Security, Privacy & Law
Cyber security, privacy and technology law for digital businesses: GDPR and US privacy rules, accessibility law, NIS2, the AI Act and practical defences.
Topics in Security, Privacy & Law
- Cyber Security3 articlesPractical cyber security for small businesses: website hardening, MFA, phishing and invoice fraud, backups and incident response.
- Compliance & Accessibility4 articlesGDPR, UK GDPR and US privacy law, cookie consent, the European Accessibility Act, ADA and WCAG 2.2 for business websites and online stores.
Latest articles

Business Email Compromise and Invoice Fraud: How Small Businesses Stop It
A defensive guide to business email compromise and invoice fraud for small businesses: how the scams work at a high level, the red flags, the payment and email controls that stop them, and what to do in the first hours after a fraudulent transfer in the US, UK and EU.
Read article →

A Practical Incident Response Plan for Small Businesses (with Template)
How a 5 to 50 person business can plan for a cyber incident: who does what, the contact list to keep offline, a first-hour checklist, containment, evidence preservation, communication, recovery, breach-notification duties under GDPR, UK GDPR and US state laws, and a fill-in template.
Read article →

Passkeys and MFA for Small Teams: What to Choose and How to Roll It Out
A practical guide to multi-factor authentication for small businesses: SMS codes vs authenticator apps vs passkeys and security keys, which accounts to protect first, how to avoid lockouts with recovery codes and backup methods, and a phased rollout plan for a small team.
Read article →

European Accessibility Act for E-Commerce Websites: What Stores Must Do
A practical guide to the European Accessibility Act (Directive (EU) 2019/882) for e-commerce and consumer service websites: who is in scope, the microenterprise exemption, EN 301 549 and WCAG, accessibility information, enforcement and a remediation plan for WooCommerce and Shopify stores.
Read article →

ADA Website Compliance for Small Businesses: A WCAG 2.2 AA Guide
A plain-English guide to ADA website compliance for US small businesses: Title III and websites, the DOJ Title II rule for governments, why demand letters happen, why overlays do not make a site compliant, a WCAG 2.2 AA checklist and what to put in an accessibility statement.
Read article →

Google Consent Mode v2 and Cookie Consent: A Setup Guide for Business Sites
How to set up Google Consent Mode v2 alongside a compliant cookie banner: ePrivacy and PECR consent rules, the GDPR consent standard, the four consent parameters, basic versus advanced mode, CMP requirements, WordPress and Shopify implementation, Tag Assistant testing and common mistakes.
Read article →

US State Privacy Laws for Small Business Websites: What Applies and What to Do
A practical 2026 guide to US state privacy laws for small business websites: CCPA/CPRA thresholds, the other comprehensive state laws, Texas and Nebraska small-business rules, privacy notices, opt-out of sale and sharing, Global Privacy Control, pixels, forms, vendor contracts and CAN-SPAM.
Read article →
