£3 Million. 79,000 Lives. One Wake-Up Call?
We all say it all the time “Cybersecurity is everyone’s responsibility.” but when the dust settles after an attack, who is really taking accountability?
This week, the ICO fined Advanced Computer Software Group Ltd over £3 million after a devastating ransomware attack on their subsidiary in 2022. The breach did not just lock files, it shut down NHS 111, delayed care, disrupted critical services, and compromised the personal data of 79,000 people.
People. Not numbers.
That includes data on how to access vulnerable people’s homes, people who rely on the NHS for care, safety, and dignity, and all because basic security controls were missed. No MFA on a critical account. Inadequate patch management. No comprehensive vulnerability scanning. The kind of stuff we all know should be in place. The kind of stuff that gets deprioritised, delayed, or dismissed until it is too late.
For what? Convenience? Cost-saving? A “we will get to it” mentality?
The ICO called this out for what it is, a failure to meet the expected standard especially for an organisation handling deeply sensitive information on behalf of the NHS. This is not just about Advanced. It is a warning shot for every supplier, every third party, and every business leader outsourcing their risk and assuming someone else has it covered.
Here is the uncomfortable truth:
We cannot keep treating cybersecurity like a game of hot potato, passing it down the line until someone else drops it. When a supplier gets hit, so do you and there is no getting away from that. When a vulnerability goes unpatched, your customers still suffer. When accountability is unclear, trust dies.
So let me ask you:
- When was the last time you audited your suppliers’ security?
- Are you enforcing MFA across all access points, or just ticking a box?
- Is “good enough” still good enough when people’s lives are on the line?
This fine may have been halved from £6 million, but the impact remains. The disruption. The loss of trust. The stark reminder that cyber negligence has real-world consequences.
We do not need more awareness. We need action. Consistent, deliberate, and uncomfortable action.
Because if your data is someone else’s responsibility, then your risk is their risk too, and the fallout? That is shared, like it or not.
Let this be more than a headline. Let it be a mirror.
The question is not and never should be just “Are we secure?”
It is very much “Are we ac countable?”
At Custodian360, we are not here to sell you fear, we are very much here to help you face it.
Whether you have outsourced your cybersecurity, or you are thinking about it, let us talk about how you are doing it. Let us talk about the blind spots, the assumptions, the gaps that get missed until the regulator comes knocking.
If you are ready for a real conversation, no pressure, just straight-talking security, we are here, because accountability starts with asking better questions.
And we are ready when you are.