News

Security alerts nobody checked: the ACRO reprimand and the question to ask your IT provider

The Information Commissioner's Office has reprimanded ACRO Criminal Records Office after an attacker had access to its website and content management system between August 2022 and March 2023.

Up to 10,920 people may have been affected. The data at risk included passport and driving licence details, bank account information, biometric data and criminal record information.

The part that should worry every business

ACRO had security software installed, and it raised alerts. They weren't investigated. ACRO also used outside providers for patching but hadn't made anyone clearly responsible for finding and applying critical updates. The ICO concluded that acting on the alerts would likely have prevented further malicious activity.

Having the tool isn't the control. Having a named person who reads the alerts, escalates them and records what was checked is the control.

Questions for your IT provider

  • Who reviews security alerts from our endpoints, firewall and Microsoft 365?
  • How quickly, and what happens outside business hours?
  • Who is responsible for critical security updates, and how do we know they've been applied?

If you aren't sure who is watching your alerts, we'll review how they're handled and put a name against it.

Want a hand with this? Talk to us.

Source: The Record: Three intrusions at UK criminal records office went undetected for two years

← All insights