1. What is this campaign about?
This campaign is about strengthening how information is protected across Avance Clinical.
It focuses on everyday behaviours that help keep trial participant data, client information, and the business secure.
2. Why is information security important here?
Avance Clinical works with sensitive information relating to trial participants, study protocols, sponsors, and internal operations.
If that information is lost, changed, or exposed, it can affect participant safety, compliance obligations, client trust, and Avance’s reputation.
3. Who does this apply to?
This applies to everyone.
If someone uses email, accesses systems, handles documents, or discusses work-related information, they play a role in information security.
4. What is I[email protected] used for?
I[email protected] is the central contact point for reporting information security concerns.
It can be used to report suspicious emails, possible data issues, lost or stolen devices, or anything that does not look right.
5. When should something be reported?
A concern should be reported as soon as there is a suspicion that something may be wrong.
There is no need to be certain an incident has occurred before reporting it.
6. What types of things should be reported?
Examples include:
- Suspicious or phishing emails, links, or attachments
- Data sent to the wrong recipient or stored in the wrong location
- Lost or stolen company devices (laptops, phones, etc)
- Unexpected account activity, such as login prompts or password reset emails
- System behaviour that seems unusual or unauthorised
7. What should someone do before reporting?
If it is safe to do so:
- Stop what they are doing and avoid clicking further, replying, or moving data
- Take screenshots or note key details such as time, sender, and system involved
- Include those details when emailing [email protected]
If unsure, the best action is to stop and report.
8. Will someone get in trouble for reporting a mistake?
No.
Early reporting is encouraged because it helps reduce impact and allows issues to be contained more quickly.
The goal is to protect trial participants, clients, and colleagues, not to blame individuals.
9. How will the Information Security team handle a report?
The team will typically:
- Acknowledge the report
- Assess the risk and gather more information if needed
- Coordinate any technical or business response actions
- Provide guidance on next steps
10. What are the five everyday actions in this campaign?
The campaign highlights five simple habits:
- Stop and check before clicking
- Protect passwords and logins
- Use only approved systems for trial and client data
- Lock devices and protect physical workspaces
- Report suspicious activity or incidents early