15/10/2025

I managed to catch some of the ICO’s Annual Conference this week, and one of the most striking takeaways was how phishing attacks have evolved.

People who once felt confident spotting a scam are now more likely to click, and they do! Apparently, the numbers of employees clicking on the links or download buttons are increasing!

The reason? The increase in volume of attacks but also more elaborate methods used.

They’re no longer the clumsy, typo-filled scams we used to laugh at. Today’s phishing attempts are highly sophisticated, often powered by AI to generate convincing messages that use regional references, authentic branding, and even personal details from your digital footprint to make them believable.

Another key insight shared at the conference was that phishing isn’t just targeting CEOs or senior managers anymore. Attackers have realised that every member of staff, from IT administrators (the ones with “keys to the kingdom” as the presenter commented) to new starters, can be a gateway in. The more emails they send, the greater the chance someone clicks, downloads, or installs something that opens the door.

As the ICO and cyber experts reminded us, technology alone can’t protect us. The strongest defence is a blend of:

  • Awareness – helping staff understand why they’re being targeted.
  • Culture – encouraging people to question, report and share near misses.
  • Design – embedding good practice into systems and processes from the outset.
  • Training – annual mandatory training for all employees

Data protection and cyber security aren’t separate challenges, but shared responsibilities rooted in people, not just policies.

Leave a comment

  • Do you need a remote DPO?

    06/04/2026 Why a Remote DPO Might Be the Smartest Decision Your Business Makes Most organisations don’t have a data protection problem. They have a capacity problem. They know they should be doing more — DPIAs, privacy notices, training, breach processes — but the reality is: So things get done reactively. Or not at all. That’s…

  • Data Protection and Formula 1:

    It’s All About Energy Management Perhaps I am delirious from a 4am race start, but I couldn’t help but see the data protection parallels with the first F1 race of the season this morning. One thing stands out more than ever in the hybrid era: The fastest driver isn’t always the one pushing flat-out every…

  • When Someone Asks for Their Data

    15/02/2026 What Every Organisation Must Understand About Subject Access Requests in 2026 When someone asks to see the personal data your organisation holds about them, it is not a favour. It is not discretionary. It is a statutory right. Under UK data protection law, now refined by the Data (Use and Access) Act 2025, individuals…

  • Data Protection in 2026: What to Be Ready For

    24/01/2026 As we move into 2026, it’s tempting to look for the big new data protection law that will change everything overnight. In reality, that isn’t how this year is shaping up. Instead, 2026 looks set to be a year of consolidation, scrutiny and expectation‑raising. The rules themselves are largely familiar. What’s changing is what…