Looking through Information Commissioner's Office enforcement against smaller UK organisations, the same causes come up repeatedly — and none of them involve advanced attackers.
The recurring themes
Unsolicited marketing. Texts and calls to people who never consented, or to lists bought from a broker with vague provenance. PECR fines here are routine and land on small companies.
Keeping data forever. Ten years of customer records, old CVs, ex-employee files. If you don't need it, holding it is only risk.
Unencrypted devices. A laptop left on a train becomes a reportable breach if the disk isn't encrypted, and doesn't if it is. BitLocker is free and takes minutes.
No process for subject access requests. The deadline is one month and complaints about missed deadlines get looked at.
A short list that covers most of it
- Turn on disk encryption everywhere and record the recovery keys centrally.
- Write a retention schedule, however simple, and actually delete things.
- Check your marketing consent basis before the next campaign.
- Know who reports a breach, and that the clock is 72 hours.
We cover encryption and device control as part of managed support, and our GDPR page walks through the rest.