Compliance

duaa uk gdpr changes what changed for businesses a three ascending rounded pillars

DUAA UK GDPR Changes: Essential Guide to Avoid Costly Risk

The Data (Use and Access) Act 2025 edits UK data protection law rather than replacing it, which is why a summary is less useful than a diff. This guide sets the pre-2026 position beside the current one across lawful basis and the new Annex 1 recognised legitimate interests, the repeal of Article 22 and the safeguards in Articles 22A to 22D, the reasonable-and-proportionate subject access standard, the universal complaints duty and its 30-day clock, and the three narrow cookie exemptions behind a PECR ceiling that rose from £500,000 to £17.5 million. It then translates every change into the document you edit, the team that owns it, a 90-hour effort register, a UK-versus-EU divergence table, and a ninety-day plan.

Read more
data use and access act 2025 a three ascending rounded pillars

Data Use and Access Act 2025: Essential UK Risk Checklist

The main data protection provisions commenced on 5 February 2026, the mandatory complaints procedure followed on 19 June 2026, and the maximum PECR penalty rose thirty-five-fold to £17.5 million. This guide sets out exactly what is in force, what is still pending, and what each change obliges a UK business to do differently: the commencement timetable tied to its statutory instruments, recognised legitimate interests and the direct-marketing trap underneath them, the repeal of Article 22 and the new Articles 22A to 22D on automated decision-making, the reasonable-and-proportionate subject access standard, the universal complaints duty and its 30-day acknowledgement clock, the three narrow cookie exemptions and why the analytics one is narrower than it looks, renewed EU adequacy to December 2031, what the Act pointedly did not change, and a sequenced six-step remediation plan for the rest of 2026.

Read more
WCAG 2.2 checklist - wcag 2 2 checklist business websites a three ascending rounded pillars

WCAG 2.2 Checklist: Proven Fixes to Avoid Costly Failures

Most business websites fail accessibility not because the team does not care but because nobody ever turned the standard into a list of things to check on a Tuesday afternoon. This guide turns WCAG 2.2 into that list: what the 86 success criteria actually are, which 55 you must meet for Level AA, the nine criteria that are new in 2.2 and catch modern sites out, the UK legal position under the Equality Act and the European Accessibility Act, a one-day testing routine using free tools, realistic UK remediation costs from a £0 in-house pass to a £14,000 rebuild, a 90-day roadmap, the overlap with SEO, and the mistakes that produce a green dashboard on an unusable site.

Read more
data governance framework for smes a three stacked hexagonal plates

Data Governance Framework: Proven SME Guide to Avoid Risk

Almost every published data governance framework assumes a team that a small business does not have. This guide is written for the reality of ten to two hundred and fifty people: the six components that carry the value, who owns each one in a firm with no chief data officer, how to build a system inventory in a fortnight rather than a year, three classification tiers with handling rules people will actually follow, the four data quality measures worth tracking, a one-page retention schedule with UK periods and triggers, access reviews and processor contracts, what AI changes, which tooling is already inside licences you own, a ninety-day implementation plan, realistic first-year costs, six metrics to report quarterly, and the five failure modes that end most attempts.

Read more
cloud security posture assessment checklist a upright shield on plinth

Cloud Security Posture: Essential Risk Assessment Checklist

Most cloud incidents do not start with a clever exploit. They start with a storage container someone made public for a demo, an access key committed to a repository years ago, or logging switched on in one region and never in the other three. A cloud security posture assessment is the structured way of finding all of that before somebody else does. This checklist walks the whole engagement in order: scoping and read-only access, the technical domains worth reviewing, how to score findings so the list is defensible, whether to use native tooling or a dedicated platform, and what the work realistically costs in money and elapsed time.

Read more
ai acceptable use policy template employees a single blank paper sheet

AI Acceptable Use Policy: Essential Template to Avoid Risk

Your staff are already using AI at work; the only question is whether they are doing it inside rules you wrote. This guide gives you a complete AI acceptable use policy template for employees: the nine clauses that actually carry weight, model wording you can copy for scope, approved tools, data entry, human accountability, disclosure and breach handling, a three-tier approved and prohibited tool model, a data table showing what may never be pasted into a public chatbot, a rollout plan that gets the policy acknowledged, the mistakes that quietly kill enforcement, and the four numbers that tell you whether any of it is working.

Read more
iso 42001 certification cost timeline a blank octagonal seal disc

ISO 42001 Certification Cost and Timeline: Proven Smart Plan

ISO 42001 certification costs a UK organisation roughly £12,000 to £180,000 in year one and takes six to fifteen months, and neither range means anything until you know what moves it. This guide splits the cost into the four budgets hiding behind one number, shows how certification bodies calculate audit days under ISO/IEC 42006, sets out a month-by-month timeline from gap analysis to certificate decision, explains the five things that reliably push the date, models the three-year cost that matters more than year one, and lists six levers that cut spend and elapsed time without weakening the certificate.

Read more
penetration testing frequency a shield with magnifying glass

Penetration Testing Frequency: Proven Rules for Safer IT

Once a year is a floor, not a schedule. This guide sets out how often a business should conduct penetration testing and why the calendar date matters far less than what changed in the estate since the last report. It covers the twelve-month baseline and where it comes from, the seven change triggers that should force an unscheduled round, exactly what PCI DSS, ISO 27001, SOC 2, Cyber Essentials Plus and NIS2 actually require, where vulnerability scanning stops and human testing starts, indicative UK programme costs at every cadence, and how to build a calendar that survives a year of competing priorities.

Read more
cybersecurity risk register template smes a upright board of blank tiles

Cybersecurity Risk Register: Proven Template for Safe SMEs

Most cybersecurity risk register templates are built for banks and abandoned by small businesses within a fortnight. This guide strips the document back to the eleven fields that earn their place, gives likelihood and impact scales anchored to time and money rather than adjectives, and shows a worked register for a sixty-person firm with real rows, owners and treatment decisions. It also covers the four treatment options and how to use each one honestly, a two-afternoon build method, the review cadence and out-of-cycle triggers that stop the register rotting, and when a spreadsheet stops being enough.

Read more
supplier contract security requirements a shield emblem on hexagonal plinth

Supplier Contract Security: Essential Clauses to Avoid Risk

Most contracts dispose of security in a single sentence promising “appropriate technical and organisational measures”, which gives you no notification deadline, no evidence rights and no route to terminate when the supplier is breached. This guide sets out the cybersecurity requirements worth writing into supplier agreements: the standards and certification scope to specify, the core control clauses, the UK GDPR processor terms that are statutory rather than optional, incident notification and cooperation, audit and evidence rights, subcontractor flow-down, exit and data return, liability and insurance, and the three-tier model that keeps the whole programme proportionate across a real supplier base.

Read more
CHAT