The British authority reprimands ACRO following cybersecurity flaws exposing sensitive data

The British data protection authority issued a reprimand against the Criminal Records Office (ACRO) due to fundamental cybersecurity failures, including inadequate patch management and alert monitoring, which allowed prolonged unauthorized access to its website.

Facts and context

The British data protection authority (ICO) published a reprimand decision against the Criminal Records Office (ACRO) for serious cybersecurity breaches potentially exposing personal data, including sensitive information, of nearly 10,920 individuals.

The case arose from an investigation conducted by the supervisory authority following a cybersecurity incident that allowed an attacker unauthorized access to the organization's website and content management system between August 2022 and March 2023.

Grounds for the decision

  • Obligation to ensure the security of processing: the authority found that the organization had not implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk. Although it engaged third-party providers for patch management, ACRO did not clearly define responsibilities for identifying and tracking critical security updates of its content management system. Furthermore, the organization did not maintain an effective patch management process and did not adequately investigate security alerts, which could have allowed earlier detection of the attacker's activity.

Authority's decision

Consequently, the authority issued a reprimand against the Criminal Records Office (ACRO). In deciding this measure, the authority took into account mitigating factors, including network segmentation that prevented the attacker from accessing main systems, as well as the prompt corrective measures implemented by the organization.

Lessons learned

This decision reminds that:

  • The responsibility for identifying, assessing, and applying security updates must be clearly defined, including when these tasks are outsourced to providers.
  • Security alerts must be actively monitored and thoroughly investigated to identify and address threats before they escalate into major incidents.
  • Implementing robust processes for patch and vulnerability management, as well as conducting regular security testing, are essential defenses against cyberattacks.
  • Network segmentation is an effective technical measure to limit the scope of a compromise and reduce the potential damage in case of intrusion.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire