Security & Information Protection
How SSB Defence approaches information security, access, recovery, continuity and responsible disclosure.
Version 1.0 — August 2026
1. Our Approach to Information Security
SSB Defence is a trade name used by StartSmartBusiness.com Inc.
Information security is an ongoing business responsibility rather than a product that can simply be installed. We seek to protect information entrusted to us through administrative, technical and organizational safeguards appropriate to the nature of the information, the systems involved and the risks reasonably associated with them.
2. Security Is Risk Management
No organization can eliminate every cybersecurity risk. Effective security involves understanding what needs to be protected, why it matters to the business, who requires access, where information is located, what systems depend on it, what threats are reasonably foreseeable, what controls are appropriate and how the business will recover when something fails.
Security decisions should be proportionate to the actual business risk.
3. Information We Protect
Depending on the nature of an engagement, SSB Defence may receive or have access to business contact information, client communications, technology inventories, network and system information, security configurations, assessment information, business processes, technical documentation, system logs, backup and recovery information and other information reasonably required to provide services.
Access to information does not create permission to use it for unrelated purposes.
4. Data Minimization
One of the most effective ways to reduce information risk is to avoid unnecessarily collecting or retaining information in the first place. SSB Defence seeks to collect and retain only information reasonably required for legitimate business, contractual, technical, security or legal purposes.
Where detailed information is unnecessary, we may seek to use summaries, redacted information, de-identified information, limited technical extracts or other methods that reduce unnecessary exposure.
5. Access Control
Access to sensitive information and systems should be limited according to legitimate business need. Depending on the system and circumstances, controls may include individual user accounts, role-based permissions, least-privilege access, multi-factor authentication, strong authentication practices, administrative account separation, controlled remote access and periodic access review.
6. Authentication and Credentials
Passwords, authentication tokens, recovery codes and other credentials require particular care. SSB Defence seeks to avoid unnecessary sharing or duplication of credentials and encourages appropriate use of multi-factor authentication, secure credential-management methods, unique accounts, appropriate password practices and controlled administrative access.
Clients should not submit passwords, credentials or authentication information through public website forms. Where credentials are required for legitimate technical work, an appropriate exchange and management method should be established.
7. Client Administrative Control
Security should not require a client to surrender reasonable control of its own environment. Where appropriate, clients should retain or have access to necessary administrative ownership information for systems and services they own.
SSB Defence does not support intentionally withholding essential client-owned credentials or administrative information merely to create dependence on a service provider.
8. System and Network Security
Where appropriate to our operations or an engagement, information-security measures may include endpoint protection, network security, firewalls, secure configuration, patch and update management, email security, access control, malware protection, logging, monitoring, remote access, encryption, segmentation and vulnerability management.
Installing a security product does not by itself establish that the environment is secure.
9. Updates and Vulnerability Management
Security updates are an important part of maintaining technology. However, an update being scheduled does not mean it was successfully installed.
Identify → Schedule → Deploy → Verify → Investigate failures
Critical or operational systems may also require compatibility testing, maintenance windows, rollback planning or vendor coordination before updates are applied.
10. Cloud and Third-Party Services
Cloud services can provide valuable security, resilience and operational capabilities, but using a cloud provider does not transfer all information-security responsibility to that provider.
Organizations remain responsible for areas that may include user accounts, permissions, authentication, configuration, data retention, individual data recovery, third-party integrations, endpoint security and business continuity. SSB Defence considers cloud security to be a shared responsibility.
11. Backup and Recovery
A backup is valuable only if the information and systems required by the business can actually be recovered. Backup planning should consider what is being backed up, frequency, retention, separation from production systems, ransomware protection, recovery credentials, application dependencies, compatible hardware or software, restoration time and periodic recovery testing.
For some legacy or proprietary systems, backing up only the data may not be enough. Recovery may require a complete system image, compatible hardware, installation media, licensing information, configuration records or specialized software.
12. Cloud Data Backup
Cloud availability and individual client-data recovery are not necessarily the same thing. A cloud provider may maintain extensive redundancy and infrastructure-level recovery capabilities while customers remain responsible for recovering information affected by accidental deletion, user error, malware, corruption, retention expiration, malicious account activity or certain synchronization events.
