IT Pro Expert
Search
IT · 25 Sep 2026 · 28 min read

UK - The leaders in global privacy invasion. Is there any escape?

UK surveillance laws now weaken encryption and expand facial recognition. Learn what's changed since 2025 and how to protect your privacy today.

Silhouetted analyst monitors global surveillance data, facial recognition, and city cameras in control room.

Governments across the democratic world are steadily widening their reach into private communications, and the United Kingdom is out in front. Secret orders against encryption, powers to scan private messages, and cameras that identify faces in the street are no longer proposals. Here is where things stand in autumn 2026, and what you can realistically do about it.

How Britain got here

No single law turned the UK into a surveillance leader. It has been a steady accumulation of powers, each justified on its own terms, which together add up to one of the most far-reaching toolkits of any major democracy.

  1. 2016: the Investigatory Powers Act

    Nicknamed the Snoopers' Charter, it lets the Home Secretary issue secret Technical Capability Notices ordering a company to remove "electronic protection" from communications. Recipients can be barred from even saying they have received one.

  2. 2023: the Online Safety Act

    Section 121 lets Ofcom order a messaging service to use "accredited technology" to detect child abuse or terrorism material, whether or not the service is end-to-end encrypted. In practice, the only way to do that is to scan messages on your device before they are encrypted. The government has said it will not use the power until it is technically feasible, but the power remains on the statute book.

  3. January 2025: the Apple order

    The Home Office served Apple a notice demanding access to encrypted iCloud data belonging to users worldwide. It later narrowed the demand to UK users only.

  4. February 2025: encryption withdrawn

    Rather than build a backdoor, Apple stopped offering Advanced Data Protection, its end-to-end encryption for iCloud, to new UK users.

  5. 2026: faces in the crowd, and a fight in the tribunal

    Live facial recognition spreads from a handful of forces towards national rollout. Apple files a fresh complaint to the Investigatory Powers Tribunal in August, and at a hearing in September its lawyers argue that the Home Office's refusal to even confirm the order exists has become untenable. A separate challenge brought by Privacy International is listed for December.

Apple is the only company publicly known to have received such an order. When a US senator asked Google in 2025 whether it had received one, it initially replied only that it would be barred from saying so, before later stating publicly that it had not.

The cameras are already out

Encryption fights happen in tribunals and in secret. Facial recognition happens on the high street. Parliament has never passed a law that specifically authorises it, yet deployment has raced ahead of the legal framework the Home Office only began consulting on in December 2025.

13 of 43police forces in England and Wales using live facial recognition (March 2026)
40new live facial recognition vans announced by the Home Office in January 2026
25,000+retrospective facial recognition searches run by police every month

The Metropolitan Police intends to install fixed cameras across the West End and Soho by the end of 2026, following a Croydon pilot. A judicial review challenging the Met's policy was dismissed by the High Court in April. Handheld devices that let officers scan the face of whoever is in front of them are also being trialled in London.

Surveillance used to start with suspicion. Increasingly, it starts with everyone.

It isn't only Britain

The UK is leading, but it is not alone. Other democracies are moving the same way, often borrowing the same arguments and the same legal language.

European Union

The proposed Child Sexual Abuse Regulation, known to critics as Chat Control, would make scanning of private messages mandatory. It remains stuck in negotiation, but in July 2026 the EU revived the temporary regime allowing platforms to scan unencrypted messages voluntarily, even though most MEPs who voted opposed it.

United States

Section 702 of FISA allows warrantless collection of foreigners' communications through US tech companies, sweeping up Americans who talk to them. Due to expire in April 2026, it was kept alive through a series of short-term extensions while Congress argued over reforms.

Australia

The 2018 Assistance and Access Act lets authorities compel companies to build new capabilities into their products to help agencies access communications, a model that closely mirrors Britain's Technical Capability Notices.

The case governments make

It is worth being clear about the other side of the argument. Ministers point to child sexual abuse material, terrorism and organised crime, all of which use encrypted apps. A Home Office survey found two in three people support police use of facial recognition, and the Met credits its Croydon pilot with 173 arrests. In the US, supporters of Section 702 say the safeguards added in 2024 are working and that the programme regularly disrupts real threats.

The problem is not the goal; it is the method. There is no known way to let a government read encrypted messages that does not also create a weakness criminals and hostile states can exploit. That is why Signal and Element have said they would leave the UK rather than scan their users' messages, and why Apple chose to withdraw a security feature rather than weaken it.

