Available 24/7 · Same-day on-site across Gloucestershire 01452 701355 sales@systemforce.co.uk Remote Help Network Status

What the ICO’s Data Breach Fines Reveal About SME Security

The Information Commissioner’s Office has changed gear. In the first half of 2025 it collected around seven times more in fines than in the whole of 2024, and the average penalty jumped from roughly £150,000 to over £2.8 million. The striking thing is not the size of the fines, though. It is what causes them. Almost every one traces back to a basic security failure that would have been cheap to fix.

For a small or medium business, the lesson is not “we might get a huge fine”, because you almost certainly will not be fined millions. It is that the same failures that cost big organisations millions are the exact ones that let attackers into small ones, with the same painful results.

Big fines, basic failures

Look at the recent cases and a pattern jumps out:

  • Advanced Computer Software (£3.07m). Attackers got in through a customer account that had no multi-factor authentication, then launched ransomware that disrupted healthcare services for tens of thousands of people.
  • 23andMe (£2.31m). A “credential stuffing” attack, where criminals reuse leaked passwords, exposed the data of over 155,000 UK residents. Again, no mandatory multi-factor authentication to stop it.
  • Capita (£14m). A malicious file downloaded to one employee’s device let attackers into the network. A key failing was taking 58 hours to isolate the compromised device, against a one-hour target.

Missing multi-factor authentication. A single compromised account. A slow response. None of these are exotic. The ICO has said plainly that there is no longer any excuse for not deploying multi-factor authentication across external connections, and that a preventable breach caused by its absence can attract a substantial fine.

What the ICO actually expects

The law does not demand perfection. It requires “appropriate technical and organisational measures” to keep personal data secure. In practice that means the basics, done consistently:

  • Multi-factor authentication on email, remote access and admin accounts, without exception.
  • Software and systems patched promptly.
  • Least-privilege access, so one compromised account cannot reach everything.
  • Monitoring, so an intrusion is spotted in hours, not days.
  • Tested backups and a breach response plan you have actually rehearsed.
  • Staff who can spot a phishing email.

This is exactly what Cyber Essentials covers

If that list looks familiar, it is because it is essentially the UK government’s Cyber Essentials scheme: secure configuration, access control, patch management, malware protection and boundary firewalls, with multi-factor authentication now central to it. Cyber Essentials is not a silver bullet, but it is the baseline the ICO effectively expects, and it blocks the overwhelming majority of the attacks that lead to breaches and fines in the first place.

For SMEs, this is about prevention, not penalties

You are unlikely to face a multi-million pound fine. You are entirely capable of suffering the same breach: ransomware that locks your systems, an attacker in your email, customer data on the dark web. The cost then is downtime, lost data, lost trust and a scramble to recover, which for a smaller business can be far more damaging than any fine. Preventing it is mostly a matter of getting the basics in place and keeping them there, which is exactly what our managed cyber security and managed IT support is built to do.

The takeaway

The ICO’s fines are a useful, if expensive, list of what “good enough” security looks like. Turn on multi-factor authentication everywhere today, work towards Cyber Essentials, and make sure someone is actually watching your systems. If you would like a hand checking where you stand, get in touch for a straightforward review.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name