top of page

DGB Cyber Security

Applies to:  All employees, contractors, and third-party partners of DGB Global.


1. Overview & Purpose
At DGB Global, Cyber Security is fundamental to protecting our people, our clients, and the data entrusted to us. This policy outlines our commitment to the secure management of digital systems, platforms, and information assets. It sets out the principles and responsibilities that guide our practices and provides the foundation for all supporting procedures and implementation frameworks.

This policy complements the Privacy & Data Stewardship Policy and is further supported by our Cyber Security Procedure & Framework.

2. Scope & Applicability

This policy applies to:

  • All DGB Global personnel, including employees, directors, contractors, and third-party providers

  • All devices, networks, platforms, cloud services, and systems used for DGB business

  • Any handling of client, donor, or organisational data in digital form.


3. Key Definitions

  • Cyber Security: The protection of digital systems, data, and infrastructure from unauthorised access, attack, or misuse.

  • Breach: Any event that compromises the confidentiality, integrity, or availability of systems or data.

  • MFA: Multi-Factor Authentication – the use of two or more verification factors to gain system access.

  • Classified Data: Data categorised by risk impact (e.g.  Red, Green, Black). 

  • Cyber Security Officer: The designated staff member (DGB Operations & Admin Co-ordinator) responsible for system-level oversight and breach coordination.
     

4. Cyber Security Principles
DGB Global adopts the following core principles:

  • Confidentiality: Protect sensitive data from unauthorised access

  • Integrity: Ensure data and systems remain accurate and unaltered

  • Availability: Maintain reliable access to systems and services

  • Accountability: Assign responsibility for cyber risk and compliance

  • Proactivity: Prevent breaches through ongoing training, patching, and monitoring.


5. Roles & Responsibilities
Organisation

  • Maintain clear policies, procedures, and controls

  • Provide secure infrastructure and regular staff training

  • Appoint a Cyber Security Officer to lead compliance and incident response. 

 
Staff 

  • Follow Cyber Security protocols in daily operations

  • Complete annual training and sign the Cyber Security Checklist

  • Immediately report suspected breaches or vulnerabilities. 

 
Cyber Security Officer

  • Oversee system-level controls and breach preparedness

  • Monitor emerging threats and lead incident response

  • Liaise with senior leadership on cyber risk. 

 
6. Governance & Oversight 

  • Cyber Security is included on DGB’s organisational risk register

  • A Cyber Security Committee (comprising the Managing Director, the Cyber Security Officer, and two members of the DGB Board) meets bi-annually to review policies, compliance and assess cyber security stance

  • The Cyber Security Officer provides bi-annual reporting to the DGB Cyber Security Committee

  • Policies are reviewed bi-annually, or sooner if prompted by incidents or major changes

  • Regular monitoring and audit processes are conducted (see Cyber Security Procedure & Framework).
     

7. Compliance and Legal Alignment 
DGB Global complies with: 

  • The Privacy Act 1988 (Cth) and associated APPs 

  • The Notifiable Data Breaches (NDB) Scheme

  • Contractual privacy and security obligations to clients

  • Internal classification and access control protocols (e.g. Red/Green/Black) For response to eligible data breaches, refer to the Privacy & Data Stewardship Policy

 
8. Related Documents 
This policy should be read in conjunction with:

  • DGB Privacy & Data Stewardship Policy

  • DGB Cyber Security Procedure & Framework

  • DGB Cyber Security Checklist

  • Cyber Security Incident Response Plan.



DGB Global
info@dgbgroup.com.au
0485 976 526
www.dgbglobal.com.au

bottom of page