2degrees security policy for third parties
Public facing supplier expectations and security requirements
1. Scope and purpose
This policy sets out the cyber security expectations for suppliers, contractors, business partners and other third parties that provide services to 2degrees or handle 2degrees information, systems or environments.
It explains the baseline controls, assurance expectations and responsibilities suppliers must meet to help protect 2degrees, our customers and the services we provide.
2. Contractual application
This policy applies alongside any agreement, statement of work, security schedule, data processing agreement or other contractual arrangement with 2degrees. If a contract sets a different requirement, the contract will take priority to the extent of the difference, unless stated otherwise.
2degrees may update this policy by publishing a revised version. Suppliers are expected to comply with the current version when providing services, subject to any written transition arrangements agreed with 2degrees.
3. Security objectives
- Manage cyber security risk consistently across supplier engagements.
- Protect the confidentiality, integrity and availability of 2degrees information, systems and services.
- Support legal, regulatory, contractual and industry obligations.
- Build security into onboarding, service delivery, technology change and operational risk management.
- Promote accountability and continuous improvement across the supplier lifecycle.
4. General supplier obligations
Suppliers must follow applicable 2degrees security requirements and any reasonable security directions notified by 2degrees. Suppliers must not bypass, weaken or disable security controls unless 2degrees has approved this in writing.
- Use 2degrees information, systems and access only for the agreed purposes.
- Maintain safeguards that are appropriate to the services provided and the risks involved.
- Ensure suppliers personnel understand their security responsibilities.
- Notify 2degrees promptly of material security risks, weaknesses or control failures.
- Cooperate with security reviews, investigations and remediation activities where required.
5. Minimum security control expectations
Suppliers must maintain effective security controls that are appropriate to the nature, scope, criticality and risk of the services provided to 2degrees.
- Access to systems and information is restricted to authorised users with a valid business need.
- Logging and monitoring are in place where required to detect suspicious or unauthorised activity.
- Vulnerabilities are identified, prioritised and remediated within risk-based timeframes.
- Systems, devices and services are securely configured, patched and protected against malicious code.
- Security controls are documented, reviewed and improved where needed.
6. Access management and authentication
- Access must be approved, based on business need and limited to the least privilege required.
- Accounts must be uniquely assigned to individuals and must not be shared unless explicitly approved.
- Multi-factor authentication must be used for privileged and remote access.
- Access must be logged, monitored and reviewed regularly where required.
- Access must be removed promptly when no longer required, including when a contract ends or a person changes role.
7. Data protection, classification and handling
2degrees information must be handled according to its sensitivity, agreed purpose and applicable legal, regulatory and contractual obligations. Suppliers must use approved tools and secure methods when accessing, storing, processing or transferring sensitive information.
- 2degrees information must be encrypted at rest and in transit where required.
- External sharing must have a valid business reason and appropriate approval.
- Bulk transfers may require formal security approval and additional controls.
- Retention, disposal and secure destruction must follow applicable 2degrees requirements.
8. Cloud and SaaS services
Where a supplier provides a cloud or Software-as-a-service that stores, processes or transmits 2degrees information, the supplier must:
- Maintain effective logical segregation between 2degrees information and information belonging to other customers.
- Host and process 2degrees information within New Zealand or Australia, including backups and disaster recovery copies, unless another location has been expressly approved by 2degrees in writing.
- Disclose the countries from which 2degrees information may be accessed, administered, supported or processed.
- Not change hosting locations or introduce new offshore processing arrangements without prior written notification to, and approval from, 2degrees where required.
- Maintain appropriate independent security assurance relevant to the service, such as current ISO/IEC 27001 certification, a SOC 2 report, or equivalent evidence accepted by 2degrees.
- Apply encryption, access control, logging, monitoring, vulnerability management and recovery controls appropriate to the sensitivity and criticality of the information and service.
- Disclose material subcontractors and sub-processors involved in storing, processing, transmitting or supporting 2degrees information.
9. Artificial intelligence and machine learning services
For the purposes of this policy, artificial intelligence includes machine learning and generative artificial intelligence. Where a supplier uses, provides or integrates artificial intelligence, machine learning or generative artificial intelligence in connection with services provided to 2degrees, the supplier must:
- Not enter, upload or disclose 2degrees information, personal information, source code, credentials, security configurations, network information or other confidential material into a public or consumer-grade artificial intelligence service.
- Not use 2degrees information to train, fine-tune, test or improve an artificial intelligence model without prior written approval from 2degrees.
- Obtain prior written approval before using an artificial intelligence service to process 2degrees information or to deliver a material part of the services provided to 2degrees.
- Disclose the artificial intelligence models, service providers, hosting locations and sub-processors used in delivering the services, including any material change to them.
- Ensure approved artificial intelligence services do not retain prompts, outputs or 2degrees information beyond the agreed period, or use that information for provider training, product improvement, advertising or any unrelated purpose.
- Apply access control, encryption, logging, monitoring, data segregation, retention, deletion and recovery controls appropriate to the sensitivity of the information and service.
- Assess and mitigate risks including unauthorised disclosure, prompt injection, insecure model output, data or model poisoning, excessive permissions, unintended automated actions and reliance on inaccurate or fabricated output.
- Ensure outputs are reviewed and validated by appropriately qualified personnel before being used for material operational, security, customer, legal or regulatory decisions.
- Not allow an artificial intelligence system to make or execute decisions that could affect 2degrees, our customers, systems or services without appropriate human oversight and any approval required by 2degrees.
- Maintain records sufficient to explain material artificial intelligence use, relevant input and output handling, testing performed, human approvals and actions taken.