Where your real exposure sits

People often worry about hidden backdoors in phone hardware. Security researchers have found serious flaws in phone modems and even undocumented hardware features in Apple chips, but the documented risks for most people are far more ordinary:

  • Cloud backups. Anything the provider holds the keys to can be handed over under legal process. As set out above, that now covers most of iCloud for UK iPhone users, and Google Photos, Drive, Gmail and synced contacts for Android users everywhere.
  • The update key. Every phone trusts software signed by its manufacturer. Whoever holds that key, and whoever can lean on them, controls the device. Because a signed update can change anything on the phone, the manufacturer could push one that gives full remote access to a device that had no such capability before, so no hidden backdoor needs to exist in advance. In 2016 the FBI tried to force Apple to sign a custom version of iOS to unlock a suspect's iPhone; Apple refused, and the FBI eventually got in using a third-party exploit.
  • The mobile network. A phone with an active SIM constantly tells the carrier roughly where it is, and that record is available to the authorities.
  • Ordinary calls and texts. Standard phone calls, including calls to landlines, and SMS messages are not end-to-end encrypted. Your operator can see SMS content as it passes through its network, and UK networks must be able to intercept any call or text in real time when served with a warrant. Operators do not routinely record every call, but they can be required to keep records of who contacted whom, when, for how long and from where for up to 12 months. Police and other public bodies can obtain those records with an authorisation that falls well short of the warrant needed to intercept content. GCHQ also runs bulk interception of communications crossing the UK's internet cables, and has said publicly that it uses AI to help analyse the data it collects. Sensitive calls and messages belong in Signal, not on the phone network.
  • Preinstalled software. Most proven abuse on Android has come from privileged bloatware and cheap-brand firmware, not from mainstream flagships. In 2016, Adups firmware on some budget phones sold in the US was caught sending texts and contacts to servers in China, and the Triada malware has been found preinstalled on cheap handsets straight from the supply chain.
  • Your internet connection. Removing the SIM stops cell-tower tracking, but every time the phone goes online, the Wi-Fi network and your internet provider see its connection. A VPN hides that from the local network, but you are then trusting the VPN provider instead.
  • Bluetooth and Wi-Fi signals. Roadside sensors that log the Bluetooth and Wi-Fi identifiers of passing devices have been used on UK roads for years to measure journey times, with the data anonymised for traffic management. In the US, police can now buy a system called SignalTrace that adds the same kind of sensor to number plate cameras and links the phones, earbuds, smartwatches and car systems that repeatedly travel together to a vehicle's plate and location history, so it can follow people rather than just cars. It has not been reported in the UK, but the sensors and the number plate cameras are already here. Modern phones disguise their own identifiers, but earbuds, watches and car infotainment systems are often easier to recognise, so switch Bluetooth off on them when you are not using it.

Encryption only protects the journey

Signal is the messaging app most trusted by security researchers, journalists and privacy advocates. It is open source, independently audited, and collects almost nothing about its users. But its encryption protects a message only while it travels. On your phone, before it is sent, and on the recipient's phone, after it arrives, the message is ordinary readable text. Anything else on either phone that can see it can copy it, and nothing about Signal's encryption will stop that.

This is also exactly where the UK's Online Safety Act scanning power would operate: on the device, before a message is encrypted. Treat the phone itself as the weak point, not the app.

  • Notification previews. In a US trial in April 2026, the FBI testified that it had recovered incoming Signal messages from a defendant's iPhone after the app had been deleted. Investigators did not break Signal's encryption; the phone's operating system had simply kept copies of the notification previews. In Signal, set notification content to show no name or content.
  • Backups and copies. Signal keeps its message history out of iCloud and Google backups, and its own optional backups are encrypted with a key only you hold. But screenshots, saved photos and attachments land in your camera roll and cloud storage, and other messaging apps often back up to the cloud without end-to-end encryption unless you switch it on.
  • Keyboards and screen readers. A third-party keyboard with network access can send what you type to its maker's servers, and on Android, apps granted accessibility access can read what is on screen. Use the built-in keyboard, turn on Signal's incognito keyboard option on Android, and review which apps hold these permissions.
  • Spyware. Commercial spyware such as NSO Group's Pegasus and Paragon's Graphite has been found on the phones of journalists and activists. Once installed, it reads messages straight off the device, so encryption never comes into play. Prompt updates and Apple's Lockdown Mode are the main defences.
  • Linked devices. Every computer or tablet linked to your Signal account holds its own copy of your messages. Check the linked devices list regularly and remove anything you do not recognise or no longer use.
  • A seized phone. Forensic tools can extract almost everything from a phone that is unlocked or has been unlocked since it last restarted. Use a long passcode rather than a short PIN, turn on disappearing messages, and note that both iOS and GrapheneOS now restart automatically after a period of inactivity, returning the phone to its most protected state.

