Skip to Primary Navigation

Capita fined for cybersecurity failings that led to data breach

London skyline at night
Photo: Leon Neal/Getty Images

Ineffective response to security alerts, inadequate access controls, lack of active directory tiering, and penetration testing shortcomings all cited as factors.

The ICO has fined Capita £14m ($18.7m), which includes a £6m ($8m) fine against subsidiary CPSL, for its failure to ensure the security of personal data and the resulting infringement of the UK’s data protection rules. The regulator categorized the rule violations as “having a high degree of seriousness” that

Get full access, free for a month

Start your 28-day free trial to continue reading and access
all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience