The security gaps in Microsoft 365 and how to manage them

According to Statista, over one million companies worldwide use Microsoft 365 (M365). However, when it comes to sharing sensitive information, the popular productivity suite leaves businesses open to some serious security risks. The fact is, while your traditional M365 license can protect against some security hazards, alone, it does very little to prevent the leading causes […]
5 Tips for Large File Transfers
It doesn’t matter if you’re a small organization, a small-to-medium-sized (SMB) business, or an enterprise: at some point, you’ll likely need to exchange a large file transfer with a trading partner, third-party vendor, or client. If you don’t know how to support a large file transfer or lack the tools to execute it properly, this […]
The Key to Compliance and Data Control Success
It is absolutely impossible to achieve compliance and apply data controls without knowing what data you hold and where that data resides. If your organisation is spending hundreds of thousands on Zero Trust, XDR and Vulnerability Management but you still don’t know where the data is then how do you plan to deploy this proverbial […]
The Cost of Doing Nothing About Data Discovery
It’s always easier to do nothing. Following the path of least resistance might work in some walks of life; Buddhism actively encourages it from what I’ve heard. In Data Security though it’s rarely the right thing to do. Most things in life are a decision of A or B and one will normally require additional […]
The Importance of Protecting Personal Data
Two serious personal data incidents were reported on Tuesday, affecting residents of the UK: Police Service of Northern Ireland (PSNI) leaked the details of Police Officers and staff UK Electoral register was hacked for 15 months and “no-one noticed†If you aren’t alarmed by this, you should be. Alarms should have been ringing before any […]
What Is Email Security?
Firstly, apologies for the title, I personally cannot stand those condescending blogs or articles that try to explain what something is because you’re far too unintelligent to work it out yourself. The good news is however, that this isn’t one of those. Email Security is a term so widely interpreted by vendors and the industry […]
DORA Regulation, Don’t Panic
The Digital Operational Resilience Act (DORA) regulation is enforceable from the 17th January 2025 to all EU financial institutions. In my working lifetime I’ve seen the introduction of a raft of pieces of legislation; GDPR, multiple updates to PCI-DSS as well as MiFID directives I & II, amongst others. Each of these have their own requirements to comply […]
What is a ‘Data Centric’ Security Baseline?
In this clip from our recent webinar ‘Data Security and Data Protection in 2024’, Sam Malkin, HANDD’s Lead Solution Architect discusses the critical importance of a data centric security baseline. Sam emphasises the need for a data-centric cybersecurity model, and advocates for increased visibility and protection across all data forms and locations, whether at rest, […]
DORA and NIS2 – What Do I Need to Know?
Discover the connection between the NIS2 security directive and DORA in this clip from HANDD’s recent webinar. NIS2, the second iteration of the network and information security directive, set to be enforced from October 17th, focuses on bolstering resilience across various industries and corporations in the European Union. View the clip and transcript below or […]
What are the 5 pillars of DORA?

In this clip from a recent webinar, HANDD’s Lead Solutions Architect Sam Malkin highlights the key pillars of DORA, focusing on ICT risk management, incident reporting, and third-party management. Articles 15, 16.3, and 18.3 are explored, outlining processes, incident classification, and third-party obligations. View the clip and transcript below or watch the full webinar. Transcript: […]