Regulatory updates, certification trends, and practical takeaways for UK SMEs — each post links to a step-by-step guide so you can act on it, not just read about it.
Not the attack chain, not the technical play-by-play — what a ransomware attack on an SME actually feels like to live through, day by day, and what incident response really looks like when you're inside one.
NIS2 is an EU directive, but UK businesses selling into the EU — or supplying an in-scope EU entity — can still inherit its obligations. The harder part isn't understanding the regulation, it's turning it into an evidenced security programme.
Cyber Essentials used to be enough to tick the compliance box in most tenders. Increasingly, procurement teams and cyber insurers are asking for the technically verified version — CE+ — instead. Here's why, and what actually changes in the assessment.
ICO enforcement makes headlines when it hits a household name, but the pattern behind most action against SMEs is far more mundane — and far more fixable. Here's what it means for how you keep your GDPR paperwork.
The guides walk through exactly how to put each of these topics into practice — from first gap check to finished evidence pack.