# Advanced Computer Software Group Ltd: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Information Commissioner (ICO)
- Date: 2025-03-26
- Original: https://www.enforcementtracker.com/ETid-2561
- Canonical: https://overview.legal/posts/48676
- Topics: Security, Access Controls, Processing Agreement, Healthcare, Controllers, Personal Data, Law Enforcement, Supervisory Authorities, Identification, Data Controller

## Summary

The UK DPA (ICO) has fined Advanced Computer Software Group Ltd £3.07 million (EUR 3.5 million) for insufficient IT security (infringiment of Art. 32 (1) UK GDPR). The controller failed to implement appropriate technical and organisational measures to protect personal data. A ransomware attack in August 2022 allowed hackers to access systems of a health subsidiary via a customer account that lacked multi-factor authentication. As a result, the personal data of 79,404 individuals was put at risk.

## Full text

The UK DPA (ICO) has fined Advanced Computer Software Group Ltd £3.07 million (EUR 3.5 million) for insufficient IT security (infringiment of Art. 32 (1) UK GDPR). The controller failed to implement appropriate technical and organisational measures to protect personal data. A ransomware attack in August 2022 allowed hackers to access systems of a health subsidiary via a customer account that lacked multi-factor authentication. As a result, the personal data of 79,404 individuals was put at risk.

GDPR Articles: Art. 32 (1) GDPR
Industry: Health Care

---
Generated by overview.legal · https://overview.legal/posts/48676 · 2026-08-22
