ACRO Criminal Records Office Breached for 7 Months Due to Poor Patching and Monitoring
The ACRO Criminal Records Office allowed unauthorised access to sensitive personal data for nearly seven months — from August 2022 to March 2023 — primarily because of inadequate patch management and insufficient security monitoring. Attackers were able to maintain prolonged access precisely because the organisation lacked the detective controls needed to identify and respond to the intrusion in a timely manner. This is particularly serious given the sensitivity of criminal records data, where exposure can have severe consequences for individuals' rights and freedoms. The ICO's reprimand under UK GDPR underscores that public sector bodies handling high-risk personal data are held to a high standard of technical and organisational security. Failing to patch known vulnerabilities and monitor systems effectively is not just a technical shortcoming — it is a legal obligation under data protection law.
Tactical Insight
Immediate actions
- Audit all internet-facing systems for outstanding patches and apply critical security updates within 24–72 hours of release.
- Deploy a Security Information and Event Management (SIEM) solution to centralise log collection and enable real-time anomaly detection.
Long-term improvements
- Establish a formal patch management policy with defined SLAs based on vulnerability severity (e.g., Critical: 24 hrs, High: 7 days).
- Conduct regular penetration testing and vulnerability assessments — at minimum annually and after significant infrastructure changes.
- Implement a Data Protection Impact Assessment (DPIA) process for systems handling sensitive personal data to identify and mitigate risks proactively.
Detection & response measures
- Configure automated alerting for indicators of compromise (IoC) such as unusual authentication patterns, lateral movement, or large data transfers.
- Define and rehearse an Incident Response Plan (IRP) that includes specific playbooks for unauthorised access to personal data.
- Establish a maximum breach detection target (e.g., mean time to detect under 24 hours) and review metrics quarterly.