Data Protection

ai procurement checklist a three interlocking rings

AI Procurement Checklist: Essential Guide for Safe Buying

Buying AI is not like buying a database. The product changes after you sign, your data may never come back, and legal, security and IT each see a different danger. This guide sets out a complete AI procurement checklist for all three teams, organised the way a purchase actually moves: intake and triage, three parallel reviews, evidence instead of assurances, scoring with three possible outcomes, and the contract clauses worth arguing over. It covers training rights, output ownership, retention limits, prompt injection, model provenance, cost ceilings and exit paths, plus how to keep the whole process fast enough that nobody bypasses it.

Read more
supplier contract security requirements a shield emblem on hexagonal plinth

Supplier Contract Security: Essential Clauses to Avoid Risk

Most contracts dispose of security in a single sentence promising “appropriate technical and organisational measures”, which gives you no notification deadline, no evidence rights and no route to terminate when the supplier is breached. This guide sets out the cybersecurity requirements worth writing into supplier agreements: the standards and certification scope to specify, the core control clauses, the UK GDPR processor terms that are statutory rather than optional, incident notification and cooperation, audit and evidence rights, subcontractor flow-down, exit and data return, liability and insurance, and the three-tier model that keeps the whole programme proportionate across a real supplier base.

Read more
cyber due diligence mergers acquisitions a magnifying glass on plinth

Cyber Due Diligence in M&A: Essential Guide to Avoid Risk

Financial diligence values the earnings and legal diligence values the contracts, but neither tells a buyer whether the target has been quietly compromised for eight months. This guide sets out proportionate cyber due diligence on a real transaction: what the exercise actually covers, the four ways weak review destroys deal value, the five phases from scoping to costed reporting, the data room evidence list and what its absence proves, the red flags that justify repricing, how deal size and sector change the scope, the mapping from findings to price adjustments, warranties, indemnities and conditions, the first hundred days after completion, who should run the exercise and what it costs, and the mistakes that keep repeating.

Read more
passkeys vs mfa replace business passwords a hexagonal shield fingerprint

Passkeys vs MFA: Proven Guide to Stop Password Risk

Adversary-in-the-middle phishing kits now defeat one-time codes and push approvals routinely, which is why the multi-factor authentication you deployed in 2020 is no longer doing the job you think it is. This guide compares passkeys and traditional MFA by the attacks each one actually stops, explains how origin binding makes a passkey unphishable, sets out the parts of a typical application estate that cannot accept a passkey yet, costs the migration in service desk time and hardware, and gives a staged rollout plan that ends with weak factors switched off rather than left as a fallback.

Read more
immutable backup 3 2 1 1 0 strategy a sealed vault cube plinth

Immutable Backup: Essential 3-2-1-1-0 Strategy to Cut Risk

Ransomware crews delete the backups before they encrypt anything, which is why the old 3-2-1 rule quietly stopped being enough. This guide explains what an immutable backup genuinely is at the storage layer, how each digit of the 3-2-1-1-0 backup strategy is proved rather than claimed, the difference between governance and compliance mode, how long the lock window needs to be against realistic dwell time, what the storage overhead actually costs, the restore verification that the final zero demands, and a 90-day plan to get there.

Read more
leaving an it provider what happens to your data a open vault door cubes

Leaving an IT Provider: Essential Guide to Avoid Data Risk

When a support contract ends, the asset most likely to go missing is the one nobody put a price on. This guide explains where your data physically lives, who owns which parts of it under UK data protection law, what a realistic thirty-day handover looks like, which systems are lost most often, how to demand exports in formats you can actually open, how to obtain evidence that the outgoing supplier destroyed its copies, what a clean exit costs in the UK, and the contract clauses that make the whole process routine rather than adversarial next time round.

Read more
CHAT