Published Security3 min read
ICO reprimands ACRO: nobody owned the CMS patches, nobody read the malware alerts
The regulator found GDPR infringement on two counts after an attacker held access to ACRO's website for roughly seven months, without proving any data was taken.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- The UK's Information Commissioner's Office issued a reprimand to the Criminal Records Office (ACRO) after multiple security failings led to a 2023 data breach affecting over 10,000 people.
- Between August 2022 and March 2023, a hacker gained unauthorized access to ACRO's website and content management system, according to the ICO.
- The ICO said poor record keeping by ACRO means it remains unclear whether the attacker ever exfiltrated the data on 10,920 victims.
- The ICO's ruling of GDPR infringement hinges on two main security failings: poor patch management and insufficient security monitoring.
- ACRO's managed service provider took care of OS patches, but not those of the Kentico CMS it used, the ICO revealed.
Compiled by The WatchSomething wrong?How this is made
Why it matters
The UK Information Commissioner's Office has reprimanded the Criminal Records Office (ACRO) over a breach in which an attacker gained unauthorised access to the policing agency's website and content management system between August 2022 and March 2023, affecting 10,920 people [1][2][3]. What makes the ruling worth reading is its structure: the ICO rested its GDPR infringement finding on two separate security failings, and it did so without establishing that any data ever left the building [4][3].
The first failing is a gap in ownership rather than in technology. ACRO's managed service provider patched the operating system but not the Kentico CMS running on it [5]. The web development supplier was responsible for applying CMS patches but not for identifying when patches were required [6]. ACRO itself did not monitor for required security patches, which the ICO called an absence of oversight for an important security control [7]. Three parties, one control, nobody holding it. That will look familiar to anyone who has read their own MSP statement of work closely: scope is defined by what the provider agreed to do, not by what needs doing.
The second failing is monitoring. ACRO had a Trend Micro product installed to detect and quarantine malware, and it generated alerts when it did so; those alerts were not reviewed or acted upon [8]. The ICO's assessment is that had they been investigated at the time, with an appropriate response, further malicious activity could likely have been prevented [9]. A detection tool whose output nobody reads is, for regulatory purposes, close to not having one.
The exfiltration point deserves emphasis. The ICO said poor record keeping by ACRO means it remains unclear whether the attacker took the data at all [3]. The exposed categories included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and criminal offence and special category information [10]. Among the dozens of complaints ACRO received were several from people connected to International Child Protection Certificates and from victims of domestic violence [11]. The inability to answer the exfiltration question was not treated as a defence.
What kept this to a reprimand: ACRO had network segmentation in place, which reduced the blast radius, and it took remedial action, including decommissioning the compromised infrastructure, migrating services elsewhere, implementing security monitoring, improving visibility of cyber threats and strengthening segmentation [12][13]. According to Infosecurity Magazine, it is also likely the agency escaped a fine because of the ICO's public sector approach, which limits financial penalties on the sector [14]. A private-sector organisation with the same facts should not assume the same landing.
Jonathan Balmforth, the ICO's group manager for civil and cyber investigations, said organisations must ensure clear accountability for identifying, assessing and applying security updates, and effective monitoring so that warning signs are identified, investigated and acted upon promptly [15]. He added that the right policies, responsibilities and oversight arrangements matter as much as the right technology [16].
Watch whether the ICO's published advice, which tells organisations to define who is responsible for updates across all systems, to ensure alerts are monitored and escalated, and to get patch and vulnerability management and regular security testing right [17], starts showing up as the benchmark in enforcement against bodies where fines are actually on the table. The seven-month access window here [18] is the part that will be quoted back at defendants.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The UK's Information Commissioner's Office issued a reprimand to the Criminal Records Office (ACRO) after multiple security failings led to a 2023 data breach affecting over 10,000 people.
- [2]
Between August 2022 and March 2023, a hacker gained unauthorized access to ACRO's website and content management system, according to the ICO.
- [3]
The ICO said poor record keeping by ACRO means it remains unclear whether the attacker ever exfiltrated the data on 10,920 victims.
- [4]
The ICO's ruling of GDPR infringement hinges on two main security failings: poor patch management and insufficient security monitoring.
- [5]
ACRO's managed service provider took care of OS patches, but not those of the Kentico CMS it used, the ICO revealed.
- [6]
ACRO's web development supplier was responsible for applying patches to the CMS, but not for identifying when patches were required.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- infosecurity-magazine.comAug 13ICO Reprimands Criminal Records Office After 2023 Breach
Additional citations
- ICO, reported by Infosecurity Magazine
- ICO
- ICO report
- Infosecurity Magazine
- Jonathan Balmforth, ICO



