Capita fined for cybersecurity failings that led to data breach

Ineffective response to security alerts, inadequate access controls, lack of active directory tiering, and penetration testing shortcomings all cited as factors.

The ICO has fined Capita £14m ($18.7m), which includes a £6m ($8m) fine against subsidiary CPSL, for its failure to ensure the security of personal data and the resulting infringement of the UK’s data protection rules. The regulator categorized the rule violations as “having a high degree of seriousness” that

Free Trial

Register for free to keep reading.

To continue reading this article and unlock full access to GRIP, register now. You’ll enjoy free access to all content until our subscription service launches in early 2026.

  • Unlimited access to industry insights
  • Stay on top of key rules and regulatory changes with our Rules Navigator
  • Ad-free experience with no distractions
  • Regular podcasts from trusted external experts
  • Fresh compliance and regulatory content every day
Register for free Already a member? Sign in