← Back to Regulatory Updates

Regulatory Update • August 2026

ACRO Reprimanded Following Cyber Security Failings

Published: 12 August 2026 Topic: Cyber Security / UK GDPR Source: ICO Enforcement

The ICO has reprimanded ACRO Criminal Records Office after cyber security failings left personal information relating to thousands of people potentially exposed.

The case highlights the importance of patch management, supplier oversight, security monitoring and clear accountability for keeping systems protected.

Reading time 2 minutes

What changed

The ICO has reprimanded ACRO Criminal Records Office after cyber security failings left personal information relating to thousands of people potentially exposed.

The incident involved a cyber attack where personal information relating to up to 10,920 people may have been affected. The ICO highlighted failings around patch management, security monitoring and accountability for responding to cyber security alerts.

What is patch management?

Patch management means keeping software, systems and security tools up to date when fixes are released. It is a basic cyber security control because known weaknesses can often be exploited if updates are missed, delayed or not properly monitored.

Why this matters

Cyber security is a data protection issue because organisations must protect personal information against unauthorised access, loss, disclosure and damage. That responsibility includes having appropriate technical and organisational measures in place.

The ACRO case is a reminder that organisations should not assume security controls are working simply because systems, suppliers or alerts exist. There needs to be clear ownership, active monitoring and a practical process for escalating risks when something needs attention.

This also connects with wider ICO action on data protection failures, staff training and governance. See our update on the Metropolitan Police data protection failures. For wider updates across privacy, cyber security and compliance, see our Regulatory Updates page.

What organisations should do

Organisations should use this case as a prompt to check whether cyber security responsibilities are clear and actively managed.

  • Confirm who is responsible for applying software and security updates.
  • Keep a record of critical systems, suppliers and security tools.
  • Check whether vulnerability alerts are reviewed and escalated quickly.
  • Make sure third-party suppliers understand their security responsibilities.
  • Review incident response plans so staff know what to do if a cyber issue is identified.
  • Test whether monitoring tools and alerts are actually being acted on.
  • Document cyber security decisions, risks and remedial actions clearly.

Practical takeaway

Cyber security controls only help if someone owns them, monitors them and acts when risks appear. Organisations should make sure patching, supplier oversight, alerts and incident escalation are clear in practice, not just written down.

Grounded in

ICO enforcement action against ACRO Criminal Records Office following cyber security failings, including findings relating to patch management, security monitoring and accountability for responding to cyber security alerts.

Sources

Future Implementation Support Waitlist