← Back
IT North Continuity pack · Mesabi Outfitters

Policy

Cyber Security Policy

Rules for people who use Mesabi Outfitters technology and information. Clear expectations beat fine print—protect the business, report problems early, and use systems for work.

Version 2026.1 Last reviewed: 2026-03-12 IT North help: 218-256-4249

Why this exists. It tells employees and contractors what “good” looks like, what is off-limits, and how to raise a hand when something feels wrong—phishing, lost devices, or odd access requests.

1. What we protect

Everyone with access helps protect:

2. Information classification

Treat company data as either confidential or business-use:

When unsure, treat the data as confidential and ask a manager or IT North.

3. System sensitivity

LevelMeaningExamples
Critical Holds confidential data or runs mission-critical services. Failure hurts operations or finances. File/domain servers, ERP, firewalls, backup appliances
Standard Day-to-day PCs and accounts used to reach Critical systems. Staff laptops, office workstations
Public Externally reachable systems with no confidential data (if used). Public website

4. Threats to keep in mind

5. Acceptable use

6. Internet, email, and messaging

Internet and email are business tools. Do not use them to harass, discriminate, trade illegal content, or run side businesses on company systems. Treat unexpected payment, gift-card, or “reset payroll” messages as suspicious— verify out-of-band before clicking.

7. Access control & passwords

8. Devices, remote access & third parties

9. Reporting incidents

Report immediately (ticket in the IT North portal, or call 218-256-4249):

If you think a device is compromised: leave it powered on if safe to do so, do not wipe files, and contact IT North so evidence and recovery options are preserved.

Early reporting limits damage. You will not be punished for reporting a genuine mistake quickly.

10. Monitoring

Mesabi Outfitters and IT North may review system logs, email filtering events, and device health as needed to protect the business and investigate incidents. Continuous personal surveillance is not the goal— security and reliability are.

11. Roles

RoleResponsibility
Employees & contractorsFollow this policy; protect credentials; report issues; complete acknowledgements when asked.
Company leadershipApprove policy; support offboarding; fund required controls; decide on serious incidents.
IT North (security administrator)Advise on controls, monitor managed systems, help investigate incidents, keep Continuity docs and evidence current.

12. Violations

Misuse can lead to loss of access and employment action under Mesabi Outfitters policies, and may involve law enforcement when required. IT North will assist leadership with technical facts.

13. Review

This policy is reviewed at least annually (or after a major incident or system change). Current version and acknowledgements live in the IT North portal under Continuity.

Prepared with IT North (Hibbing, MN). This document is company-specific guidance for systems IT North helps manage. It does not create insurance coverage or guarantee zero downtime.