Blog

Hallucinated Rigour – Privacy Space 2026

Example One – DPIA Pursuant to Article 35(3)(a) GDPR, a Data Protection Impact Assessment is required for this processing activity as it involves a systematic and extensive evaluation of personal aspects relating to natural persons, based on automated processing. The controller relies on legitimate interests under Article 6(1)(f) as the lawful basis. A legitimate interests…
Read more

Office burning whilst lawyer checks definition of fire.

Interpreting Legal Definitions – the GDPR “Personal Data Breach”

Many DPOs lack a law degree and those without may also lack basic legal training. It’s not a fault of the DPO as they may have been given the DPO role as a “side-of-the-desk” task alongside their primary role. But a DPO without some basic legal training could cause issues for a Controller or Processor,…
Read more

CISO Fire

Nice CISOs MUST Retaliate!

Are you a CISO who doesn’t want to rock the boat? Maybe you feel like to be collaborative you need to let the business units just get on – standing in their way will lead to conflict and bad relationships right? You just want to be seen as helpful…nice even? Well, Robert Axelrod’s seminal work…
Read more

Ordnung

Ordnung! How Rigid is your Approach to Governance?

In the research for my latest book (this new one is on leadership) I came across the German cultural philosophy of “Ordnung”. It appears to be a significant part of the German way of life. For the history buffs, it appears to originate with the German Monk, Martin Luther (Not to be confused with Dr…
Read more

Teacher

Securing the Digital Classroom: Why Teachers Must Embrace Multi-Factor Authentication (MFA)

In this digital age, the lines between the virtual and the real world are increasingly blurring. We’ve all heard tales of a friend who got hacked. Perhaps, you’ve even been a victim yourself? As educators, navigating this digital world is hard enough without having to manage a cyber attack on top! Multi-Factor Authentication (MFA) is…
Read more

Weighing Scales

Comparing Security Return on Investment (ROI) – Without Maths*

Anyone who has operated at the CISO level will know there is a finite budget, which is small. There are constantly changing threats and an ever-growing market of solutions. Navigating the landscape requires a keen sense of prioritisation, a profound understanding of risk, and the ability to communicate value to leadership. It is not just…
Read more

Right to Access Fulfilment Model (RAFM)

Subject Access Requests: Introducing the RAFM

The right to access is a fundamental right contained within many data protection regulations globally. In particular the EU and UK General Data Protection Regulations. The right to access can often cause headaches for business. Tens of thousands of Data Subject Access Requests are made every month and sadly, many are not fulfilled properly. Many…
Read more

DSAR Documents

DSAR – Dealing with the Contentious Data Subject Access Request

DID YOU KNOW: We now have a comprehensive DSAR Course – Check it out here: Click to see Course Landing Page Data Subject Access Requests (DSARs) can be onerous at the best of times but there are some situations which send a shudder down the backs of many a Data Protection Officer. The DSAR could…
Read more

vuln scan - info

Vulnerability Scanning – It’s not all about the High and Critical items!

Don’t blindly trust the output of automated scans. This article talks about the key mistakes made when scanning for vulnerabilities.

Christmas Hacking Season

Let’s Avoid a Cost-of-Hacking Crisis this Christmas!

Normally around this time of year, I pick a nice Christmas film and write a themed piece to remind the defenders that whilst they are playing the new Call of Duty, hackers from around the world might be playing on their corporate networks. This year is different, there are many people who are struggling this…
Read more