At WorkBuzz, we help organisations to build a great culture, make smarter people decisions and retain their best talent to improve employee engagement and workplace culture. We understand the important responsibility of safeguarding the data you trust us to hold on your behalf. Information security is at the heart of everything we do and is deeply engrained in our culture. It is embedded in the design of our platform, tools and products and is part of our daily operations.
At WorkBuzz, we maintain an information security management system (ISMS) designed to meet evolving security challenges and we subject our systems to rigorous internal and external security assessments and penetration tests. We are ISO27001:2022 and Cyber Essentials certified, and we are fully compliant with the UK GDPR and a range of other legislation and controls.
It is our policy to:
- Make the details of our policies and procedures known to all other interested parties including external parties where appropriate and determine the need for communication and by what methods relevant to the business management system
- Comply with all legal requirements, codes of practice and all other requirements applicable to our activities; therefore, as a company, we are committed to satisfying applicable requirements related to information security and the continual improvement of the ISMS
- Provide details of resources of equipment, trained and competent staff and any other requirements to enable these objectives to be met
- Ensure that all employees are made aware of their individual obligations in respect of this information security policy
- Maintain an information security management system that will achieve these objectives and seek continual improvement in the effectiveness and performance of our management system, based on “risk”.
Our stance on information security is continually evolving and we are committed to staying ahead of threats through vigilance, ensuring that we implement ‘privacy by design’ into everything we do, ensuring that we strictly control access to data and that we review our stance at regular intervals.
This information security statement provides an overview of the framework for setting, monitoring, reviewing and achieving our objectives, programmes and targets and to ensure the company maintains its awareness for continuous improvement of the ISMS. The ISMS is controlled by the ISMS Manager and is reviewed annually by the WorkBuzz Leadership team to ensure it remains appropriate and suitable to our business.
Steve Frost, CEO at WorkBuzz