information security

Close-up of hands adjusting a small brass gear within a larger, intricate clockwork mechanism

A Forgotten Certificate Just Broke Email for Millions. That’s the Real Story.

On Monday evening, Outlook and Exchange Online stopped working. Not for one company, for a meaningful slice of the world. People couldn’t log in. Messages sat unsent. Search returned nothing. IT teams spent hours fielding calls from colleagues who couldn’t do their jobs, because the one tool most of us touch fifty times a day

A Forgotten Certificate Just Broke Email for Millions. That’s the Real Story. Read More »

An upward trending graph line behind the figure $4.99 million, representing the rising average cost of a data breach.

The Real Cost of a Breach Just Went Up Again — Here’s What the Number Doesn’t Tell You

IBM published its Cost of a Data Breach Report last month, and the headline figure is the one everyone will quote: the global average cost of a breach has hit a record $4.99 million, a 12% increase on last year. In the UK specifically, that average sits at around $4.27 million (£3.13 million). Numbers like

The Real Cost of a Breach Just Went Up Again — Here’s What the Number Doesn’t Tell You Read More »

A small business leadership team of four reviews a recovery plan together around a meeting table, discussing priorities calmly and analytically

What the NCSC’s new incident recovery guidance gets right, and where it falls short

On 29 July, the NCSC published What To Do When Cyber-Attacks Disrupt Your Organisation, a detailed framework covering the first hours of a disruptive attack through to the months of rebuild that follow. It’s well timed. Attack volumes are up, and the guidance is clear-eyed about something many boards still underestimate: recovery from a serious

What the NCSC’s new incident recovery guidance gets right, and where it falls short Read More »

Smartphone capturing an augmented reality scan of a city street, illustrating spatial data collection for AI training

When Catching Pokémon Becomes Training Data for War: What the Niantic-Vantor Story Teaches Us About Data Protection

Few stories illustrate the gap between “what data subjects think they agreed to” and “what actually happens to their data” as vividly as the one that broke in June 2026. Millions of people who spent years scanning parks, murals and landmarks to catch Pokémon on their smartphones have discovered that those scans didn’t stay in

When Catching Pokémon Becomes Training Data for War: What the Niantic-Vantor Story Teaches Us About Data Protection Read More »

Close-up of a woman's wrist wearing a fitness tracker at a kitchen table, illustrating everyday wearable data collection

Who knew you were pregnant before you did?

Who knew you were pregnant before you did? There’s a story doing the rounds this week about a woman whose fitness tracker flagged her pregnancy weeks before a test did. Elevated resting heart rate, a shift in temperature, the usual pattern. It’s a nice human interest story, and it’s also, if you sit with it

Who knew you were pregnant before you did? Read More »

what makes a supplier risk assessment

What Makes a Supplier (And When a Tool Is Not Simply a Tool)

What Makes a Supplier (And When a Tool Is Not Simply a Tool) Every organisation I’ve worked with over the years has a supplier list. It sits somewhere in a spreadsheet, gets reviewed once a year around audit time, and contains the names you’d expect: the IT support company, the payroll provider, maybe a facilities

What Makes a Supplier (And When a Tool Is Not Simply a Tool) Read More »

Aerial view of a stone architectural maze with a clear navy blue path marked through it, representing navigation through complex ISO standards

ISO Spaghetti: Why the Standards Landscape Is Confusing (and What to Do About It)

The five standards worth knowing about ISO Spaghetti: Why the Standards Landscape Is Confusing (and What to Do About It) I have lost count of the number of tender documents I have reviewed that specify ISO 22301 and ISO 27001 and ISO 31000, sometimes with ISO 22361 thrown in for good measure. Occasionally all four

ISO Spaghetti: Why the Standards Landscape Is Confusing (and What to Do About It) Read More »

Aerial view of a port at dusk with a network of connected transport and logistics icons overlaid, illustrating supply chain interdependency.

The cyber law your organisation probably doesn’t need to worry about — and why that might be exactly the problem

The cyber law your organisation probably doesn’t need to worry about — and why that might be exactly the problem The Cyber Security and Resilience Bill passed its third reading in the House of Commons on 16 June and arrived in the Lords the following day. If you’ve seen coverage of it, you could be

The cyber law your organisation probably doesn’t need to worry about — and why that might be exactly the problem Read More »

Teenager holding a smartphone displaying an age verification prompt — illustrating the data protection challenges of the UK social media ban for under-16s

Banning Social Media for Under-16s: The Data Protection Question Nobody’s Answering

Banning Social Media for Under-16s: The Data Protection Question Nobody’s Answering So it’s official. This morning, the Prime Minister stood in Downing Street and announced a full ban on social media for children under 16. TikTok, Instagram, Snapchat, X, YouTube, Reddit — the lot. Legislation before Christmas, enforcement potentially from Spring 2027. As a parent

Banning Social Media for Under-16s: The Data Protection Question Nobody’s Answering Read More »

A framed certificate hanging on an office wall, slightly out of focus, with a laptop screen showing a security alert in the foreground

Does Your ISO 27001 Certificate Mean You’re Secure?

Does Your ISO 27001 Certificate Mean You’re Secure? After I published my recent piece on the GCHQ Director’s Bletchley Park lecture, a fellow practitioner left a comment that I’ve been turning over in my head ever since. It’s a question about ISO 27001 certification and what it really proves about security that deserves more than

Does Your ISO 27001 Certificate Mean You’re Secure? Read More »