Category: Advent IM Blog
News and information from the Advent IM team.
A King’s Speech can feel a long way from the day-to-day reality of security work. It sounds formal, ceremonial and not necessarily very connected to the messy business of risk registers, supplier meetings, training plans and incident exercises. This one is different. Not because every Bill will land exactly as described, or because legislation alone fixes security. It does not. But the […]
Read MoreIf recent AI research tells us anything, it is this: adoption is winning the race, and governance is still trying not to lose a shoe. McKinsey’s 2026 AI Trust Maturity Survey found that only about 30% of organisations had reached a stronger maturity level in strategy, governance and agentic AI controls. Nearly 60% said knowledge […]
Read MoreReturning this Easter following his Christmas volunteering, Mike once again joined the team at The Bread and Butter Thing, a UK organisation that makes life easier for people struggling to afford food. Much like Mike’s volunteering over Christmas, the work required vans to be loaded with bulk pallets and individual food bags before heading out […]
Read MoreThe old governance problem in a new and much riskier suit Most organisations have seen this pattern before. First it was shadow IT: unknown tools, services and workarounds adopted outside formal controls because they were quicker, easier or simply less irritating than the approved route. Then came BYOD, where convenience, flexibility and speed collided with […]
Read MoreCyber risk is no longer an abstract technical problem, it is a lived reality for organisations of all sizes. Recent surveys show that cyber attacks and breaches are not only common, but increasingly unavoidable. Yet despite rising threat levels, many organisations still lack the governance foundations needed to manage cyber risk effectively. The latest data […]
Read MorePost‑quantum cryptography (PQC) has rapidly moved from academic research to a topic of board‑level concern. Two recent articles capture the debate clearly. Computer Weekly’s “Shrinking PQC timeline highlights immediate risk to data security” argues that organisations must act now to mitigate growing cryptographic risk. In contrast, The Register’s “Cryptographers place $5,000 bet whether quantum will […]
Read MoreThe Data (Use and Access) Act 2025, which became law on 19 June 2025, introduces several meaningful shifts in how data is handled, accessed, and governed across the UK, and adult social care providers will feel its impact in practical and positive ways. One of the most significant changes is the new legal duty on […]
Read MoreCyber security, data protection, privacy, governance and risk management were never meant to operate as separate worlds. The ICO’s evolving stance reflects a more realistic view of how organisations actually manage risk, protect data and build trust. There has been a noticeable shift in the ICO’s tone on cyber security, and it is a significant one. For years, many organisations have treated cyber […]
Read MoreThe Home Office’s consultation on a new legal framework for live facial recognition (LFR) and broader biometric technologies is more than another policy exercise, it is, as the Biometrics and Surveillance Camera Commissioner recently described it, a “once‑in‑a‑generation opportunity” to get this right. And getting it right means placing governance, ethics, and public trust at […]
Read MoreHaving spent decades championing security, privacy, and robust governance, I’ve seen the pattern play out enough times to recognise it instantly: innovation races ahead, controls lag behind, and society ends up dealing with the fallout. The recent revelations about Meta’s Ray-Ban smart glasses should worry anyone who values ethics and public trust and they should […]
Read More