The same rules apply to the Meshtastic set-ups below: an encrypted radio link protects the message in the air, not on a phone that is leaking its notifications.

Leaving the networks altogether: Meshtastic

Every option above still relies on someone else's infrastructure: a mobile carrier, an internet provider, or a cloud service that can be served with an order. The most private approach is to step off those networks entirely. That is what Meshtastic does.

Meshtastic is open-source firmware for small, inexpensive LoRa radios. Each device relays messages for the others, forming a mesh with no mobile network, no internet, no SIM and no account. In the UK it runs on the licence-free 868 MHz band. You can use it in two ways:

An offline phone plus a radio node

A phone with no SIM and Wi-Fi switched off pairs over Bluetooth with a pocket Meshtastic node and uses the Meshtastic app for typing and reading. The phone never touches the internet or a mobile network.

A standalone handheld

Devices such as the LilyGo T-Deck Plus and T-Pager have a built-in keyboard, screen and radio, so no phone is needed at all. They look and feel much like an old BlackBerry.

Direct messages between two people have been end-to-end encrypted with public-key cryptography since firmware 2.5 in 2024, so the nodes relaying a message cannot read it. Group channels use a shared 256-bit key instead, which protects the content from anyone outside the group.

The trade-off is range. Depending on terrain, buildings and how many other nodes are nearby, a message may travel a few hundred metres in a dense city or many kilometres between hilltops. Messages are short, both people need compatible devices, and delivery is not guaranteed. For everyday use it complements a secure phone rather than replacing one, but for private messages that never touch a provider's servers, nothing mainstream comes closer.

Which devices hold up best

We scored the most common options for private messaging, including with and without a SIM card so you can see how much the mobile network alone costs you in privacy. The table also covers the two Meshtastic set-ups, the main Linux phone operating systems, and the phones most people actually carry, set up the way most people use them. These are our own assessments; unless a row says "default settings", we assume the device is set up carefully with minimal accounts.

RankOptionSecurity against hackingHard to trackSignal supportEveryday practicalityOverall /10
1Pixel + GrapheneOS, no SIM981089
2Pixel + GrapheneOS, no SIM, no Wi-Fi, with Meshtastic node89n/a (Meshtastic encryption)47.5
3Pixel + GrapheneOS, with SIM8410107.5
4iPhone with Lockdown Mode, no SIM861097.5
5Standalone Meshtastic handheld (e.g. T-Deck Plus)59n/a (Meshtastic encryption)46.5
6iPhone with Lockdown Mode, with SIM7310106.5
7Wi-Fi-only iPad876 (linked device only)56.5
8Linux: Sailfish OS (e.g. Jolla Phone), no SIM477 (Android app via compatibility layer)65
9Linux: Purism Librem 5 (PureOS, hardware kill switches)583 (unofficial clients)45
10Stock Android flagship, no SIM641095
11Everyday iPhone, default settings, with SIM (what most people use)6210104.5
12Linux: Ubuntu Touch (e.g. Volla, Fairphone), no SIM473 (unofficial clients)44.5
13Linux: postmarketOS or Mobian (e.g. PinePhone), no SIM373 (unofficial clients)34
14Everyday Android flagship, default settings, with SIM (what most people use)5210104
15Budget or lesser-known Android brand, default settings, with SIM211092.5
16Dedicated "encrypted phone" vendorsUnverifiable2131

The phones most people carry sit in the bottom half. That is less about the hardware than the defaults: a Google or Apple account signed in, cloud backups switched on, message previews on the lock screen, location history recording, and an active SIM. The same iPhone or flagship Android moves up the table several places once it is set up carefully, and the gap between a default and a hardened set-up on the same handset is bigger than the gap between most brands. Budget and lesser-known brands score lowest because preinstalled software and slow or missing security updates are where most proven Android abuse has come from.

