As cited
Citation snapshot as of .
regulatory
What organisations can learn from the record breaking fine over Capita’s ransomware incident
The UK Information Commissioner's Office issued a record £14 million fine to Capita for negligent cybersecurity practices surrounding a Black Basta ransomware incident, citing failures in their Security Operations Center (SOC) operations including unresponded alerts, inadequate staffing, and missed service level agreements. The incident involved initial compromise via Qakbot malware, with critical alerts left unaddressed for over 58 hours, and Capita initially misrepresented the attack to customers as a technical issue rather than a security breach. The decision establishes significant regulatory precedent regarding organizational accountability for preventable cybersecurity failures, even when companies contest the regulator's jurisdiction over internal operational standards.
Why it matters: Security leaders and managed service providers should understand that regulators now hold organizations accountable for internal SOC SLAs and alert response times, regardless of claimed affordability constraints, making documented incident response procedures and staffing adequacy critical to avoid substantial regulatory penalties.
- Source published
- First seen by Cybersecurity Tracker