How to Conduct a Cybersecurity Risk Assessment: A Practical Guide
A five-step framework for identifying assets, mapping threats, scoring risks, and building a prioritised treatment plan. Includes regulatory mapping for NIS2, ISO 27001, and UK GDPR.
Endpoint Security Guide: EDR, Patching, and Device Hardening for UK Businesses
How to move from antivirus to EDR, automate patch deployment within the Cyber Essentials 14-day window, enforce BitLocker encryption, and manage devices with Microsoft Intune.
Email Security Guide: SPF, DKIM, DMARC and BEC Controls for UK Businesses
How to configure SPF, DKIM, and DMARC, secure mailboxes with MFA, deploy Microsoft Defender for Office 365, and build process controls that block business email compromise.
How to Write an Incident Response Plan: A Practical Guide for UK Businesses
The six NIST phases, playbooks for ransomware, BEC, data breaches, and account compromise, GDPR and NIS2 notification obligations, and how to test the plan with tabletop exercises.
Ransomware: What to Do Before, During and After an Attack
Ransomware appeared in 88% of SMB breaches. Covers what it does, key defences, what to do in the first 48 hours, and how to recover without paying.
AI Governance for UK Organisations: A Practical Framework
How to govern AI use in your organisation: map what you are using, classify by risk, write an AI policy, meet UK GDPR obligations, and assess EU AI Act applicability.
AI Implementation for UK Businesses: A Practical Framework
How to implement AI in your business: define the objective, prioritise use cases, assess data readiness, select technology, pilot, test, and measure the business result.