InfoSec & cyber security

Where security controls meet legal obligation

Good security isn't automatically good data protection, and vice versa — but they need to be talking to each other. I advise on the overlap: where Article 32's "appropriate technical and organisational measures" actually lands for your systems, and how to evidence it.

Ask about security advice

Areas of focus

Security & privacy alignment

Making sure technical security controls actually satisfy the "appropriate technical and organisational measures" requirement under Article 32.

Data breach response

Incident response support and guidance on the 72-hour ICO notification requirement, including drafting notifications.

Security policy review

Reviewing access control, encryption, retention and third-party security policies for consistency with your data protection obligations.

Vendor & supply chain risk

Assessing the security posture of processors and sub-processors as part of due diligence and DPA review.

A note on scope

This isn't penetration testing or technical security auditing — for that, you want a specialist security firm, and I'm glad to help you interpret their findings against your data protection obligations once you have them. What I offer sits one layer up: making sure the security decisions your engineering and IT teams make are ones you can defend from a data protection standpoint, too.

Need security and data protection advice that actually agree with each other?

Tell me what's prompted the question — an incident, an audit, a new system — and I'll tell you honestly how I can help.

Book a consultation