Legal & compliance centre

HLD Group

Security assessment policy

Penetration testing, scans, and customer audit coordination.

Last updated: 24 July 2026

Version 1.0 · Review cycle: 365 days · View all frameworks

1. Purpose

This policy defines how HLD Group assesses the security of its systems through testing, including vulnerability assessment, penetration testing, and red-team exercises, and how findings are managed. Independent assessment validates that controls work in practice, not just on paper.

2. Scope

This policy applies to security assessments of HLD Group systems, applications, and infrastructure, whether conducted internally or by engaged third parties, and to the authorisation and handling of such testing.

3. Types of assessment

  • Vulnerability assessment — automated and manual identification of known weaknesses
  • Penetration testing — authorised simulated attack to find and exploit weaknesses
  • Red-team exercises — objective-based adversary simulation testing detection and response
  • Configuration and architecture review — assessment against secure baselines and design principles

4. Authorisation and rules of engagement

All testing is explicitly authorised in writing, with defined scope, timing, methods, and rules of engagement. Testing without authorisation is prohibited and may be unlawful. Testing of systems that involve customers or third parties requires their agreement, and sensitive data encountered during testing is handled under our data policies.

5. Frequency

  • Independent penetration testing of key external-facing systems at least annually and after significant change
  • Regular vulnerability assessment as set out in the Vulnerability Management Policy
  • Assessments additionally performed where required by customers or certification

6. Findings management

Assessment findings are risk-rated, assigned owners, and remediated within the timeframes in the Vulnerability Management Policy. Reports are treated as confidential, retained for assurance, and shared with customers only under appropriate confidentiality terms.

7. Framework alignment

  • ISO/IEC 27001:2022 Annex A control 8.8 (management of technical vulnerabilities)
  • NIST SP 800-53 Rev. 5 controls CA-2 (control assessments) and CA-8 (penetration testing)
  • NIST SP 800-115 (technical guide to information security testing)
  • SOC 2 Trust Services Criteria CC4.1 and CC7.1

8. Roles, exceptions, and review

The security function owns the assessment programme under the CISO. Exceptions require documented CISO approval. This policy is reviewed at least annually.

Related frameworks

For contractual attestations or audit packs, contact [email protected].