UHUBS POLICY

Threat & Vulnerability Management Policy

Last reviewed on 5 August 2026
This Threat & Vulnerability Management Policy outlines continuous assessments and monitoring, annual third-party penetration testing, timely mitigation strategies with defined remediation targets, a collaborative response framework, and a 'Pre-Mortems' and 'Post-Mortems' framework. It emphasizes regular vulnerability scans, integration of external threat intelligence sources, clear threat severity classification, defined remediation timeframes, mitigation measures, incident communication plan, stakeholder responsibilities, tabletop exercises, and continuous improvement.

1. Continuous Assessments and Monitoring:

1.1 Regular Vulnerability Scans:

Uhubs conducts regular vulnerability scans on its infrastructure and applications, utilising industry-standard tools. Scans are scheduled at least monthly, with immediate scans triggered for any significant changes to the environment.

1.2 External Threat Intelligence Sources:

Integration of external threat intelligence sources to stay informed about emerging threats. Regular monitoring of these sources ensures timely awareness of potential risks.

1.3 Third-Party Penetration Testing:

Uhubs commissions a penetration test of the Platform at least once every 12 months, carried out by an independent qualified third party. A summary of each test is available to customers on request. Findings are remediated under the timeframes in section 2.2.

2. Timely Mitigation Strategies:

2.1 Threat Severity Classification:

Define a clear classification system for threat severity, considering factors such as exploitability, potential impact, and affected assets.

2.2 Mitigation Response Timeframes:

Remediation targets by severity, measured from confirmation of the finding:

  • Critical: Within 8 business hours.
  • High: Within 2 business days.
  • Medium: Prioritised by risk and addressed in the normal release cycle.
  • Low: Prioritised by risk and addressed in the normal release cycle.

Where a fix is not available within the target, Uhubs applies a documented compensating control and records the reason for the extension. These targets apply to findings from internal scanning, third-party penetration testing, and provider security advisories alike.

2.3 Mitigation Measures:

Clearly defined measures for mitigating identified vulnerabilities, ranging from software patches and configuration changes to temporary workarounds.

3. Collaborative Response Framework:

3.1 Incident Communication Plan:

Develop a detailed incident communication plan outlining:

  • Points of contact.
  • Communication channels.
  • Escalation procedures.

3.2 Stakeholder Responsibilities:

Clearly define roles and responsibilities for stakeholders during a security incident. This includes communication responsibilities, technical response actions, and managerial oversight.

3.3 Tabletop Exercises:

Conduct regular tabletop exercises to simulate security incidents. This collaborative approach helps identify gaps in the response framework and ensures effective communication among stakeholders.

4. 'Pre-Mortems' and 'Post-Mortems' Framework:

4.1 Pre-Mortems - Predicting Future Risks:

Hold 'pre-mortems' before major releases or changes to predict potential security risks. This involves scenario-based discussions and risk identification to proactively address vulnerabilities.

4.2 Post-Mortems - Learning from Incidents:

Following any security incident, conduct a comprehensive 'post-mortem' analysis. This includes:

  • Root cause identification.
  • Assessment of incident response effectiveness.
  • Documentation of lessons learned.
  • Implementation of corrective measures to prevent recurrence.

4.3 Continuous Improvement:

Implement an iterative approach to threat and vulnerability management, incorporating insights from 'pre-mortems' and 'post-mortems' into future risk assessments and response strategies.

5. Regular Policy Review and Updates:

Uhubs places a strong emphasis on the regular review and update of the policy. An annual review process will be in place to assess the plan's alignment with the evolving environment. This commitment ensures that the policy remains current, adaptable, and effective in addressing emerging challenges and maintaining adherence.

‍

No items found.