[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbbk8S6wRkneHKGsxxz-OPwrDXegEv0_dEaZ2AWmP02w":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"87480b36-77f2-40ef-bc5c-c57fce729693","acro-criminal-records-office-breached-for-two-years-due-to-poor-patching-and-monitoring","83eb75ea-a3c1-4e49-835e-53c1cc7e9c99","ACRO Criminal Records Office Breached for Two Years Due to Poor Patching and Monitoring","ACRO Criminal Records Office suffered a prolonged unauthorised intrusion lasting nearly two years — from July 2021 to June 2023 — exposing the sensitive personal data of nearly 11,000 individuals. The root cause was a failure to apply timely security patches combined with inadequate security monitoring, allowing the threat actor to persist undetected for an extended period. This case highlights that organisations handling highly sensitive data, such as criminal records, carry an elevated duty of care and must implement robust, proactive security controls. The ICO reprimand serves as a stark reminder that reactive security postures are insufficient when the consequences of a breach involve deeply personal and potentially life-altering information.","**Immediate actions:**\n- Audit all systems for outstanding patches and prioritise critical and high-severity vulnerabilities for immediate remediation.\n- Deploy a Security Information and Event Management (SIEM) solution to centralise log collection and enable real-time threat detection.\n\n**Long-term improvements:**\n- Establish a formal, risk-based patch management policy with defined SLAs for patching based on vulnerability severity.\n- Implement a continuous vulnerability management programme using automated scanning tools on both internal and internet-facing assets.\n- Enforce data minimisation and access controls to limit exposure of sensitive personal records to only authorised personnel.\n\n**Detection measures:**\n- Configure alerts for anomalous authentication events, lateral movement, and unusual data access patterns to reduce attacker dwell time.\n- Conduct regular penetration testing and red team exercises to validate the effectiveness of detective and preventive controls.\n- Establish a mean-time-to-detect (MTTD) KPI and review it quarterly to ensure monitoring capabilities are improving over time.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 7: Continuous Vulnerability Management","CIS Control 8: Audit Log Management","CIS Control 3: Data Protection","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 AU-6: Audit Record Review, Analysis, and Reporting","NIST SP 800-53 AC-3: Access Enforcement","NIST CSF DE.CM: Security Continuous Monitoring","GDPR Article 5(1)(f): Integrity and Confidentiality","GDPR Article 32: Security of Processing","UK Data Protection Act 2018","ISO\u002FIEC 27001:2022 Annex A 8.8: Management of Technical Vulnerabilities","ITIL Change Management: Emergency Change Procedures","published","2026-08-21T14:22:10.603194+00:00","2026-08-21T14:22:10.484+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=ICO_(UK)_-_ACRO_Criminal_Records_Office&diff=52747&oldid=0","ico-uk-acro-criminal-records-office-a26b5c","ICO (UK) - ACRO Criminal Records Office",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":39,"name":40,"slug":41,"description":42,"color":43},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":45,"name":46,"slug":47,"description":48,"color":49},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]