We advise on putting in place security measures to protect data. The service is tailored to the nature of the data processed, the Client’s technology landscape and its sector, and can cover individual processing operations or the entire information system. We identify the appropriate technical and organisational measures, including for the purposes of Article 32 GDPR, define incident and breach management procedures, support the selection and configuration of protection solutions (access controls, encryption, backup) and verify their effectiveness over time. We also prepare the procedures for managing incidents and personal data breaches (Articles 33 and 34 GDPR), the policies on the use of company tools and the rules on IT authentication and credential management, covering the secure storage of passwords, data encryption and the other applicable technical controls.