Securious Data Protection

Our knowledge and experience will help keep you fully compliant with the Data Protection Act, particularly Principle 7.  Did you know the ICO could fine you £500,000 for a serious data security breach?  And that’s before you consider the cost to your reputation and customer relationships.

Our professional and flexible service will help keep you and your data safe by designing your ideal compliance solution, typically this includes:

  • A statement of information security policy
  • Controlling physical security
  • Controls on access to information (including monitoring and logging)
  • A business continuity plan
  • Training staff on security systems and procedures
  • Detecting and investigating breaches of security when they occur

Physical Security

Network protection starts with the physical security of your equipment.  We help organisations design and implement effective security measures.

Remember, an experienced hacker with physical access to a computer on your network can access, steal or damage data in minutes.   READ MORE

Technical Security

Securious will help you implement effective security policies and processes.  Success to us means you remain compliant, without compromising your team’s ability to carry out their work or burdening yourself with unnecessary costs.

Endpoint Security

The potential for damage is greatest where data resides.   Securious designs solutions which meet corporate security, manageability, and flexibility requirements – comprehensive protection without disproportionate complexity or cost.

Endpoint security products include distributed personal firewalls to protect against network-borne threats, antivirus scanners for detection of file-based threats, and audit or integrity products for detection of malicious configuration activity.

Data Encryption

Securious offers expertise and advice on the latest data encryption standards, software and policies.  We design and implement robust, fully-compliant solutions based on the way that you need to store, access and use personal data.

Secure Disposal

We help organisations choose fully-compliant partners and develop appropriate policies for secure disposal of data.  These must comply with the Environmental Protection Act and the Data Protection Act.  We will help you meet your legal duty to maintain compliance with the WEEE Directive and the ISO 9001, 14001 and 27001 standards.

Security Breaches

Securious will help you implement appropriate data security measures to minimise the risks of a security breach.  We will also ensure your disaster recovery plan lets you restore data quickly in the event of an incident.
A security breach may arise from:-

  • Accidental loss or theft of equipment (see Encryption)
  • A deliberate attack on your systems (see Network Security)
  • Unauthorised use of personal data by a member of staff (see Network Security)
  • Equipment failure (see Business Continuity Planning)

Your Data Controller must have a policy for responding to a security breach where personal data is lost or stolen.  We can design a policy for you, or advise whether your existing one is compliant and effective.

Business Continuity Planning

Have you thought about how quickly you could recover and use critical data if disaster struck?  How much would each day of interruption cost you?  What are the legal implications of losing commercial or personal data?   Securious will help you put an appropriate continuity plan in place, minimising your financial and legal exposure.  READ MORE

GET IN TOUCH to see how Securious can help protect you and your data.

Data Protection Act 1998
Organisations that process personal data, which includes its use, disclosure, retention or destruction must comply with the 8 Data Protection Principles.  The information Commissioner’s office (ICO) has a very useful guide www.ico.gov.uk
An organisation must design and organise their security to prevent personal data they hold from being accidentally lost or compromised.  This should fit the nature of that data and the harm that may result from a security breach.

Notification is a statutory requirement and every organisation that processes personal information must notify the Information Commissioner’s Office (ICO), unless they are exempt. Failure to notify is a criminal offence.

When notifying the ICO the data controller (person in your organisation responsible for ensuring information security) must give a general description of the measures to be taken for the purpose of protecting against unauthorised or unlawful processing of personal information, and against accidental loss or destruction of, or damage to, personal information.