1. Purpose
This policy sets out Murzo Group's approach to connected robotics, IoT products, smart devices, embedded systems, sensors, cameras, drones, controllers, firmware, software updates, vulnerability handling, and remote access.
The purpose is to reduce cyber, safety, privacy, product, operational, and supply chain risk where physical products connect to networks, cloud services, apps, platforms, or other devices.
2. Scope
This policy applies to consumer connectable products, business IoT, robotics, drones, routers, cameras, sensors, access control devices, farm automation, smart packaging, monitoring equipment, servers, connected tools, wearable devices, mobile apps, cloud dashboards, APIs, firmware, and software supplied, used, tested, resold, or integrated by Murzo Group.
It applies across procurement, design, configuration, deployment, resale, operation, support, software update, vulnerability disclosure, incident response, and product withdrawal.
3. Secure-by-Design Principles
Connected products and software must be treated as security-sensitive where they can process data, control movement, record audio or video, unlock access, affect safety, connect to networks, or support remote commands.
- Default passwords, shared credentials, unsupported firmware, unknown cloud accounts, and insecure remote access must be avoided
- Security updates, support periods, vulnerability reporting, user instructions, and secure configuration should be understood before deployment or sale
- Products should be configured with least privilege, strong authentication, suitable encryption, secure logging, and unnecessary services disabled where practicable
- Products must not be connected to Murzo Group systems without approval where they may create material risk
4. UK, EU and International Product Security
Where connected products are supplied to consumers or placed on regulated markets, Murzo Group should consider applicable UK product security requirements, EU Cyber Resilience Act obligations, CE/UKCA, product safety, data protection, radio equipment, electrical safety, and marketplace rules.
Where Murzo Group is not the manufacturer, importer, distributor, seller of record, or responsible economic operator, the relevant third party remains responsible for its legal obligations unless Murzo Group has expressly accepted responsibility in writing.
5. Software Updates and Support
Software and firmware updates must be handled carefully because they may affect safety, cyber security, functionality, warranties, certification, conformity, data protection, and product liability.
Updates should come from trusted sources, be appropriate for the product, and be tested or reviewed where failure could create safety, operational, product, or security risk. Unsupported products should not be used for sensitive operations without risk review.
6. Vulnerability Handling
Known or suspected vulnerabilities in connected products, robotics, IoT devices, apps, cloud dashboards, firmware, APIs, or embedded software must be escalated promptly under cybersecurity and vulnerability disclosure procedures.
Murzo Group may isolate devices, disable features, rotate credentials, contact suppliers, notify customers, issue instructions, withdraw products, or stop use where risk requires it.
7. Remote Access and Cloud Services
Remote access must be authorised, limited, monitored where appropriate, and removed when no longer needed. Suppliers must not retain remote access to Murzo Group products, premises, robotics, CCTV, access control, customer data, or production systems unless approved.
Cloud services used by connected products should be assessed for account ownership, hosting location, data use, support, exit route, security updates, incident reporting, and continuity risk.
8. Data, CCTV and Sensor Outputs
Connected products may collect personal data, location data, audio, video, biometric data, telemetry, operational data, security logs, or commercially sensitive information. Data collection must be lawful, necessary, proportionate, transparent where required, and protected against unauthorised access.
Sensor and telemetry outputs must not be used for hidden worker monitoring, customer profiling, surveillance, law enforcement-style activity, or AI training unless specifically approved and lawful.
9. Third-Party Products and Customer Responsibility
Customers, suppliers, installers, manufacturers, platforms, landlords, carriers, and integrators remain responsible for their own networks, configurations, installations, updates, support, passwords, misuse, unsafe environments, and unauthorised modifications unless Murzo Group has expressly accepted responsibility in writing.
To the fullest extent permitted by law, Murzo Group does not accept responsibility for compromise, loss, injury, damage, data breach, downtime, or false output caused by third-party hacking, customer configuration, unsupported firmware, unauthorised modification, unsafe installation, or operation outside written instructions.
10. Review and Evidence
Murzo Group may keep proportionate evidence of supplier instructions, update decisions, vulnerability reports, product security claims, remote access approvals, incidents, and customer communications where needed for legal, security, product, insurance, or dispute purposes.
This policy should be reviewed when product security law, connected products, suppliers, cloud services, vulnerabilities, or Murzo Group technology activity change.