[Company Logo][Company Name]
- Ref. No.:
- [Reference Number]
- Date:
- [Date]
- IT Incident Ticket:
- [Ticket Number]
To,
[Employee Name]
[Designation], [Department]
Employee ID: [Employee ID]
Subject: Violation of IT and Information Security Policy
Dear [Employee Name],
The IT Security team has reported the following incident relating to systems or accounts assigned to you:
| Particulars | Details |
|---|
| Date and time detected | [DD/MM/YYYY], [Time] |
| Device / account | [Asset Tag / User ID] |
| Nature of incident | [e.g. unapproved USB storage device connected; customer file copied] |
| Detected by | [Endpoint security alert / audit / user report] |
| Policy clause | [IT Security Policy], Clause [Clause Number] |
This activity is not permitted under the company's IT Security and Acceptable Use Policy, which you acknowledged on [DD/MM/YYYY]. It created a risk of [factual risk, e.g. malware infection or unauthorised transfer of customer data].
The IT team has already taken the following steps: [e.g. blocked the device, reset your password, scanned the laptop]. No conclusion has been reached about whether any data left the company's systems.
You are required to:
- Submit a written explanation within [Number] days of receipt of this notice, including the purpose of the activity and whether any data was copied or shared.
- Hand over the device or media concerned to IT, if in your possession.
- Complete the information security refresher module by [DD/MM/YYYY].
Based on your explanation and the IT findings, the matter will be closed or dealt with under the company's disciplinary policy and standing orders. Please report any future security concern immediately to [IT Security Contact].
For
[Company Name][HR Name]HR Department
IT Security
[IT Security Lead][Designation]Received by
[Employee Name]Date:
[Date]