ICO Rebukes ACRO Over Patch Ownership Failures

The UK Information Commissioner’s Office has formally reprimanded ACRO after a 2023 breach that affected 10,920 people and exposed sensitive records from its website and content management system. The regulator said the incident has moved from breach reporting into enforcement because the failure was not a single flaw, but poor patching and weak monitoring over months of access. ACRO’s managed service provider handled operating-system patches, while a web supplier applied Kentico content management system fixes but did not track when those fixes were due. ACRO itself did not check for required CMS updates, and Trend Micro malware alerts were generated but not reviewed or acted on. In plain terms, the warning signs were there, but no one owned the response. The case sits with any public-sector team that outsources CMS patching or alert review: if responsibility is split, a stale web platform can stay exposed long enough for repeated intrusions, and detections may never reach anyone who can stop them.

Sources