$
grep -l "category: policy" articles/*.txt
Policy.
Policy 15 articles
2026·09·10
What shipped, and when did you know: the Cyber Resilience Act's clock starts tomorrow From 11 September 2026, anyone selling software or connected hardware into the EU has 24 hours from the moment they know a flaw is being exploited to tell a national CSIRT. What that means, what it does not yet mean, and why it reaches British firms that never signed up to it.
22 min
2026·09·08
No personal liability, no change: the Cyber Security and Resilience Bill misses the one lever that works Peers asked why the Cyber Security and Resilience Bill lets executives off the personal liability hook. The Government said corporate fines are enough. Thirty years of watching boards tells me they are not, and here is why.
9 min
2026·07·17
Cyber security for the non-executive director: the NED's real job Cyber is now a tier-one board risk, but most non-executive directors were never trained for it. What the cyber security NED role actually demands — the questions to ask, the frameworks that matter, and how to hold a board to account without being technical.
10 min
2026·05·22
The regulator pivot Four documents in May, from four different parts of the UK regulatory apparatus, tell one story. ICO five-step guide. BoE/FCA/HMT joint statement. Cabinet Office letter. South Staffordshire Water fine. The polite phase is over.
6 min
2026·05·14
Things I wish boards would actually ask Twelve questions that would tell you more than any maturity score. None of them mention zero-trust.
7 min
2026·05·04
The £320 myth: what Cyber Essentials actually costs Cyber Essentials is marketed from £320. For an unprepared 10-person UK business under the new v3.3 Danzell question set, the true first-year cost is £13,000 to £30,000 over 10 to 14 weeks. Here is the breakdown.
9 min
2026·02·14
The Cyber Security and Resilience Bill, a board read What the Bill actually does, what it changes for boards in and out of scope, and what the executive should be preparing to evidence over the next twelve months.
8 min
2026·01·20
The CSR Bill and AI in cyber: what the regulator now expects Post 18 of the AI series. The Cyber Security and Resilience Bill is moving toward commencement. What it changes for AI in cyber security specifically, what the secondary legislation drafting suggests, and what vendors and customers should be preparing.
7 min
2025·09·27
The line the ICO is now drawing Capita £14m. Advanced Computer Software £3.07m. Neither fine was for the breach. Both were for the controls that preceded it. The ICO has redrawn what "adequate security" means in evidence — and most boards have not noticed.
6 min
2025·07·08
The thing an accreditation cannot do I have sat on the CREST European Council since 2022. This is what the work has taught me about what accreditation can and cannot do, and why I think the next chapter is harder than the last.
6 min
2024·12·10
The law, the insurance, the incident plan, and the culture that holds it all together Year-end consolidation. Your UK GDPR obligations, cyber insurance, the one-page incident response plan you need, and how to build a security culture that lasts beyond this series.
9 min
2024·02·20
Board portals and document handling Part 12 of 18. Diligent, BoardEffect, Nasdaq Boards, the email-attachment habit, and the moments in board-paper handling when sensitive material is most likely to leak. The practical posture for non-executive directors.
7 min
2023·11·30
The CISO in the dock The SEC's charges against Tim Brown over the SolarWinds disclosures, alongside Joe Sullivan's conviction over Uber a year ago, signal a regime change in personal accountability for security leaders. What it means for UK CISOs and the boards that employ them.
7 min
2023·10·17
The board director's public exposure Part 10 of 18. Companies House, LinkedIn, conference speaker lists, the corporate website. The footprint your board role creates whether you want it or not, and the small set of choices that determine how much it reveals.
7 min
2023·02·07
Digital privacy for board directors: the eighteen-post version An honest start to a long series. What digital privacy actually means for a board director in 2023, why the home / travel / work boundary is the right framing even though it leaks, and why children deserve four of the eighteen posts.
6 min