UK ICO Reprimands ACRO Following Cybersecurity Failings

The UK’s Information Commissioner’s Office has reprimanded ACRO, the Criminal Records Office, following cybersecurity failures involving a website compromise that potentially affected up to 10,000 people.

The case highlights the relationship between cybersecurity controls and data protection compliance. Organizations processing sensitive personal information are expected to maintain appropriate technical and organizational measures to protect that information against unauthorized access and security incidents.

The ICO’s action demonstrates that cybersecurity weaknesses can result in regulatory consequences even when an incident is not described simply as a traditional large-scale data breach.

Organizations should therefore assess whether their websites, authentication systems, access controls, monitoring capabilities and incident response procedures are sufficiently robust.

Picture of Dposphere

Dposphere

Recent Post

The European cybersecurity certification ecosystem is continuing to develop as organizations face growing pressure to demonstrate

The European Union Agency for Cybersecurity (ENISA) announced that it is expanding its role within the

The UK Information Commissioner’s Office has highlighted the growing importance of strong data protection governance when