The Information Commissioner's Office reprimanded ACRO Criminal Records Office in March 2024 after a hacker spent seven months inside their systems, staging personal data for exfiltration. The breach potentially exposed 10,920 individuals' records, including biometric data, criminal offence information, and financial details. The root cause? Failures in basic patch management and security alert response.
This enforcement action reveals a pattern your team should examine closely: the gap between engaging security providers and maintaining actual accountability for critical updates.
What the Investigation Found
The ICO identified three specific failures that violated Articles 32(1), 32(1)(b), and 32(1)(d) of the UK GDPR:
No clear ownership of critical updates. ACRO engaged third-party providers for patch management but never established who was responsible for identifying and monitoring security updates to their content management system. The patches existed, but no one had clear responsibility to apply them.
Ineffective patch management process. Even with external security services contracted, ACRO lacked a functioning process to ensure critical updates reached production systems. This isn't about budget or resources; it's about defined workflows and verification steps.
Ignored security alerts. The investigation found ACRO failed to adequately investigate alerts that would have identified the attacker's presence earlier. For seven months, between August 2022 and March 2023, the hacker maintained access while staging data for theft.
The data potentially exposed included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and criminal offence information. Affected individuals included applicants for Police Certificates and International Child Protection Certificates, plus third parties connected to those applications.
One mitigating factor limited the damage: network segmentation prevented lateral movement into core systems. The ICO acknowledged this in choosing a reprimand over a fine, along with ACRO's post-incident remediation including decommissioning compromised infrastructure and implementing enhanced monitoring.
What This Means for Your Team
The third-party accountability gap is wider than most teams realize. You can't outsource responsibility for appropriate technical and organisational measures under Article 32. When you engage a processor or security provider for patch management, you remain the controller accountable for ensuring those patches actually get applied. Your contract must specify who monitors for critical updates, who tests them, who approves deployment, and what the timeline is from processor release to production.
"Patch management" without defined ownership is security theater. ACRO had contracted services but no one clearly responsible for the CMS. Consider your own environment: who owns patch decisions for your customer portal? Your marketing automation platform? Your HR system? If the answer is "IT handles that" or "our processor manages it," you haven't answered the question.
Security alerts require investigation protocols, not just logging. The investigation found inadequate response to alerts that could have caught the breach earlier. Your team needs documented escalation paths: which alerts trigger immediate investigation, who reviews them, what constitutes sufficient follow-up, and how you verify resolution.
Action Items by Priority
Immediate (this week):
Map every system processing personal data to a named individual responsible for security updates. Include SaaS platforms, self-hosted applications, and infrastructure components. Where third parties provide patch services, document in writing who monitors processor security bulletins and who approves deployment timing.
Create a register showing: system name, data processed, update responsibility owner, last patch date, next scheduled review. If you can't complete this for a system, that system has an accountability gap.
Within 30 days:
Audit your processor agreements for patch management obligations. Your contracts should specify maximum timeframes from critical patch release to deployment, testing requirements before production, and notification procedures if patches can't be applied on schedule.
Document your security alert triage process. Define severity levels, investigation requirements for each level, escalation triggers, and verification steps before closing alerts. Test the process with a tabletop exercise.
Review network segmentation for your most sensitive processing activities. Can an attacker who compromises your web-facing systems reach databases containing special category data? If yes, prioritize additional controls.
Within 90 days:
Implement vulnerability scanning that covers all systems processing personal data, not just infrastructure. Many breaches exploit application-layer vulnerabilities in CMS platforms, customer portals, and business applications that infrastructure scans miss.
Establish a formal patch management policy that addresses: monitoring for security updates, risk assessment for each patch, testing requirements, deployment timelines based on severity, exception procedures when patches break functionality, and verification that patches deployed successfully.
Create a security alert dashboard showing open investigations, time to initial review, and time to resolution. Track whether your team is actually investigating alerts or just acknowledging them.
The Framework Question
Some commentators have questioned whether this breach should have been assessed under Part 3 of the Data Protection Act 2018, which applies to law enforcement processing, rather than UK GDPR. This matters beyond ACRO's case. If your organization processes data for law enforcement purposes, verify which framework applies to your activities and whether your security measures meet the applicable standard.
The ICO's decision to cite UK GDPR Articles 32(1), 32(1)(b), and 32(1)(d) suggests they viewed ACRO's processing as falling outside the law enforcement exemption, but this remains a developing area of interpretation.



