Blog

  • Why Housing Associations should prepare for STAIRs now

    September 23, 20265 min

    The first STAIRs deadline is 1 October 2026, but housing associations also need to be preparing now for the information request requirements coming into force on 1 April 2027. The [...]

  • Why Housing Associations should prepare for STAIRs now
    |September 23, 2026|

    The first STAIRs deadline is 1 October 2026, but housing associations also need to be preparing now for the information [...]

  • This Is How Your STAIRs Publication Scheme Should Work
    |September 23, 2026|

    From 1 October 2026, Private Registered Providers (PRPs) of social housing in England will need to proactively publish specified information [...]

  • How to Prepare for a TISAX Audit: 10 Questions Your Staff Must Be Ready For
    |September 10, 2026|

    "Do you encrypt your endpoint devices?" "Yes. We use BitLocker." "Great. Show me. On that laptop, in front of you." [...]

  • STAIRs vs DSARs: What’s the Difference?
    |August 18, 2026|

    Social Tenant Access to Information Requirements (STAIRs) vs Data Subject Access Requests (DSARs) Transparency, accountability, and access to information [...]

  • What is STAIRs? (Social Tenant Access to Information Requirements)
    |August 7, 2026|

    What is STAIRs? STAIRs or Social Tenant Access to Information Requirements is a new set of rules that gives housing [...]

  • TISAX® 1.2.1: What the Assessor Actually Wants to See in Your ISMS Scope
    |August 5, 2026|

    TISAX® 1.2.1: What the Assessor Actually Wants to See in Your ISMS Scope If you have arrived here with the [...]

  • VDA ISA 2027: Should You Get Your TISAX® Assessment Done Before 1 January?
    |August 5, 2026|

    The VDA published the next version of the Information Security Assessment catalogue on 1 July 2026. If you have been [...]

  • Shadow AI: Your Employees Are Already Using It – Are You Protected?
    |July 13, 2026|

    What You’ll Learn Your employees may be using public AI tools at work without your business knowing, approving or controlling [...]

  • Templeton Advisory Partners: Cyber Essentials Certification
    |July 13, 2026|

    Templeton Advisory Partners is an executive talent and transformation consultancy, placing interim executives and senior leaders into financial institutions, private [...]

  • Yet Another Automotive Cyber Attack. This Is Exactly Why TISAX Exists.
    |June 26, 2026|

    Last week it was Tata Electronics. More than 200,000 files, over 630GB, dumped on a dark web leak site by [...]

  • TMW Resilience appointed as outsourced Data Protection Officer for Life Sciences Hub Wales
    |June 22, 2026|

    We're delighted to share that TMW Resilience has been appointed as the outsourced Data Protection Officer (DPO) for Life [...]

  • Do You Need a Virtual DPO? What It Is and Why It Matters More Than Ever
    |June 16, 2026|

    If data protection is part of your job, you'll know the pressure is mounting. Tightening regulation, growing volumes of personal [...]

  • Cyber Threat and Resilience Intelligence Briefing Series – Aerospace
    |June 10, 2026|

    Cyber threats facing the aerospace sector are evolving rapidly, and resilience now needs to be built into every part of [...]

  • What the Data (Use and Access) Act 2025 means for your complaints process
    |May 21, 2026|

    If you handle personal data, there is a significant change coming on the 19th June 2026 that you need to [...]

  • Virtual Data Protection Services (vDPO)
    |April 22, 2026|

    Data is at the heart of your business. But so is the risk. The UK GDPR requires many organisations to [...]

  • Good Practice Cyber Recovery Planning Flow
    |April 22, 2026|

    While prevention is essential, true cyber resilience depends on having a clear and structured recovery plan in place. By following [...]

  • AI Governance as a Service
    |April 22, 2026|

    AI has the power to transform your organisation, but how do you proceed when boards won’t sign off on AI [...]

  • Cyber Essentials
for the Water Sector
    |April 22, 2026|

    Cyber attacks on the UK water sector are increasing in frequency, sophistication and operational impact. The Government’s FTSE 350 Cyber [...]

  • TISAX Compliance Made Simple
    |April 22, 2026|

    Originally developed by leading German automotive manufacturers, TISAX has become a benchmark for cybersecurity across the entire manufacturing and engineering [...]

  • Protecting data at pace:
How HIYH partnered with TMW Resilience for virtual DPO support
    |April 16, 2026|

    HIYH is one of 15 organisations set up by NHS England to operate as the key innovation arm of the [...]

  • How to Recover From a Cyber-Attack: A Step-by-Step Playbook
    |April 10, 2026|

    In cybersecurity, planning for and defending against attacks is essential. However, a truly resilient organization does not assume prevention is [...]

