Cybersecurity Policy

Last updated: July 2026

Garrison Hill Group is committed to protecting the confidentiality, integrity, and availability of information entrusted to us by clients, partners, and employees.

Scope

This policy applies to all employees, contractors, systems, and data used in connection with Garrison Hill Group operations.

Guiding Principles

  • Least-privilege access to systems and data.
  • Strong authentication, including multi-factor authentication where available.
  • Encryption of sensitive data in transit and at rest.
  • Regular software updates, patching, and endpoint protection.
  • Ongoing security awareness training for personnel.

Data Handling

Client and project information is stored on reputable, access-controlled platforms. Access is granted only to personnel with a legitimate business need.

Incident Response

Suspected security incidents are investigated promptly. Where required by law or contract, affected parties will be notified in a timely manner.

Third-Party Vendors

We evaluate the security practices of third-party service providers and require appropriate contractual safeguards for data they process on our behalf.

Reporting Concerns

If you believe you have identified a security vulnerability or incident involving Garrison Hill Group, please contact us at dosullivan@garrisonhillgroup.com.

Review

This policy is reviewed periodically and updated to reflect changes in our practices, technology, and the threat landscape.