Infrastructure Security
Infrastructure security is designed to provide a secure, resilient, and reliable operating environment for business applications and customer data. Enterprise-grade firewall protection, operating system hardening, secure administrative controls, regular security patching, and continuous infrastructure monitoring are implemented to reduce operational and cybersecurity risks. Administrative access is restricted to authorized personnel based on the principle of least privilege, while periodic configuration reviews help ensure alignment with recognized security best practices.
Network Security
Network communications are protected through multiple layers of security designed to prevent unauthorized access and minimize exposure to cyber threats. Enterprise firewall policies, traffic filtering, secure remote administration, DNS protection, and controlled inbound and outbound network access help safeguard business systems and customer information. Continuous monitoring of network devices and services enables early detection of security events and supports timely incident response to maintain service availability.
Identity & Access Management
Access to business systems and customer information is managed through Microsoft Entra ID and Microsoft 365 using Role-Based Access Control (RBAC) and the principle of least privilege. Multi-Factor Authentication (MFA) is enforced using Microsoft Authenticator and mobile number verification to strengthen account security. User access is reviewed periodically, and permissions are promptly updated or revoked when employees change roles or leave the organization, helping ensure that only authorized users have access to corporate resources.
Endpoint Security
Corporate endpoints, including workstations, laptops, and servers, are protected through enterprise endpoint security solutions that provide real-time defense against malware, ransomware, viruses, and other cybersecurity threats. Security policies, automatic signature updates, operating system patch management, and continuous endpoint monitoring help maintain device integrity and reduce exposure to known vulnerabilities. Access to corporate resources is permitted only from authorized and managed devices to ensure a secure computing environment.
Email Security
Business email communications are protected through multiple security controls designed to reduce the risk of phishing, spoofing, malware, and other email-based threats. Industry-standard email authentication technologies, including Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting and Conformance (DMARC), are implemented where applicable to validate message authenticity. Anti-spam, anti-phishing, and malware filtering mechanisms further enhance email security by helping prevent unauthorized or malicious messages from reaching users.
Data Protection & Encryption
Customer and business information is protected through a combination of technical and organizational security controls designed to prevent unauthorized access, modification, disclosure, or loss. Data transmitted across public networks is secured using HTTPS with Transport Layer Security (TLS) 1.2 or higher, while data stored within Microsoft 365 and Microsoft OneDrive benefits from Microsoft's encryption-at-rest mechanisms, including AES-256 encryption. Access to sensitive information is restricted according to business responsibilities, and user permissions are reviewed periodically to ensure appropriate levels of access are maintained.
Backup & Disaster Recovery
Business continuity is supported through a cloud-based backup and recovery strategy that safeguards critical organizational data against accidental loss, hardware failure, or operational disruption. Business documents and essential information are securely synchronized with Microsoft OneDrive, providing version history, secure cloud storage, and recovery capabilities. Backup processes are monitored regularly, and recovery procedures are maintained to facilitate the timely restoration of information and minimize service interruptions during unexpected events.
Secure Source Code Management
Application source code and development assets are managed using GitHub Organization repositories with centralized administration and delegated access controls. Repository permissions are assigned based on employee roles to ensure that only authorized personnel can access or modify source code. Version control, authenticated user access, and comprehensive change tracking support secure software development practices while protecting intellectual property and maintaining the integrity of development activities.
Vulnerability & Patch Management
Security vulnerabilities are managed through a structured process of regular system assessments, software updates, and timely deployment of security patches. Operating systems, applications, and supporting software components are monitored for vendor-released updates, with critical vulnerabilities prioritized according to their potential impact. Unsupported or end-of-life software is upgraded or retired wherever practical to reduce the organization's exposure to known security risks and maintain a secure operating environment.
Infrastructure Monitoring & Alerting
Continuous monitoring of business-critical infrastructure is performed using Zabbix to provide visibility into the health, availability, and performance of servers, network devices, and essential services. System resources including CPU utilization, memory consumption, storage capacity, and network connectivity are monitored around the clock, with automated alerts generated whenever predefined thresholds, service interruptions, or operational anomalies are detected. This proactive approach enables timely investigation, rapid incident response, and improved service reliability.
