Cyber Security Insights March 2025

Cyber Security Insights March 2025

Written by Bryan Altimas

A very busy month at RCC towers! We have had 2 data privacy issues of cyber security insights looking at the UK government's attempts under the Investigatory Powers Act 2016 to force Apple to develop a backdoor into iCloud storage encryption. Apple appealed to the Investigatory Powers Tribunal which is held in secret and is presumably ongoing.

In this edition we look at:

  • What makes a good cyber security strategy
  • The Data Use and Access Bill is a significant update to the UK GDPR. We look at what the changes and impact may be.

Two relatively long articles so grab a delicious coffee and make yourselves comfortable.

What Makes a Good Cyber Security Strategy

When we develop a cyber security strategy we are not doing it in a silo. The company's objectives and strategy must be considered as well as the external environment.

The internal and external inputs create a strong foundation for the strategy. The strategic inputs in a cyber security strategy are:

  • global industry reports and research - understand emerging threats, identify trends and innovative solutions that can inform the strategy from reputable cyber security company reports, white papers and research.
  • past risk assessments, audit reports, penetration tests and vulnerability management data from the last 18 months provide insights into the organisations current security posture highlighting areas of strength and vulnerabilities requiring attention.
  • cyber insurance and assurance requirements; understanding and adhering to the policy requirements assists in identifying potential risks.
  • business strategy and cyber security strategy must be aligned making sure that cyber security and data protection initiatives support and enable operational objectives.
  • regulatory and compliance requirements are a massive input to a cyber security strategy. Compliance GDPR, PCIDSS, ISO27001, NIST Cyber Security Framework etc helps maintain trust with the supply chain and customers.

What we call the threat landscape is continuously evolving with emerging cyber security risks such as AI (probably a maturing risk and evolving at the same time), quantum computing and the internet of things (IOT meaning internet connected home devices such as white goods) whilst at the same time providing opportunities. To mitigate the evolving threat landscape a robust cyber security strategy is required which will have 7 fundamental foundations.

Secure by Design

Involving cyber security during the design phase identifies vulnerabilities and mitigations early on and saves money. Retro-fitting cyber security and data protection controls is very expensive.

Secure by design builds resilient systems that safeguard critical assets and generates stakeholder trust.

Prioritise the Basic Cyber Security Controls

Implementing and successfully operating the basic cyber security controls are non-negotiable. The basic controls are:

  • An inventory of critical assets including interactions between the assets.
  • Strong access credentials managed by a password manager and transitioning to passkeys
  • Enforcing MFA (multi factor authentication)
  • Patch management is ensuring the monthly (and emergency updates) from Microsoft, Apple, Google and other tech companies are implemented after a risk assessment.
  • Extended and endpoint detection and response software on networks and devices (antimalware).
  • For larger and growing companies a Security Information and Event Management (SIEM), Managed Detection and Response (MDR), Security Orchestration Automation and Response (SOAR) and threat intelligence.
  • Back up your data to a third party cloud backup provider.

Inform and Educate Your Team

A properly educated and informed team are, simply, your strongest asset.

Prepare for the Incident

A breach is inevitable and organisation must prepare for rapid incident detection, containment and recovery. A well-documented but agile incident response plan minimises disruption and enhances resilience.

Proactively Manage Stakeholders

Engaging with stakeholders ensures alignment between cybersecurity and business strategy. Clear communication fosters trust and secures buy-in for strategic initiatives.

Secure the Supply Chain

Third-party vendors often introduce vulnerabilities. Organisations should assess vendor security postures, enforce contractual safeguards and implement continuous monitoring to mitigate supply chain risks.

Implement Continuous Independent Assurance

Regular independent assessments of security controls validate their effectiveness. This ongoing process strengthens the organization’s risk posture and ensures compliance with industry standards.

If you have been promoted to consider your cyber security strategy contact us on LinkedIn messenger or by email at info@riversidecourtconsulting.co.uk with the message strategy.

Data Use and Access Bill

The Data Use and Access Bill (DUAB) proposes significant changes to the UK's data privacy framework and introduces potential risks to our ability to freely transfer data to the EU and wider EEA, the US and other countries that have an adequacy agreement with the UK over their data privacy frameworks. We feel your pain as you think back to the implementation of GDPR.

AI and Automated Decision Making

Perhaps the most controversial aspect of DUAB is its approach to automated decision-making and AI-driven data processing. Unlike GDPR, which imposes strict limitations on automated decision-making affecting individuals, DUAB allows broader use of AI and other automated processes for most personal data, with the exception of special category data such as health or biometric information.

This shift could enable businesses to implement AI-driven profiling and employment screening but will require safeguards to allow individuals to challenge or appeal decisions made solely by automated systems.

While special category data remains subject to stricter rules, the bill signals a more relaxed regulatory approach to AI compared to the European Union.

