Processing...

 Security and Data Protection Compliance

Find out what applies to you, close the gaps and evidence it

Every UK organisation carries security and data protection obligations, and very few know exactly which ones. Some are law, some are written into contracts and tenders, and some are schemes a customer or insurer has asked for. We work out which of them actually apply to you, close the gaps in your systems and your processes, and help you build the evidence that shows it.

We have worked under GDPR since it took effect in 2018, as a data processor ourselves, and the engineers who assess your systems are the engineers who patch, secure and investigate them. Compliance here is the practical work of running systems properly and being able to prove it.

  • "The tender asks for Cyber Essentials"
  • "A customer has sent us a security questionnaire"
  • "We have had a subject access request"
  • "We think someone is in our email"
2018Working under GDPR since it took effect, as a processor ourselves
72 hoursTo notify the ICO of a reportable breach, and our reports support it
Self-serveSubject access software that integrates with your systems
UKIn-house engineers, no offshore outsourcing

What Actually Applies to You

The first job is to separate what binds you from what does not. Most organisations are subject to UK GDPR and PECR and little else by law, while others sit under sector rules they may not know about. Selling into the EU brings its own set. The table below is where we start, and we go through it with you against what you actually do.

LawApplies toWhat it asks of you
UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025 Any organisation processing personal data in the UK, as controller or processor A lawful basis for each use of personal data, security appropriate to the risk, records of processing, answers to people exercising their rights, and reporting of qualifying breaches to the ICO within 72 hours
The Privacy and Electronic Communications Regulations 2003 (PECR) Anyone sending electronic marketing, or using cookies and similar technologies on a website or app Consent before most marketing emails, texts and non-essential cookies, and a working way to opt out
The Network and Information Systems Regulations 2018 Operators of essential services in energy, transport, health, drinking water and digital infrastructure, and relevant digital service providers: online marketplaces, online search engines and cloud computing services Appropriate and proportionate security measures, and incident reporting to the regulator for your sector
The Freedom of Information Act 2000 Public authorities, and the suppliers who hold information on their behalf Answers to requests for information within 20 working days, which reaches suppliers through their contracts
The Online Safety Act 2023 Only services that host content shared by their users, or that provide search Risk assessments for illegal content and, where children may use the service, for their safety, overseen by Ofcom
EU GDPR UK organisations offering goods or services to, or monitoring, people in the EU Much the same as UK GDPR, sometimes with an EU representative and dealings with an EU supervisory authority
NIS2 Organisations in the listed sectors providing services within the EU, and their suppliers through contract terms Risk management measures, supply chain security and staged incident reporting, the first within 24 hours
The Cyber Resilience Act Manufacturers, importers and distributors of hardware and software products placed on the EU market In force since December 2024. Reporting of actively exploited vulnerabilities and severe incidents has applied since September 2026, and the main security and vulnerability handling obligations apply from December 2027

Frameworks and Schemes

Beyond the law sit the standards that customers, regulators and insurers ask for. None of them is a box to tick once. Each is a set of controls that has to be true of your systems every day, and the value is in making it true rather than in the certificate.

Cyber Essentials and Cyber Essentials Plus

The UK government backed baseline: firewalls, secure configuration, security update management, user access control and malware protection. Plus adds an independent technical audit. Required for some central government contracts and asked for by many supply chains.

ISO/IEC 27001:2022

The international standard for an information security management system. It asks you to identify your risks, choose controls to treat them and prove the system works, and it is certified by an accredited body.

NCSC Cyber Assessment Framework

Outcome based objectives and principles for organisations running important services, used by NIS regulators and increasingly across the public sector and its suppliers.

PCI DSS v4.0

For anyone who stores, processes or transmits payment card data. The cheapest compliance is usually a smaller scope, and we look at how card data moves before we look at anything else.

NHS Data Security and Protection Toolkit

The annual self-assessment required of NHS suppliers and anyone else with access to NHS patient data and systems, now being brought into line with the Cyber Assessment Framework.

