Security
At Lyquix, we prioritize the security of our systems, data, and client information. Maintaining a high level of security requires both technical measures and vigilant human practices. This document outlines the security protocols that all employees must follow to help protect our organization and our clients.
Security is Everyone's Responsibility
At Lyquix, maintaining the security of our systems, data, and client information is a top priority. It is your personal responsibility to adhere to security protocols, remain vigilant, and take proactive steps to protect sensitive information. Remember, a single lapse in security can have serious consequences for the entire organization. Disregarding these policies or exhibiting negligence is considered a serious breach of trust and may result in disciplinary action.
Employee Training
Human factors play a crucial role in maintaining security. To ensure that all team members are well-equipped to handle security challenges, all Lyquix employees are required to complete comprehensive security awareness training.
The Security Awareness Training is available online at Coursera. The course covers essential topics such as recognizing phishing attempts, understanding secure communication practices, and safeguarding sensitive information.
Password Management
To safeguard sensitive information and client credentials, Lyquix uses robust password management protocols:
Team Password Manager: We use a secure team password manager system, Passwork.me, to store and manage client passwords. This system provides a secure and centralized way to handle sensitive credentials, ensuring that passwords are stored and shared securely among team members.
Access Control: Access to the Passwork system is granted on an as-needed basis. Team members are given access only to the passwords necessary for their work. When access is no longer required, the team member's access is promptly removed to maintain security.
Personal Password Managers: Each team member is required to use a personal password manager to manage their individual passwords. This practice helps ensure that all passwords, whether for Lyquix systems or personal accounts, are strong, unique, and securely stored.
Additional Security Policies
To further enhance security, all team members are expected to adhere to the following:
Lock Devices with a Password or PIN: Set up your computer and mobile device with a password and PIN, and configure them to lock automatically after a period of inactivity. Lock your computer and devices when walking away. On your mobile device, enable face recognition or fingerprint authentication to access apps with sensitive information, such as password managers.
Always Use Strong, Unique Passwords: Always create strong, unique passwords for each account. Passwords should be a mix of letters, numbers, and special characters, be at least 10 characters long, and should not contain easily guessable information like birthdays or common words. Use the password generator in your password manager to create secure passwords.
Enable Two-Factor Authentication (2FA): Whenever possible, enable two-factor authentication (2FA) for an additional layer of security. This helps protect accounts even if a password is compromised by requiring a second form of verification, such as a code sent to your phone.
Regularly Update Software: Ensure that all software, including personal devices and workstations, is regularly updated to the latest versions. This helps protect against known vulnerabilities. Enable automatic updates where possible to ensure you always have the latest security patches.
Be Vigilant Against Phishing: Always be cautious when receiving unsolicited emails, especially those that ask for sensitive information or include suspicious links. If an email seems suspicious, do not click on any links or download attachments. Verify the legitimacy of the communication through other channels before responding.
Install Security Browser Extensions: Enhance your browser security by installing the following extensions:
- AdBlock: Blocks ads and prevents ad-related tracking.
- uBlock Origin: An efficient, lightweight blocker for unwanted content.
- Privacy Badger: Blocks invisible trackers.
- Microsoft Defender: Provides an extra layer of protection against phishing and malware.
Please Note
You may experience websites breaking or becoming non-responsive when using the uBlock Origin and Privacy Badger extensions. Additionally, some websites that rely on advertising and user tracking may block access to their content if you have these extensions, or AdBlock, enabled. You can disable these extensions for specific websites as needed.
Avoid Suspicious Websites: Be cautious when browsing the web. Avoid visiting suspicious or unsecured websites, especially those that prompt you to download files or enter personal information. Look for the padlock symbol and "https://" in the URL to ensure that a website is secure.
Use Incognito Browser Windows: When browsing in incognito mode, your browser does not save your browsing history, cookies, or form data, which provides an added layer of privacy.
Use Sandbox Environments: On Windows or MacOS, use a sandbox environment for testing potentially unsafe files or applications. Sandboxing isolates the program from the rest of your system, reducing the risk of malware or other security threats.
Be Mindful in Public: When in public spaces, be aware of your surroundings. Avoid displaying sensitive information on your screen, and keep conversations about confidential matters discreet.
Following these security guidelines helps protect not only Lyquix but also our clients' sensitive information. Security is a shared responsibility, and your vigilance is key to maintaining a secure working environment. If you have any questions or need further assistance with security practices, please contact our IT department.