Tagged: compliance
IT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read → GuideIT Support for Recruitment Agencies in the UK
A plain-English guide to IT and cyber security for UK recruitment agencies: protecting candidate data, securing your CRM/ATS, mobile working and stopping placement invoice fraud.
Read → GuideCyber Essentials Explained: A Plain-English Guide for UK Small Businesses
What Cyber Essentials is, the five controls, CE vs CE Plus, why it wins contracts and helps insurance, and how a small UK business gets certified.
Read → GuideIT and Cyber Security for Financial Advisers in the UK
A practical guide to IT and cyber security for UK financial advisers and IFAs: meeting FCA expectations, protecting client financial data, secure email, backups and Cyber Essentials.
Read → GuideIT Security for Dental and Healthcare Practices: A Practical Guide
How UK dental and healthcare practices can protect patient data under UK GDPR and the NHS DSPT, keep clinical software running, back up safely and control access.
Read → GuideIT Support for Nurseries and Childcare Settings in the UK
Plain-English IT and cyber security guidance for UK nurseries: protect children's and safeguarding data, control access, manage retention, and reassure parents.
Read → ArticleAI Tools at Work: The Real Security Risk Nobody Mentions
Staff are already using ChatGPT and other AI tools at work. The real danger isn't the robots — it's confidential data being pasted into public tools. Here's a sensible approach.
Read → GuideIT Support for Care Homes in the UK: A Practical Security Guide
A plain-English guide to IT for UK care homes: protecting resident and staff data, CQC-aware information governance, reliable Wi-Fi and devices, and business continuity.
Read → ArticleHow to Securely Dispose of Old Computers and Data
Selling or scrapping an old work computer? Here's how to wipe data properly, when to destroy the drive, and how to recycle old kit legally — in plain English.
Read → ArticleGDPR Basics for UK Small Businesses: A Plain-English Guide
A jargon-free guide to UK GDPR for small businesses: what personal data is, lawful basis, ICO registration and fee, your security duty, and handling breaches.
Read → ArticleHow to Report a Data Breach to the ICO: The 72-Hour Rule Explained
When a data breach is reportable, how the ICO's 72-hour rule works, what to include in your report and when to tell affected individuals. Plain-English UK guide.
Read → ArticleData Retention and Records of Processing: A Plain-English Guide for Small Businesses
How UK small businesses can handle data retention, ROPA and data minimisation under UK GDPR — in plain English, with practical steps you can start this week.
Read → ArticleInsider Threats for Small Business: The Risk From People You Already Trust
Understand accidental and malicious insider risk, and how least privilege, careful offboarding and sensible monitoring protect your small business.
Read → ArticleHow to Write a Password Policy for a Small Business (the Sensible Way)
An NCSC-aligned password policy for UK small businesses: length over complexity, no pointless forced changes, MFA everywhere and a password manager. A plain template.
Read → ArticleCyber Security for a Small Ecommerce Business
How to protect a small UK online store: securing your platform and plugins, safe payments, customer data under UK GDPR, spotting fraud, and backups that actually restore.
Read → GuideInternational Data Transfers Under UK GDPR, Explained
A plain-English guide to UK GDPR international data transfers for small businesses using US-hosted tools — mechanisms, the UK-US bridge, IDTA and TRAs.
Read → ArticleDo I Need a Data Protection Officer (DPO)?
Do you need a Data Protection Officer? When a DPO is legally required under UK GDPR — and what most UK small businesses actually need instead.
Read → ArticleICO Fines and Enforcement: What Small Businesses Should Know
A plain-English guide to ICO enforcement for UK small businesses: reprimands vs fines, the real maximum penalties, and what actually triggers action.
Read → ArticleHow to Handle a Subject Access Request (SAR)
What a subject access request is, the one-month deadline, how to respond step by step, and the common mistakes UK small businesses make with SARs.
Read → ArticleHow to Write a Privacy Notice for a Small Business
What must a privacy notice include under UK GDPR? A plain-English structure for UK small businesses, the required content, and the common gaps to avoid.
Read → ArticleLawful Basis for Processing Personal Data, Explained
The six lawful bases under UK GDPR in plain English for small businesses: how to choose one, and when to use consent versus legitimate interests.
Read → ArticleCookies and PECR for UK Business Websites
Cookie consent and PECR basics for UK small businesses — what needs consent, how to build a compliant banner, and how to handle analytics lawfully.
Read → ArticleCCTV and GDPR: Using Cameras Lawfully in Your Business
How to use CCTV lawfully under UK GDPR: signage, a clear purpose, sensible retention, handling footage requests, and what the ICO expects of you.
Read → GuideData Protection Impact Assessment (DPIA): A Simple Guide
What a DPIA is, when UK GDPR requires one, and how a small business can complete a simple, practical Data Protection Impact Assessment step by step.
Read → ArticleThird-Party and Supply-Chain Risk for Small Businesses
The suppliers and software you rely on can become your security problem. A plain-English guide to supply-chain risk for UK small firms, plus what to ask vendors.
Read → ArticleEmail Marketing for Small Business: Getting Started the Right Way
How to build a mailing list properly under UK PECR rules, pick the right tool, and get your emails delivered. A plain-English guide for small businesses.
Read → ArticleCyber Insurance for UK Small Businesses: What It Covers and How to Avoid a Denied Claim
What cyber insurance actually covers, why UK insurers now check for MFA and DMARC, what to put in place first, and the common reasons small-business claims get denied.
Read → ArticleCyber Essentials vs Cyber Essentials Plus: Which One Does Your Business Need?
The plain-English difference between Cyber Essentials and Cyber Essentials Plus, which one you need, what the audit involves, the cost and effort, and the 2026 MFA change.
Read → ArticleThe IT Support Checklist for UK Accountancy Practices
A practical IT and cyber-security checklist for UK accountants: protecting client data, staying online through tax season, and meeting Cyber Essentials.
Read →