WholeServ Limited – Cybersecurity & Compliance Transparency Statement

WholeServ Limited is committed to transparency and accountability in the delivery of secure IT services. This document outlines the controls, policies, and governance frameworks we have in place to safeguard client data, systems, and operations.

Security & Compliance Frameworks
WholeServ aligns with the following standards and directives:

  • ISO/IEC 27001:2022 (Information Security Management System)
  • UK General Data Protection Regulation (UK GDPR)
  • NIS2 Directive (where applicable to our role in digital infrastructure)

Policy and Governance Oversight

  • WholeServ maintains a full suite of reviewed and version-controlled security policies
  • These cover access control, incident response, data protection, backup, patching, supplier risk, and more
  • Policies are signed and approved by the Technical Director and reviewed annually or upon material change

Board-Level Cyber Accountability

  • The board receives annual cyber awareness briefings and participates in tabletop exercises
  • Cybersecurity is overseen by a named Senior Responsible Person (Jamie Hirst) with board-level authority

Risk & Incident Management

  • WholeServ performs formal risk assessments and maintains a live risk register
  • All security incidents follow a defined triage and escalation process
  • NIS2-aligned incident notification procedures are in place for significant events affecting service or data

Technical Controls & Monitoring

  • Weekly vulnerability scanning using Bitdefender GravityZone (internal and client environments)
  • Real-time alerting and patching using SuperOps RMM and M365 Defender
  • Encrypted backups validated quarterly (Dropsuite and client local platforms)

Third-Party & Data Processing Assurance

  • All suppliers are classified by risk level and reviewed annually
  • Data Processing Agreements (DPAs) are in place with all relevant third parties

Staff & Client Assurance

  • All staff complete cyber awareness training and sign the Acceptable Use Policy
  • Clients under managed services benefit from enforced MFA, patch management, backups, and endpoint protection

Supporting Documentation Available Upon Request:

  • Signed Statement of Applicability (SoA)
  • Data Protection Policy & DPA templates
  • Incident Management and Notification Procedures
  • Supplier Risk Classification and Assurance Documentation

Contact
For audit support, data assurance queries, or requests for supporting documentation, please contact:
Jamie Hirst –Director
📧 services@wholeserv.com

This statement is reviewed annually or upon material changes in legal, regulatory, or contractual obligations.

 

Approved by: Jamie Hirst, Director
Date: 20/06/2025
Version: 1.0