Linux Server Security
Linux-based servers are secured using industry-standard security controls to protect systems from unauthorized access and cyber threats. Administrative access is permitted only through Secure Shell (SSH) using PEM key-based authentication, eliminating the need for password-based logins wherever applicable. Firewall policies, regular operating system updates, security patch management, and restricted administrative privileges help maintain a secure server environment and reduce the organization's attack surface.
Incident Management
Security incidents are managed through a structured process designed to identify, assess, contain, investigate, and resolve events that may affect the confidentiality, integrity, or availability of business information and services. Infrastructure monitoring and automated alerting enable early detection of operational or security-related issues, while corrective actions are implemented to minimize impact, restore normal operations, and reduce the likelihood of recurrence. Significant incidents are documented and reviewed to support continuous improvement of security practices.
Business Continuity
Business continuity measures are established to support the availability of critical business services during unexpected disruptions. Cloud-based data backups, infrastructure monitoring, recovery procedures, and preventive maintenance activities help reduce operational risks and enable the timely restoration of essential systems and information. Recovery planning is reviewed periodically to improve organizational resilience and support the continuity of business operations.
Employee Security
Access to information systems is granted according to job responsibilities and business requirements through Role-Based Access Control (RBAC). Employees are required to comply with organizational security policies, maintain the confidentiality of business information, and use corporate systems responsibly. User accounts and access privileges are reviewed periodically, while access is modified or revoked promptly following role changes or employment termination to ensure continued protection of organizational assets.
Retention and Erasure of Data
Customer data is retained only for the period necessary to deliver contracted services and to satisfy applicable legal, regulatory, and contractual obligations. Appropriate technical and organizational measures are applied to protect information throughout its lifecycle. Upon termination of services or completion of contractual requirements, customer data is securely removed from production systems in accordance with established data retention procedures. Backup copies are retained only for the applicable backup retention period and are securely deleted upon expiration of the retention cycle. Access to retained information is restricted to authorized personnel, and secure deletion methods are followed to help ensure that data cannot be recovered once permanently erased.
Data Portability
Customer-owned data can be made available upon authorized request in commonly accepted electronic formats, subject to contractual agreements and applicable legal requirements. Appropriate identity verification procedures are completed before any data is released to ensure that information is provided only to authorized individuals. Data exports are performed through secure transfer methods to preserve confidentiality and maintain the integrity of customer information during transmission.
Service Availability
Service availability is supported through continuous infrastructure monitoring, preventive maintenance, regular system updates, and proactive incident management. Critical infrastructure components are monitored around the clock using automated monitoring solutions to identify potential issues before they impact business operations. Planned maintenance activities are scheduled to minimize disruption, and reasonable efforts are made to maintain reliable and consistent service availability. Although every effort is made to ensure uninterrupted operations, temporary service interruptions may occur due to scheduled maintenance, infrastructure upgrades, or circumstances beyond organizational control.
Privacy & GDPR Support
The protection of personal information is supported through appropriate technical and organizational measures designed to meet applicable privacy and data protection requirements. Security controls such as access management, encryption, secure data transmission, cloud-based protection, and continuous monitoring help safeguard personal information against unauthorized access, disclosure, alteration, or loss. Personal data is processed only for legitimate business purposes and handled in accordance with applicable contractual, legal, and regulatory obligations, including the principles of the General Data Protection Regulation (GDPR), where applicable.
Compliance Statement
Information security is an integral part of MN Groups' operational and software development practices. Security controls are continuously reviewed and enhanced to address emerging cybersecurity threats, evolving regulatory requirements, and changing business needs. Industry-recognized security principles, including secure access management, encryption technologies, continuous infrastructure monitoring, secure software development practices, vulnerability management, and data protection controls, are incorporated into daily operations to support a secure and resilient technology environment. Through ongoing improvements and the adoption of established security best practices, MN Groups remains committed to protecting the confidentiality, integrity, and availability of customer information while delivering secure, reliable, and trusted technology solutions.