The short answer: Since 1 October 2026, private registered providers of social housing in England must have a STAIRs publication scheme. It covers information they hold about governance, spending, homes, performance, services, registers and housing management. Providers do not have to create new records. Appropriate redaction is allowed. The separate requirements for tenant information requests…
-
-
External Attack Surface Management, usually shortened to EASM, is the continuous discovery and monitoring of everything your organisation exposes to the internet, domains, subdomains, cloud services, servers and applications, including the ones nobody currently has on a list. What “attack surface” actually means Your external attack surface is every point an attacker could potentially reach…
-
Generative AI tools like ChatGPT, Microsoft Copilot and Gemini can be used in schools under UK GDPR if used safely and effectively, with appropriate data protection policies in place. To remain GDPR-compliant, schools should avoid using free versions of generative AI tools, as they may lack the necessary safety features. Instead, schools should use enterprise…
-
Pentesting, short for penetration testing, is an authorised, simulated attack on your organisation’s systems, carried out by a security professional using the same techniques a real attacker would, to find exploitable vulnerabilities before someone with genuinely bad intentions does. How pentesting differs from a vulnerability scan These two are often confused but they’re not the…
-
Cyber security support is an ongoing, retained service that gives your organisation continued access to expert security guidance. Rather than a single project with a fixed end date, it’s a standing relationship, someone you can turn to as questions, decisions and issues come up, rather than starting from scratch every time. How support differs from…
-
What Is a Weaponised Subject Access Request? A “weaponised” Subject Access Request (SAR) is a SAR that is being used as part of a wider dispute or strategy, rather than simply because someone wants to understand what personal data an organisation holds about them. You often see this during a grievance, disciplinary process, redundancy consultation…
-
Cyber security consultancy is independent expert advice on identifying, prioritising and managing your organisation’s information security risk. Rather than a single product or a fixed technical check, it’s guidance shaped around your actual business, what data and systems you have, what threatens them, and what a sensible, proportionate response looks like. What a cyber security…
-
ISO 27001 is the international standard for an Information Security Management System, or ISMS. It’s not a single technical control or a piece of software, it’s a structured framework for how an organisation identifies its information security risks, decides how to manage them, and proves it’s actually doing so consistently. What an ISMS actually is…
-
With the Information Commissioner’s Office (ICO) transition to the “Information Commission” under the Data (Use and Access) Act (DUAA) 2025 set to be confirmed on 30 September 2026, it is an appropriate moment to look at what this change actually means for the regulator. The transition is a structural evolution that will not change the…
-
PCI DSS stands for the Payment Card Industry Data Security Standard. It’s a set of security requirements created by the major card schemes (Visa, Mastercard and the others) that applies to any organisation that stores, processes, or transmits cardholder data, regardless of size or sector. Who PCI DSS actually applies to If your organisation takes…
Join our community
Our mission is to make data protection easy: easy to understand and easy to do. We do that through the mantra of benchmark, improve, maintain.