Compliance

data governance framework for smes a three stacked hexagonal plates

Data Governance Framework: Proven SME Guide to Avoid Risk

Almost every published data governance framework assumes a team that a small business does not have. This guide is written for the reality of ten to two hundred and fifty people: the six components that carry the value, who owns each one in a firm with no chief data officer, how to build a system inventory in a fortnight rather than a year, three classification tiers with handling rules people will actually follow, the four data quality measures worth tracking, a one-page retention schedule with UK periods and triggers, access reviews and processor contracts, what AI changes, which tooling is already inside licences you own, a ninety-day implementation plan, realistic first-year costs, six metrics to report quarterly, and the five failure modes that end most attempts.

Read more
cloud security posture assessment checklist a upright shield on plinth

Cloud Security Posture: Essential Risk Assessment Checklist

Most cloud incidents do not start with a clever exploit. They start with a storage container someone made public for a demo, an access key committed to a repository years ago, or logging switched on in one region and never in the other three. A cloud security posture assessment is the structured way of finding all of that before somebody else does. This checklist walks the whole engagement in order: scoping and read-only access, the technical domains worth reviewing, how to score findings so the list is defensible, whether to use native tooling or a dedicated platform, and what the work realistically costs in money and elapsed time.

Read more
ai acceptable use policy template employees a single blank paper sheet

AI Acceptable Use Policy: Essential Template to Avoid Risk

Your staff are already using AI at work; the only question is whether they are doing it inside rules you wrote. This guide gives you a complete AI acceptable use policy template for employees: the nine clauses that actually carry weight, model wording you can copy for scope, approved tools, data entry, human accountability, disclosure and breach handling, a three-tier approved and prohibited tool model, a data table showing what may never be pasted into a public chatbot, a rollout plan that gets the policy acknowledged, the mistakes that quietly kill enforcement, and the four numbers that tell you whether any of it is working.

Read more
iso 42001 certification cost timeline a blank octagonal seal disc

ISO 42001 Certification Cost and Timeline: Proven Smart Plan

ISO 42001 certification costs a UK organisation roughly £12,000 to £180,000 in year one and takes six to fifteen months, and neither range means anything until you know what moves it. This guide splits the cost into the four budgets hiding behind one number, shows how certification bodies calculate audit days under ISO/IEC 42006, sets out a month-by-month timeline from gap analysis to certificate decision, explains the five things that reliably push the date, models the three-year cost that matters more than year one, and lists six levers that cut spend and elapsed time without weakening the certificate.

Read more
penetration testing frequency a shield with magnifying glass

Penetration Testing Frequency: Proven Rules for Safer IT

Once a year is a floor, not a schedule. This guide sets out how often a business should conduct penetration testing and why the calendar date matters far less than what changed in the estate since the last report. It covers the twelve-month baseline and where it comes from, the seven change triggers that should force an unscheduled round, exactly what PCI DSS, ISO 27001, SOC 2, Cyber Essentials Plus and NIS2 actually require, where vulnerability scanning stops and human testing starts, indicative UK programme costs at every cadence, and how to build a calendar that survives a year of competing priorities.

Read more
cybersecurity risk register template smes a upright board of blank tiles

Cybersecurity Risk Register: Proven Template for Safe SMEs

Most cybersecurity risk register templates are built for banks and abandoned by small businesses within a fortnight. This guide strips the document back to the eleven fields that earn their place, gives likelihood and impact scales anchored to time and money rather than adjectives, and shows a worked register for a sixty-person firm with real rows, owners and treatment decisions. It also covers the four treatment options and how to use each one honestly, a two-afternoon build method, the review cadence and out-of-cycle triggers that stop the register rotting, and when a spreadsheet stops being enough.

Read more
supplier contract security requirements a shield emblem on hexagonal plinth

Supplier Contract Security: Essential Clauses to Avoid Risk

Most contracts dispose of security in a single sentence promising “appropriate technical and organisational measures”, which gives you no notification deadline, no evidence rights and no route to terminate when the supplier is breached. This guide sets out the cybersecurity requirements worth writing into supplier agreements: the standards and certification scope to specify, the core control clauses, the UK GDPR processor terms that are statutory rather than optional, incident notification and cooperation, audit and evidence rights, subcontractor flow-down, exit and data return, liability and insurance, and the three-tier model that keeps the whole programme proportionate across a real supplier base.

Read more
third-party cybersecurity questionnaire - third party cybersecurity questionnaire template a central hub six satellite nodes plinth

Third-Party Cybersecurity Questionnaire: Proven Risk Guide

Most supplier security questionnaires are inherited spreadsheets that produce documented false assurance rather than real risk reduction. This guide provides a working third-party cybersecurity questionnaire template: the eight domains it must cover, the full 47-question Tier 1 set written as closed questions, a three-tier model so you stop sending 180 rows to low-risk suppliers, a four-outcome scoring rubric that produces decisions instead of percentages, the evidence artefact to demand behind every claim, the red flags that separate a filed document from a real finding, a mapping to Cyber Essentials, ISO 27001 and NIS2 Article 21, and the contract clauses that turn questionnaire answers into enforceable obligations.

Read more
nis2 compliance uk businesses eu customers a shield padlock hexring plinth

NIS2 Compliance for UK Suppliers: Essential Risk Guide

NIS2 compliance reaches UK businesses along two routes, and the second catches far more of them than the first. This guide explains which UK companies fall directly under Directive (EU) 2022/2555 and must appoint an EU representative, how the Article 21 supply chain clause pulls every other UK supplier in through customer contracts, what the ten security measures actually require, how the 24-hour, 72-hour and one-month reporting clocks work when you are the supplier rather than the reporting entity, how the regime compares with the UK NIS Regulations 2018 and the Cyber Security and Resilience Bill, what fines and management liability look like, and a 90-day programme that gets a UK supplier to a defensible position.

Read more
iso 27001 readiness assessment checklist a shield tick hexagonal plinth

ISO 27001 Readiness Assessment: Essential Risk Checklist

An ISO 27001 readiness assessment is the honest audit you run on yourself before a certification body runs one on you. This checklist walks through the mandatory requirements of Clauses 4 to 10, scores the 93 Annex A controls across the four 2022 themes, sets out the documented information an auditor asks for by name, and names the seven gaps that turn up in almost every first assessment. It covers a maturity scoring method that produces a remediation plan rather than a dashboard, realistic remediation timescales per gap type, the difference between doing the assessment in-house, consultant-led or platform-led, and the single biggest predictor of failing Stage 2.

Read more
CHAT