ICO warning as business fined £60,000 following cyber attack

The Information Commissioner's Office (ICO) is warning SMEs to take care or face a fine. The warning comes after a company which suffered a cyber attack was fined £60,000.

The investigation by the ICO found Boomerang Video Ltd based in Berkshire failed to take basic steps to stop its website being attacked.

Sally Anne Poole, ICO enforcement manager, said:

'Regardless of your size, if you are a business that handles personal information then data protection laws apply to you.'  

'If a company is subject to a cyber attack and we find they haven't taken steps to protect people's personal information in line with the law, they could face a fine from the ICO. And under the new General Data Protection Legislation (GDPR) coming into force next year, those fines could be a lot higher.'

'Boomerang Video failed to take basic steps to protect its customers' information from cyber attackers. Had it done so, it could have prevented this attack and protected the personal details of more than 26,000 of its customers.'

Further details of the case can be found using the links below together with guidance on data protection issues including guidance on the new General Data Protection Regulations which come into effect on 25 May 2018.

Internet links: ICO news ICO report Boomerang data protection reform updated toolkit for SMEs

Home | Newsletters | May 2023Contact us | Site map | Accessibility | Help | Privacy |

© 2024 Wilson Sandford. All rights reserved.
Wilson Sandford Limited is registered in England & Wales.


Registered Office: Wilson Sandford, 85 Church Road, Hove, East Sussex BN3 2BB

In accordance with the disclosure requirements of the Provision of Services Regulations 2009, our professional indemnity insurers are Certain Underwriters at Lloyd’s & Allianz Global Corporate & Specialty SE of 30 Fenchurch Avenue, London, England, EC3M 5AD. The territorial coverage is worldwide excluding professional business carried out from an office in the United States of America or Canada and excludes any action for a claim brought in any court in the United States of America or Canada.