Phishing simulation testing shows exactly who clicks and who reports, but NCSC and UK GDPR both set limits on how to run it fairly. Here is how the process works.
Tag:
GDPR
-
-
Shadow AI is unapproved AI tool use by staff, and it now outpaces shadow IT as a data risk. A clear breakdown of the danger and a practical checklist to …
-
A cyber security risk assessment ranks your threats by likelihood and impact so security spending goes where it matters most. Here is what it covers, who needs one, and how …
-
A practitioner’s view on setting third party penetration testing requirements: what to ask suppliers and vendors for, how to tier them by risk, and where GDPR, ISO 27001 and PCI …
-
A data breach is any incident where information is accessed, lost or exposed without authorisation. Here is what counts, how common they are in the UK, what they cost, and …