Nobody knew whose job the patching was

· · Security Commentary

Somewhere in your business is a system that somebody else patches. The website, most likely, or the online booking form, or the customer portal. You pay a company to look after it, and you have reasonably assumed that looking after it includes keeping it up to date.

Here is the question worth asking this week. Does your provider watch for security updates, or do they only install the ones you ask for? Those are different jobs, and a contract can easily buy one without the other.

That distinction is the whole of what the Information Commissioner's Office found when it reprimanded a national police unit last week.

What the regulator actually found

ACRO Criminal Records Office issues police certificates and handles subject access requests. Its public website ran on Kentico, a content management system, and from September 2019 to March 2023 it stayed on the same version, 12.0.0, with known published vulnerabilities. Kentico released cumulative security hotfixes throughout that period. None were applied.

Attackers were in that website for a long time. The ICO's reprimand, issued on 7 August, describes three separate intrusions between July 2021 and June 2023. The most serious ran from August 2022 to March 2023, seven months of access, during which the attacker staged the personal data of up to 10,920 people for removal: names, dates of birth, national insurance and passport numbers, bank details, criminal conviction records, and information identifying victims of domestic violence.

The reason for the reprimand is not that the patches were missed. It is why they were missed, and this is the part to sit with:

ACRO did not clearly define who was responsible for monitoring for required security patches.

The web development supplier was responsible for applying patches. It was not responsible for identifying when patches were required. ACRO did not monitor for them either. An email exchange in February 2020 confirmed the supplier would implement updates under the support agreement, but, in the ICO's words, "it did not establish whether [the supplier] was obligated to actively monitor for these". A separate managed service provider handled operating system and server patching, which specifically excluded the content management system, because that role was limited to infrastructure.

So three organisations were involved, each doing its defined job properly, and the thing nobody had been given was the job of noticing. The ICO called it "an absence of oversight for this important security control".

There was no documented patching policy covering the system, either. Without one, ACRO could not show how vulnerabilities were identified, prioritised, or tested, nor how responsibility was assigned.

The alerts nobody owned

The same shape repeats with the warnings.

The servers ran Trend Micro antivirus, and it worked. It detected and quarantined attacker tools during the intrusions. On 23 February 2023 it caught and quarantined four attempts to install Mimikatz, a well-known tool for harvesting passwords from a machine. That is about as unambiguous a signal as security software produces.

Nobody looked. ACRO told the ICO it could not establish what business process existed for handling security alerts at the time, or which roles were responsible for reviewing and escalating them. The ICO's conclusion is worth quoting plainly: had the alerts been investigated, "it is likely that further malicious activity could have been prevented".

The detection was bought, installed, and working. The deciding factor was whether a named person had the job of reading what it said.

There is a third failure that hurts most in the long run. Because logging was insufficient, ACRO could not determine whether the staged data was ever actually taken. Three years on, the people whose records those were still cannot be told what happened to them. It notified 84,048 people in April 2023 on a precautionary basis, because precaution was all it had.

Why a smaller business should care

It is tempting to file this under public sector incompetence. That reading is comfortable and wrong, because the failure was structural rather than technical, and the structure is more common in small businesses, not less.

You are more exposed to this than ACRO was if your website was built by an agency, handed over, and is now maintained by whoever answers the email; if your IT support contract covers servers and laptops but nobody ever discussed the website; if you have a managed service provider for infrastructure and a separate developer for the application. Each of those is an ordinary, sensible arrangement. Each creates a seam, and this failure lives in seams.

Worth noting what the ICO also found: ACRO's network segmentation stopped the attacker reaching core policing systems, which limited the damage. It got a reprimand rather than a fine, partly because it is a public body and fining one moves public money around, and it has since moved the portal to a managed platform and put proper monitoring in place. This is not a story about uniquely bad people. It is a story about an ordinary gap.

The three questions

You can settle this in one email, and the answers should be in writing.

"Who watches for security updates for our website, and how often?" Not who installs them. Who checks whether any exist. If the answer is "we apply them when they come through", ask what "come through" means, because a content management system may not tell anyone.

"Who reads the security alerts, and what happens when one fires?" Ask for the name of a role, not a reassurance. Then ask what happened to the last one.

"If we were breached tomorrow, could you tell me what was taken?" This is the logging question in plain terms. ACRO could not answer it, and that inability is now a permanent part of its record.

If you and your provider give different answers to any of these, you have found your gap, and you have found it on a quiet Wednesday rather than during a forensic investigation. That is the entire point of asking.

Write down what you agree. The ICO's finding against ACRO was not that the wrong party was doing the work. It was that nobody could demonstrate who was supposed to be.

How Steelwise can help

Finding the seams between your suppliers, and getting a written answer on who owns patching, alerting, and logging, is a security review that takes days rather than months. Get in touch.

Further reading

← All filings