Local Government Lawyer

 


Cyber security failings at ACRO Criminal Records Office left the personal information of up to ten thousand people, including some individuals’ sensitive data, potentially exposed.

These are the findings of an investigation carried out by the Information Commissioner's Office (ICO), which has now urged organisations to strengthen “patching and security monitoring processes”.

The investigation found that between August 2022 and March 2023, a hacker gained unauthorised access to ACRO’s website and content management system (CMS).

The attacker was then able to stage personal information to be stolen, although ACRO could not conclusively determine whether the information was removed from its systems, the ICO said.

The investigation found that up to 10,920 people may have been affected.

The ICO said: “The data potentially exposed included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and highly sensitive criminal offence and special category information.

“Those affected included applicants for Police Certificates and International Child Protection Certificates, subject access request applicants, and third parties connected to those applications.”

Concluding the investigation, the watchdog found that ACRO had engaged third-party providers to deliver certain security services, including patch management.

However, ACRO “did not ensure clear responsibility for identifying and monitoring critical CMS security updates, failed to maintain an effective patch management process, and did not adequately investigate security alerts that could have identified the hacker’s activity earlier”. 

In deciding to issue a reprimand, the ICO took into account a number of mitigating factors.

It noted: “Network segmentation prevented the hacker from moving beyond the compromised website environment into core systems, reducing the potential scale of harm”.

The ICO additionally welcomed remedial action taken by ACRO following the incident, including decommissioning the compromised infrastructure, migrating services elsewhere, implementing security monitoring, improving visibility of cyber threats and strengthening network segmentation. 

The ICO issued the following advice for other organisations:

  • “Make accountability clear: Define who is responsible for identifying, assessing and implementing security updates across all systems and suppliers. 
  • Act on warning signs: Ensure security alerts are actively monitored, investigated and escalated so threats are identified before they become major incidents. 
  • Get the basics right: Effective patch management, vulnerability management and regular security testing remain some of the most important defences against cyber attacks.”

Jonathan Balmforth, ICO’s Group Manager - Civil and Cyber Investigations, said: “This case highlights how basic cyber security failings can create significant risks for thousands of people, particularly where organisations process large volumes of highly sensitive personal information. 

"Organisations must ensure there is clear accountability for identifying, assessing and applying security updates. They must also have effective monitoring in place so that warning signs of cyber-attacks are identified, investigated and acted upon promptly. 

"The lessons from this incident are clear. Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology.”

He added: "We welcome the improvements ACRO has made since these incidents. We hope other organisations will use this case as an opportunity to review their own processes and responses to ensure personal information remains properly protected." 

A spokesperson for ACRO said: “Since the cyber security incident was identified in March 2023, we have worked hard to strengthen our systems and safeguards.

“In particular, we immediately took the previous website offline and subsequently decommissioned it. We also took steps to protect customers, including making sure anyone potentially affected was informed at the earliest possible stage.

“We now have a new website that has been rigorously tested and migrated to the Salesforce Experience Cloud. We have implemented Security Information and Event Management (SIEM), and enhanced visibility and monitoring. These actions have ensured a robust and secure platform.

“We accept the ICO's findings of the infringements. We are grateful for the recognition from the Information Commissioner of the multiple remedial steps ACRO has taken in light of this incident and are committed to maintaining high standards of data protection and information security in future.”

Lottie Winson

Directory

Events

Newsletter signup