Recognised Legitimate Interests

One of the core elements of DUAB is the addition of a lawful basis for processing personal data. Recognised legitimate interests means that public bodies will be able to request data from private companies to support their work, with limited rights for individuals to object to this data sharing.

Neurodata

A notable new addition in the legislation is the recognition of neurodata as a special category of sensitive data.

Neurodata refers to information generated from devices or technologies that interact with the human brain or nervous system, such as smartwatches and neural interfaces.

Given the highly personal nature of this data, the ICO has taken a proactive stance in ensuring heightened protections and ethical considerations when processing neurodata.

Subject Access Requests

Clarification is provided the handling of data subject access requests (SAR) by introducing timelines and defining reasonable and proportionate searches for requested data. Organisations will have the ability to stop repeated clarification requests on provided data to the individual.

The clarification aims to reduce the administrative burden on organisations responding to a SAR.

Another significant revision concerns the exemption for ‘disproportionate effort or impossibility’ in providing information to individuals whose data was not directly collected from them. For instance, historical records used for research purposes may not require direct notification if informing each data subject would be unreasonably difficult or impossible.

Complaints

Procedural changes are aimed at resolving data-related complaints more efficiently. Individuals will now need to file complaints directly with the organisations data controller before escalating them to the Information Commissioner’s Office (ICO). This approach is designed to streamline resolutions at the company level and reduce the regulatory workload on the ICO.

Marketing and Consent

DUAB relaxes restrictions by allowing third parties to contact individuals using an opt-out approach, rather than requiring explicit consent.

This change will likely benefit businesses engaged in direct marketing, but organisations must still conduct a balancing test to ensure that their interests do not override individuals’ rights.

Data subjects will retain the right to object to such processing, ensuring some level of control over their personal information.

Data Processing Beyond the Original Purpose

One of the most impactful changes for businesses relates to data processing beyond its original purpose. DUAB permits further processing if it aligns with the initial reason for data collection, with the government determining what qualifies as “compatible” processing.

Additionally, the bill upholds the lawful basis for US law enforcement agencies to access UK telecommunications data in serious crime investigations. This measure ensures that businesses remain compliant when handling cross-border law enforcement requests.

e-Privacy Regulations

Modernising rules that originated from the Privacy and Electronic Communications (PECR) Regulations 2003. A key update involves the regulation of data collected automatically from user devices, including IP addresses and device identifiers. The revised rules extend to remote data collection techniques such as server-side tracking, aiming to close loopholes that previously allowed tracking without user knowledge or consent.

Further ePrivacy changes introduce new exemptions for certain cookies and tracking technologies. In some cases, explicit user consent will no longer be required, provided that individuals receive clear information and retain the right to object. This includes analytics cookies used for website performance measurement, preference cookies that store user settings, and security-related cookies that detect fraud or enhance network security. In many cases the cookie pop-up requesting consent will not be required.

The government will have the authority to modify cookie consent exemptions in the future, allowing for regulatory flexibility in response to technological advancements and emerging privacy concerns.

Enforcement Measures

DUAB significantly strengthens enforcement measures, particularly in direct marketing and cookie-related breaches. While previous fines were capped at £500,000, under the new framework, violations could incur penalties equivalent to those under UK GDPR—up to £17.5 million or 4% of a company’s total worldwide turnover. This increased penalty structure serves as a strong deterrent against unlawful tracking and intrusive marketing practices.

Smart Data Schemes

The bill also promotes Smart Data schemes, aiming to facilitate controlled and regulated data exchanges between businesses.

Similar to the UK’s Open Banking initiative, Smart Data schemes could drive innovation and competition across industries such as energy and telecommunications. By establishing open standards and interoperability, businesses could enhance customer experiences, improve service customisation, and increase efficiency in switching providers.

Organisations operating in sectors that may adopt Smart Data schemes should consider how this shift could impact their business models and customer relationships.

Risks of Changing our Data Privacy Framework

There are potential risks to our adequacy agreement with the EU and the UK extension to the EU-US data privacy framework as well as adequacy agreements we have with other countries.

Certainly the EU will review the changes to satisfy themselves that there are no weaknesses compared to the EU GDPR and our current UK GDPR.

Preparing for the DUAB

  • Evaluate AI and automated decision making processes
  • Review data processing practices, processes and policies for the new recognised legitimate interests legal basis for processing personal data.
  • Strengthen data security measures for neurodata.
  • Update processes for the the new SAR regulations.
  • Implement internal complaint resolution processes.
  • Review marketing and consent management processes so that customers can opt-out of direct marketing.
  • Businesses should update their website cookie policies, ensure transparency in data collection.
  • Prepare for stricter enforcement measures as the PECR fines are brought in line with GDPR fines increasing from £500 to a maximum of £17.5 million or 4% of global turnover.

Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right