Resource Library
Download security policies, reference guides and documentation for your team.
A starter policy template your organization can adapt. Covers: scope and purpose; roles and responsibilities (Staff, Managers, ICT/Incident Handlers); severity definitions (Low/Medium/High/Critical) with MTTA/MTTR targets; reporting requirements and channels; evidence preservation rules; data-handling and beneficiary-data protection; notification obligations (Legal, Data Protection, Donor, Partner, Regulator); post-incident review requirements. Replace bracketed placeholders with your org details and have leadership approve before publishing.
When something feels wrong, act in this order: 1) STOP — stop interacting with the suspect message, link, file or device. 2) PRESERVE — do not delete anything; keep emails, screenshots and files as evidence. 3) DISCONNECT — if you suspect your device is affected, disconnect it from the network (Wi-Fi/Ethernet/VPN) but do not power off unless told to. 4) REPORT — use your organization's approved reporting channel immediately. Do not delay reporting because some details are missing. When in doubt, report.
How to report a security incident: WHO reports — any staff member who notices something suspicious. WHEN — immediately; do not wait to confirm. WHAT to include — your name and department, date/time noticed, what happened, what was affected, whether personal data is involved, any action you took, and evidence attached. WHERE — use the in-app 'Report Incident' form, or for Save the Children staff, email itsecurity@savethechildren.org. WHAT HAPPENS NEXT — your ICT team acknowledges, triages severity, and manages the response; you will be contacted for follow-up. Reporting a non-incident is always better than missing a real one.