Linux phones are the reverse of the everyday phones. They score well on tracking because there is no Google or Apple account and very little data sent home. They score poorly on security because their app sandboxing and exploit protections are far less mature than Android's or iOS's, and Signal support mostly relies on unofficial apps. Sailfish OS runs the Android version of Signal through its compatibility layer, which makes it the most practical of the group, but parts of Sailfish are still closed-source. A Linux phone gives you control and independence from the big platforms; it does not yet give you the strongest protection against a determined attacker.

The two Meshtastic set-ups score highest of all for being hard to track, because nothing they send passes through a carrier, an internet provider or a cloud service. Range and convenience hold their overall scores back. The offline Pixel beats the standalone handheld on security because GrapheneOS is far more hardened than the small microcontroller firmware that runs on devices like the T-Deck. If avoiding providers matters more to you than convenience, treat the "hard to track" column as the one to read.

Adding a SIM costs around four points on tracking for every device. With an active SIM, the phone registers with nearby cell towers, carries fixed identifiers that fake base stations can capture, and exposes its modem to remote attack. GrapheneOS softens the blow by isolating the modem and letting you switch off 2G, the easiest network to abuse.

The dedicated "secure phone" vendors come last for a reason, explained below.

Why "privacy phones" are often the riskiest choice

A whole industry sells locked-down handsets marketed as untraceable and uncrackable. Their track record is the strongest argument against them. Because these networks attract intense police and intelligence interest, one after another has been infiltrated, taken over or dismantled, often after investigators had been reading messages in real time for months.

  1. 2018: Phantom Secure

    The Canadian encrypted phone company was shut down by the FBI and its chief executive was arrested and later jailed in the United States.

  2. 2020: EncroChat

    French and Dutch investigators penetrated the network and pushed surveillance software to users' handsets through the company's own update system. Messages harvested from EncroChat fed prosecutions across Europe, including the UK.

  3. 2021: Sky ECC

    Belgian, Dutch and French police cracked another network marketed as unbreakable and read its traffic before shutting it down.

  4. 2021: ANOM revealed

    ANOM was never a real privacy company. It was secretly run by the FBI with Australian police, which read every message its users sent until the sting was made public.

  5. 2023: Exclu

    Dutch and German authorities dismantled the service, which had an estimated 3,000 users, arresting 45 people including its owners and administrators.

  6. 2024: Ghost and MATRIX

    Police from nine countries took down Ghost despite its triple-layered encryption. Months later, French and Dutch investigators dismantled MATRIX, an invite-only network running on more than 40 servers, after monitoring its messages for three months.

The pattern is not an accident. These products share three weaknesses that a carefully set-up mainstream phone does not have:

  • They are magnets for investigation. A network marketed to people who want to avoid the police concentrates exactly the users law enforcement most wants to watch, so it receives resources and attention an ordinary app never will.
  • One company holds all the keys. Closed software, central servers and a single update channel give investigators one point to seize, subpoena or quietly take over, as EncroChat showed.
  • Owning one draws attention. Carrying a phone from a network associated with organised crime can itself make you a person of interest, and law-abiding users have been swept up alongside everyone else.

Your computer and everything you do online

Phones get most of the attention, but laptops and desktops leave an even richer trail. Everything a phone reveals, a computer can reveal too, and most people have done far less to lock theirs down.

What your internet provider keeps

Under the Investigatory Powers Act, UK internet providers can be required to keep "internet connection records" for up to 12 months. These are not a record of every page you read, but they do log which websites and online services each connection reached, and when. Two major UK broadband providers were confirmed to be trialling their collection in 2021, and police and other public bodies can obtain the records without a judge's warrant. Even when the pages themselves are encrypted, your provider can still see the names of the sites you connect to, unless you route your traffic through a VPN or Tor.

Windows and your data

Windows has a long, documented history of serving as a route into its users' data. None of it required a secret backdoor:

  • Your disk encryption key may not be yours. Windows 11 turns on BitLocker encryption on many new PCs and, if you sign in with a Microsoft account, quietly uploads the recovery key to Microsoft's cloud. In 2025 the FBI obtained a warrant and Microsoft handed over the keys to unlock three seized laptops. Microsoft says it receives around 20 such requests a year.
  • PRISM. Documents leaked by Edward Snowden in 2013 showed that Microsoft had worked with the US National Security Agency to give it access to Outlook.com, Skype and cloud storage, including help getting around its own encryption on web chats.
  • EternalBlue. The NSA found a serious flaw in Windows and kept it for its own use instead of telling Microsoft. When the tool was stolen and leaked in 2017, criminals used it to build the WannaCry ransomware, which crippled parts of the NHS.
  • Telemetry and Recall. Windows sends diagnostic data to Microsoft that cannot be switched off entirely on Home and Pro editions, and increasingly expects you to sign in with a Microsoft account. On newer Copilot+ PCs, the optional Recall feature takes screenshots of your screen every few seconds and makes them searchable. Signal considered it serious enough to block Windows from capturing its chat windows by default.

