Blog
Notes from the work
Write-ups on pattern-finding, tooling, and what 20+ years of independent IT security practice actually looks like day to day.
September 2026
The channel SYSC 10A didn't anticipate is the one everyone already has
Call recording was built for phones. The conversations that actually slip the record now increasingly happen somewhere else — on a device the firm never provisioned for the job.
August 2026
What happens when a SYSC 10A recording doesn't happen
Capture almost always works — until the one time it doesn't. Notes on treating a recording gap as an event to detect and document, rather than a fact to discover under pressure.
August 2026
Photos, safeguarding, and what a club is actually allowed to publish
Match-day photos and a public website are ordinary parts of running a club — until a child is in the picture and nobody decided what the rule actually is.
July 2026
What happens when a SYSC 10A retention period actually ends
Retention gets the engineering attention. Disposal at the end of the clock — and proving it happened on schedule — usually doesn't. Notes on the other half of the records lifecycle.
June 2026
What actually happens when an examiner asks for the records
SYSC 10A compliance and SYSC 10A audit-readiness aren't the same thing. Notes on what a live records request actually asks of a firm, and why most gaps only surface then.
June 2026
What happens when a member asks what data your club holds on them
A subject access request doesn't pause for a busy committee. Notes on what a volunteer-run club actually has to do, and by when.
May 2026
SYSC 10A call recording, explained simply
A plain-language walkthrough of what the recording and monitoring obligation actually requires — and where firms most often get caught out.
April 2026
Building AI-assisted tools without losing professional judgement
Where AI genuinely reduces manual review overhead in dense, regulated workflows — and where it just moves the risk somewhere less visible.
April 2026
The real exposure isn't the fine — it's not knowing what you hold
For most small organisations, the practical risk isn't a headline fine — it's not being able to say what personal data is held, or why.
March 2026
What a longitudinal view of messages can (and can't) tell you
Looking at a relationship's communication history as a shape over time, not a single message — and where that view is useful versus misleading.
February 2026
Why log noise hides the signal you actually need
Most firewall and network logs aren't short on data — they're short on a way to see what matters in it. Some notes on what actually helps.
February 2026
Why "we're too small for GDPR to apply" is the wrong starting point
The size test that actually exists in UK GDPR is narrower — and different — than the one most small organisations assume applies to them.
January 2026
Jack of all trades, one deep specialism
What 20+ years of independent IT work actually looks like when you're not chasing a single career ladder — and why the breadth turned out to matter.