Records office reprimanded after nobody owned the patching

Tech and AI

Records office reprimanded after nobody owned the patching

By Staff Writer  |  13 August 2026

Rows of server cabinets and patch cabling in a data centre aisle

An attacker sat inside the UK criminal records office website for seven months. The regulator found no one had settled whose job it was to apply the updates.

The Information Commissioner's Office reprimanded ACRO Criminal Records Office on 12 August over failings that left the personal information of up to 10,920 people potentially exposed. An attacker held unauthorised access to the office's website and content management system between August 2022 and March 2023, and staged personal data ready to be taken. ACRO could not establish whether it was ever removed.

The material at risk was not routine. It included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account details, biometric data and criminal offence information. Those affected included applicants for Police Certificates and International Child Protection Certificates, subject access request applicants and third parties connected to those applications.

The regulator's finding is not that the technology failed. It is that responsibility for maintaining it was never fixed on anyone.

A gap between the client and the supplier

ACRO had engaged third-party providers to deliver security services, patch management among them. The regulator found that ACRO did not ensure clear responsibility for identifying and monitoring critical updates to the content management system, did not maintain an effective patch management process, and did not adequately investigate the security alerts that could have exposed the intrusion sooner.

The reported detail is worse than the summary. The office ran the same version of its content management system from September 2019 until March 2023 without applying the patches and hotfixes issued over that period. The managed service provider did not learn that patching fell to it until February 2020, and continued to assume it had no duty to watch for updates. There was no documented policy covering the patching of that system at all.

Antivirus alerts were generated. The office told the regulator it could not establish what processes existed at the time for assessing or handling them, nor which roles were responsible for reviewing them, so they went unread.

Organisations must ensure there is clear accountability for identifying, assessing and applying security updates. They must also have effective monitoring in place so that warning signs of cyber-attacks are identified, investigated and acted upon promptly.

Jonathan Balmforth, Group Manager for Civil and Cyber Investigations, Information Commissioner's Office

Why it was a reprimand and not a fine

Network segmentation stopped the attacker moving out of the compromised website environment and into core systems, which the regulator treated as a mitigating factor and which limited the scale of the harm. It also credited the remedial work done since: the compromised infrastructure was decommissioned, services were migrated, security monitoring was implemented and segmentation was strengthened.

A reprimand is the lightest of the three enforcement routes available, below an enforcement notice and well below a monetary penalty, and it is used often for public bodies where a fine simply moves money between public accounts. ACRO said it accepts the findings, that it took the previous website offline immediately and later decommissioned it, and that anyone potentially affected was told at the earliest possible stage.

The transferable point

The failure here is contractual before it is technical. Two organisations each believed the other was watching for security updates, nobody wrote it down, and the gap ran for three and a half years until somebody walked through it. Poor logging then meant that even an extensive forensic investigation could not answer the only question the affected individuals cared about, which was whether their data actually left the building.

The regulator's advice to everyone else is three lines long: define who is responsible for identifying, assessing and applying updates across all systems and suppliers; make sure alerts are monitored, investigated and escalated; and get patching, vulnerability management and regular testing right before anything more sophisticated. Anyone who has ever argued about scope at the boundary between a client and its supplier will recognise the shape of it.