Macs are more restrained but not immune: FileVault can also store its recovery key with Apple through your iCloud account. Desktop Linux sends almost nothing home by default, and Tails, a Linux system that runs from a USB stick and routes everything through Tor, is designed to leave no trace on the computer once it is shut down.

Why a VPN helps less than you think

A VPN does two useful things: it stops your internet provider seeing which sites you visit, and it stops those sites seeing your home IP address. It does not make you anonymous, and it is easy to undo by accident.

  • You are moving your trust, not removing it. The VPN company now sees everything your provider used to. Several services marketed as "no logs" have turned out to hold records that identified users in US criminal cases, including PureVPN in 2017 and IPVanish in 2018.
  • Leaks give your real location away. Browsers can reveal your real IP address through WebRTC, the technology behind video calls and some streaming. DNS lookups can bypass the tunnel and go straight to your provider, and many VPNs protect only IPv4 traffic, leaving an IPv6 connection exposed. If the VPN drops without a kill switch, your traffic carries on in the open.
  • Streaming and casting go round it. Streaming services compare your IP address with your phone's location, payment details, time zone and account history. Casting to a smart TV or streaming stick usually bypasses the laptop's VPN entirely, because the TV fetches the video over your home connection.
  • Your browser is a fingerprint. Screen size, fonts, graphics hardware, language and dozens of other details combine into an identifier that follows you across sites whatever your IP address. Since February 2025 Google has allowed advertisers using its platforms to fingerprint users, a change the UK Information Commissioner's Office criticised. And if you are signed into Google, Microsoft or Facebook, they know exactly who you are regardless.

VPNs are also in the government's sights. In January 2026 the House of Lords voted to ban VPN services for under-18s, to stop children getting round the Online Safety Act, which in practice would have meant age checks for every UK VPN user. In March, MPs rejected the Lords' restrictions on VPNs and social media in favour of consulting first, but the debate shows where policy may be heading.

What police forensic tools can open

Once a laptop or phone is seized, it goes to a forensic lab equipped with commercial tools such as Passware, for computers and files, and Cellebrite, for phones. Passware's own product comparison lists more than 420 file types and nearly every mainstream encryption product as "supported". That sounds as though nothing is safe, but "supported" means the tool can try, not that it will succeed.

The encryption itself is almost never broken. Modern ciphers such as AES remain effectively uncrackable. The tools go around the maths instead, in five ways:

  • Keys left in memory. While a computer is switched on, asleep or locked, the keys to its encrypted drive sit in RAM. Forensic tools capture that memory, or read the hibernation and page files Windows writes to disk, and extract the keys for BitLocker, FileVault, VeraCrypt and TrueCrypt, along with saved passwords.
  • Keys stored somewhere else. A recovery key saved in your Microsoft or Apple account can simply be requested from the company, as the FBI did with BitLocker.
  • Guessing the password. Graphics cards and cloud servers can try billions of guesses. Short or predictable passwords fall quickly; a long passphrase of five or six random words does not.
  • Weak or outdated protection. Some "passwords" were never real encryption: PDF permission passwords and Outlook data file passwords can be removed almost instantly, and older Office and ZIP formats have known weaknesses that can bypass the password altogether.
  • Hardware and software flaws. Specialist add-ons attack BitLocker set up without a PIN, self-encrypting drives from several manufacturers, and older Macs, while phone tools such as Cellebrite exploit bugs to unlock handsets without the passcode.

The table below summarises the main software and devices these tools target, and how exposed each one really is. It is based on Passware's published product comparison and on Cellebrite support documents leaked in 2024 and 2025. Capabilities change with every update, so treat it as a guide rather than a guarantee.

