Cybersecurity Law

Cybersecurity or information security is a crucial part of information management. We are experts on the legal aspects regards the security of information (infosec). You can read our advice, or about the products or services we offer related to this focus area below:

Cybersecurity due diligence

Cybersecurity acts like a watchtower in our connected world, vigilantly spotting potential threats. As businesses link more closely, protecting their supply chains from cyber attacks becomes increasingly vital. This article focuses on the essential role of Service Level Agreements (SLAs) [...]

By |2025-03-20T13:24:45+02:00July 2nd, 2024|Categories: Cybersecurity Law|Tags: |

Edward Nathan Sonnenbergs (ENS) v Hawarden | BEC

In Edward Nathan Sonnenbergs(ENS) v Hawarden, ENS appealed the judgment handed down in Hawarden v Edward Nathan Sonnenbergs. The Supreme Court of Appeal (SCA) upheld the appeal and dismissed the original order from the high court. Hawarden may appeal this [...]

Data subject breach notification

Imagine a castle under siege, and the guards fail to alert the inhabitants. In the world of data protection, data subject breach notifications act as crucial alarms, ensuring individuals are aware of threats to their personal data. Data protection laws, [...]

Data breach legal strategies

Dealing with a data breach is like trying to turn off a complex alarm system, where cutting the wrong wire can make things worse instead of quieting the alarm. Breaches include leaks, hacks and other information security compromises. As we [...]

Access control policy development

An access control policy is a permission slip for an organisation's crucial assets, such as data and systems. It specifies who can access particular resources, ensuring the security of operations and adherence to standards like ISO 27001. Essential elements of [...]

By |2024-04-23T13:47:01+02:00April 23rd, 2024|Categories: Cybersecurity Law|Tags: |

CISO cybersecurity liability in the US

For CISOs looking to avoid cybersecurity liability, managing cybersecurity can feel like tensely moving blocks in a tower and hoping it doesn't fall over. Each move by Chief Information Security Officers (CISOs) must ensure their company's digital safety without inviting [...]

By |2024-03-27T00:29:37+02:00March 27th, 2024|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

Running an information security programme in the UAE

In the UAE’s ever-evolving digital landscape, the need for robust information security practices cannot be overstated. From the bustling economic hub of Dubai to the advanced infrastructure of Abu Dhabi, businesses operating within the UAE, including its free zones like [...]

By |2024-08-26T21:27:14+02:00March 19th, 2024|Categories: Cybersecurity Law|Tags: |

Information security incident reporting trends

Understanding how to effectively report and manage cybersecurity incidents is crucial in our fast-paced digital age. Indeed, it requires precision, quick thinking, and a deep understanding of the ever-changing cybersecurity landscape, like carefully threading a needle amidst a whirlwind of [...]

By |2024-03-12T11:42:35+02:00March 12th, 2024|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

ISO 27001 policies: What does the infosec standard require?

In today's digital world, robust cybersecurity is essential. Enter ISO 27001 – a stalwart standard that serves as a comprehensive blueprint for constructing an impregnable information security fortress. ISO 27001 offers a detailed plan for organisations to create a secure [...]

By |2024-03-08T13:00:39+02:00March 8th, 2024|Categories: Cybersecurity Law|Tags: |

AI and data protection: a new age love story

Shakespeare’s Sonnet 116 characterises love as a permanent and unending state, and with the rise of AI, your data will be forever memorialised. “Love is… an ever-fixed mark, that looks on tempests and is never shaken.”  – William Shakespeare. We [...]

By |2024-02-28T21:35:51+02:00February 14th, 2024|Categories: AI Governance, Cybersecurity Law, POPI and Data Protection|Tags: |

SEC cyber disclosure: Navigating new rules and compliance

New rules from the Securities and Exchange Commission (SEC) have changed how public companies report cybersecurity incidents and risks in the USA. These rules aim to simplify things and protect investors from cyber attacks. To navigate the new rules as [...]

By |2024-02-01T09:48:02+02:00February 1st, 2024|Categories: Cybersecurity Law|