Start-ups
Building security foundations for start-ups that support growth.
Helping small businesses and organisations reduce risk without it slowing delivery through human-first information security and data protection consultancy and delivery.
At Relatable Security we strip away the complexities and jargon of information security and data protection. This gives you confidence in your systems, processes and compliance requirements.
Whether you are the technical lead within your business, or a non-technical manager with overall responsibility, we are with you every step-of-the-way. We understand that better-informed people are almost always better than more software.
By putting humans at the centre of our support, we leave your organisation stronger, more resilient and prepared for the future.
Information security can cover a long list of topics, often described using acronyms and jargon understood by the few not the many. That's why at Relatable Security we group our services into three distinct areas with simple explanations of the services available.
Understand your organisation's readiness to protect itself from cyber threats. We ensure you can detect, respond to and recover from a variety of threats posed by cyber criminals.
Services available:
Make better decisions for your business by integrating security, quality and business objectives. We help you create governance and accountability without unnecessary complexity.
Services available:
Build business resilience with support that helps people respond under pressure and build better habits.
Services available:
From start-ups and small businesses through to healthcare providers and voluntary organisations we guide you through the world of information security. We know it can feel confusing, especially for those of you in non-technical roles. That's why we focus on clear plans, in language everyone can understand – no jargon marathons! Practical over perfect is something you'll hear a lot when working with us.
Building security foundations for start-ups that support growth.
Practical support for small businesses without unnecessary complexity.
Helping healthcare providers keep people at the heart of rigorous compliance.
Proportionate security that protects the people and reputation of charities.
Yes - this is one of the most common ways clients bring us in. We can act as an interim DPO, ISMS owner, or compliance lead while you recruit, or on a longer-term outsourced basis if that suits you better. The role doesn't have to be a full-time internal hire to be done well, and having someone independent in the seat often brings a useful outside perspective. Tell us what you need covering and we'll scope it with you. Read more about our virtual CISO service and how it keeps security decisions practical.
You don't have to recruit permanently before the audit date. We can run the preparation and internal audit programme on an interim basis, which is usually faster than hiring and onboarding someone in time. It also gives you an independent set of eyes heading into a surveillance or recertification audit - and we work to leave your team self-sufficient rather than dependent on us. See our certification support page and get in touch. We'll be honest about what's realistic in the time you've got.
If it's your data, the responsibility still sits with you, even though the breach happened somewhere else. The first step is to check your contract and data processing agreement: these should set out what the supplier owes you in terms of notifying you and cooperating with your response. Depending on what data was involved, you may have your own duties to the ICO or to affected people, and the clock on those can be short. If you're not sure where you stand, it's worth a quick conversation before assuming the supplier has it covered. You can read more here about data controllers and processors.
You don't have to take it on trust. Because the app was built by someone else doesn't mean the risk sits with them - if it's handling your beneficiaries' data, the responsibility is yours. A security review looks at how the application actually behaves, not just what the developer told you, and a maturity review can tell you whether the right practices are in place around it. For charities especially, we keep this proportionate: the aim is confidence that sensitive data is protected, without spending money you don't need to. See how our security assessments can help you.
It depends on what the app does and what data it holds, but for something new to market the usual starting point is a web application security review, often alongside some threat modelling to catch design issues early rather than after launch. Our white-box testing works particularly well here: because we look at the code and architecture directly, we find things a purely external test would miss. We'll help you focus effort where the real risk is, so testing supports your launch rather than holding it up. Read about how we perform penetration tests and security reviews that provide the assurance you need to confidently take your product to market.
They're not separate at all - in our experience, good security tends to fall out of good practice. When a process is clear, consistent and well designed, the security gaps close as a by-product, and people are far more likely to follow something that makes sense than a control bolted on afterwards. We bring proper process-improvement discipline to this (Lean Six Sigma and Agile backgrounds), with a security focus but not only security. The result is usually an organisation that runs better and is safer. Read how process improvement can make you more resiliant, secure, and more efficient.
Not every organisation is legally required to appoint a DPO - it depends on things like the scale and nature of the data you process. Where one is required, they need genuine expertise and enough independence to do the job properly, but it doesn't have to be an internal, full-time position; the role can be outsourced. If you're unsure whether you need one, that's exactly the kind of thing we can help you work out quickly. Read how our governance services can help.
Most organisations know who their data processor is. Fewer think about who that processor relies on to deliver the service - the hosting provider, the email platform, the analytics tool sitting quietly in the background.
Under UK GDPR, those organisations are sub-processors, and understanding them is part of your responsibility as a controller. This article explains what sub-processors are, what the law requires of both controllers and processors, and the practical questions you should be asking before you sign - or renew - a contract.
Explores how the UK GDPR distinction between data controller and processor determines who sets data retention periods and carries security and compliance risk.
Learn a practical framework for managing security, compliance, and data protection risks in AI-powered no-code development without slowing your teams down.
Tell us where you are today and we will help you improve your information security without unnecessary complexity.