Britain's ICO, the Information Commissioner's Office, reprimanded ACRO Criminal Records Office on 12 August after a compromise of its website and content management system put data relating to up to 10,920 people at risk 1. ACRO is the UK police body that runs criminal record checks, including the certificates people need for visas and overseas employment, so the records in question describe who has and has not been convicted of what.
The regulator's findings name three failures: unclear ownership of critical updates to the content management system, ineffective patch management, and inadequate investigation of security alerts. None of those is an attacker capability. All three are questions about who inside an organisation is answerable for a piece of software, and the ICO's answer in this case was that nobody clearly was. Network segmentation and later remedial work counted as mitigation, so the regulator stopped short of a fine.
Enforcement on this beat usually points at the intruder. Two members of Scattered Spider were jailed at Woolwich Crown Court in July over the attack on Transport for London . A reprimand points the other way, at the organisation that held the data, and it does so on evidence that never needed a suspect to be identified: the patching record and the alert log were enough.
A reprimand carries no financial penalty, which is the standing criticism of the instrument, though it does put a named public body's patch-management practice on the regulator's published record. For any organisation reading it as a benchmark, the checkable question is not whether a patch policy exists. It is whether a named person owns updates to each internet-facing system, and whether anyone acted on the last alert the monitoring produced.
