You've been asked to produce an information security policy before a customer review, a supplier questionnaire has landed in the inbox, or an insurer wants evidence of controls. HR has a template. The director has a few opinions. Your IT provider knows where the systems are, but nobody has written down who can approve access,...
Read MoreTag: gdpr compliance
IT Policy and Procedures: A Guide for UK SMEs
Around 60% of UK SMEs lack formal IT policies and procedures, according to the 2025 NCSC SME Survey summary referenced here. That sounds like an admin problem until you look at what happens next. In regulated sectors, 78% of firms without formal policies experienced a data breach between 2023 and 2024, based on the same...
Read MoreIncident Response Planning: A Practical Guide for UK SMEs
Most UK SMEs already know they should have an incident response plan. The problem is that many of them have a document, a few named contacts, and no real confidence that any of it will work at 08:47 on a Tuesday when Microsoft 365 accounts start locking out, files go missing, and the person who...
Read More