Trust Center: Data Security | isolved HCM
Security
From infrastructure to interface, learn how isolved defends your organization by embedding protection into every layer of isolved People Cloud™.
Prioritizing Your Security
At isolved, protecting your information and data is essential to earning and keeping your trust. That’s why we continuously assess our security capabilities and make strategic investments in people, processes and technologies. We conduct independent assessments, have board-level visibility into strategic cybersecurity and operational risk objectives, leverage industry-leading providers and have dedicated resources to ensure viable risk and security management. Every safeguard is designed to reduce risk and deliver peace of mind so you can focus on growing your business with confidence.
This security section of the isolved Trust Center is designed to cover aspects of what the isolved team manages from application hosting, telecommunications, desktops, networking, infrastructure, cybersecurity, vendor management, software development lifecycle and fraud prevention. Risk analysis includes various testing of cyber, system and process controls conducted on a regular basis either internally or by a certified third-party provider across control types to ensure necessary and ongoing safeguards.
Ongoing Security Safeguards
Administrative Safeguards
Training, documentation, practices, policies and procedures that define business and personal-use practices in accordance with security and compliance goals. These can apply to employee hiring, termination, equipment, internet usage, physical access to company facilities, separation of duties, data classification, auditing, security and/or other risk training.
Technical Safeguards
Hardware, software and other technology mechanisms are used to protect assets. Common examples include authentication solutions, firewalls, antivirus software, intrusion detection systems (IDSs), intrusion protection systems (IPSs), constrained interfaces, and access control lists (ACLs) that protect access to/from data, networks and systems.
Physical Safeguards
Mechanisms are used to prevent or detect unauthorized access to physical areas, systems or assets. This may include, but is not limited to, security badges, locking doors, access cards, biometrics access controls, video cameras, surveillance cameras, motion sensors, fire suppression, and other environmental controls like HVAC and humidity controls.
Security Resources
Security FAQs
What is business email compromise (BEC)?
Business email compromise is a type of cyberattack in which a criminal impersonates a trusted business contact, such as a vendor, CEO or payroll manager, to trick employees into transferring funds or revealing sensitive data. These attacks are often highly targeted and convincing, using spoofed email addresses and urgent language to bypass normal verification procedures.
To protect against BEC:
- Always validate email requests for payments or sensitive data, especially if they seem urgent or unusual.
- Contact the sender through a known, trusted channel before taking action.
- Enable multi-factor authentication (MFA) on all email accounts.
What is ransomware?
Ransomware is a form of malware that encrypts a victim’s files or systems, holding them hostage until a ransom is paid, often in cryptocurrency. In many cases, even paying the ransom does not guarantee full recovery. Ransomware can enter through phishing emails, malicious downloads or unsecured networks.
Prevent ransomware attacks by:
- Keeping software and systems up to date with the latest security patches.
- Backing up data regularly and storing backups offline.
- Training employees to spot suspicious attachments and links.
What is credential stuffing?
Credential stuffing occurs when cybercriminals use stolen username-password pairs from one breach to try logging into other systems. Because many people reuse passwords, attackers often succeed.
To prevent credential stuffing:
- Never reuse passwords across sites or applications.
- Use a password manager to store and generate unique credentials.
- Enforce MFA and monitor for unusual login behavior.
What is phishing?
Phishing is a type of cyberattack where scammers impersonate trusted entities—such as a known company, vendor or colleague—to trick recipients into revealing personal information, clicking malicious links or downloading malware. These messages often arrive via email or text and may appear highly convincing, using real logos or spoofed addresses.
To protect against phishing:
- Verify the sender’s email address—legitimate isolved emails will always come from @isolvedhcm.com.
- Hover over links to preview URLs before clicking and ensure they begin with https://.
- Be cautious of urgent requests or threats demanding immediate action.
- Never share passwords or login credentials via email.
- Enable MFA to protect accounts even if credentials are compromised.
If you receive a suspicious message, report it to your IT/security team and delete it. If you’ve already clicked or entered information, change your password immediately and notify your administrator.
What is zero-day vulnerability?
A zero-day vulnerability is a software flaw that is unknown to the vendor and actively exploited by attackers before it can be patched. These vulnerabilities are especially dangerous because there is no defense until the flaw is discovered and fixed.
Protect your business by:
- Keeping all systems updated and patched as soon as fixes are released.
- Using endpoint protection tools that detect abnormal behavior, not just known threats.
What is man-in-the-middle (MitM) attack?
In a MitM attack, a hacker secretly intercepts and possibly alters the communication between two parties, such as between an employee and a payroll system, without their knowledge.
MitM prevention tips:
- Avoid using public Wi-Fi for work-related tasks unless connected via a secure VPN.
- Always check for HTTPS in the browser when accessing sensitive systems.
- Use encrypted communication channels and ensure session timeouts are enabled.
What is spoofing?
Spoofing refers to a cybercriminal disguising their communication—email, website, phone number, or IP address—to appear as someone trustworthy. The goal is to deceive the recipient into providing access or information.
To identify and avoid spoofing:
- Double-check email addresses, URLs and sender details.
- Be wary of slight misspellings or formatting inconsistencies.
- Validate requests through secondary means.
What is multi-factor authentication (MFA)?
MFA requires users to verify their identity using more than one credential, usually something they know (password) and something they have (authenticator app, code or hardware token). MFA dramatically reduces the risk of unauthorized access, even if a password is compromised.
What is a data breach?
A data breach occurs when unauthorized individuals gain access to confidential, sensitive or protected information. Breaches can involve personal data, financial records, employee credentials or customer databases.
To minimize risk:
- Restrict data access to only those who need it.
- Monitor systems for anomalies and maintain robust logging.
- Train employees on proper data handling and incident reporting protocols.