The Information Commissioner’s Office (ICO) has fined Advanced Computer Software Group Ltd (ACSG) £3.07 million following a ransomware incident that exposed the personal data of 79,404 people. The ICO found that ACSG failed to implement adequate security measures, leaving sensitive healthcare data vulnerable. The Advanced Computer Software Group enforcement action highlights the critical importance of strong cybersecurity practices, especially when handling personal and health information on behalf of others.

The Advanced Computer Software Group enforcement action

On 27 March 2025, the ICO concluded its investigation into ACSG and issued a monetary penalty of £3,076,320. This enforcement action followed a ransomware attack in August 2022 that disrupted NHS 111 and other vital health services.

The ICO had initially proposed a fine of £6.09 million in August 2024. After reviewing ACSG’s representations, the ICO reduced the final penalty. ACSG accepted the findings and agreed to pay the reduced fine without lodging an appeal.

This Advanced Computer Software Group enforcement action reinforces that the ICO expects all data processors to meet high security standards, especially when managing large volumes of sensitive personal information.

Timeline to comply

ACSG and the ICO reached a voluntary settlement, which means the case is now closed. ACSG must pay the fine as agreed. No further legal proceedings will follow. Although the formal enforcement process has concluded, organisations should act now to prevent similar incidents. Delaying action until after a breach or enforcement notice increases legal, financial, and reputational risks.

What happened

In August 2022, hackers accessed systems belonging to ACSG’s health and care subsidiary. The attackers exploited a customer account that did not have multi-factor authentication (MFA) enabled. This security lapse allowed unauthorised access and caused significant disruptions to NHS services.

The attack compromised personal data of 79,404 individuals. In 890 cases, the attackers accessed information about how to enter the homes of individuals receiving care at home.

ACSG failed to prevent this breach, and the consequences affected critical public services and exposed vulnerable people to further risk.

ICO’s findings

The ICO found that ACSG had not implemented appropriate technical and organisational measures to protect its health and care systems. Specifically, the ICO identified the following failings:

  • Gaps in multi-factor authentication coverage
  • Inadequate vulnerability scanning
  • Poor patch management

The Information Commissioner, stated that ACSG’s security controls “fell seriously short” of what the law requires from organisations processing highly sensitive data.

The ICO emphasised that individuals must trust organisations to protect their personal information, especially in healthcare. This Advanced Computer Software Group enforcement action demonstrates that regulators will not tolerate weak security in critical sectors.

What organisations can learn from the Advanced Computer Software Group enforcement action

This enforcement notice offers several key lessons for organisations:

  • Implement strong MFA. Apply multi-factor authentication to all external access points partial implementation is not enough.
  • Conduct regular vulnerability scanning. Identify and address weaknesses in systems before attackers exploit them.
  • Keep systems up to date. Apply patches promptly to fix known security issues.
  • Take full responsibility as a processor. If your organisation processes data on behalf of others, you must meet the same security standards required of data controllers.
  • Engage proactively with regulators. Cooperating with the ICO and other authorities may reduce penalties and limit damage.

Actions to take

  • Keep yourself updated on the latest developments in data protection regulations by joining the Michalsons Data Protection Programme.
  • Identify gaps in your organisations information security practices by asking us to conduct a gap analysis.
  • Ensure your organisations policies are up to date by asking us to review your information security and data protection policies.
  • Educate your team by asking us to train them on how to recognise and respond to data protection risks and responsibilities.