ICO reports a voluntary settlement. Earlier proposed penalties are not the final amount.
What happened
The ICO announced a £3.07 million fine against Advanced Computer Software Group Limited in March 2025 following a 2022 ransomware incident. Its findings included gaps in multi-factor authentication coverage. The regulator had previously proposed a larger fine; the published outcome followed a voluntary settlement. The proposed figure and final penalty are different stages of the case.
Source: ICO — original source ↗
What it means for your website
Outsourcing a system does not make the questions disappear. You still need to understand who operates it, which responsibilities sit with the supplier and how incidents are communicated. When commissioning website work, agree the access needed and how it will be removed after completion. For ongoing hosting or software, make security expectations explicit instead of assuming they are included in a monthly invoice. A cookie-consent remediation project is not a full audit of every supplier. If the work reveals a wider concern, record it separately and assign it to someone with the appropriate expertise.
Three useful next steps
- Ask suppliers which security controls cover your service.
- Agree incident contacts and escalation arrangements.
- Remove temporary access after a project ends.
Sources & context
Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.
ICO — original sourceOur practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.