Wrongly sent emails ‘most common data breach’

Yet again we are reminded that sending an email to the wrong recipient is the most common form of data beach. The BBC tech report https://www.bbc.co.uk/news/articles/c363w8pjpklo concerns Guernsey, but this is a serious issue in the UK too. In its guidance on common data protection mistakes and how to fix them at https://ico.org.uk/for-organisations/advice-for-small-organisations/getting-started-with-gdpr/common-data-protection-mistakes-and-how-to-fix-them, the ICO […]

Continue reading


Cyber Essentials is changing from April 2026

Each year Cyber Essentials is updated to reflect changing cybersecurity trends and risks, and IASME has just announced the changes to take effect in April 2026. You can read them in their blog https://iasme.co.uk/articles/important-update-changes-to-cyber-essentials-for-april-2026/, but one item of note is that MFA will be mandatory for all cloud services from that date.

Continue reading


Next phase of DUAA has commenced but …

The Data (Use and Access) Bill was designed to have a phased implementation, and the next phase commenced last week on 5th February. You can read the ICO’s statement at https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/02/statement-on-the-commencement-of-the-data-use-and-access-act-duaa/ but for most charities, the key provision is the Charitable Soft Opt-In changes and the guidance from the ICO is still not ready. Claire […]

Continue reading