Hawk Sight Security Risk Management Ltd
Version 2.0 — Effective 25 September 2026
Last reviewed: 25 September 2026 · Next review: September 2027
1. Our mission
1.1 HawkSight’s mission is to help clients achieve their security objectives by providing outstanding security risk management solutions, including, where applicable, the HawkSight SRM platform and its optional modules, together with our consultancy, managed and training services. We aim to fully meet client needs and expectations, demonstrate consistency across all security risk reporting, and comply with international standards, applicable laws and regulations, contractual obligations and relevant codes of practice.
2. Our Integrated Management System
2.1 To achieve these aims, we operate an Integrated Management System (IMS) that meets the requirements of ISO 9001:2015 (quality management) and ISO/IEC 27001:2022 (information security management), and is independently certified to both standards.
2.2 Our approach to risk management is aligned with ISO 31000:2018 Risk management – Guidelines.
3. Information security
3.1 We are committed to protecting the confidentiality, integrity and availability of the information entrusted to us by our clients, partners and staff, as well as our own. Information is identified and handled according to its sensitivity, and information security risks are assessed and treated in line with ISO/IEC 27001.
3.2 We comply with applicable legal, regulatory and contractual requirements relating to information security and data protection, including the UK GDPR and the Data Protection Act 2018.
4. Objectives and continual improvement
4.1 We set measurable quality and information security objectives, monitor performance against them, and review them through internal audit and management review.
4.2 We are committed to continually improving the IMS and its effectiveness.
5. Responsibilities
5.1 The Managing Director has overall accountability for the IMS and this policy. All employees, contractors and associates working on HawkSight’s behalf are expected to understand and follow it.
6. Review and communication
6.1 This policy is reviewed at least annually, and whenever significant changes occur, to ensure it remains suitable. It is communicated to all employees and associates, displayed at our registered office, and published on our website so that it is available to all interested parties.
Paul Mercer
Managing Director
Hawk Sight Security Risk Management Ltd
25 September 2026
