SmartHost Web Services Limited (SmartHost) is committed to providing secure and reliable services to our customers while maintaining compliance with national and international cybersecurity regulations. As an Operator of Essential Services (OES) under the NIS Directive, our primary responsibility is to ensure the resilience, security, and continuity of the critical services we deliver.
This policy outlines SmartHost’s approach to managing cybersecurity risks, reporting and responding to incidents, and fulfilling our obligations under the European Union’s NIS Directive and the Irish NIS Regulations (S.I. 360 of 2018). It provides a structured framework to address threats, minimise their impact, and support recovery in line with best practices and regulatory requirements.
This policy applies to all SmartHost systems, personnel, contractors, third-party vendors, and stakeholders involved in the delivery, management, and support of essential services. It covers:
Our objective is not only to comply with regulatory mandates but also to embed a culture of risk management across SmartHost. This ensures that all risks to our network and information systems are assessed and managed appropriately, enabling us to provide uninterrupted services while safeguarding the confidentiality, integrity, and availability of critical data.
By adhering to this policy, SmartHost strives to maintain the trust of our customers, stakeholders, and the broader digital ecosystem, reinforcing our role as a reliable provider of services.
SmartHost operates in alignment with the requirements of the NIS Directive and the Irish NIS Regulations (S.I. 360 of 2018). These regulations establish obligations for Operators of Essential Services (OES) to ensure the security of their network and information systems and to report incidents that may significantly impact the continuity of essential services.
Our compliance framework is built on the following five core functions, as outlined in the NIS Guidelines:
SmartHost identifies critical assets, services, and processes that support essential services.
This includes:
SmartHost implements appropriate and proportionate measures to protect the confidentiality, integrity, and availability of its network and information systems. This involves:
SmartHost employs monitoring systems to identify and respond to potential security threats. Key activities include:
SmartHost has established response procedures to contain and mitigate the effects of incidents. These include:
SmartHost ensures the timely restoration of essential services following an incident. This is achieved by:
SmartHost adheres to the NIS Directive and other applicable laws, including GDPR for data protection. The organisation cooperates with the Department of Communications, Climate Action, and Environment, as well as the National Cyber Security Centre (NCSC), to meet reporting obligations and compliance requirements.
SmartHost reviews its security policies annually or after major incidents, incorporating lessons learned and updated standards.
Effective risk management is central to SmartHost’s approach to ensuring the security and continuity of essential services. By identifying, assessing, and mitigating risks to our network and information systems, SmartHost ensures a proactive stance against potential disruptions and threats.
SmartHost maintains an up-to-date inventory of all assets supporting essential services, including:
SmartHost prioritises a clear understanding of the business environment to guide risk management activities:
SmartHost employs a structured approach to assess cybersecurity risks:
SmartHost implements measures to minimise identified risks:
SmartHost recognises that vulnerabilities in the supply chain can compromise its internal systems:
Risk management at SmartHost is an ongoing process:
SmartHost maintains detailed records of risk management activities, including:
SmartHost implements a range of technical and organisational security measures to protect the confidentiality, integrity, and availability of its network and information systems. These measures are designed to align with the NIS Directive’s requirements and ensure the delivery and continuity of essential services.
4.1.1 Identity Management and Access Control
4.1.2 Data Security
4.1.3 Protective Technologies
4.1.4 Monitoring and Detection
4.2.1 Policies and Procedures
4.2.2 Training and Awareness
4.2.3 Supply Chain Security
4.2.4 Maintenance and Testing
4.4.1 Threat Landscape Updates
4.4.2 Post-Incident Analysis
SmartHost employs a structured and efficient approach to managing incidents that impact the security or availability of its network and information systems. This ensures that disruptions are minimised and essential services are restored as quickly as possible.
SmartHost’s commitment to continuous improvement ensures that its cybersecurity practices remain effective in the face of evolving threats.
SmartHost complies with all applicable legal and regulatory requirements to ensure secure and reliable operations.
SmartHost maintains comprehensive records to ensure transparency and accountability in its cybersecurity practices.
To ensure timely communication during incidents and compliance activities, SmartHost provides clear contact details.
Date of last review: November 2024
This website uses cookies.