Cyber Hygiene Essentials
A free, beginner-friendly introduction to safer everyday internet habits.
Courses, downloads, and a free security, privacy and compliance glossary - practical guidance you can use across your team.
Structured learning for people and teams who need security, privacy, and compliance habits they can keep.
A free, beginner-friendly introduction to safer everyday internet habits.
AI tools can make work faster, but they can also expose sensitive business information. A live, practical course for safer AI use at work.
Practical ways to notice urgent messages, fake logins, and social pressure before they become an incident.
Guides, checklists, and tools you can use today.
Plain-language definitions for GDPR, ISO 27001, DORA, the EU AI Act, the Cyber Resilience Act, and related terms. This is a short preview - open the full glossary to browse by letter.
General Data Protection Regulation. The EU law that sets rules for processing personal data, including lawful bases, individual rights, security, and accountability for controllers and processors.
Digital Operational Resilience Act. EU rules for financial entities covering ICT risk, incident reporting, testing, and oversight of critical ICT third-party providers.
EU product-security law for products with digital elements. It expects manufacturers to design, maintain, and document security throughout the product lifecycle, including vulnerability handling.
The European Union’s risk-based law for AI systems. Obligations scale with risk, from transparency for some uses to strict requirements for high-risk systems affecting safety or fundamental rights.
An international standard for establishing, running, and improving an ISMS. Certification is optional; the value is a repeatable way to manage risk, controls, and evidence.
The rules and technical measures that decide who can view, change, or use information, systems, and services. Proportionate access control limits privileges to what people need for their role.
Building data-protection into products and processes from the start, rather than adding a notice at the end. It covers minimisation, purpose limits, security, and user rights in everyday workflows.
The unsanctioned use of AI tools with work data. It can leak information, create unapproved processing, and bypass security or privacy rules unless teams have clear, usable alternatives.
Browse insights from Boxfish Labs, or get in touch to talk through what your team needs next.