This document is a guide detailing the organization's commitment to cyber security and the measures implemented to protect sensitive data. It outlines various technical security protocols, including network and host-based intrusion prevention systems, as well as the use of Multi-Factor Authentication (MFA) to enhance user account security. The guide describes data protection strategies such as multi-tier backups and adherence to the least privilege principle for data access. It also addresses redundancy and continuity through the maintenance of redundant resources and regular security audits. Network security measures are discussed, including advanced firewall systems and intrusion detection systems. Additionally, the document highlights software security practices, including regular updates and change tracking. Compliance efforts are noted with the mention of ISO 9001 certification and preparation for ISO 27001 certification. Employee training initiatives, such as phishing simulations, are also included to ensure staff are equipped to handle security threats.