Category: Advent IM Blog
News and information from the Advent IM team.
Cyber security, data protection, privacy, governance and risk management were never meant to operate as separate worlds. The ICO’s evolving stance reflects a more realistic view of how organisations actually manage risk, protect data and build trust. There has been a noticeable shift in the ICO’s tone on cyber security, and it is a significant one. For years, many organisations have treated cyber […]
Read MoreThe Home Office’s consultation on a new legal framework for live facial recognition (LFR) and broader biometric technologies is more than another policy exercise, it is, as the Biometrics and Surveillance Camera Commissioner recently described it, a “once‑in‑a‑generation opportunity” to get this right. And getting it right means placing governance, ethics, and public trust at […]
Read MoreHaving spent decades championing security, privacy, and robust governance, I’ve seen the pattern play out enough times to recognise it instantly: innovation races ahead, controls lag behind, and society ends up dealing with the fallout. The recent revelations about Meta’s Ray-Ban smart glasses should worry anyone who values ethics and public trust and they should […]
Read MoreOne of the most famous stories from the early days of hacking did not involve sophisticated code, advanced persistence or organised cyber crime. It involved a plastic whistle found in boxes of Cap’n Crunch, an American breakfast cereal. In the early 1970s, phone phreaks discovered that the whistle could generate a 2600 Hz tone. At […]
Read MoreFor many of us, Christmas is a time spent with family, comfort and celebration — but for others, it can be one of the hardest days of the year. In December 2025, our CEO, Mike, chose to spend his Christmas supporting a remarkable organisation that makes sure no one in their community is left behind: […]
Read MoreWho really owns cyber incidents involving information — your IT team or your Information Governance team? 🤔 IT often gets treated as the default owner, but in reality, IT is essentially the filing cabinet: they store it, move it, and protect it — but they don’t own the information inside. That responsibility sits firmly with […]
Read MoreThe UK is moving towards a tougher stance on ransomware payments, particularly for the public sector and regulated critical national infrastructure. Policy proposals have included a targeted ban for those sectors, alongside measures that increase incident reporting and introduce a notify-to-pay approach for organisations outside the ban. This shift matters because it changes the shape […]
Read MoreThe UK Government has renewed its pledge to increase defence spending to 2.5% of GDP by 2027. The announcement, reinforced in recent speeches by Prime Minister Keir Starmer, has generated strong headlines and a sense of urgency across the sector. But beyond the political messaging, what has materially changed? In the latest episode of Risk […]
Read MoreThe Data (Use and Access) Act does more than introduce new legal obligations — it quietly raises the bar on organisational accountability. By making formal data protection complaints handling a regulatory requirement, the legislation shifts responsibility firmly back to organisations to resolve issues properly before they reach the regulator. This reflects a wider move in […]
Read MoreSchools have always had to think about site security: keeping pupils safe, keeping the premises secure, and keeping the day moving without turning reception into passport control. What’s changed is the threat landscape and the scrutiny. It’s no longer just “will CCTV deter vandalism?” It’s also “what happens when a camera system is offline?”, “who […]
Read More