Data Security
Sensitive data identified, protected proportionately, accessible only to those who need it, and deleted when it should be.
Classification, encryption, access governance, retention and loss prevention for the records your organisation is accountable for.
What this service is usually brought in to fix
Nobody knows where the sensitive data is
Personal and financial records have been copied into exports, test environments and shared drives with no inventory.
Access grows and never shrinks
Permissions accumulate as people change role, and leavers retain access because offboarding never reaches every system.
Nothing is ever deleted
Without retention rules, organisations hold personal data indefinitely, increasing both breach impact and legal exposure.
What the service covers
- Data discovery, inventory and classification
- Encryption at rest and in transit, with key management
- Access governance and periodic entitlement review
- Masking and anonymisation for test and reporting environments
- Retention schedules and defensible deletion
- Data loss prevention and egress monitoring
What you receive
- Data inventory and classification register
- Encryption and key management design
- Role-to-entitlement matrix and review procedure
- Retention and deletion schedule
- Masking configuration for non-production environments
How the work runs
Each stage produces something reviewable, so scope, risk and progress stay visible to your team throughout.
Discover
Locate and classify the data you hold, including copies in exports, backups and test systems.
Protect
Apply encryption, access control and masking proportionate to the classification of each data set.
Govern
Establish entitlement review, joiner-mover-leaver process and monitoring of access to the most sensitive records.
Retire
Define and enforce retention, and prove deletion when the retention period ends.
Where we apply it
- Healthcare and patient records
- Financial services and payments
- Government registries and citizen data
- HR and payroll operations
The controls that apply
- Personal data collection minimised and its lawful basis recorded.
- Non-production environments use masked or synthetic data, never live personal records.
- Retention and deletion rules defined for enquiries, applications, logs and backups.
Frequently asked
If your question is not here, ask it directly — we would rather answer it before a proposal than after a contract.
Ask a questionWith discovery. Automated scanning plus structured interviews across departments usually produces a workable inventory within weeks, and that inventory is what makes every subsequent control decision possible.
What this is usually combined with
Discuss your Data Security requirement
Tell us the outcome you need and the constraints you are working within. We will respond with a scoped approach and the documentation your evaluation process requires.
