Media and publishing

Keep every title, station, and platform running.

In media, an outage or breach reaches audiences and advertisers immediately. We help media groups bring many brands and platforms under one standard of governance, contain incidents before they take content or revenue offline, and introduce AI into production with clear rules on rights and accountability.

Situations we help with

Across publishing and digital titles; broadcast, radio, and audio; subscriptions and events; and advertising and audience data.

  • Each brand or country runs its own platforms and security, and the board has no single view of cyber risk across the group.
  • Publishing, streaming, and advertising run on cloud platforms, and an outage or compromise at one could take several titles offline.
  • Subscriber and audience data sit across many systems, and nobody can say with confidence where personal data is held or who can reach it.
  • Editorial and production teams are using AI tools without agreed rules on rights, sources, or accountability.
  • Your cyber insurer is asking for evidence of controls and recovery before renewal.

The challenges

Many brands, one board

Media groups can run many titles, stations, and platforms across several countries, each with its own technology and teams, which makes a consistent view of cyber risk hard to maintain.

Always-on digital revenue

Publishing, streaming, subscriptions, and advertising depend on platforms that need to be available around the clock, so an outage translates directly into lost revenue and audience.

Audience and subscriber data

Subscriber, payment, and audience data can sit across many systems and partners, and a breach brings data protection obligations and reputational harm.

Visible targets

Media organisations are prominent online and can attract denial-of-service attacks, account takeovers, and attempts to publish false content through compromised systems.

ENISA's 2025 threat landscape found that low-impact denial-of-service campaigns against organisations' websites made up most recorded incidents in the EU, with media and entertainment among the ten most targeted sectors.

Source: ENISA Threat Landscape 2025, October 2025

AI in media and publishing

Content production and translation

The value
Faster production and wider reach across languages.
What needs governing
Rights in source material, accuracy, and clear editorial accountability for what is published.

Audience and advertising analysis

The value
Better targeting and subscriber retention.
What needs governing
Personal data used beyond agreed purposes, and models nobody can explain to regulators or advertisers.

Archive and metadata

The value
Faster search and reuse of archive content.
What needs governing
Licensed and third-party material reused outside the rights the organisation holds.

AI Factory Design sets the rules for rights, data use, and editorial approval across these uses, so AI can scale across brands under one standard. It is part of our AI Governance and Transformation practice.

Regulation that may apply

UK GDPR and EU GDPR

Applies to
Organisations processing the personal data of subscribers, audiences, and staff.
What it asks
Appropriate security for personal data, and notification of a personal data breach to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it.
Timing
In force.

PCI DSS

Applies to
Organisations that store, process, or transmit payment card data, for example for subscriptions and events.
What it asks
Security requirements for the systems that handle card data, validated as required by card brands and acquirers.
Timing
The future-dated requirements of version 4.0 have been mandatory since 31 March 2025.

NIS2 (EU)

Applies to
Publishing and broadcasting are not NIS2 sectors. Group entities that provide digital services such as online marketplaces can fall within it as digital providers.
What it asks
Where an entity is in scope, management body approval and oversight of the cybersecurity risk management measures, and incident notification.
Timing
Applies through national law.

We use analytics cookies to understand how this site is used. See our Privacy Notice for details. You can change your choice at any time.