Partner Content UK GDPR Article 32 mandates "appropriate security measures". The ICO has defined what that means: multi-million-pound fines for password failures. The violations that trigger them? Small, familiar, and happening in your organization right now. Your sysadmin shares SSH keys via WhatsApp in "defnotsshkeys.txt". Your HR manager stores employee ID scans in Gmail. Your intern has admin access because it was easier than configuring permissions. And your former contractor from 2017 still receives reports with client data because his email was never removed from the distribution list. These scenarios range from the simplest to more complex, like misconfigured cloud storage with cascading access rights across departments. But they share a common outcome: this is exactly how cybersecurity breaches happen. And when they do, ICO responds with fines that can cripple businesses. Capita plc just learned this expensive lesson — unsecured AWS buckets and extractable passwords cost them £14 million. The pattern continues across industries: Advanced Computer Software received a £3.07 million fine for incomplete MFA coverage. 23andMe paid £2.31 million after credential stuffing attacks exploited password reuse. Even small firms like DPP Law Ltd faced a £60,000 penalty when a brute-force attack breached an admin account that lacked MFA protection. The statutory maximum? Four percent of worldwide annual revenue. For a mid-sized UK business with £10 million turnover, that's a potent...
Why UK businesses are paying ICO millions for password mistakes you're probably making right now
The Register
·Eirik Salmi, system analyst, Passwork
·Published Nov 6, 2025
·Updated
Affected Software
1 affected component
AWS S3
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses UK businesses facing significant fines from the ICO due to password management failures.
2
What security implications are discussed in relation to password management?
The article highlights that improper password practices can lead to breaches of UK GDPR and hefty financial penalties.
3
What specific violations contribute to these fines?
Common violations include sharing SSH keys via insecure channels like WhatsApp.
4
Which software is mentioned as being affected by these security issues?
AWS S3 is identified as one of the software products affected by password management failures.
5
How are UK businesses responding to these GDPR-related fines?
UK businesses are paying millions of pounds due to non-compliance with security measures mandated by GDPR.