Information Security Policy

Overview 

This policy applies to the McLarens group of companies* including their subsidiaries and affiliates.

Information is a critical asset that underpins the operations of McLarens. The management and protection of information is a vital part of corporate governance and the compliance requirements of our clients and relevant legislation across all the countries in which we operate.

This Information Security Policy seeks to complement our established culture of openness, trust and integrity and sets out our commitment to protecting our employees, partners, and clients from illegal cyber activity or damaging actions by individuals or groups, either knowingly or unknowingly.

Effective information security is a team effort involving the participation and support of every McLarens employee and affiliate who deals with our information and/or information systems. It is the responsibility of every employee to understand the requirements and expectations of this Policy, and to conduct their activities accordingly.

Purpose 

The fundamental objectives of this Policy are as follows:

  • To protect McLarens information assets throughout their lifecycle in respect to confidentiality, integrity, and availability to minimise disruptions and damage to the business.
  • To protect McLarens information assets, systems, and processing facilities from all threats whether internal, external, deliberate, or accidental.
  • Detail high level responsibilities for Information Security
  • To provide assurance to the board, investors, staff, clients, third parties and other interested parties.

Scope 

The scope of this Policy includes the storage, access, transmission, and destruction of information across McLarens. It therefore applies to the conduct of all employees and contractors with access to information assets (wherever information or they are located) as well as the applications, systems, equipment, and premises that create, process, transmit, host, or store it, whether in-house, personally owned or provided by external suppliers.

 

This Policy applies to the following:

  • All information assets identified within the McLarens environment, both physical and electronic in nature.
  • All information systems that service or have access to McLarens information assets or that of our clients, whether operated directly by McLarens or contracted with third parties on our behalf.
  • All McLarens employees, regardless of position or level of seniority.
  • McLarens employees located in McLarens offices, at home or at any other location while travelling.
  • All third parties, vendors and contractors that may have an impact on McLarens information assets or that of our clients.
  • All facilities that house or provide access to McLarens information assets or that of our clients.

This Policy applies to the McLarens Group, and as such extends to group companies and countries.

Policy Statements 

McLarens approach to information security is based on the strong ethics and culture of the company; as such it is paramount that we ensure that our information and information entrusted to us by our clients is adequately protected in line with our overall business objectives, strategy, and regulatory requirements.

  • The McLarens Global Management Team (GMT) has approved and endorsed this, Policy.
  • The McLarens GMT is committed to the alignment of information security requirements with the company strategy and objectives, and to reducing information and cyber related risk to an acceptable level.
  • McLarens information assets will be appropriately protected against all types of information and cyber security threats whether internal, external, deliberate, or accidental.
  • McLarens is committed to preserving the confidentiality, integrity, and availability of all physical and electronic information assets throughout the company, to maintain its competitive edge, ensure legal and contractual compliance and protect McLarens brand and reputation.
  • McLarens is committed to the implementation and maintenance of an Information Security Management System (ISMS) and to achieving security standard attestations and alignment where applicable.
  • Information and systems must be classified according to a company agreed classification schema and owners must be identified.
  • Staffs are made aware of information security obligations and cyber threats through terms and conditions of employment, annual policy acceptance and mandatory annual security compliance training and awareness which is undertaken at the commencement of employment and annually thereafter. We also undertake periodic phishing campaigns to create security awareness, along with email communication educating the employees on the significance of cybersecurity.
  • McLarens emphasizes robust measures to safeguard proprietary information. This includes implementing access controls, encryption protocols, and regular audits to ensure the confidentiality and integrity of intellectual assets.
  • All breaches of information security, whether actual or suspected must be reported and investigated. McLarens acknowledges the importance of promptly reporting and communicating any data breaches to the relevant authorities, including the Information Commissioner’s Office (ICO) or equivalent authority, by following the ICO’s or equivalent authority) prescribed notification process and as required by applicable data protection laws.
  • Compliance with this Policy, applicable standards, legislative and regulatory requirements must be maintained.

Policy Principles 

The following principles must be applied:

  • Information security is considered as a fundamental and integral part of McLarens systems and operations.
  • Information security considerations will be embedded into applications, processes, and services in line with the principle secure by design and by default.
  • Policies, standards guidelines, and processes must be developed, implemented, maintained, monitored, and reviewed with an aim of continual improvement.
  • All information assets must only be accessible on a need-to-know basis to specifically identified, authenticated, and authorised personnel. This embodies the principle of least privilege.
  • Cyber resilience plans must be developed, available, fully documented and tested for all prioritised services in line with business continuity plans.
  • All McLarens employees must be made aware of information security within McLarens, through awareness training and communications.
  • The stance of this Policy is prudent – anything not explicitly permitted is prohibited.
  • McLarens employees are encouraged to suggest improvements to information security procedures.

Information Security Responsibilities  

Effectively managing information security across McLarens requires that a clearly defined security organisational structure is in place with associated ownership, accountability, and responsibilities.

All staff contribute to the effective management of information security. Every individual under McLarens employment or contract must have an awareness of information security and must therefore be familiar with the information security policies and processes applicable to their specific function and role.