7 posts found
3 August 2026 · By P LarnerBlog post
A practitioner's refresher on GDPR and UK GDPR, the principles, lawful bases, breach duties and fines, and where UK divergence is heading.
Regulation & Legislation#accountability#UK GDPR#GDPR#ICO#data protection#breach notification
Read more →2 August 2026 · By P LarnerBlog post
What Secure by Design actually asks of delivery teams, how continuous assurance replaces accreditation, and the failure mode to avoid.
Regulation & Legislation#accreditation#continuous assurance#MOD#Secure by Design#SbD#delivery teams
Read more →2 August 2026 · By P LarnerBlog post
What UK Secure by Design is, who it applies to across government and the MOD, how continuous assurance works, and what suppliers must do.
Regulation & Legislation#GovAssure#accreditation#suppliers#government#Secure by Design#SbD
Read more →31 July 2026 · By P LarnerBlog post
What DORA requires of financial firms and their ICT suppliers, the five pillars explained, and how UK organisations end up in scope.
Regulation & Legislation#EU regulation#financial services#operational resilience#third-party risk#DORA
Read more →30 July 2026 · By P LarnerBlog post
What NIS2 is, who the essential and important entity tiers catch, what boards must now own, and where UK organisations stand.
Regulation & Legislation#EU regulation#NIS2#managed service providers#critical infrastructure#board accountability
Read more →25 July 2026 · By P LarnerBlog post
The UK's NIS overhaul as it stands: MSPs and data centres in scope, 24 and 72 hour reporting clocks, turnover-linked fines, and what to do before Royal Assent.
Regulation & Legislation#Cyber Security and Resilience Bill#NIS Regulations#CAF#MSPs#NCSC#incident reporting
Read more →25 July 2026 · By P LarnerBlog post
The 24 hour, 72 hour and one month NIS2 deadlines, what each report must contain, and why the templates need writing before the incident starts.
Regulation & Legislation#NIS2#early warning#GDPR#incident reporting#CSIRT#DORA
Read more →