The ICO has just written up what happens when nobody owns the patching
Compliance & Data

The ICO has just written up what happens when nobody owns the patching

A content management system sat unpatched for years because each supplier understood the job to be somebody else's. The regulator named that gap, not the software, as the failure.

17 August 20265 min read

On 12 August the Information Commissioner's Office reprimanded ACRO Criminal Records Office after an attacker held unauthorised access to its website and content management system between August 2022 and March 2023. Up to 10,920 people may have been affected, and the data at risk included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data and criminal offence records. ACRO could not conclusively establish whether any of it was actually removed from its systems. The part worth reading for any business that buys IT from somebody else is not the scale. It is the reason the regulator gave.

The gap sat between two suppliers

ACRO had engaged third-party providers to deliver security services, patch management among them. A managed service provider looked after operating system patches. A web development supplier applied patches to the content management system but was not responsible for working out when they were needed. ACRO itself did not monitor for required security patches. In the ICO's words, it "did not ensure clear responsibility for identifying and monitoring critical CMS security updates" and "failed to maintain an effective patch management process". The Register reported the platform involved was Kentico CMS version 12.0.0, running unpatched from September 2019 until March 2023, and that ACRO went on to notify 84,048 individuals in total. Every supplier was doing the job it thought it had. The job of noticing what nobody had claimed did not exist.

The alerts fired and went unread

Malware detection was installed and it worked. Trend Micro raised alerts on the malicious activity, and those alerts were not reviewed or acted upon. The ICO's assessment is blunt: had they been investigated at the time and an appropriate response carried out, it is likely that further malicious activity could have been prevented. A detection product that nobody reads is a line on the invoice rather than a defence, and it is a particularly expensive kind of gap because it looks covered on any inventory of controls.

What kept it to a reprimand

The ICO issued a reprimand rather than a fine, and set out why. Network segmentation stopped the attacker moving out of the compromised website environment and into core systems, which limited how far the incident could reach. The regulator also credited the remedial work afterwards: decommissioning the compromised infrastructure, migrating services elsewhere, putting security monitoring in place, improving visibility of threats and strengthening segmentation. The architectural decision taken before the incident is the one that capped the damage.

The same shape in a 30-person business

Swap the criminal records office for a firm with three sites and a website. The site is with a web agency. The laptops and servers are with an IT provider. The accounts package updates itself, or so everybody assumes. The firewall is with whoever installed it, the card terminals with the payment provider, and the CCTV recorder with the installer who has not been on site since it went in. Ask each of them which updates they apply and you will get four confident answers that do not join up along the edges. The vulnerable thing is rarely the system everybody argues about. It is the one nobody has named.

What the ICO is telling everyone else to do

The regulator published its advice alongside the reprimand, in three lines. Make accountability clear: define who is responsible for identifying, assessing and implementing security updates across all systems and suppliers. Act on warning signs: make sure security alerts are actively monitored, investigated and escalated so threats are caught before they become incidents. Get the basics right: patch management, vulnerability management and regular security testing remain some of the most important defences there are. Jonathan Balmforth, the ICO's group manager for civil and cyber investigations, put it as having the right policies, responsibilities and oversight arrangements in place being just as important as having the right technology.

What this means for your business

Write the list. Every system the business runs, who applies its updates, and who checks that they were applied. Include the website, the payment terminals, the firewall, the CCTV recorder and anything with a web login, because those are the ones that fall between contracts. Then find out who reads the alerts from your antivirus and your firewall, and what happens to one that fires at two on a Sunday morning. If the answer is that it lands in a console nobody opens, you are paying for detection and taking none of the benefit. ACRO avoided a fine largely because network segmentation had already limited how far an attacker could get, which is the useful lesson buried in it: the decisions that set how bad an incident becomes are made long before anyone notices it has started.

#WEARECOBALT

Ready when you are.

Tell us what's slowing your business down. We'll tell you exactly how we'd fix it — plainly, with no obligation.