Governance

Moneytree's security programme is built on a formal Information Security Management System (ISMS), independently certified to ISO/IEC 27001. The policies below provide management direction, define controls, and assign accountability across the organisation.

🦅
CrowdStrike Falcon Endpoint Protection

AI-powered endpoint detection and response (EDR) for malware prevention, threat hunting, and real-time device protection across all managed endpoints.

🔐
Code42 Incydr Data Loss Prevention

Monitors and prevents insider-driven data exposure across file movement, cloud uploads, and removable media — aligned with the Data Loss Prevention Policy.

🤖
GitHub Dependabot Vulnerability Management

Automatically detects and raises pull requests to remediate known vulnerabilities in third-party dependencies across all code repositories.

☁️
AWS Security Hub Cloud Security Posture

Aggregates and prioritises findings from GuardDuty, Inspector, Config, Health, Trusted Advisor, and other AWS services into a unified security dashboard.

📊
Sumo Logic Log Analysis & SIEM

Centralised log ingestion and real-time analysis across infrastructure and applications, enabling threat detection, alerting, and compliance reporting.

🪪
Okta Identity & Access Control

Single sign-on (SSO) and multi-factor authentication (MFA) for all managed applications, enforcing least-privilege access and streamlining access lifecycle management.

📱
JAMF & JumpCloud Mobile Device Management

Fleet management for macOS, iOS, and other devices — enforcing encryption, OS updates, compliance baselines, and remote wipe capabilities.

🔄

All policies are reviewed on a defined schedule aligned with the ISMS programme calendar. Core documents are reviewed at least annually; operational policies are reviewed when there is a material change or on a risk-driven basis. Review outcomes are reported to the Information Security Committee.