Trust Center: Data Security | isolved HCM

Security

From infrastructure to interface, learn how isolved defends your organization by embedding protection into every layer of isolved People Cloud™.

Prioritizing Your Security

At isolved, protecting your information and data is essential to earning and keeping your trust. That’s why we continuously assess our security capabilities and make strategic investments in people, processes and technologies. We conduct independent assessments, have board-level visibility into strategic cybersecurity and operational risk objectives, leverage industry-leading providers and have dedicated resources to ensure viable risk and security management. Every safeguard is designed to reduce risk and deliver peace of mind so you can focus on growing your business with confidence.

This security section of the isolved Trust Center is designed to cover aspects of what the isolved team manages from application hosting, telecommunications, desktops, networking, infrastructure, cybersecurity, vendor management, software development lifecycle and fraud prevention. Risk analysis includes various testing of cyber, system and process controls conducted on a regular basis either internally or by a certified third-party provider across control types to ensure necessary and ongoing safeguards.

Ongoing Security Safeguards

Administrative Safeguards

Training, documentation, practices, policies and procedures that define business and personal-use practices in accordance with security and compliance goals. These can apply to employee hiring, termination, equipment, internet usage, physical access to company facilities, separation of duties, data classification, auditing, security and/or other risk training.

Read More

Technical Safeguards

Hardware, software and other technology mechanisms are used to protect assets. Common examples include authentication solutions, firewalls, antivirus software, intrusion detection systems (IDSs), intrusion protection systems (IPSs), constrained interfaces, and access control lists (ACLs) that protect access to/from data, networks and systems.

Read More

Physical Safeguards

Mechanisms are used to prevent or detect unauthorized access to physical areas, systems or assets. This may include, but is not limited to, security badges, locking doors, access cards, biometrics access controls, video cameras, surveillance cameras, motion sensors, fire suppression, and other environmental controls like HVAC and humidity controls.

Read More

Security Resources

Security FAQs

What is business email compromise (BEC)?

Business email compromise is a type of cyberattack in which a criminal impersonates a trusted business contact, such as a vendor, CEO or payroll manager, to trick employees into transferring funds or revealing sensitive data. These attacks are often highly targeted and convincing, using spoofed email addresses and urgent language to bypass normal verification procedures.

To protect against BEC:

What is ransomware?

Ransomware is a form of malware that encrypts a victim’s files or systems, holding them hostage until a ransom is paid, often in cryptocurrency. In many cases, even paying the ransom does not guarantee full recovery. Ransomware can enter through phishing emails, malicious downloads or unsecured networks.

Prevent ransomware attacks by:

What is credential stuffing?

Credential stuffing occurs when cybercriminals use stolen username-password pairs from one breach to try logging into other systems. Because many people reuse passwords, attackers often succeed.

To prevent credential stuffing:

What is phishing?

Phishing is a type of cyberattack where scammers impersonate trusted entities—such as a known company, vendor or colleague—to trick recipients into revealing personal information, clicking malicious links or downloading malware. These messages often arrive via email or text and may appear highly convincing, using real logos or spoofed addresses.

To protect against phishing:

If you receive a suspicious message, report it to your IT/security team and delete it. If you’ve already clicked or entered information, change your password immediately and notify your administrator.

What is zero-day vulnerability?

A zero-day vulnerability is a software flaw that is unknown to the vendor and actively exploited by attackers before it can be patched. These vulnerabilities are especially dangerous because there is no defense until the flaw is discovered and fixed.

Protect your business by:

What is man-in-the-middle (MitM) attack?

In a MitM attack, a hacker secretly intercepts and possibly alters the communication between two parties, such as between an employee and a payroll system, without their knowledge.

MitM prevention tips:

What is spoofing?

Spoofing refers to a cybercriminal disguising their communication—email, website, phone number, or IP address—to appear as someone trustworthy. The goal is to deceive the recipient into providing access or information.

To identify and avoid spoofing:

What is multi-factor authentication (MFA)?

MFA requires users to verify their identity using more than one credential, usually something they know (password) and something they have (authenticator app, code or hardware token). MFA dramatically reduces the risk of unauthorized access, even if a password is compromised.

What is a data breach?

A data breach occurs when unauthorized individuals gain access to confidential, sensitive or protected information. Breaches can involve personal data, financial records, employee credentials or customer databases.

To minimize risk: