Back to all lessons
Awareness Lessons
2 months ago

ACRO Criminal Records Office Breached for Two Years Due to Poor Patching and Monitoring

ACRO Criminal Records Office suffered a prolonged unauthorised intrusion lasting nearly two years — from July 2021 to June 2023 — exposing the sensitive personal data of nearly 11,000 individuals. The root cause was a failure to apply timely security patches combined with inadequate security monitoring, allowing the threat actor to persist undetected for an extended period. This case highlights that organisations handling highly sensitive data, such as criminal records, carry an elevated duty of care and must implement robust, proactive security controls. The ICO reprimand serves as a stark reminder that reactive security postures are insufficient when the consequences of a breach involve deeply personal and potentially life-altering information.

Tactical Insight

Immediate actions

  • Audit all systems for outstanding patches and prioritise critical and high-severity vulnerabilities for immediate remediation.
  • Deploy a Security Information and Event Management (SIEM) solution to centralise log collection and enable real-time threat detection.

Long-term improvements

  • Establish a formal, risk-based patch management policy with defined SLAs for patching based on vulnerability severity.
  • Implement a continuous vulnerability management programme using automated scanning tools on both internal and internet-facing assets.
  • Enforce data minimisation and access controls to limit exposure of sensitive personal records to only authorised personnel.

Detection measures

  • Configure alerts for anomalous authentication events, lateral movement, and unusual data access patterns to reduce attacker dwell time.
  • Conduct regular penetration testing and red team exercises to validate the effectiveness of detective and preventive controls.
  • Establish a mean-time-to-detect (MTTD) KPI and review it quarterly to ensure monitoring capabilities are improving over time.