  • What is a vDPO and why might it be exactly what you’re looking for?
    |March 11, 2026|

    Data protection responsibilities have never been easy but with tightening regulation, growing volumes of personal data, and the added [...]

  • Our 8 security and compliance predictions for 2026
    |December 17, 2025|

    It’s been an exciting year for TMW Resilience and as the dust settles on 2025, I thought now would [...]

  • UK Cyber Security and Resilience (UKCSR): Trust, power, and the rebalancing of cyber governance
    |December 17, 2025|

    Introduction: A different kind of cyber legislation Most cyber regulation arrives with a familiar tone: prescriptive controls, technical checklists, [...]

  • From Policy to Proof: The EU’s AI Code of Practice Is Now in Force
    |October 16, 2025|

    In our earlier articles, we argued that an AI policy is more than just documentation; it's a mark of operational [...]

  • Cyber Security & AI Risk: Key UK Developments – September 2025
    |September 23, 2025|

    Cybersecurity and AI risks are evolving faster than ever, with regulators, threat actors, and industry leaders all reshaping the [...]

  • Top Cyber Risk Trends for 2025 and How to Stay Resilient
    |September 12, 2025|

    Cyber risk is no longer a question of if, but how fast it evolves. In 2025, organisations must contend with an [...]

  • From Defence to Resilience: Rethinking How Cybersecurity Policies Are Implemented
    |September 1, 2025|

    In a time when cyber threats are growing more sophisticated—and regulators are becoming more demanding - businesses can no longer [...]

  • UK GDPR Compliance: What’s Changed for 2025’s Data Protection Principles
    |August 25, 2025|

    Compliance is No Longer Just Legal- It’s Leadership In 2025, UK GDPR compliance has moved from legal formality to a [...]

  • AI Governance Frameworks for SMEs: Why It Matters More Than Ever
    |August 12, 2025|

    The Hidden Vulnerability of SMEs Artificial Intelligence (AI) is no longer an emerging technology - it’s a critical component of [...]

  • Meeting TISAX Requirements: 10 Things to Prepare Ahead of Your Audit
    |July 18, 2025|

    TISAX - the Trusted Information Security Assessment Exchange - is no longer optional for many automotive suppliers and technology firms [...]

  • Earn Trust, Build Resilience: A Strategic Response to the UK Cyber Security Bill
    |June 30, 2025|

    Introduction: Trust Is the New Differentiator The UK's Cyber Security and Resilience Bill marks a watershed moment for executive accountability and [...]

  • A Non-Negotiable: TISAX for Automotive Industry Suppliers
    |June 24, 2025|

    Competition. In the world of automotive manufacturing, it's fierce. This means that before you even think of a partnership with [...]

  • Don’t Just Write It. Prove It: AI Policy as Operational Maturity
    |June 21, 2025|

    As artificial intelligence moves from experimental to essential, organisations are being forced to confront an uncomfortable truth: deploying AI without [...]

  • Trust, Security Resilience: Governing AI in Healthcare with Confidence
    |June 20, 2025|

    How international standards and NHS principles shape the future of safe, accountable AI in health. The potential for artificial intelligence [...]

  • Do You Really Need a Data Protection Officer? Here’s What the Law Says About Data Protection Regulations
    |June 18, 2025|

    A Data Protection Officer (DPO) is an individual who reports to the highest management level of a company due [...]

  • TISAX vs ISO 27001: Are You Asking the Right Question?
    |June 9, 2025|

    In a climate of growing regulatory scrutiny, complex supply chains, and rising expectations around trust, businesses need a clear and [...]

  • From Data Security to AI Governance: How ISO 27001 and ISO 42001 Work Together to Build Security, Resilience, and Trust
    |June 6, 2025|

    From Infrastructure to Intelligence - Trust Must Be Built As businesses become increasingly data-reliant and AI-enabled, the ability to demonstrate [...]

  • How Cyber Essentials Certification Builds Trust in a Digital World
    |May 29, 2025|

    As cyber threats grow more sophisticated, foundational frameworks like Cyber Essentials help organisations take the first meaningful step toward long-term [...]

  • TISAX Compliance: Earn Trust Before You’re Asked To
    |May 23, 2025|

    Trust isn’t granted - it’s assessed. And in the automotive supply chain, TISAX is the signal that your business is [...]

  • What Is AI Governance? And Why Your Business Needs It
    |May 8, 2025|

    Guidelines for Responsible AI, Data Oversight, and EU AI Act Compliance As artificial intelligence moves from experimental to essential, the [...]

  • Why We Built TMWResilience
    |May 7, 2025|

    Rethinking AI Compliance for a New Era In today’s regulatory environment, compliance is often seen as a cost [...]