Notes from the work

Write-ups on pattern-finding, tooling, and what 20+ years of independent IT security practice actually looks like day to day.

September 2026

The channel SYSC 10A didn't anticipate is the one everyone already has

Call recording was built for phones. The conversations that actually slip the record now increasingly happen somewhere else — on a device the firm never provisioned for the job.

August 2026

What happens when a SYSC 10A recording doesn't happen

Capture almost always works — until the one time it doesn't. Notes on treating a recording gap as an event to detect and document, rather than a fact to discover under pressure.

August 2026

Photos, safeguarding, and what a club is actually allowed to publish

Match-day photos and a public website are ordinary parts of running a club — until a child is in the picture and nobody decided what the rule actually is.

July 2026

What happens when a SYSC 10A retention period actually ends

Retention gets the engineering attention. Disposal at the end of the clock — and proving it happened on schedule — usually doesn't. Notes on the other half of the records lifecycle.

June 2026

What actually happens when an examiner asks for the records

SYSC 10A compliance and SYSC 10A audit-readiness aren't the same thing. Notes on what a live records request actually asks of a firm, and why most gaps only surface then.

June 2026

What happens when a member asks what data your club holds on them

A subject access request doesn't pause for a busy committee. Notes on what a volunteer-run club actually has to do, and by when.

May 2026

SYSC 10A call recording, explained simply

A plain-language walkthrough of what the recording and monitoring obligation actually requires — and where firms most often get caught out.

April 2026

Building AI-assisted tools without losing professional judgement

Where AI genuinely reduces manual review overhead in dense, regulated workflows — and where it just moves the risk somewhere less visible.

April 2026

The real exposure isn't the fine — it's not knowing what you hold

For most small organisations, the practical risk isn't a headline fine — it's not being able to say what personal data is held, or why.

March 2026

What a longitudinal view of messages can (and can't) tell you

Looking at a relationship's communication history as a shape over time, not a single message — and where that view is useful versus misleading.

February 2026

Why log noise hides the signal you actually need

Most firewall and network logs aren't short on data — they're short on a way to see what matters in it. Some notes on what actually helps.

February 2026

Why "we're too small for GDPR to apply" is the wrong starting point

The size test that actually exists in UK GDPR is narrower — and different — than the one most small organisations assume applies to them.

January 2026

Jack of all trades, one deep specialism

What 20+ years of independent IT work actually looks like when you're not chasing a single career ladder — and why the breadth turned out to matter.