the ability of network and information systems to resist, at a given level of confidence, any action that compromises the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data, or the related services offered by, or accessible via, those systems. As noted in the ICO’s guidance, this definition essentially refers to the concept of ‘information security’, and aligns closely with established standards such as ISO/IEC 27000: 2018