Three Intrusions at UK Criminal Records Office Undetected for Two Years
What Happened — Between July 2021 and June 2023, three separate attackers compromised ACRO’s public‑facing portal built on an unpatched Kentico CMS. Antivirus alerts (including Mimikatz detections) were never acted on, allowing persistent access and exposure of personal data for thousands of individuals, including domestic‑violence victims.
Why It Matters for Compliance & Audit Readiness
- The incident illustrates a classic SOC 2 control‑mapping gap: no documented process for patch management or security‑alert triage, leaving the organization unable to demonstrate the CC6.1 (System Operations) and CC6.2 (Change Management) controls.
- Continuous evidence collection (e.g., patch‑status logs, alert‑handling tickets) is essential to prove that controls are operating effectively over time.
- Verisq’s Control Mapping capability automates evidence capture for these controls, turning patch‑and‑alert data into audit‑ready artifacts.
Who Is Affected — Government‑public sector (national policing unit) handling sensitive criminal‑record data.
Recommended Actions
- Formalize a patch‑management policy tied to a schedule and assign clear ownership.
- Deploy a security‑alert workflow that logs receipt, investigation, and remediation steps.
- Map these processes to SOC 2 criteria and begin continuous evidence collection to close the audit gap.
Technical Notes — The Kentico CMS version (unchanged since Sep 2019) contained multiple publicly disclosed vulnerabilities; none were patched. Trend Micro alerts flagged four Mimikatz installation attempts, all ignored. Source: The Record