Cyber Security Statement

Last Updated: 26 March 2025

Table of content

1. Our Commitment to Cyber Security

At Lambson Innovate Ltd, the protection of data, systems, and digital infrastructure is a core priority. As a UK-based manufacturing company operating in a digitally connected world, we are committed to safeguarding our business, employees, partners, and clients from cyber threats.

We take a proactive, risk-based approach to cyber security — ensuring that our systems are resilient, our people are trained, and our practices are aligned with recognised national standards.

2. Cyber Essentials Plus Certified

We are proud to be Cyber Essentials Plus certified — the UK government-backed scheme that verifies our adherence to high standards of cyber security. This certification confirms that we have:

• Protected our internet-connected infrastructure against the most common cyber threats

• Implemented technical controls across firewalls, access management, software updates, and malware protection

• Undergone independent external testing and verification of our systems

Cyber Essentials Plus gives our stakeholders confidence that Lambson Innovate Ltd is serious about cyber hygiene and responsible data handling.

3. Key Areas of Focus

We maintain strong cyber security practices across the following areas:

Network Security

• Firewall and router configurations that prevent unauthorised access

• Segregation of internal networks where appropriate

• Secure configuration of all hardware and software

Access Controls

• Role-based access permissions

• Strong password policies and multi-factor authentication (MFA)

• User accounts audited regularly to remove unnecessary access

Device and Software Management

• Centralised control of device security and patch management

• Automatic software updates and vulnerability monitoring

• Use of reputable antivirus and anti-malware solutions

Data Protection

• Secure storage, encryption, and backup of sensitive information

• Compliance with UK GDPR and Data Protection Act 2018

• Controlled access to client data and intellectual property

User Awareness

• Regular staff training on cyber threats, phishing, and safe digital practices

• Clear policies for acceptable IT use, remote working, and incident reporting

4. Third-Party Security and Supply Chain

We work only with trusted technology suppliers and service providers who meet high standards of cyber security. As part of our supply chain management, we consider the security posture of third parties and include relevant clauses in our contracts and due diligence processes.

5. Incident Response

We maintain a documented incident response plan to identify, manage, and mitigate any cyber incidents. In the event of a data breach or system compromise, we act swiftly to isolate threats, recover systems, and inform affected parties in accordance with legal obligations.

6. Continuous Improvement

Cyber threats are constantly evolving, and so are we. Lambson Innovate Ltd:

• Regularly reviews and updates our cyber policies and procedures

• Monitors emerging threats and adjusts controls accordingly

• Reassesses risks through annual audits and certification reviews

We treat cyber security as an ongoing journey, not a one-time task.

7. Contact

If you have questions about our cyber security practices, please contact:

Lambson Innovate Ltd

Hunt Street

Whitwood Mere

Castleford

West Yorkshire

WF10 1NS

📧 info@lambson-innovate.co.uk