2026-07-23

SECURITY HINTS & TIPS:

EMAIL FORWARDING VETTING

Before you click the send button, let’s talk about “vetting”. It isn’t just a buzzword; it’s our best defence against sharing sensitive information.

Why the Fuss Over a Forward?
When we share documents like a Statement of Work (SOW) or login credentials, we aren’t just sharing a contract or credentials; we are sharing costs, project scopes, and sensitive information. If this lands in the wrong hands, it exposes our internal processes and details. This is especially critical for maintaining our ISO 27001 certification, which requires us to be specific about how we classify, handle and transmit information.

Living the ‘Zero Trust’ Life
The core philosophy of our security protocol is Zero Trust: Never Trust, Always Verify. When it comes to emails, this means performing three quick checks:

  • Verify the Recipient: Does this person actually need this for their job, or are you just sending it because they asked?
  • Verify the Content: Does the attachment contain sensitive Data, Applications, Assets, or Services (DAAS)?
  • Verify the Source: Spoofing can look incredibly real. While our tools catch most of it, your eyes are the final line of defence.

Quick Vetting Checklist
Use this checklist before every forward to keep our data locked down:

Action Why it Matters
Check the Domain Ensure it is exactly the domain and not a slight variation.
Scrub the History Always check what is at the bottom of a long email thread before forwarding.
Limit the ‘Chunks’ Use secure methods; don’t bypass system limits just to get it sent.
Ask ‘Why?’ Consider if the recipient really needs all the details or just a summary.

What if you accidentally sent sensitive data?
Don’t panic. Contact the IT Service Desk immediately so that we can help assess and contain the risk.

ISMS References
05.12 Information Classification Policy
05.14 Information Transfer Policy

Manitoulin Group of Companies Security Team
Cybersecurity@manitoulingroup.com

Stop, Look, and Think. Don’t be fooled.