C3 Plus – Governance, Assurance & Trust Statement
At C3 Plus, strong governance isn’t an aspiration — it’s the way we operate every day.
We apply the same discipline, controls, and security principles to our own business that we expect from our clients, ensuring our advice is grounded in lived experience and proven practice.
We maintain a robust internal governance framework built on:
Cyber hygiene as a daily habit
We protect our systems from unauthorised access, maintain secure configurations, manage access responsibly, defend against malicious threats, and keep systems up to date. As our Cyber Hygiene Statement notes, these controls are “daily habits and strategic choices that reflect our values.”
Clear, transparent data protection practices
Our Data Processing Agreement and Privacy Notice set out how we collect, use, store, and protect personal data in line with UK GDPR and the Data Protection Act 2018. We process data only on documented instructions, implement appropriate technical and organisational measures, and always ensure confidentiality.
Defined service standards and accountability
Our Service Level Agreement outlines the service levels, responsibilities, and response times clients can expect, ensuring clarity, reliability, and professional delivery throughout every engagement.
Comprehensive professional and cyber liability insurance
We maintain appropriate Professional Liability, Cyber Liability, and Security Insurance to protect our clients and our business, reflecting the level of assurance expected of a modern cyber governance consultancy.
Together, these measures demonstrate our commitment to operating with integrity, transparency, and resilience. They ensure that when clients work with C3 Plus, they are partnering with a consultancy that not only advises on best practice — but embodies it.

Copyright © 2026 C3Plus Limited - All Rights Reserved.