Digital risk

OSINT, cyber security and digital workplace risk.

People, technology and organisational risk increasingly overlap. We support responsible online investigation, cyber governance, home-working security and the introduction of AI and digital monitoring in the workplace.

Digital risk is rarely purely technical. It affects employees, investigations, governance, home working, confidential information and the responsible use of AI. We help organisations define the people and governance controls around those risks.

Areas covered

  • OSINT and online investigations

    Proportionate use of publicly available information in workplace investigations, due diligence and organisational decision-making, with clear boundaries around relevance, necessity and fairness.

  • Cyber security governance

    Responsibilities, policies, decision routes and working practices that sit around technical systems and help leaders exercise meaningful oversight.

  • Home and remote-working security

    Practical controls for staff accessing systems and confidential information from home, while travelling or through personal devices.

  • AI and digital workplace governance

    Responsible introduction of AI, automated tools, monitoring and digital decision support, including acceptable use, data handling and management accountability.

What you can expect

  • clear scoping and proportionality;
  • documented boundaries around the use of information;
  • practical policy and governance recommendations;
  • alignment between people, legal, operational and technical responsibilities;
  • explicit referral where specialist technical expertise is required.

Where technical support is required

Your People Team does not provide penetration testing, digital forensics or managed cyber security services. Where specialist technical work is required, we help define the organisational need, identify the people and governance implications and work alongside appropriately qualified providers.

Where this work leads to documented policy, the Policy Store covers the same ground. The Technology, Data and AI Pack is the closest match.

Common questions

Do you carry out penetration testing or digital forensics?

No. We focus on the people, governance, investigation and workplace-policy aspects of digital risk and refer specialist technical work where required.

Can public online information be used in a workplace investigation?

Sometimes, but relevance, necessity, accuracy, proportionality, data protection and fairness must all be considered. The fact that information is public does not make every use appropriate.

Can you help us create an AI policy?

Yes. The work can cover acceptable use, confidential information, decision accountability, manager expectations, procurement questions and practical implementation.

This page describes an approach rather than a fixed product. Scope, and whether this is the right service at all, are established in the first conversation. Nothing here is legal advice.

Need an experienced independent perspective?

Tell us what is happening. We will help you understand the immediate risks, practical options and sensible next step.