Software or deviceTargeted byMain way inReal-world risk
Windows login password (local or Microsoft account)PasswareReset or bypassed directlyVery high. A login password alone does not encrypt anything.
PDF permission passwords, Outlook PST filesPasswareProtection removed rather than crackedVery high. These were never real encryption.
Older Office files (.doc, .xls) and legacy ZIP encryptionPasswareKnown weaknesses in the encryption bypass the passwordVery high. Re-save in modern formats with AES encryption.
Modern Office, PDF, 7-Zip, RAR, Apple NotesPasswarePassword guessingDepends on you. Safe with a long passphrase, weak with a typical password.
QuickBooks, FileMaker, Access and similar business filesPasswarePassword guessing; weaker in older versionsOften high. Many business apps use short passwords and older formats.
BitLocker (Windows)PasswareKeys from memory or hibernation file; recovery key from Microsoft account; attacks on TPM-only set-upsHigh on default settings. Low with a pre-boot PIN, the recovery key kept offline, and the PC fully shut down.
FileVault 2 (Mac)PasswareKeys from memory; recovery key stored with Apple; password guessing on older MacsModerate. Low with a strong password, no iCloud recovery key and the Mac shut down.
VeraCrypt and TrueCryptPasswareKeys from memory or hibernation file; password guessingHigh if seized while mounted. Very low if powered off with a strong passphrase.
LUKS and LUKS2 (Linux)PasswarePassword guessing on disk imagesLow with a strong passphrase, as LUKS2 is deliberately slow to guess against.
Hardware and vendor encryption (Dell, SanDisk, WD, Seagate, Transcend, McAfee, Symantec)PasswareDevice-specific flaws; password guessingVaries, often high. Several self-encrypting drives have had serious published flaws.
Password managers (1Password, Dashlane, Enpass, KeePass, LastPass, macOS Keychain)PasswareGuessing the master password against the vault file; extraction from memory while unlockedDepends on the master password. Strong if it is a long passphrase and the vault is locked.
Cryptocurrency wallets (Bitcoin, Ethereum and others)PasswarePassword guessingDepends on you. As strong as the wallet password.
Stock Android phones (most brands, including standard Pixels)CellebriteSoftware exploits, especially after first unlock since bootHigh. Leaked documents showed extraction from most models.
iPhoneCellebriteExploits and passcode guessing on older models and iOS versionsModerate. Lowest on the latest iOS with a long passcode, restarted before seizure.
Pixel with GrapheneOSCellebriteNo working method in leaked 2025 documents for devices patched since late 2022Low. The strongest result of any phone in the leaks.
Any unlocked phone or computerBothFull copy of everything, no cracking neededTotal. Encryption only protects a locked, powered-off device.

The practical lessons are simple. Shut devices down fully rather than leaving them asleep, especially when travelling. Use a pre-boot PIN with BitLocker and keep recovery keys offline. Replace passwords with long passphrases, particularly for disk encryption and password managers. And keep phones updated and restart them regularly, since both iOS and GrapheneOS now do this automatically after a period of inactivity.

What you can do now

  • Keep backups local and encrypted if you are in the UK and do not have Advanced Data Protection. An encrypted backup to your own computer keeps it out of reach of a legal demand to Apple.
  • Use end-to-end encrypted messaging such as Signal, and set a registration lock PIN. Use a username so your number is not shared with contacts.
  • Hide message content from notifications in Signal's settings, and set your phone to show previews only when unlocked, or never.
  • Strip the phone back. Remove apps you do not use, disable preinstalled bloatware, stick to the built-in keyboard, and check which apps have accessibility, microphone and location access.
  • Use a long passcode rather than a short PIN or fingerprint alone, and turn on Lockdown Mode on an iPhone if you have reason to think you could be targeted.
  • Choose hardware with a track record. Buy from manufacturers with published security update commitments, and apply updates promptly.
  • Switch off radios you are not using. Wi-Fi and Bluetooth scanning leak location even without a SIM.
  • Take back your computer's keys. Store your disk encryption recovery key offline rather than in your Microsoft or Apple account, and switch off features that record your screen.
  • Treat a VPN as one layer, not a cloak. Use one with a kill switch, test it for leaks, and remember that signed-in accounts and browser fingerprints identify you regardless.

For businesses the stakes are higher still: client confidentiality, legal privilege and commercial secrets all sit in the same cloud services and messaging apps. If you want an independent review of how your organisation's devices, backups and communications would stand up, our cyber security team can help.

Know where your data actually lives

We'll audit your devices, cloud storage and messaging, and show you where the exposure is.

Get in touch