Features 29.09.2026
AI Autopsy: ACRO Breach Shows What Happens When Teams Ignore the Basics
The ICO’s reprimand is a warning to others
Features 29.09.2026
The ICO’s reprimand is a warning to others
Critics of the UK’s data protection regime often point to the unfairness of its controversial public sector approach. In practice, the policy means that public authorities found wanting are more likely to receive a warning, reprimand or enforcement notice than a fine. That stands in stark contrast to private sector organisations, which are regularly fined millions for similar offences.
So it was little surprise when the Information Commissioner’s Office (ICO) recently chose only to reprimand the ACRO Criminal Records Office (ACRO), after basic security failings led to a major data breach. While the police-run agency may have escaped a fine, businesses displaying similarly poor security posture may not be so lucky. They should take note.
ACRO in fact suffered three security incidents between July 2021-June 2023, all involving its customer portal website, built on the Kentico CMS. One of these involved an SQL injection attack which exposed 15 username and password credentials, most of which were linked to ACRO employees. Another had a similarly small impact. However, it’s believed that the third incident may have impacted over 10,000 portal users.
“These are exactly the kind of control failures a regulator would scrutinise closely” Findlay Whitelaw
“Believed” is the operable word here, because ACRO, which is run by Hampshire and Isle of Wight Constabulary, had such poor log management and retention that the ICO couldn’t even determine if the records were ultimately exfiltrated or not. ACRO was forced to notify over 84,000 data subjects as a result, the regulator revealed in a detailed reprimand document.
“When you don’t have sufficient telemetry, the problem isn’t simply that the investigation becomes harder,” Exabeam field CISO, Findlay Whitelaw, tells Assured Intelligence. “You lose the ability to establish impact with confidence. That uncertainty itself creates regulatory, operational, reputational and notification consequences.”
So what happened? The post-mortem highlights two major issues which allowed a threat actor to gain unauthorised access to ACRO’s website and CMS between August 2022 and March 2023.
The first relates to patching. ACRO’s managed service provider (MSP) handled OS patches, but not those related to the CMS. That was the job of its web development supplier. However, the supplier was not responsible for identifying when patches needed to be applied. This created a major security blind spot.
“ACRO did not provide a documented patching policy covering CMS updates, despite the ICO requesting this during the investigation. As a result, ACRO could not demonstrate how vulnerabilities were identified, prioritised and/or tested, nor how responsibility for these activities was assigned or assured,” the ICO said. “The absence of such a policy reinforced the fragmented and poor approach to patch management, leaving critical responsibilities unclear.”
The second issue involves security monitoring. ACRO had a Trend Micro solution installed to “detect and quarantine malware”. However, the alerts it generated – including four attempts to install credential harvesting tool Mimikatz – were “not reviewed or acted upon”, the ICO revealed.
“Had the alerts been investigated by ACRO at the time, and an appropriate response conducted, it is likely that further malicious activity could have been prevented,” the ICO said. The regulator couldn’t establish which roles at the force were responsible for monitoring security alerts.
The data compromised in the breach was extremely sensitive. Alongside personally identifiable information (PII) and ID details, it included info on criminal convictions and offences, gender reassignment and biometrics. Among the 30+ complaints made directly to ACRO, several were connected to International Child Protection Certificates, and victims of domestic violence.
“The tooling was never the hard part here” Bob Maley
The ICO received several more from victims expressing “distress and anxiety” about possible identity theft and financial loss. That kind of impact creates “significant regulatory exposure for a private sector organisation,” according to Whitelaw.
“These are exactly the kind of control failures a regulator would scrutinise closely,” he tells Assured Intelligence.
In its defence, the ICO acknowledged that ACRO at least had network segmentation in place, which minimised the blast radius of the attack. And that it took action following the incident, including migrating its CMS to Salesforce where patching is governed by the vendor’s change management process.
“Those are process and accountability failures as much as they are security failures” Ross Filipek
However, CISOs Assured Intelligence spoke to are clear about what went wrong.
“Those are process and accountability failures as much as they are security failures,” Corsica Technologies CISO, Ross Filipek, tells Assured Intelligence.
“Most established security frameworks account for these basics, but a framework is only as effective as the processes behind it. CISOs need clear ownership for patching and alert response, along with enough visibility to know when something is going wrong.”
Black Kite CSO, Bob Maley, agrees that the incident stemmed from an accountability rather than a technology issue.
“The tooling was never the hard part here,” he tells Assured Intelligence. “When the ICO asked ACRO which role was responsible for reading those alerts, nobody could answer, and there’s no purchase order that fixes that. We’ve also been talking about patching for forty years and it’s still the problem. At some point that stops being a technology story.”
Maley urges CISOs to ensure they have dedicated individuals responsible for “knowing that a patch exists” for every internet-facing system. “If you can’t put a name against the noticing for every one of those systems, you have the gap ACRO had, and you have it today,” he says.
Security leaders should do the same with their alerting, and go beyond merely assigning an accountable individual on paper.
“Inject a detection into your environment at an inconvenient hour, on a Sunday night, and time how long it takes before a human escalates,” Maley continues.
“A policy stating that alerts are reviewed daily is worth nothing if you can’t name the person on shift and say what they’re empowered to do at two in the morning without waking anyone up. ACRO couldn’t identify that role afterward, which tells you the question had never been tested while it still mattered.”
Exabeam’s Whitelaw adds that CISOs should assume that individual controls will sometimes fail, and plan for layered defences.
“ACRO’s network segmentation limited the attacker’s ability to move into core systems,” he explains. “This is a good example of why defence in depth matters. The objective isn’t to rely on one perfect control but to prevent one failure becoming an enterprise-wide failure.”
Ultimately, the ACRO case proves why cybersecurity leaders need to lead by example, says Maley. “Ever since I’ve been in this business, I can’t remember anybody putting their hand up and volunteering to own a risk. Nobody does,” he concludes.
“Then something goes wrong and the security lead wears it, because if nobody else owned it, you have to. Sitting back is comfortable, but it’s also expensive. In this case those 10,000 people are the ones paying.”