Spring Development Bank

Cyber Security Policy

SDB is committed to providing all users with secure digital solutions that enable the users to have full control of their finances instantly. SDB’s absolute commitment to cybersecurity ensures that all users can enjoy our services and products with complete trust and peace of mind. This Cybersecurity Policy (Policy) sets out our approach to safeguarding the users information.

This Policy applies to everyone associate with SDB from employees, consultants, third parties, suppliers, and partners who handle or have access to SDB’s information.

The objectives of the Policy are:

  • Safeguarding data by keeping the users’ information confidential, to preserve the integrity and availability of SDB’s information.
  • Implement protective measures for the systems supporting our business operations.
  • To proactively identify, manage and mitigate vulnerabilities to prevent cyber incidents.

Information Security Principles

SDB adhere to the following principles in relation to Information:

  • Restrict information access and disclosure will only be made with the authorised entities.
  • Ensure to maintain information accurate and protect against unauthorised malicious attempts.
  • The information must be accessible when requested by authorised entities.

Guidance

To achieve the above objectives, the following guidelines have been established:

  • Access to the systems and resources must be based on business necessity, division of duties to be clearly set out, and monitor user access from creation to deactivation, and reviews process in place.
  • Passwords must meet the relevant complexity requirements, unique and not stored or shared.
  • Maintain activities logs for audit trails and regular review process in place.
  • As and when necessary Cryptographic algorithms are to be applied to protect data.
  • Measures are in place to prevent any unauthorised data leaving our internal systems.
  • Appropriate processes are in place to detect threats timely to prevent and mitigate against any infrastructural attacks.
  • Establish a robust process to mange vulnerabilities from identification to remediation.
  • Implement anti-malware solutions to protect against malicious software.
  • Restrict critical or sensitive information assets to segregated network zones with stringent access controls.
  • Ensure the availability of backups to recover data and resume services after disruptions.
  • Integrate security requirements throughout the software development process.
  • Conduct security evaluations prior to deploying new technologies, tools, or solutions.
  • Develop procedures and controls to manage, record, analyse, and reduce the impact of cybersecurity incidents.
  • Categorise information to establish appropriate levels of protection during storage and transmission.
  • Develop and annually test a Business Continuity Plan (BCP) to preserve critical business operations during crises.
  • Provide regular training on security principles to enable staff to identify and respond correctly to security risks.
  • Review the Cybersecurity Policy at least annually.

Important Security Recommendations for SDB Users

  • Create complex passwords without incorporating personal information and combinations of at least random words and numbers.
  • Activate additional authentication layers where possible.
  • Use secure devices and networks and avoid public or untrusted ones.
  • Regularly update operating systems and applications.
  • Consider using updated antivirus solutions.
  • Do not open any suspicious emails and click on unfamiliar links.
  • Do not share your personal and financial information on suspicious platforms.
  • Lock your devices when not in use.
  • Maintain backups of critical data.

SDB takes Cybersecurity very seriously and we are committed to maintaining robust Cybersecurity Policy to ensure your peace of mind while using our services and enable your digital experience safe and secured.