Response Strategy.
7. Reporting and open culture
Anyone can report a suspected security issue, mistake, or near miss immediately, without blame. Early reporting is valued over perfect judgement. Questions about security can be raised with BeeTcore’s technical leadership at any time.
8. Compliance updates
The team is kept informed of changes to the data protection laws and security standards BeeTcore aligns to, including the GDPR, the NDPA, and updates to the OWASP Top 10, and of what those changes mean for day-to-day work.
9. Offboarding
When someone leaves BeeTcore or finishes an engagement, their access to all systems, client platforms, and shared credentials is removed. Shared credentials they could access are rotated.
10. Public awareness
BeeTcore shares practical security guidance publicly, through its own channels and through its leadership’s professional profiles, to help clients and the wider community stay safe online.
11. Review
This program is reviewed annually and after any incident involving human error, to keep training relevant to real risks.
Frequently asked questions
Is BeeTcore's team trained in information security?
Yes. Every team member, contractor, and delivery partner is trained before they receive access to client systems, and training is refreshed regularly and matched to their role.
What happens to access when someone leaves BeeTcore?
Their access to all systems, client platforms, and shared credentials is removed, and any shared credentials they could access are rotated.
How are client passwords and credentials handled?
Credentials are held only in an approved team password manager, protected by multi-factor authentication, and never shared by email, chat, or documents.