Purpose
This policy aims to reduce the risks arising from ransomware, phishing attacks and other malicious activities. It also establishes the principles governing employees’ use of email and the internet in a manner that protects the Company’s interests, systems and reputation.
Email Use
Employees must send and receive business-related emails through the email accounts designated by the Company. Personal email accounts must not be used for business communications.
Emails identified as suspicious or marked as spam must be reviewed with caution and reported to the Company’s IT department or the relevant department manager where necessary.
Files received by email must be checked carefully. Employees must not open or download unknown or suspicious files.
Business emails must be written using appropriate, accurate and professional language to ensure effective communication and protect the Company’s reputation.
Ransomware and Phishing Attacks
Employees must remain aware of the risks associated with ransomware and phishing attacks. The Company provides regular training and awareness activities to keep employees informed about emerging threats and appropriate security practices.
Suspicious emails must be assessed carefully and reported, particularly where they request personal or financial information or contain links that the recipient is asked to click.
Employees must comply with the security measures established by the Company and ensure that approved antivirus software and security patches are kept up to date on their devices.
Internet Use
Internet access must primarily be used for business-related activities. Personal internet use may be limited in accordance with Company policies.
Employees must use the internet in compliance with applicable laws, regulations and Company policies. Engaging in illegal activities online or sharing content that may damage the Company’s reputation is strictly prohibited.
Websites and downloaded files must be assessed carefully and obtained only from trusted sources. Suspicious, harmful or malicious content must be avoided.
Responsibilities and Reporting Violations
Employees must immediately report ransomware incidents, phishing attempts and other suspected security breaches to the Company’s IT department, information security representative or relevant department manager.
The Company will respond to reported security incidents promptly and effectively and will implement the necessary containment, corrective and preventive measures.