ICO Enforcement in 2025 and 2026: Key Cyber Security Lessons for UK Businesses
- September 15, 2026
- Posted by: Gradeon
- Category: Cyber Security

What can UK businesses learn from ICO enforcement in 2025 and 2026?
ICO enforcement decisions published during 2025 and 2026 provide useful insight into how the regulator assesses the security of personal data. Recent cases have addressed issues including incomplete multi-factor authentication, inadequate vulnerability management, weak access controls, delayed responses to security alerts, poor patch management and unclear security responsibilities.
The important lesson is not simply the size of an ICO penalty. Enforcement decisions show why organisations need to identify security risks, implement appropriate technical and organisational measures and be able to demonstrate that those measures are being maintained.
For UK businesses, this means treating cyber security and data protection as ongoing risk-management responsibilities rather than activities that only become important after a breach.
Why ICO enforcement matters to UK organisations
The Information Commissioner’s Office regulates data protection and information rights in the UK and has a range of enforcement powers. Depending on the circumstances, regulatory action can include monetary penalties, reprimands and enforcement notices.
Recent cases also demonstrate that an enforcement decision may relate to an incident that happened years earlier. For example, the ICO’s 2025 decision involving Advanced concerned a ransomware attack from 2022, while its 2026 decision involving South Staffordshire followed a cyber incident in which personal data relating to approximately 633,887 UK data subjects was exfiltrated.
This distinction matters when interpreting enforcement trends. The year of an ICO decision does not necessarily represent the year in which the cyber incident occurred.
The underlying requirement remains clear: organisations processing personal data must implement security measures that are appropriate to the risks involved. The ICO’s current guidance also emphasises the importance of considering data protection from the design stage and throughout the lifecycle of processing activities.
What do recent ICO enforcement decisions show?
Several decisions published in 2025 and 2026 provide practical examples of the security weaknesses regulators may examine following a cyber incident.
Advanced: incomplete MFA and vulnerability management
In March 2025, the ICO fined Advanced Computer Software Group Ltd £3,076,320 following a 2022 ransomware incident. The investigation found gaps in multi-factor authentication, vulnerability scanning and patch management. The incident affected personal information relating to 79,404 people.
The case demonstrates that having a security control in place is not necessarily enough if important systems or accounts remain outside its coverage. Organisations should periodically verify whether controls are consistently applied across relevant systems, users and third-party connections.
23andMe: security measures and large-scale personal data
In June 2025, the ICO fined 23andMe £2.31 million following a cyber attack affecting the personal information of 155,592 UK users. The ICO found infringements relating to the security of processing under Articles 5(1)(f) and 32(1) of the UK GDPR.
The case illustrates why organisations handling significant volumes of personal information need to assess security measures against the nature and scale of the information they process.
Capita: vulnerabilities, privilege escalation and incident response
In October 2025, the ICO issued a combined £14 million fine against Capita plc and Capita Pension Solutions Limited following the 2023 cyber attack in which information relating to approximately 6.6 million people was stolen.
The ICO identified several security weaknesses, including inadequate controls around administrative accounts, privilege escalation and lateral movement. It also found that Capita did not respond appropriately to a high-priority security alert within its target response time.
This highlights an important point for businesses: security monitoring only provides value when alerts are investigated and acted upon promptly.
LastPass: protecting data stored in backup environments
In November 2025, the ICO issued LastPass UK Ltd with a £1,228,283 penalty. The ICO found that insufficient technical and organisational security measures allowed a threat actor to exfiltrate personal data relating to approximately 1.6 million UK customers from a backup database.
The case is a reminder that organisations need to consider the security of backup environments and supporting infrastructure, not just their primary production systems.
South Staffordshire: security of personal data after a cyber incident
In May 2026, the ICO imposed a £963,900 penalty on South Staffordshire Plc and South Staffordshire Water Plc following a cyber incident involving the exfiltration of personal data relating to approximately 633,887 UK data subjects. The enforcement action cited Articles 5(1)(f) and 32(1) of the UK GDPR.
The decision reinforces the importance of maintaining appropriate security measures around systems that process personal information.
ACRO: a reprimand can also follow cyber security failures
Not every enforcement action results in a financial penalty.
In August 2026, the ICO issued a reprimand to ACRO Criminal Records Office following a cyber incident in which personal data relating to approximately 10,000 UK data subjects may have been affected. The ICO’s subsequent explanation identified weaknesses in patch management, monitoring and accountability for security updates.
This is important for businesses to understand because regulatory exposure is not limited to situations where a large monetary penalty is imposed.
The recurring security issues businesses should address
Although individual enforcement decisions have different circumstances, several practical security themes appear across recent cases.
1. Security controls must be properly implemented
Multi-factor authentication, access controls, patching and vulnerability management are only effective when they cover the systems and accounts that actually create risk.
The Advanced case, for example, involved gaps in MFA coverage as well as vulnerability scanning and patch management.
Businesses should therefore regularly verify:
- Which systems contain personal data.
- Which accounts can access those systems.
- Whether MFA covers privileged and externally accessible accounts where appropriate.
- Whether critical vulnerabilities are identified and prioritised.
- Whether security patches are being applied within defined timescales.
Businesses looking at the wider resilience picture can also review data breach resilience strategies, which cover practical approaches to improving preparedness and reducing the impact of cyber incidents.
2. Vulnerability and patch management need clear ownership
The ACRO enforcement action is particularly relevant here. The ICO found that responsibility for identifying and monitoring critical CMS security updates was not sufficiently clear and that security alerts were not adequately investigated.