Organizations should understand exactly what their cloud provider protects and what remains the customer's responsibility. Where appropriate, independent backup or recovery capabilities should be considered for important cloud-hosted information.
13. Business Continuity
Cybersecurity planning should consider how the business continues operating when technology becomes unavailable. Potential disruptions include Internet outages, cloud-provider outages, cyberattacks, ransomware, hardware failures, power interruptions, telecommunications failures, software corruption and third-party service interruptions.
14. Verification and Testing
Important controls should be verified where reasonably appropriate.
- Backup configured → test restoration.
- Security update deployed → confirm installation.
- Account removed → verify access is gone.
- Security product installed → confirm it is operating.
- Recovery plan documented → determine whether it can actually be followed.
15. Security Monitoring and Logging
Logging and monitoring can help identify unusual activity, diagnose problems and investigate security incidents. Where monitoring is used, consideration should also be given to privacy, retention, access to logs, alert quality, review responsibilities and whether someone is actually responding to meaningful alerts.
16. Incident Response
Depending on the circumstances, appropriate actions may include containment, preservation of relevant information, technical investigation, credential protection, system recovery, communication with affected parties, engagement of specialist assistance, legal or insurance notification, and regulatory or privacy reporting where required.
Significant incidents may require specialized forensic, legal, privacy, insurance or law-enforcement involvement beyond the normal scope of IT support.
17. Client Security Information
Detailed information about a client's cybersecurity environment can itself be sensitive. Public website forms should not be used to submit passwords, credentials, detailed vulnerability reports, private encryption keys, sensitive network configurations or other information that could materially increase security risk if exposed.
18. Artificial Intelligence and Information Security
Before confidential or security-sensitive information is provided to an AI platform, organizations should understand what information the platform receives, where it is processed, whether it is retained, who can access it, whether it may be used for model improvement, what contractual protections apply and whether the information should be provided at all.
SSB Defence does not knowingly submit sensitive client information to public or consumer AI services where doing so would be inconsistent with our obligations to the client. Additional information is provided in our Responsible AI Statement.
19. Third-Party and Supply-Chain Risk
An organization's security increasingly depends on other organizations. Technology suppliers, cloud platforms, managed services, software vendors and other service providers can create dependencies that affect security, privacy, availability, recovery, data sovereignty and business continuity.
Vendor reputation alone does not eliminate third-party risk.
20. Legacy and Operational Technology
Older technology is not automatically insecure, and newer technology is not automatically secure. Legacy and operational systems should be evaluated according to their actual exposure, function, supportability, vulnerabilities, dependencies, recovery capability and business importance.
Where replacement is impractical, appropriate compensating controls may include segmentation, restricted access, application control, monitoring, isolation, enhanced backup or other measures.
21. Physical Security
Information security is not limited to networks and software. Depending on the environment, organizations should also consider physical access to servers, network equipment, workstations, backup media, portable devices, communications equipment and sensitive records.
22. Employee and User Responsibility
Users should understand their responsibilities regarding credentials, phishing, email, sensitive information, approved applications, remote access, mobile devices, AI tools, reporting suspicious activity and following established security procedures.
Security awareness should be practical, relevant and periodically reinforced.
23. Continuous Improvement
Cybersecurity is not a one-time project. Technology changes. Businesses change. Employees change. Threats change. Information-security practices should therefore be reviewed periodically and when significant changes occur.
24. Responsible Disclosure of Security Concerns
If someone believes they have identified a security issue involving the SSB Defence website or systems, we ask that they report the concern responsibly and avoid actions that could disrupt services, access information without authorization or affect other users.
A report should contain enough information for us to understand and investigate the concern without unnecessarily exposing sensitive information.
Security concerns: Email Security
25. Related Policies
Our information-security approach should be read together with our Privacy Policy, Responsible AI Statement, Professional Standards, Our Commitments and Client Bill of Rights.
26. Contact
Questions regarding this Security & Information Protection Statement may be directed to:
SSB Defence
A trade name of StartSmartBusiness.com Inc.
Email SSB Defence
27. Updates
We may revise this statement as technology, threats, services, standards and applicable requirements evolve. The current version published on the SSB Defence website will apply from its stated effective date.
Version 1.0 — August 2026