← Front PageCompliance Desk
Compliance
UK water company allowed hackers to lurk undetected for nearly two years, regulator finds
Nearly £1M fine demonstrates how prolonged attacker dwell time amplifies regulatory penalties under UK data protection law, with 630K+ records exposed after two-year compromise window.
Summary written by editorial AI · Source link below
The Information Commissioner's Office (ICO) fined South Staffordshire Water £963,900 ($1.3 million) on Monday over an attack by the Cl0p ransomware group that led to the personal data of 633,887 customers and employees being published in August 2022.
Continue at the source
Read the full report at The RecordExternal link — opens at The Record in a new tab.
§
Continue with
More from the Compliance Desk
- X-rated Compliance Theater: An Empirical Evaluation of European Age Verification Systems in Adult Websites17 Jul
- 23andMe to pay $18 million in new genetics data breach settlement16 Jul
- Designing a GDPR-Compliant Security Architecture for Remote Elderly Care Systems: A Privacy-by-Design Approach16 Jul
- Manage Vendor Risk in a Few Practical Steps14 Jul
- Reverse Engineering Compliance: A Dual-Graph Verification Framework for Auditing Legacy IT Security Concepts10 Jul