🟠 High | Source: The Register — Security
The UK’s ACRO Criminal Records Office suffered a sensitive data breach after failing to patch its content management system and ignoring security alerts. The organisation still cannot confirm whether personal data was actually exfiltrated, raising serious concerns about both its technical controls and incident response capability. This is a significant failure in basic cyber hygiene at a government body handling highly sensitive criminal records data.
Security Architect’s Take: Use this case to validate your own patch management and alerting pipelines — specifically, confirm that vulnerability scan findings and SIEM alerts have documented owners, SLAs, and escalation paths. If you manage government or sensitive workloads, ensure you have immutable audit logging and network egress monitoring sufficient to definitively answer the question ‘was data exfiltrated?’ during an incident.
Original advisory: Exposed: Woeful security at UK criminal records office that led to sensitive data leak