INFORMATION SECURITY
Security begins with controlled information
-
Coastlight Global Risk handles information according to its purpose, sensitivity, materiality and authorised use.
Security controls are embedded in how information is received, accessed, structured, analysed, shared, retained and removed from active use.
-
Information is used within a defined business, advisory or research purpose.
Before material information enters a workflow, Coastlight considers:
why the information is required;
which systems and processes are appropriate;
who requires access;
which outputs may be created;
how long the information remains relevant;
which review or approval boundaries apply.
Clear purpose is the first control.
-
Access is limited to the people, systems and processes required for the authorised work.
Coastlight applies a least-privilege approach to sensitive information, with access shaped by role, task, materiality and duration.
The objective is controlled availability: the right information, available to the right capability, for the right purpose.
-
Information is handled through systems and services selected for the relevant purpose and risk level.
Coastlight considers security, access control, data handling, operational resilience and provider dependency when determining how a workflow should be structured.
Material work remains subject to Coastlight’s own governance and approval architecture across tools and providers.
-
Company, policy, claim, financial, contractual and operational information may carry significant commercial and strategic sensitivity.
Such information is handled within the authorised scope of the work, with appropriate separation between:
source material;
working analysis;
approved outputs;
shared deliverables;
archived or superseded records.
Access and disclosure remain governed by necessity, purpose and approval.
-
AI-supported work follows the same information-security principles as other Coastlight processes.
The use of AI is shaped by:
data sensitivity;
authorised purpose;
provider and system suitability;
access control;
output materiality;
required human review;
retention and reuse boundaries.
Sensitive information remains subject to controlled handling throughout the workflow.
-
Coastlight seeks the information required for the defined purpose and keeps the active working set proportionate to that purpose.
Data minimisation reduces unnecessary exposure, simplifies review and strengthens control over downstream use.
-
Information security includes the integrity of the record.
Where material, Coastlight preserves:
source identity;
version;
retrieval or receipt date;
change history;
review state;
approval state;
supersession;
correction records.
A controlled record should show what changed, when it changed and which outputs were affected.
-
Information is shared according to the purpose of the work and the authority of the recipient.
External sharing, underwriter access, protected client-room access and other forms of disclosure require a defined scope and an appropriate access route.
Sensitive information should travel through controlled channels with clear ownership and recipient purpose.
-
Information is retained according to its continuing purpose, legal or professional relevance and the requirements of the work.
When information is no longer required for active use, Coastlight applies the appropriate archival, restriction, deletion or supersession treatment.
-
Security events require timely assessment, containment, escalation and recovery.
Coastlight’s approach connects technical response with evidence preservation, decision authority, communication and continuity of material work.
Lessons from an incident are incorporated into future controls, workflows and review requirements.
-
Information security remains a matter of professional judgement and executive responsibility.
At Coastlight, material security, disclosure and irreversible decisions remain subject to the authority of the Managing Partner.
-
Questions concerning this statement or Coastlight’s institutional information-security approach may be directed to:
-
The objective is secure, proportionate and accountable use of information across the full path from source to decision.