Guidance
Protecting bulk personal data
Fifteen best-practice measures to protect digital bulk data.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 5 of 5
1. Knowing what data you hold and why
8. Not exposing vulnerable interfaces externally
14. Prevent spear-phishing emails targeting an administrator from resulting in total compromise of the data
10. Detecting basic attacks
11. Monitoring atypical access to the data
In some scenarios, the use of encryption to protect bulk data should be the norm. For example, where data is transmitted over the internet, stored on a laptop, or stored on removable media.
However, encryption relies on good key management, and in some scenarios it is challenging to engineer a solution which makes meaningful use of encryption to protect data.
This is sometimes the case in systems which are always online, where data needs to be available to query. In these scenarios your systems architects and designers will need to think carefully about how encryption can be used in a meaningful way.
Further advice on secure design
We have published a set of security design principles to inform technical architects and developers building systems and services that need to protect important data.

