Home / Acceptable Use Policy
Legal & Compliance

Acceptable
Use Policy.

Rules of the road for using Cyber Compliance Pro IT systems, networks and cloud services — designed to keep our people, our data and our customers safe.

Quick answer: Cyber Compliance Pro's Acceptable Use Policy sets the rules for using its IT systems, networks and cloud services, covering what counts as acceptable and unacceptable use and what happens when the policy is breached.
Version 1.0
Effective: 30 July 2026
Classification: Internal
Document Control
Owner Information Security Officer
Approved By Managing Director
Review Annual or upon significant change
Applies To Employees, contractors and third-party users
Classification Internal
Version 1.0 — Effective 30 July 2026

1 Purpose of This Acceptable Use Policy

This acceptable use policy outlines acceptable and unacceptable use of the organisation’s IT systems and resources to ensure their secure and responsible use. It sets clear expectations so that every user can do their work confidently while protecting the organisation, its customers and its data from avoidable risk.

2 Scope of This Acceptable Use Policy

This acceptable use policy applies to all employees, contractors and third-party users accessing or using organisational IT systems, including email, internet, cloud services, collaboration platforms, corporate devices and mobile devices — whether owned by the organisation or personally owned and used for work.

3 Acceptable Use

Users are expected to:

Use organisational IT systems only for authorised business activities.

Protect user credentials and never share passwords with anyone, including colleagues.

Report any suspected security incidents, phishing attempts or breaches immediately.

Ensure data is accessed and stored securely in line with information classification levels.

4 Unacceptable Use

The following activities are prohibited:

Accessing, storing or distributing offensive, illegal or discriminatory material.

Using IT systems for personal financial gain or unauthorised commercial activity.

Circumventing or attempting to bypass security controls such as firewalls, filters, MFA or endpoint protection.

Downloading unauthorised software or knowingly introducing malware to any system.

Connecting unapproved personal devices to the corporate network.

5 Monitoring & Privacy

As a result, the organisation reserves the right to monitor IT systems to ensure compliance with this policy and to protect the security and integrity of its systems and data. Specifically, users have no expectation of privacy when using corporate resources.

Note. Overall, monitoring is carried out in accordance with applicable laws and our Privacy Policy. Personal information collected through monitoring is handled with the same care as any other personal information we hold.

6 Acceptable Use Policy Enforcement

Ultimately, non-compliance with this policy may lead to disciplinary action, including revocation of access privileges or termination of employment or engagement. Where conduct may also constitute a criminal offence, the matter may be referred to the appropriate authorities.

Report an incident. If you believe this policy has been breached, or you suspect a security incident, contact the Information Security Officer immediately at security@cybercompliancepro.com.

7 Review

Typically, this policy must be reviewed annually or whenever significant technology, business or legal changes occur. The effective date at the top of this page indicates the most recent revision.

8 Contact Details

For questions about this policy, or to report suspected non-compliance, please contact:

Cyber Compliance Pro (ABN 86 711 059 645)