Join the next in-person event in London - spaces limited:

register now
Close Notice

The data you hold isn’t yours. That changes everything about how you protect it

Posted : 17 August 2026

Posted In : Blogs

AdobeStock_549726788 bb

How a care sector IT and security leader is thinking about security without enterprise budgets or enterprise headcount, and why he's pausing before he says yes to AI

Gavin Maynard at Hesley Group, Director of IT and Data, has made security the deliberate foundation of how his organisation operates. Hesley Group provides specialist residential care, supported living and further education for people with learning disabilities and intensive specialist support needs, many of whom are autistic. The data it holds is sensitive. The people it supports depend on its systems being available without exception. “Having access to business applications and care data of the people we support is critical to us,” says Gavin. That reality is why Gavin has built security into the fabric of how the organisation is governed, not as a compliance exercise but as an ongoing operational commitment shaped by experience. Alongside that, he is actively exploring where AI can improve what Hesley Group does and working out how to do it without putting that foundation at risk. 

“Having access to business applications, care data of the people we support is critical to us.” Gavin Maynard, Director of IT and Data, Hesley Group. Watch Gavin’s 80-second interview here:

 

Building security that fits 

The frameworks, the vendor marketing materials, the guidance that circulates about how to build and run a mature security function, are primarily designed with large enterprises in mind. The ones that have dedicated security teams, ring-fenced budgets, clear lines of ownership and someone senior enough to own the problem at board level. That is not most mid-sized organisations in the UK, and it is not Hesley Group. 

Gavin says it directly. “A lot of security advice is targeted towards larger organisations. This advice doesn’t take into account the smaller teams and resource capabilities we have, the smaller budgets that we have, and also the competing priorities that we have across the organisation.” What he is describing is not a failure of effort or ambition. It is a structural mismatch between what the industry produces and what organisations like his genuinely need. 

The data makes that mismatch harder to ignore. The UK Government’s Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found that 43% of UK businesses – that’s 612,000 organisations – experienced a cybersecurity breach or attack in the past 12 months, with revenue impact more than doubling year on year. In adult social care specifically, Government-commissioned research from the Department of Health and Social Care, published in March 2025, found that just under half of all attacks on care providers originated from a third-party organisation, and the most common consequence was not a fine or a headline but the demand on additional staff time. The resource that organisations like Hesley Group have least of. 

 Reframing security so it lands 

Gavin applies discipline to how he makes the case for security investment. “We prioritise security based on risk,” he says. “For us, it’s about assessing what budget we have available and how we can utilise it to minimise the biggest risks across the organisation. We map the risks in a proposal explaining why investment is needed and present that case to the board and C-suite to get buy-in. Then we implement the solutions needed to minimise that risk.” It is the approach of someone who understands that the board stops being a passive audience and becomes the decision-maker on risk appetite, which is where accountability for it belongs. 

The 2025/2026 Breaches Survey recorded a significant decline in medium-sized businesses updating senior management on cybersecurity at least annually, dropping from 78% to 70% in a single year. The awareness gap is not the main problem. The ownership gap is. 

 The AI question Gavin is living with 

 This is where what Gavin is doing carries the most weight for any mid-market organisation facing pressure to move faster on AI. 

AI is coming into care with genuine momentum, and Hesley Group can see where it would help across operational uses. The board interest is real. But Gavin is not ready to say yes yet, and what he says about why is worth hearing before your own board asks you the same question. 

What Gavin is describing is not reluctance. It is governance: the understanding that AI governance is downstream of data governance, and that data governance requires you to already know what you hold, where it sits and who can reach it. Gavin puts it clearly. “Within Hesley Group, we see multiple uses for AI. One of the biggest considerations for us now is how we implement AI while ensuring our data remains secure. We need to have security around that data, visibility of it, and understand exactly where the data is being used across the organisation. Once we’ve got those guardrails in place, we can start on the AI journey.” 

The 2025/2026 Breaches Survey found that while AI adoption is growing across UK businesses, only around a quarter of organisations already using or considering AI have security practices in place to manage the risks. The organisations most exposed are not the ones being cautious. They are the ones that said yes before the foundations were ready. 

For social care providers handling service-user data, the consequences of that miscalculation are not financial abstractions. They are breaches of trust that affect real people. 

Getting there without doing it alone 

Gavin is candid about how Hesley Group has handled the resource problem. “Our partnership with Softwerx bolsters our capabilities and resources while still delivering the security changes that are needed to secure Hesley Group’s environment,” is how he describes it. Not outsourcing. Not handing the problem to someone else. Extending the reach of a lean team when the scope of what is needed exceeds what internal headcount can sustain. 

Most of the security industry is still designing its thinking, its products and its frameworks for someone larger than Hesley Group. Gavin’s approach proves that a mid-market organisation in a sensitive sector can build a security programme that is proportionate, risk-based and fit for purpose. He is also clear that he did not get there by trying to do it alone. 

If this sounds like your organisation 

Softwerx works with mid-sized organisations running Microsoft environments who need the security foundations in place before AI adoption, evolving regulatory obligations or the next incident forces the decision. If you recognise the gap but have not yet found a way to close it with the team and budget you have, that is exactly where we start. 

Talk to us. 

Share

Related insights

Getting started with us couldn’t be easier.

Just use the form or call us on +44 (0) 1223 834 333 to set up a call.

Sign up for our monthly Security Decoded newsletter
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

3rd Party Cookies

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.