top of page

Information Security & SAT Policy

Financial Mind (PTY) LTD

Effective Date: October 2026

Contact Email: admin@financialmind.college

 

1. Purpose and Scope

This policy establishes the technical, administrative, and physical security standards for safeguarding system infrastructure, learner personal information, financial transaction data, and intellectual property maintained by Financial Mind (PTY) LTD (“Financial Mind”, “we”, “us”, or “our”).

 

It also defines the operational standards governing our Security Awareness Training (SAT) solutions delivered internally and to corporate clients.

 

This policy complies with the Protection of Personal Information Act 4 of 2013 (POPIA), the Electronic Communications and Transactions Act 25 of 2002 (ECTA), and the regulatory expectations of the Financial Sector Conduct Authority (FSCA).

 

2. Legal and Regulatory Disclaimer

IMPORTANT NOTICE: All information security guidelines, technical controls, and Security Awareness Training (SAT) modules provided by Financial Mind (PTY) LTD are strictly for educational, operational security, and competence training purposes.

  1. No Financial or Legal Advice: Nothing contained in this policy or within our SAT courseware constitutes legal, cyber-risk underwriting, or financial advice under the Financial Advisory and Intermediary Services (FAIS) Act 37 of 2002, or as regulated by the FSCA.

     

  2. Organizational Responsibility: Corporate Clients and FSPs remain independently responsible for implementing their own IT governance policies, firewalls, and cyber incident response plans.

     

3. Access Control and Authentication Management

  • Role-Based Access Control (RBAC): Administrative access to internal systems, subscriber databases, and our 3rd-party Learning Management System (MoodleCloud) is granted strictly on a need-to-know basis based on job function.

     

  • Password Standards: All administrative staff, Subject Matter Experts (SMEs), and corporate portal managers must utilize strong passwords (minimum 12 characters combining uppercase, lowercase, numerical, and special characters).

     

  • Multi-Factor Authentication (MFA): MFA is mandatory for all administrative access points, email platforms, cloud storage environments, and third-party portal integrations.

     

  • Credential Sharing Prohibited: Sharing account credentials across employees or learners is strictly forbidden. Credential sharing will trigger account suspension on MoodleCloud.

     

4. Technical and Data Security Controls

  • Data Encryption: All data in transit across our platforms and MoodleCloud LMS subdomains is secured using standard Transport Layer Security (TLS/SSL) encryption. Sensitive data at rest is encrypted using industry-standard AES-256 protocols.

     

  • Payment Gateway Security: Financial Mind does not process or store raw credit card numbers or banking passwords on its servers. All payment transactions are handled via tokenized, PCI-DSS Level 1 compliant payment gateways (Peach Payments and Yoco).

     

  • System Patching and Maintenance: Cloud platforms and MoodleCloud plugins are updated regularly to patch security vulnerabilities and maintain uptime.

     

5. Security Awareness Training (SAT) Framework

Financial Mind designs and delivers specialized Security Awareness Training (SAT) programmes covering:

 

  • Phishing & Social Engineering: Identifying deceptive emails, malicious URL links, credential harvesting, and spear-phishing tactics targeted at financial services professionals.

     

  • Data Protection & POPIA Compliance: Safe handling of special personal information, secure file transfer methods, and clean desk/screen protocols.

     

  • Password Hygiene & Account Protection: Passphrase generation, multi-factor authentication setup, and avoiding credential reuse.

     

  • Remote Work & Mobile Security: Securing home Wi-Fi networks, VPN usage, and preventing physical visual eavesdropping.

     

SAT completion criteria require learners to complete 100% of video/text modules and pass a security comprehension assessment with a minimum score of 70%.

 

6. Incident Management and POPIA Section 22 Breach Notification

In the event of a suspected or confirmed security compromise or data breach involving personal information:

 

  • Immediate Containment: The Information Officer and technical administrators will immediately isolate affected systems or MoodleCloud user modules to prevent further data exposure.

     

  • Investigation: An internal audit will determine the source, scope, and categories of personal information involved.

     

  • Statutory Notification: In compliance with Section 22 of POPIA, Financial Mind will notify the Information Regulator (South Africa) and affected data subjects in writing as soon as reasonably possible after discovering the breach.

     

  • Remediation: Vulnerabilities will be patched immediately, and an incident report detailing preventive measures will be logged and archived for 5 years.

     

7. Policy Governance and Reviews

This policy is reviewed annually by the Information Officer to adapt to emerging cyber threats, regulatory updates from the FSCA, and infrastructure changes.

 

bottom of page