FCA Operational Resilience

For regulated firms in scope: identify important business services, set impact tolerances, and show you can stay within them, including when an IT supplier fails.

For customers with US parents or US customers, we can also map the same controls to the NIST Cybersecurity Framework or SOC 2, so one set of work answers both.

Process Compliance

Most data protection failures are failures of process, not technology: data kept because nobody decided when to delete it, a supplier with no contract, a request for data that nobody knew how to answer. The legislation is not easy reading, and it helps to have worked with it long enough to know what it means in practice. Our consultants find where you fall short and put in place what is missing, sized to the organisation you are rather than a template written for a bank.

Our own Data Retention Policy and Data Processing Policy and Schedule are public, and show the level of detail we work to ourselves. For cloud hosting in particular, see our blog post about GDPR and cloud hosting.

Subject access is where most organisations feel the pressure. We have self-serve subject access software that integrates with your existing systems and processes, so people can see, update or ask for the removal of their data without your staff searching by hand each time.

What we put in place

  • Records of processing: what you hold, why, where and for how long
  • Lawful basis: decided and recorded for each purpose, with legitimate interests assessments where needed
  • DPIAs: for new or high risk processing, before it starts
  • Retention schedules: a period for every category, and deletion that actually happens
  • Subject access: a process and the software to answer within the month
  • Supplier and processor contracts: the terms UK GDPR requires, and a record of who holds what

Technical Controls

If you hold personal data you must take appropriate steps to protect it, and every framework above comes down to the same handful of controls. We do not just recommend them: we run them, on your systems or ours.

Patch Management and CVEs

Known vulnerabilities with published fixes are one of the commonest ways in. We keep an inventory of the CVEs relevant to the software you actually run, available for your review, prioritise them by severity and exposure, and patch with the least disruption we can manage.

Perimeter and Segmentation

Firewalls configured for what the business needs, remote access through a managed VPN, and networks divided so one compromised device does not reach everything. Part of our IT outsourcing.

Email Protection

Email is the commonest route to a breach. EmailProtect checks links, attachments and sender behaviour before a message reaches anybody's inbox.

Account Takeover

A stolen password is only useful if it works from wherever the attacker is. Takeover is detected on the provider side, through geofencing, impossible travel, unfamiliar networks and analysis of sending and behavioural patterns, without relying on anyone noticing.

Encryption and Access

Personal data encrypted where it is stored and while it moves, and access limited to the people whose job needs it, managed through your directory rather than scattered local accounts.

Backups and Recovery

UK GDPR counts the ability to restore access to personal data after an incident among the security measures it expects. That means backups held apart from the systems they protect, and restores tested, because a backup that has never been restored is an assumption.

People

It is an uncomfortable truth that your staff are the most likely way into your systems, and email is the most common route. Everybody knows not to open an unexpected attachment, and people still do, because a well made lure arrives at a busy moment and looks like something they were expecting.

Many organisations answer this with automated phishing tests, and they deliver little. Individually targeted simulations, which mirror the techniques professional attackers use and combine compromise, phishing and social engineering, are worth far more. They show your staff what a real attack on them would look like, and they tell you where your organisation is actually exposed.

We pair them with training built around what the simulations found, delivered remotely or on site.

Why generic tests fall short

  • Everyone receives the same simulation, so it teaches nobody much
  • They are often poorly made and easy to spot
  • They rarely reflect the risks your organisation actually faces
  • They interrupt the working day for little return
  • They frustrate staff rather than teach them

Audit and Assessment

There is no legal requirement in the UK to be audited for GDPR. You are required to be able to demonstrate compliance, though, and an audit of your processes is the plainest way to find out whether you can. Many organisations also find it worthwhile alongside other standards, such as ISO 9001, ISO/IEC 27001 or PCI DSS, where the same records and controls are examined.

We audit your processes and systems, and set out the weaknesses and improvements in writing, in order of risk. Where you are heading for Cyber Essentials or another scheme, we run a gap analysis against it first, close the gaps with you, and tell you when you are ready to be assessed. We do not issue certificates: that is for an accredited certification body.

What an assessment covers

  • Gap analysis against the law and the schemes that apply to you
  • Readiness for Cyber Essentials and Cyber Essentials Plus
  • Security analysis and penetration testing of your network and physical security
  • Review of policies, records and supplier contracts
  • An evidence pack you can hand to a customer, insurer or regulator

Breach Investigation

If you are reading this because you suspect your systems have already been compromised, call us first and change as little as you can: the evidence of what happened is on the affected systems, and rebuilding them destroys it.

Our forensic investigation establishes the scope of the compromise, how the attacker got in, what they reached and what they took, whether it began with phishing, malware, social engineering or an unpatched system. We assess the impact on data, finances and reputation, and close the route that was used.

Where personal data is involved, the ICO must be notified within 72 hours of you becoming aware of a reportable breach, and our findings are written to support that notification and any insurance claim.

The report sets out the scope, the cause, the data affected and the steps taken, in the form the ICO notification and your insurer will ask for, and then what needs to change so that the same route cannot be used again.

Compliance Questions

Do we need Cyber Essentials?

For most organisations it is not a legal requirement. It is required for some central government contracts, and it is increasingly asked for by larger customers in their supply chains and by insurers. Even where nobody asks for it, its five controls are a sensible baseline. GEN assess your readiness, close the gaps and prepare you for assessment; the certificate itself is issued by a certification body.

Are we required to be audited for GDPR?

No. There is no routine legal requirement in the UK to have your data protection compliance audited, although the ICO can carry out audits of its own. What the law does require is that you can demonstrate compliance, which means records, policies and decisions written down. An independent audit is a practical way to test that, and it is often worth doing alongside ISO 9001, ISO/IEC 27001 or PCI DSS work.

What changed with the Data (Use and Access) Act 2025?

The Act amends UK GDPR, the Data Protection Act 2018 and PECR rather than replacing them. The changes include how subject access requests are handled, recognised legitimate interests, the rules on automated decision-making, and fines under PECR brought into line with UK GDPR levels. Its provisions come into effect in stages, so what it means depends on what you do with personal data. GEN can review your processing and tell you which changes affect you and what, if anything, needs to change.

Do you certify us?

No. GEN prepare you, assess you against the standard and help you close the gaps, but certification to Cyber Essentials, ISO/IEC 27001 or any other scheme is issued by an accredited certification body. We do not hold or claim any certification on your behalf, and we will tell you plainly when we think you are not ready to be assessed.

We think we have been breached. What should we do first?

Call GEN, and do not wipe or rebuild anything yet, because the evidence of what happened is on the affected systems. Where a personal data breach is likely to result in a risk to individuals, the ICO must be told within 72 hours of you becoming aware of it, and the notification can be made in stages as the investigation progresses. Our investigation establishes the scope and cause and produces the report that the notification and any insurance claim will need.

Does the Cyber Resilience Act affect us?

Only if you make, import or distribute hardware or software products that are placed on the EU market. It has been in force since December 2024, the obligation to report actively exploited vulnerabilities and severe incidents has applied since September 2026, and the main obligations apply from December 2027. If you sell software or connected devices into the EU, now is the time to find out where you stand.

Can you help us with a subject access request?

Yes. A request normally has to be answered within one month, and the difficult part is usually finding every place the person's data is held. GEN can help with an individual request, and we have self-serve subject access software that integrates with your existing systems, so people can see, correct or ask for the removal of their data without a manual search each time.

Do you run phishing simulations?

Yes, but not the generic kind. Individually targeted simulations that mirror the techniques real attackers use against your organisation teach far more than the same automated email sent to every member of staff, and they cause less disruption and resentment along the way.

Find Out Where You Stand

Start with what applies to you. We look at what you do, what you hold and who you sell to, and tell you which obligations bind you, which ones your customers expect, and where the gaps are, before anything is spent on closing them.

The work is done by UK engineers, in-house, with no offshore outsourcing, drawing on more than three decades of running systems that other people depend on.

Contact Us