Your equipment
The rules for devices sit in the Mobile Device Policy, the Remote Working Policy and the Access Control Policy. This page pulls out what you need day to day.
What you get
Section titled “What you get”- A laptop. Every employee gets one, and so do contractors and associates who need one. It is for business use, with reasonable personal use allowed. There is no expectation of privacy for company data on it, and nobody else uses it, including family.
- A proper home workstation. You complete a display screen equipment self-assessment when you join and every year after. Where it identifies a need, we provide a monitor, riser, keyboard, mouse or chair. You can also have an eyesight test at our expense, and a contribution towards glasses needed specifically for screen work. See the Health and Safety Policy.
- What we do not cover. Home broadband and utilities are not reimbursed, though you can claim the HMRC working-from-home allowance if you are eligible. Our insurance covers company equipment, not your home or its contents, so check your home policy does not exclude clerical work.
How it is set up
Section titled “How it is set up”The Mobile Device Policy sets this baseline for every company device. Keep your laptop to it, and do not disable or work around any of it.
- Full-disk encryption, with the recovery key held by amarti.
- A named account with a strong passphrase and biometric unlock where supported. No shared logins.
- Automatic screen lock after five minutes on laptops and two on phones and tablets.
- Endpoint security software, a host firewall, and a supported operating system. Critical and high-severity updates are applied within 14 days. Repeatedly deferring them is a policy breach and can mean access is suspended until the device is patched.
- Standard user rights. Local administrator rights need James’s approval and a role that requires them, and administrative work is done from a separate named admin account, never your everyday one.
- Work data lives in approved cloud locations, which are backed up centrally. Storing business data only on the device is not permitted.
Only approved software, browser extensions and developer tools may touch company or client data, and only approved cloud services may hold it. That excludes personal file storage, note-taking apps, file conversion websites and the free tiers of AI assistants, which train on their inputs. If you need something new, email Amardeep with what it does and what data it would see; approval usually takes a few days. See the AI and Machine Learning Policy and Developing software with AI.
Accounts and passwords
Section titled “Accounts and passwords”- Every work credential goes in 1Password, the password manager we license for everyone. Not in a browser, a spreadsheet, a notes app or a document.
- Passwords are at least 12 characters, 16 for anything administrative. Three or more random words beat a short string of symbols. Every account gets its own; a work password is never reused elsewhere and a personal one is never reused at work.
- We do not force password changes on a schedule, because forced expiry produces weaker choices. A password is changed immediately if there is any suspicion of compromise, or if it turns up in a breach notification.
- Multi-factor authentication is on everywhere it is supported. Never approve a prompt you did not start; report it as a suspected incident instead.
- Credentials are never shared, even with colleagues, and never sent by email or chat. Use 1Password’s secure sharing if you must share one.
- In engineering work, keys, tokens and connection strings never go into source control, code, notebooks or scripts. Use the platform’s secret manager. If a secret has been committed, revoke and rotate it first; deleting it from the repository does not remove it from history.
Personal devices
Section titled “Personal devices”| Activity | Personal laptop or desktop | Personal phone or tablet |
|---|---|---|
| amarti or client data, code or systems | Not permitted | Not permitted |
| Company email and collaboration apps | Not permitted | Only through the approved managed apps |
| Multi-factor authentication app | Not applicable | Permitted and encouraged |
| Client environments | Not permitted | Not permitted |
A personal phone used for email or Slack needs a passcode or biometric lock, encryption, a current operating system and no jailbreak, and it is enrolled so that we can wipe company data and nothing else. Remove it from company systems when you leave or replace the phone. Any exception needs James’s written approval in advance.
USB drives, external disks and memory cards are not used for amarti or client data. Never plug in media of unknown origin, promotional sticks included; hand them to Amardeep instead.
Networks and working away from home
Section titled “Networks and working away from home”- Home broadband: change the router’s default admin password, use WPA2 or WPA3 with a strong passphrase, keep the firmware updated, and do not expose services to the internet.
- Out and about: tethering to your phone is preferred over public Wi-Fi. Public or guest Wi-Fi is only used with the company VPN on, and open networks with no password are never used. The VPN stays on whenever you are on a network you do not control.
- In public: use a privacy filter, keep the device with you, and never leave it visible in a vehicle or in hold luggage. Do not use public USB charging points; carry your own charger. Turn off Bluetooth and Wi-Fi auto-connect when you are not using them.
- Abroad: taking a device outside the UK needs the approval described in the Remote Working Policy.
Lost, stolen or broken
Section titled “Lost, stolen or broken”- Lost or stolen: phone Amardeep immediately, at any hour. Report first and search afterwards. If you cannot reach her within 15 minutes, phone James. She locks and, where possible, wipes the device remotely, and revokes its sessions and tokens. Theft is reported to the police for a crime reference. Because devices are encrypted, a prompt report usually turns a loss into a manageable incident rather than a breach. Nobody is disciplined for losing a device and saying so quickly. See the Information Security Incident Management Procedure.
- Possibly compromised: if you think malware has got in or someone else has been in your account, disconnect the device from the network and call Amardeep. Do not power it off and do not start investigating; both destroy evidence.
- Damaged: stop using a frayed cable, cracked plug or faulty charger and report it. Do not overload sockets or daisy-chain extension leads at your desk.
Returning kit
Section titled “Returning kit”Everything comes back by your last working day: the laptop, any accessories, and any media. Returned devices are wiped with a cryptographic erase and rebuilt before being reissued or disposed of, under the Disposal and Reuse of Equipment Policy. Occasionally a departing colleague can buy their laptop at a fair value; it is sanitised and rebuilt first, and never handed over holding company or client data.