- Notify 2degrees of an artificial intelligence-related security incident, unauthorised disclosure or material control failure in accordance with section 11.
- On request, provide evidence of artificial intelligence risk assessments, security testing, privacy assessments, control effectiveness and remediation activities.
The supplier remains responsible for all acts, omissions, outputs and security consequences arising from its use of artificial intelligence, including use by its personnel, subcontractors and downstream providers.
10. Personnel security and vetting
Suppliers must ensure that personnel who access 2degrees information, systems, services or controlled environments are trustworthy, appropriately vetted and subject to enforceable confidentiality obligations.
Vetting must:
- Be completed before access is granted.
- Be proportionate to the sensitivity of the information, level of privilege, access involved and risks associated with the role.
- Include identity and employment eligibility verification and, where appropriate and legally permitted, employment history, reference, qualification, criminal history or other relevant checks.
- Be conducted in accordance with applicable employment, privacy and human rights requirements.
- Be repeated or reviewed where there is a material change in role, access, risk or relevant circumstances.
- Apply to subcontractor and temporary personnel where they may receive equivalent access.
Suppliers must promptly notify 2degrees where a personnel-related issue could materially affect the security of 2degrees information, systems or services, subject to applicable law. Access must be removed promptly when it is no longer required or when personnel leave or change roles.
11. Security incidents
Where the applicable contract specifies an incident notification, update or reporting timeframe or reporting method, the contractual requirement applies. Otherwise, suppliers must notify 2degrees without undue delay and no later than 24 hours after becoming aware of any suspected or actual security incident, security weakness, unauthorised activity, data loss, system compromise or service disruption that could affect 2degrees, our customers or our services. Notifications must be sent to the 2degrees Security Team at sec.notify@2degrees.nz. Notification must not be delayed because all information is not yet available.
- Initial notification must include, to the extent available, what happened; when it occurred and was discovered; the affected services, systems, data and people; the actual or likely impact; and the containment and recovery action taken or planned.
- Where the contract does not specify update intervals, suppliers must provide a written update within 48 hours after the initial notification, updates at least every 24 hours until the incident is contained, and updates at least every five business days thereafter until recovery and remediation are complete. More frequent updates must be provided where reasonably requested by 2degrees.
- Suppliers must support investigation, containment, recovery, remediation and evidence preservation activities.
- Where the contract does not specify a final-report deadline, suppliers must provide a final written incident report within seven calendar days after the incident is resolved. The report must document the incident timeline, impact, root cause, containment and recovery actions, affected services, systems and data, lessons learned, and corrective actions with owners and due dates.
- External notifications relating to 2degrees, our customers or our services must be coordinated with 2degrees unless prohibited by law.
12. Secure development and software supply
Where a supplier develops, supplies, integrates or maintains software for 2degrees, security must be built into the software development lifecycle. This includes secure design, secure coding, vulnerability management, testing and controlled release practices.
- Secure coding practices must be followed, including input validation, least privilege and secure error handling.
- Deprecated libraries, insecure components and unsupported software must be avoided or risk-assessed.
- Security testing must be included in development and release activities.
- High-risk applications may require vulnerability assessment, penetration testing or other security assurance before release.
- Vulnerabilities must be remediated and verified within agreed timeframes.
13. Assurance, evidence and audit
2degrees may ask suppliers to provide evidence that security controls are in place and operating effectively. The level of evidence required will depend on the nature, criticality and risk of the services provided.
- Evidence may include security questionnaires, policy summaries, certification evidence, audit reports, penetration testing summaries, vulnerability remediation evidence or control testing results.
- Suppliers may be required to provide current certifications or attestations where relevant, such as ISO/IEC 27001 or SOC 2.
- 2degrees may conduct or request independent security assessments where permitted by contract or where a material risk is identified.
- Material deficiencies must be addressed through agreed corrective actions, owners and due dates.
- Failure to provide reasonable assurance or remediate material deficiencies may result in restricted access, additional controls, delayed onboarding or other contractual remedies.
14. Subcontracting and downstream providers
Suppliers must not use subcontractors, affiliates or downstream providers to access, process, store, transmit or support 2degrees information, systems or services unless this is permitted by contract or approved by 2degrees. Suppliers remain responsible for the security performance of those parties.
15. Resilience, continuity and recovery
Suppliers must maintain continuity and recovery arrangements that match the criticality of the services they provide to 2degrees. This may include documented recovery plans, backup and restoration practices, escalation paths and participation in continuity or disaster recovery assurance activities where required.
16. Compliance and governance alignment
2degrees security governance is informed by recognised frameworks and obligations, including ISO/IEC 27001:2022, NZISM, Protective Security Requirements, PCI DSS, the Privacy Act 2020, the Telecommunications Information Privacy Code 2020 and the Telecommunications (Interception Capability and Security) Act 2013. Supplier obligations will depend on the services provided, contractual scope and risk assessment outcomes.
17. Exceptions and non-compliance
Exceptions must be risk-assessed, approved by the relevant 2degrees policy or risk owner, documented with compensating controls and reviewed within an agreed timeframe. Where a supplier does not meet these requirements, 2degrees may require additional controls, remediation plans, restricted access, enhanced monitoring or other risk treatment measures.
18. Document control
| Document owner | 2degrees |
| Document audience | Suppliers, contractors, business partners, customers and other third parties |
| Document classification | TLP:CLEAR Public-facing supplier expectations policy |
| Contractual status | Applies where referenced by contract, onboarding requirements, security schedules or supplier assurance activities |
| Source alignment | 2degrees Security Policy and Standards |
| Effective | September 2026 |