15/10/2025

I managed to catch some of the ICO’s Annual Conference this week, and one of the most striking takeaways was how phishing attacks have evolved.

People who once felt confident spotting a scam are now more likely to click, and they do! Apparently, the numbers of employees clicking on the links or download buttons are increasing!

The reason? The increase in volume of attacks but also more elaborate methods used.

They’re no longer the clumsy, typo-filled scams we used to laugh at. Today’s phishing attempts are highly sophisticated, often powered by AI to generate convincing messages that use regional references, authentic branding, and even personal details from your digital footprint to make them believable.

Another key insight shared at the conference was that phishing isn’t just targeting CEOs or senior managers anymore. Attackers have realised that every member of staff, from IT administrators (the ones with “keys to the kingdom” as the presenter commented) to new starters, can be a gateway in. The more emails they send, the greater the chance someone clicks, downloads, or installs something that opens the door.

As the ICO and cyber experts reminded us, technology alone can’t protect us. The strongest defence is a blend of:

  • Awareness – helping staff understand why they’re being targeted.
  • Culture – encouraging people to question, report and share near misses.
  • Design – embedding good practice into systems and processes from the outset.
  • Training – annual mandatory training for all employees

Data protection and cyber security aren’t separate challenges, but shared responsibilities rooted in people, not just policies.

Leave a comment

  • 19 June 2026: Is Your Data Protection Complaints Procedure Ready?

    Need a Data Protection Complaints Procedure in place before 19 June 2026? The deadline under the Data (Use and Access) Act 2025 is approaching fast, and many organisations still do not have a compliant process published. Email dpo@jhdataprotection.com to find out more about reviewing or implementing your data protection complaints procedure.

  • When curiosity becomes misconduct: lessons from the Nottingham NHS records scandal

    Data protection can often be dismissed as bureaucracy, policies and “tick-box exercises”. This week’s Nottingham NHS records scandal is a stark reminder that it is something far more important than that. When staff access sensitive personal data without lawful reason, the consequences are not merely regulatory, they are deeply human. Trust, dignity and confidentiality sit…

  • ARE YOU AI READY?

    AI is already regulated. Organisations just haven’t caught up 3 May 2026 There is still a perception that artificial intelligence sits ahead of regulation. From a UK GDPR perspective, it doesn’t. The legal framework is already in place. The issue for most organisations is not a lack of regulation, it is a lack of structured…

  • When data protection doesn’t protect you.

    17/04/2026 Recently, the Information Commissioner’s Office published the outcome of a criminal prosecution. The title? Just two names:Christopher Munro and William Chipoma. No explanation. No softening. No anonymity. And that, in itself, is a powerful lesson in how data protection law really works. Data protection isn’t about secrecy There’s a persistent myth that data protection…