Security responsibilities should therefore be clearly assigned across internal teams and third-party suppliers.
A business should be able to answer basic questions such as:
- Who monitors critical vulnerabilities?
- Who approves emergency patches?
- Who confirms that patches have been applied?
- Who investigates security alerts?
- Who escalates unresolved risks to senior management?
Without clear ownership, important security tasks can fall between teams.
3. Access management should be reviewed regularly
The Capita enforcement action identified weaknesses involving administrative accounts, privilege escalation and lateral movement.
Businesses should review whether users have more access than they need and whether privileged accounts are appropriately separated and protected.
Regular access reviews should cover employees, contractors, administrators and relevant third-party accounts. Access should also be removed or adjusted when roles change or users leave the organisation.
4. Incident response matters as much as prevention
Preventive controls are essential, but organisations also need effective processes for responding when something goes wrong.
The Capita case illustrates the importance of responding to security alerts quickly and appropriately.
An effective incident response process should define:
- Who receives security alerts.
- How incidents are classified.
- When senior management is notified.
- How affected systems are isolated.
- How evidence is preserved.
- How data protection obligations are assessed.
- How lessons from the incident are documented.
Businesses looking at the wider resilience picture can also review data breach resilience strategies, which cover practical approaches to improving preparedness and reducing the impact of cyber incidents.
Why governance matters alongside technology
Recent enforcement decisions also demonstrate that cyber security is not simply a technical issue.
The ICO’s guidance places emphasis on appropriate technical and organisational measures, accountability and ongoing consideration of data protection risks.
For senior management, this means cyber security should form part of wider organisational risk management.
Good governance can include:
- Clearly assigned security responsibilities.
- Regular reporting of significant cyber risks.
- Documented security policies and procedures.
- Periodic access and vulnerability reviews.
- Security testing based on risk.
- Documented incident response procedures.
- Evidence that identified weaknesses are being addressed.
The objective is not to create unnecessary administration. It is to make sure the organisation can identify risks, assign responsibility and demonstrate that reasonable action is being taken.
Penetration testing can help identify weaknesses before an incident
Penetration testing is one component of a wider security programme. It should not replace vulnerability management, patching, access controls or continuous monitoring.
Its value is in testing whether security controls work as expected under simulated attack conditions.
Businesses considering penetration testing can review the penetration testing process, which explains the stages involved and how a professional penetration test differs from a basic vulnerability scan.
Where testing identifies weaknesses, the next step should be remediation followed by appropriate validation. Organisations can also consider specialist penetration testing services where an independent assessment is required.
What should UK businesses do now?
The practical response to recent ICO enforcement is not simply to prepare for a potential fine. Businesses should use the lessons from enforcement decisions to review whether their existing controls are appropriate for the personal information and systems they operate.
A useful review should cover:
- Personal data: Identify what personal information the organisation processes and where it is stored.
- Access: Review user, administrator and third-party access permissions.
- MFA: Confirm that appropriate multi-factor authentication is implemented across relevant systems and accounts.
- Vulnerability management: Maintain a process for identifying, prioritising and remediating vulnerabilities.
- Patching: Define responsibilities and timescales for applying security updates.
- Monitoring: Ensure important security alerts are monitored, investigated and escalated.
- Backups: Test whether backups are protected and can be restored when required.
- Incident response: Regularly review and test the organisation’s response procedures.
- Security testing: Use vulnerability assessments and penetration testing where appropriate to the organisation’s risk profile.
- Governance: Keep evidence showing who owns security risks and what actions have been taken to address them.
These measures do not guarantee that a cyber incident will never occur. They help organisations build a more structured approach to identifying and managing security risks.
Frequently asked questions
Does the ICO only take action after a data breach?
No. The ICO has several enforcement powers, including monetary penalties, reprimands and enforcement notices. The appropriate regulatory response depends on the circumstances of each case.
Can small businesses face ICO enforcement?
Yes. UK data protection requirements apply based on an organisation’s processing of personal data and the applicable legal requirements, not simply its employee count. Security measures should be appropriate to the risks associated with the processing.
What security issues have recent ICO cases highlighted?
Recent decisions have highlighted issues including incomplete MFA coverage, vulnerability management, patching, access controls, administrative privileges, security monitoring and incident response. The exact findings vary between cases.
Does an ICO enforcement action always result in a fine?
No. The ICO can use different enforcement measures. For example, ACRO received a reprimand in August 2026 following a cyber security incident.
How can businesses prepare for future ICO scrutiny?
Organisations should maintain appropriate technical and organisational measures, regularly review cyber risks, assign clear security responsibilities and keep evidence of security assessments and remediation activities. The ICO’s guidance states that data protection by design should be considered throughout the lifecycle of processing activities.
Turning ICO Enforcement Lessons into Better Cyber Resilience
The ICO enforcement decisions published during 2025 and 2026 provide practical examples of the security and governance issues that can arise when personal data is not adequately protected.
The cases involving Advanced, 23andMe, Capita, LastPass, South Staffordshire and ACRO differ in their circumstances, but they demonstrate why organisations should not rely on a single security control or wait until after an incident to review their defences.
For UK businesses, the practical priority should be to understand where personal data is exposed, identify the security risks that matter most, assign clear ownership and regularly test whether controls are working as intended.
A proactive approach to cyber security can help organisations strengthen resilience while supporting their wider data protection and governance responsibilities.