Version 1.0 · Draft · Owner: Security Lead
Download .md →Touch2Sign Ltd
Version: 1.0
Effective date: 11 July 2026
Owner: Robert — Security Lead
Approved by: Robert — CEO / Managing Director
Next review: 11 July 2027
Establish a consistent approach to identifying, assessing, treating, and monitoring information security risks across the Touch2Sign eSignature and eWitness platform. Supports ISO 27001 Clause 6.1 and SOC 2 risk assessment requirements.
Covers risks affecting:
Applies to all Touch2Sign departments; owned operationally by the Security Lead.
Touch2Sign follows a continuous cycle:
Maintained by Security Lead in [GRC tool / spreadsheet — location TBD].
Minimum fields:
| Field | Description | Risk ID | RISK-YYYY-NNN |
|---|---|
| Title | Short description |
| Category | Technical / legal / operational / third-party |
| Threat | What could happen |
| Vulnerability | Weakness exploited |
| Asset affected | Documents, IDV, platform, reputation |
| Existing controls | Current mitigations |
| Likelihood | 1–5 (see matrix) |
| Impact | 1–5 (see matrix) |
| Inherent risk | L × I before treatment |
| Treatment | Mitigate / transfer / accept / avoid |
| Action plan | Specific tasks, owner, due date |
| Residual risk | L × I after treatment |
| Risk owner | Named individual |
| Review date | Next review |
| Status | Open / monitoring / closed |
| Score | Label | Description | 1 | Rare | Unlikely in 3+ years |
|---|---|---|
| 2 | Unlikely | Possible but not expected annually |
| 3 | Possible | May occur once per year |
| 4 | Likely | Expected annually |
| 5 | Almost certain | Multiple times per year or active trend |
| Score | Label | Description | 1 | Negligible | No customer impact; internal only |
|---|---|---|
| 2 | Minor | Single customer inconvenience; < €10k |
| 3 | Moderate | Multi-customer impact; regulatory inquiry possible |
| 4 | Major | Data breach; ICO/DPC investigation; significant revenue loss |
| 5 | Severe | Mass document leak; platform outage > 24h; existential reputational harm |
Risk score = Likelihood × Impact
| Score range | Rating | Action | 1–4 | Low | Monitor; accept with documentation |
|---|---|---|
| 5–9 | Medium | Treat within 90 days; Security Lead owner |
| 10–15 | High | Treat within 30 days; CEO informed |
| 16–25 | Critical | Immediate treatment; CEO approval for acceptance |
Touch2Sign's risk appetite statements:
Residual risks above High require CEO written acceptance with expiry date.
| Option | When to use | Example | Mitigate | Controls can reduce likelihood or impact | Enable WAF; quarterly access reviews |
|---|---|---|
| Transfer | Insurance or contractual shift | Cyber insurance; Stripe PCI scope |
| Accept | Cost of control exceeds risk; documented | Low legacy dependency |
| Avoid | Stop the activity | Discontinue Veriff without DPIA |
Security Lead convenes quarterly risk review with Engineering Lead, DPO, and CEO (or delegate):
Agenda:
Minutes retained 3 years.
Risk register updated within 10 business days of:
| Risk | Category | Initial treatment | Signing token compromise | Technical | Time-limited tokens; IR playbook §7.1 |
|---|---|---|
| RDS/S3 misconfiguration | Technical | IAM least privilege; Security Hub |
| IDV sub-processor breach | Third-party | DPA; vendor monitoring |
| Anthropic document exposure | Third-party | DPIA; minimise content; SCCs |
| Single-region AWS dependency | Operational | DR plan; backup restore tests |
| Insider access abuse | Operational | Access reviews; audit logging |
| Customer uploads PHI | Legal | HIPAA Scope Policy; terms prohibition |
Detailed scoring maintained in live risk register.
This policy reviewed annually and when risk methodology changes.
Approval
| Name | Role | Signature | Date | Robert | CEO / Security Lead | Electronic | 11 July 2026 |
|---|
Questions: security@touch2sign.com · privacy@touch2sign.com