
South Staffordshire Water
A UK critical national infrastructure water utility serving the West Midlands, fined £963,900 by the ICO in May 2026 for a 2022 ransomware breach with 20-month dwell time.
The ICO fined South Staffordshire Water £963,900 on 12 May 2026 for a 2022 ransomware breach in which an attacker went undetected for 20 months across 95% of its unmonitored IT estate.
Last refreshed: 3 August 2026 · Appears in 1 active topic
If 95 per cent of a water company's IT was unmonitored for 20 months, how many others are in the same position?
Timeline for South Staffordshire Water
Mentioned in: Water plants told to unplug controllers
Cybersecurity: Threats and DefencesReceived £963,900 fine after a 20-month attacker dwell exposing 633,887 individuals' data and 4.1 terabytes of exfiltrated data
Cybersecurity: Threats and Defences: ICO fines South Staffs Water £963,900Background
South Staffordshire Water, trading as South Staffs Water and Cambridge Water, is a UK water utility supplying drinking water to approximately 1.6 million customers across the West Midlands and Cambridgeshire. The company is a subsidiary of South Staffordshire Plc, operates under Ofwat regulation, and is classified as Critical National Infrastructure under UK Government sector designations.
The South Staffordshire fine establishes that NCSC technical guidance on monitoring coverage and network segmentation now carries enforceable weight via ICO interpretation of existing law, ahead of Parliament finalising the new statutory cyber regime for CNI. It is the first explicit CNI water-sector enforcement action, following the Capita precedent of 2023, and gives regulators a citable template for other Ofwat-regulated utilities with similar monitoring gaps.
ICO fines water utility for 20-month gap
The Information Commissioner's Office fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 on 12 May 2026 for a 2022 ransomware intrusion in which an attacker, who entered via phishing, went undetected for 20 months, reached domain administrator privileges and exfiltrated 4.1 terabytes of data . The ICO found only 5 per cent of the company's IT estate was monitored, with no Privileged Access Management and no segmentation between corporate IT and operational technology.
The fine, covering 633,887 affected individuals and including a 40 per cent reduction for early admission, was enforced under existing UK GDPR Article 32 and the Data Protection Act 2018, not the still-pending Cyber Security and Resilience Bill. It is the first explicit CNI water-sector enforcement action, extending the Capita precedent (2023) and giving Parliament a live example of the detection gap its 24-hour notification clause targets.