Observation No. 31 · The safeguard nobody tested
The alarm nobody was assigned to hear.
On August 5, 2022, an intruder got into the website and Kentico content management system of ACRO, the UK’s national Criminal Records Office. They kept that access, undetected, until March 14, 2023. Seven months and nine days.
The security software noticed. ACRO ran a Trend Micro product installed, in the regulator’s phrasing, to “detect and quarantine malware,” and on multiple occasions it did exactly that. Each time, it raised an alert.
The alerts were, per the Information Commissioner’s Office, “not reviewed or acted upon.”
When the ICO asked why, ACRO could not say. It was “unable to establish what business processes existed for the assessment or handling of security alerts at the relevant time,” and it could not identify which roles were responsible for reviewing them. There was no procedure that broke down under pressure, and no named person who let one slide. The step simply had never been built.
The regulator’s judgment on that gap is blunt: had the alerts been investigated at the time and an appropriate response conducted, “it is likely that further malicious activity could have been prevented.”
Nobody caught the intrusion on purpose. ACRO found it in March 2023 while investigating a separate compromise. By then the attackers had staged data for possible exfiltration on February 15 and 16. ACRO’s logging was poor enough that, after an outside forensics investigation, it still cannot say whether the data left the building.
ACRO notified 84,048 people. Investigators later narrowed the potentially staged records to no more than 10,920 individuals. The material included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and criminal offence records. Among the 35 formal complaints ACRO received were people connected to International Child Protection Certificates and victims of domestic violence.
The ICO issued a reprimand on August 12, 2026, without a fine. Jonathan Balmforth, its group manager for civil and cyber investigations, drew the lesson this way: “Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology.”
Your shop has alarms too. They are less dramatic and they work the same way.
The inventory system that flags a negative count. The card processor that emails you about a declined recurring charge. The backup service that sends a status message every night, including the nights it failed. The accounting software’s exception report. The bank alert for a transaction over some threshold you set once, years ago. The smoke detector in the back room that chirps.
Every one of those was installed by somebody who assumed the signal would reach a person who would then do something. Two of those three parts usually get built. The detection gets bought and configured, because that is the part with a product attached. The response is the part you were going to sort out later.
So ask a smaller question than “are we monitoring this.” Ask who, by name, opens the message. Ask what they are supposed to do at eight in the morning when it says something is wrong, and whether that is written anywhere, and whether they know it is their job. Ask when one last fired and what happened next. If the honest answer is that they go to an inbox nobody has opened since the bookkeeper left, you own a detection system and no alarm.
A cheap version of the fix: pick the three alerts that matter most, put a name against each one, and send yourself a fake one next Tuesday. See how long it takes to come back to you. That drill costs an afternoon and tells you what seven months of silence told ACRO.
For every alert, exception report, and error flag your operation produces, who specifically is responsible for acting on one when it fires, and have you ever confirmed that the person exists and the process is real?
