Skip to main content
Infrastructure & Security

Data Security

Sensitive data identified, protected proportionately, accessible only to those who need it, and deleted when it should be.

Classification, encryption, access governance, retention and loss prevention for the records your organisation is accountable for.

The problem

What this service is usually brought in to fix

01

Nobody knows where the sensitive data is

Personal and financial records have been copied into exports, test environments and shared drives with no inventory.

02

Access grows and never shrinks

Permissions accumulate as people change role, and leavers retain access because offboarding never reaches every system.

03

Nothing is ever deleted

Without retention rules, organisations hold personal data indefinitely, increasing both breach impact and legal exposure.

Capabilities

What the service covers

  • Data discovery, inventory and classification
  • Encryption at rest and in transit, with key management
  • Access governance and periodic entitlement review
  • Masking and anonymisation for test and reporting environments
  • Retention schedules and defensible deletion
  • Data loss prevention and egress monitoring
Deliverables

What you receive

  • Data inventory and classification register
  • Encryption and key management design
  • Role-to-entitlement matrix and review procedure
  • Retention and deletion schedule
  • Masking configuration for non-production environments
Engagement process

How the work runs

Each stage produces something reviewable, so scope, risk and progress stay visible to your team throughout.

01

Discover

Locate and classify the data you hold, including copies in exports, backups and test systems.

02

Protect

Apply encryption, access control and masking proportionate to the classification of each data set.

03

Govern

Establish entitlement review, joiner-mover-leaver process and monitoring of access to the most sensitive records.

04

Retire

Define and enforce retention, and prove deletion when the retention period ends.

Industries & use cases

Where we apply it

  • Healthcare and patient records
  • Financial services and payments
  • Government registries and citizen data
  • HR and payroll operations
Security, quality & compliance

The controls that apply

  • Personal data collection minimised and its lawful basis recorded.
  • Non-production environments use masked or synthetic data, never live personal records.
  • Retention and deletion rules defined for enquiries, applications, logs and backups.
Questions

Frequently asked

If your question is not here, ask it directly — we would rather answer it before a proposal than after a contract.

Ask a question

With discovery. Automated scanning plus structured interviews across departments usually produces a workable inventory within weeks, and that inventory is what makes every subsequent control decision possible.

Discuss your Data Security requirement

Tell us the outcome you need and the constraints you are working within. We will respond with a scoped approach and the documentation your evaluation process requires.