1. Purpose
This Security Policy explains FirstGold’s approach to protecting customer information, accounts, transactions and technology systems. It is intended as a public statement of our security principles. Detailed internal controls, configurations and incident playbooks are confidential and are not published because doing so could increase security risk.
2. Security Governance
FirstGold assigns responsibility for information security and regularly reviews security risks, incidents, suppliers and controls. Security measures are selected having regard to the nature and sensitivity of information, the services provided, foreseeable threats, legal obligations and proportionality. We aim to align our control programme with recognised Australian cyber-security guidance, including the Australian Signals Directorate’s Essential Eight, where appropriate to our environment.
3. Core Security Controls
- Identity and access management: role-based access, least privilege, strong authentication and periodic access reviews.
- Multi-factor authentication: used for privileged or sensitive access and offered or required for customer access where supported.
- Encryption: encryption in transit and at rest where appropriate, together with secure key-management practices.
- Secure development and change management: review, testing and controlled deployment of system changes.
- Vulnerability and patch management: identification, prioritisation and remediation of vulnerabilities and security updates based on risk.
- Monitoring and logging: security-relevant activity is logged and monitored to detect suspicious behaviour and support investigations.
- Backups and recovery: protected backups and recovery processes are maintained and tested according to business requirements.
- Endpoint and email protection: anti-malware, application controls, filtering and other protections are applied where appropriate.
- Supplier security: material service providers are assessed according to risk and subject to contractual security and privacy obligations.
- Personnel security and awareness: staff receive security guidance, and access is removed or changed promptly when roles change.
4. Customer Account Protection
Customers are responsible for using a unique, strong password, enabling multi-factor authentication where available, securing their devices and email account, and reviewing transactions and communications. FirstGold will never ask you to disclose your password. Treat unexpected payment-detail changes, urgent transfer requests and links in unsolicited messages with caution. Verify sensitive instructions using a trusted contact channel.
5. Payment and Transaction Security
We apply verification and fraud-prevention controls to payment and transaction instructions. For security or compliance reasons, we may delay or pause a transaction while we verify identity, authority, bank details, source of funds or unusual activity. Customers should independently verify FirstGold bank details before sending funds, particularly where details appear to have changed.
6. Data Protection and Privacy
Personal information is handled in accordance with our Privacy Policy. Access is limited to personnel and service providers who need it for authorised purposes. We retain information according to legal, operational and security requirements and securely destroy or de-identify it when no longer required.
7. Incident Response and Breach Notification
We maintain processes to identify, contain, investigate, remediate and learn from security incidents. Where a security incident involves personal information and meets the legal threshold for an eligible data breach, we will notify affected individuals and the OAIC as required by the Privacy Act and Notifiable Data Breaches scheme.
8. Business Continuity
We maintain continuity and recovery arrangements proportionate to our services and risks. These may include backups, alternative communication methods, recovery priorities and supplier contingency arrangements. No system can be guaranteed to be continuously available, but we work to restore affected services safely and as soon as reasonably practicable.
9. Responsible Vulnerability Reporting
If you believe you have identified a security vulnerability affecting FirstGold, report it promptly to [email protected]. Include enough detail to help us reproduce and assess the issue. Do not access, alter, download or retain customer data; disrupt services; conduct denial-of-service testing; use social engineering; or publicly disclose the issue before we have had a reasonable opportunity to investigate and remediate it. We will acknowledge good-faith reports and coordinate next steps where appropriate.
10. What Customers Should Do
- Use a strong, unique password and do not reuse it on other services.
- Enable multi-factor authentication wherever available.
- Keep your operating system, browser and security software updated.
- Access FirstGold only through official websites or applications and check the domain carefully.
- Do not share verification codes, passwords or recovery information.
- Contact us immediately if you notice unfamiliar activity, receive a suspicious message claiming to be from FirstGold, or believe your account or email has been compromised.
11. Security Limitations
No security programme can eliminate all risk. Internet communications, customer devices and third-party systems may be compromised despite reasonable safeguards. This Policy describes our general approach and is not a warranty that incidents will never occur or that every control applies in every circumstance.
12. Updates and Contact
We may update this Security Policy as our systems, services, risks and legal obligations evolve. The latest version will be published with its effective date.
Security enquiries and vulnerability reports: [email protected]
Urgent account concerns: 02 9020 5150
