ICO Reprimand Issued to ACRO Criminal Records Office 

The Information Commissioner’s Office has issued a reprimand to ACRO Criminal Records Office (ACRO) after cyber security failings left the personal data of up to ten thousand people potentially exposed. 

The ICO’s investigation found that between August 2022 and March 2023, a hacker gained unauthorised access to ACRO’s website and content management system (CMS). The attacker was able to stage personal data to be stolen, although ACRO could not conclusively determine whether the information was removed from its systems. 

The investigation found that up to 10,920 people may have been affected.
The data potentially exposed included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and highly sensitive criminal offence and special category information. Those affected included applicants for Police Certificates and International Child Protection Certificates, subject access request applicants, and third parties connected to those applications. 

The ICO found ACRO had engaged third-party providers to deliver certain security services, including patch management. However, ACRO did not ensure clear responsibility for identifying and monitoring critical CMS security updates, failed to maintain an effective patch management process, and did not adequately investigate security alerts that could have identified the hacker’s activity earlier. 

In deciding to issue a reprimand, the ICO considered a number of mitigating factors. Network segmentation prevented the hacker from moving beyond the compromised website environment into core systems, reducing the potential scale of harm.
The ICO additionally welcomed the remedial action taken by ACRO following the incident, including decommissioning the compromised infrastructure, migrating services elsewhere, implementing security monitoring, improving visibility of cyber threats and strengthening network segmentation. 

The Reprimand mentions infringements of Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR. However some commentators have questioned whether it should be for breaches of Part 3 of the Data Protection Act 2018 which applies to law enforcement processing (See Jon Baines post here.) 

With the rapid advance of AI, including emerging threats from AI agents, it is critical that organisations focus on cyber security. The ICO has highlighted the following action points for organisations to avoid similar breaches: 

Make accountability clear: Define who is responsible for identifying, assessing and implementing security updates across all systems and suppliers. 

Act on warning signs: Ensure security alerts are actively monitored, investigated and escalated so threats are identified before they become major incidents. 

Get the basics right: Effective patch management, vulnerability management and regular security testing remain some of the most important defences against cyber attacks. 

The ICO’s guidance on cyber security can be read here

For more on this topic, listen to Caroline Wong, an AI cyber security expert, speaking on the Guardians of Data podcast. 

We have two workshops coming up (How to Increase Cyber Security in your Organisation and Cyber Security for DPOs) which are ideal for organisations who wish to upskill their employees about cyber security.  

Author: actnowtraining

Act Now Training is Europe's leading provider of information governance training, serving government agencies, multinational corporations, financial institutions, and corporate law firms. Our associates have decades of information governance experience. We pride ourselves on delivering high quality training that is practical and makes the complex simple. Our extensive programme ranges from short webinars and one day workshops through to higher level practitioner certificate courses delivered online or in the classroom.

Leave a Reply

Discover more from Your Front Page For Information Governance News

Subscribe now to keep reading and get access to the full archive.

Continue reading