
Know a small business winging it on security?
No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
The ICO has decided not to open a formal probe after reviewing the MoD’s handling of the 2021 leak that exposed thousands of Afghan allies. But with people still at risk and fixes only partly implemented, can that judgement reassure those whose lives were put in danger?

Did the ICO get it right? Its decision not to formally investigate the MoD breach that humanitarians warn may have put Afghans who helped UK forces at risk has ignited a heated debate about accountability, safety and public oversight.

Cyber risk management is no longer just an IT problem—its a legal one. Embed legal strategy into governance, contracting and incident playbooks to prevent fines, lawsuits and vendor fallout before they strike.

When a misconfigured cloud bucket or a single line of code can become a courtroom exhibit, cyber incidents stop being just IT problems and become legal, regulatory and contractual risks that keep boards and general counsel awake. Treat cybersecurity as corporate governance: shore up vendor contracts, document AI use, and preserve evidence before the litigation starts.

Carter Farmer is shifting the EPA from counting inputs to measuring lives improved, using data and modern IT to tie technology spending to cleaner air, faster permitting, and stronger public accountability.

The Dutch data watchdog fined Experian €2.7m for collecting and keeping more personal data than necessary, a sharp reminder that GDPR’s data‑minimisation rules aren’t optional. The ruling signals that data brokers and businesses must justify every data point they hold — or face stricter enforcement that could reshape product design, retention policies and privacy controls.

When the company you trust with your data leaves the front door ajar, millions can pay the price — Capita was fined £14m after a 2023 breach exposed 6.6 million records, a sharp reminder that outsourcing data demands airtight security and clear accountability.

An Austrian regulator has ruled Microsoft 365 Education illegally tracked pupils, a landmark GDPR decision that could force cloud giants to adopt privacy-by-default settings and clarify who’s truly responsible for protecting kids’ data. Parents and schools deserve tools that safeguard students without breaking classroom tech.

No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
After a big court win, the ICO can now press ahead with a proposed £7.5m fine against Clearview AI — a landmark ruling that reinforces the UK’s power to hold foreign tech firms to account for using Britons’ facial data without consent.

Agencies sit on mountains of untapped data that could transform services and power trustworthy AI — but only if leaders invest in clear governance, modern infrastructure, skilled teams, and privacy-first practices to turn messy records into actionable insight.

Imgur has blocked UK access after the ICO threatened fines over age‑verification failures, leaving memers and creators locked out and sparking a bigger clash between child‑safety rules and open platforms. The abrupt exit forces users to scramble for alternatives while regulators and companies argue over who should shoulder the cost of a safer internet.

Imgur’s sudden decision to block UK users after an ICO regulatory notice raises a stark question: can tech platforms really sidestep data-protection rules by simply cutting off access? The ICO says no — and this standoff could cost users services, reshape where creators host content, and test whether regulators can hold global platforms accountable.

Fed up with nonstop spam calls? The ICO has slapped two UK-linked firms with a combined £550,000 fine after offshore call centres blasted prerecorded marketing to people who never gave consent — a reminder that nuisance calls aren’t just annoying, they’re illegal, and stronger tech and enforcement are needed to protect our privacy.

Oracle will host U.S. TikTok data on American servers — a move pitched as a security-first fix to ease fears about Chinese access, but skeptics worry it could be more paper shield than real protection. The deal’s success will hinge on strong cryptographic controls, independent audits and transparent oversight, not just where the servers sit.

Upgrading hardware? Improperly decommissioned SSDs and laptops can leave recoverable data that leads to fines, lawsuits and reputational damage—follow media-specific sanitization, certified destruction and auditable disposal practices to avoid costly penalties.

The U.K.’s ICO warns that sharing photos of suspected shoplifters can breach GDPR and unfairly tarnish people before guilt is proven. Retailers need to balance crime prevention with privacy rights and legal risk.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Think twice before sharing photos of suspected shoplifters: the ICO warns that public shaming—whether in-store or on social media—can breach GDPR and bring serious legal and reputational risks. As retailers hunt for deterrents, this reminder puts privacy, fairness and safer policing at the heart of the debate.

In today’s data-driven world, protecting your organization’s valuable information is more crucial than ever—especially with data breaches costing businesses millions. Discover the essential steps to safeguard your data and maintain customer trust while harnessing its transformative power!

As AI becomes a part of our everyday tech, the question of data control is more crucial than ever! WeTransfers recent ToS changes sparked a wave of user concern, highlighting the ongoing struggle between innovation and privacy—reminding us all just how important it is to stay informed about how our data is being used.

In a world where data is king, a striking 64% of business leaders are deeply worried about data sovereignty, highlighting the clash between rapid technological advancement and the need for secure, compliant practices. As they race towards innovation, many find themselves stuck in a cycle of caution, navigating an increasingly complex landscape of regulations.

When invisible sensors, apps, and algorithms start measuring what we buy, use, and trust, old rules for accuracy struggle to keep up — and consumers can lose out. Discover practical, tech-savvy solutions that balance transparency, security, and innovation so digital measurements remain fair, verifiable, and dependable.

Data sovereignty isn’t just policy jargon—it’s a real, high-stakes challenge that can make or break competitiveness, compliance, and customer trust as regulations and geopolitics shift. The smart play: embrace strategic localization, interoperable standards, and privacy-enhancing tech to protect data, reduce risk, and keep innovation moving.

As sensors, algorithms and cloud services replace needles and balances, legal metrology must modernize to keep commerce fair and consumers safe—this practical guide lays out the digital standards, tools and steps regulators, developers and businesses need for transparent, auditable measurements. Learn how to balance innovation with enforceable rules—from cryptographic attestation and continuous conformity to clear consumer verification—so technology builds trust, not confusion.

TikTok is back under the EU microscope, as regulators dive deep into whether your data is being stored in China—raising big questions about privacy, trust, and who really holds the keys to your information.