HLD Group
Network security policy
Segmentation, remote access, and perimeter controls.
Last updated: 24 July 2026
Version 1.0 · Review cycle: 365 days · View all frameworks
1. Purpose
This policy defines the controls that protect HLD Group networks and the data that traverses them. It establishes how networks are segmented, how traffic is filtered and monitored, and how remote and cloud connectivity is secured, in support of a defence-in-depth and zero-trust posture.
2. Scope
This policy applies to all networks owned, operated, or used by HLD Group for business, including corporate, production, cloud virtual networks, and remote-access connectivity.
3. Definitions
- Segmentation — dividing a network into zones to contain compromise and control traffic
- Zero trust — an architecture that never implicitly trusts based on network location and verifies every request
- Ingress and egress filtering — controlling inbound and outbound traffic
- Micro-segmentation — fine-grained isolation between workloads
- Intrusion detection and prevention (IDS/IPS) — systems that detect and block malicious traffic
4. Policy statement
HLD Group networks are designed on least-privilege and zero-trust principles. Trust is not granted on the basis of network location alone; identity, device posture, and context are evaluated for access. Networks are segmented so that compromise of one zone does not grant free movement across the estate.
5. Network segmentation and architecture
- Production, corporate, and management networks are separated with controlled interfaces between them
- Sensitive systems are placed in restricted zones with tightly limited connectivity
- Micro-segmentation is applied to production workloads where the platform supports it
- Default-deny rules govern traffic between zones, with only required flows permitted and documented
6. Perimeter and traffic controls
- Firewalls and cloud security groups enforce least-privilege ingress and egress
- Egress filtering restricts outbound connections to prevent data exfiltration and command-and-control traffic
- Web application firewalls and DDoS protection defend internet-facing services
- Remote access is provided through controlled, MFA-protected channels rather than broad network exposure
7. Monitoring and detection
- Intrusion detection and prevention on critical network paths
- Network flow logging retained and analysed for anomalies
- Alerting integrated with the logging and monitoring capability and the incident response process
8. Wireless and remote connectivity
- Corporate wireless uses strong authentication and encryption; guest wireless is isolated from corporate and production networks
- Remote connectivity is encrypted and authenticated, with device posture checks where supported
9. Framework alignment
- ISO/IEC 27001:2022 Annex A controls 8.20 (networks security), 8.21 (security of network services), and 8.22 (segregation of networks)
- NIST SP 800-53 Rev. 5 control family SC (System and Communications Protection)
- NIST SP 800-207 (Zero Trust Architecture)
- SOC 2 Trust Services Criteria CC6.6 and CC6.7
- PCI DSS v4.0 Requirement 1 where cardholder data is in scope
10. Roles, exceptions, and review
Network security is owned by the infrastructure and security functions under the CISO. Firewall and segmentation rules are reviewed periodically for necessity. Exceptions require documented CISO approval with compensating controls and an expiry date. This policy is reviewed at least annually.
Related frameworks
For contractual attestations or audit packs, contact [email protected].