Guides

Practical guides to cyber resilience and compliance

Step-by-step guidance for getting compliant without a security background — written for business owners, operations managers, and the people who actually have to make it happen.

Certification8 min read

How to prepare for Cyber Essentials certification

From understanding the five control areas to fixing gaps and submitting your assessment — a complete preparation guide.

Data protection10 min read

How to collect GDPR evidence

What evidence the ICO actually looks for, how to build your ROPA, document lawful basis, and manage consent records.

Supply chain8 min read

How to assess vendor risk

Identifying critical suppliers, tiering by risk, sending security questionnaires, and maintaining an ongoing vendor risk register.

Planning9 min read

How to build a cyber resilience roadmap

Baseline your posture, prioritise your gaps, build a 30/60/90 day plan, and set up a quarterly review cycle.

Getting started10 min read

How to manage compliance without an IT team

Practical steps for business owners and operations leads who need to handle compliance without technical expertise or internal IT support.

Certification15 min read

How to prepare for ISO 27001 certification

From gap assessment and ISMS scope to risk treatment, mandatory documentation, and passing your Stage 1 and Stage 2 certification audits.

Data protection12 min read

How to conduct a DPIA

When a Data Protection Impact Assessment is mandatory, how to assess risks to individuals, document your outcome, and when to consult the ICO.

Insurance12 min read

How to prepare for cyber insurance

What insurers actually assess, how to document your controls before applying, and how to compare policies beyond the headline premium.

Planning10 min read

How to build a disaster recovery plan

What to prioritise, how to set a recovery time objective that means something, and how to test a plan before a real incident does it for you.

Certification9 min read

How to prepare a DSPT submission

How the NHS Data Security and Protection Toolkit is actually structured, the two standards that cause the most last-minute scrambles, and how to make next year easier.

Planning11 min read

How to build a business continuity plan

How to run a business impact analysis, set recovery objectives, write real continuity procedures, and test them — the whole business, not just backups.

Ready to put it into practice?

The free Digital Resilience Assessment gives you a baseline score and a prioritised action plan — in 10 minutes, no account required.