Practical guides on data protection, security and audit.
Short, plain explanations from the MH Consulting team.
We write these guides for managers, compliance officers and IT teams who need a clear answer without the legal jargon. Each one explains a single topic, what it requires in practice and the mistakes we see most often, and links to the service that covers it.
What a DPO does: duties, independence and limits
What a Data Protection Officer (DPO) does: the main duties, why the role must be independent and what is not the DPO's responsibility.
Read the articleData subject requests: how to respond
How to respond to requests for access, correction or erasure of personal data: a five-step process and the mistakes to avoid.
Read the articleData breach: what to do in the first hours
What to do when a personal data breach happens: containing the damage, assessing the risk, notifications and documentation.
Read the articleISO 27001: the steps to certification
The steps to ISO 27001 certification: scope, risk assessment, controls, internal audit and the two stages of the certification audit.
Read the articleEU AI Act: the four risk categories
How the EU AI Act classifies artificial intelligence systems into four risk levels and what that means for your company.
Read the articleBusiness continuity plan: where to start
How to build a business continuity plan: impact analysis, RTO and RPO, recovery strategies and testing the plan.
Read the articleDPIA: what it is and when to do one
What a data protection impact assessment (DPIA) is, when it is required, what it contains and the most common mistakes.
Read the articleRecord of processing activities: how to build one
What a record of processing activities is, what goes into it, and how to build it and keep it current in four steps.
Read the articleSOC 2 or ISO 27001: which to choose
A comparison of SOC 2 and ISO 27001: what each one is, how they differ, who asks for them and how to decide which your company needs.
Read the articleHow to prepare for a penetration test
How to prepare for a penetration test: scope, type of test, rules of engagement, your internal team and what to do with the report.
Read the articleTopics we work on
- Law 124 and GDPR Compliance
- Data Protection Officer (DPO)
- ISO 27001 Implementation and Audit
- SOC 1, SOC 2 and SOC 3 Reports
- Penetration Testing and Red Teaming
- IT Audit
- Cybersecurity and Resilience
- AI Compliance and Security
- Governance, Risk and Compliance (GRC)
- Cloud Security Architecture
- SOX and J-SOX Compliance
- ESG and Sustainability Reporting
- IT Strategy and Service Management
Let's talk about your next engagement.
Tell us about your engagement — we typically respond within one business day.
