ICO fines Interserve Group Ltd

The ICO recently fined construction company Interserve Group Ltd £4.4m in response to their failure to sufficiently protect the personal information of their staff, breaching data protection law. 

So, what happened? 

A seemingly innocuous chain of events with disastrous consequences: an employee forwarded a phishing email to another employee, who then opened and downloaded its contents – installing malware in the process. One email which evaded Interserves’ security system was able to compromise 283 systems and 16 accounts, with around 133,000 members of staff affected. 

The data accessed by hackers included some special category data, increasing the severity of the data breach. The information collected included;  

  • Contact details 
  • National Insurance numbers 
  • Bank account details
  • Ethnic origin 
  • Religion 
  • Disabilities 
  • Sexual orientation 
  • Medical information 

Interserves’ culpability 

The ICO concluded that Interserve had not only failed to recognise and respond to warning signs of suspicious activity but had neglected to implement a successful data protection culture in the workplace. Their security systems were outdated and their staff were not sufficiently trained to recognise potential data breaches. 

The Interserve incident serves as a reminder to all of us that complacency remains the greatest asset in a hacker’s arsenal. As ICO Commissioner John Edwards warned; 

“If your business doesn’t regularly monitor for suspicious activity in its systems and fails to act on warnings, or doesn’t update software and fails to provide training to staff, you can expect a similar fine from my office.”

We couldn’t have said it any better ourselves! 

DPAS is here to help your organisation comply with data protection laws. Staff training and awareness for both Information Security, Cyber Security and Data Protection should be on the agenda at all times. It doesn’t always need to be a day-long course, there are so many options available. 

From conducting an audit to identify areas of weakness to providing staff training, you can get in touch with us at info@dataprivacyadvisory.com or give us a call on 0203 301 3384 and we can walk you through the best options for your business.

related posts

Alex Haslam

DPAS Data Protection Bulletin – July 2026

Welcome back to our monthly DPAS bulletin, where we cover the latest data protection news and developments from around the world.

Ever wondered how a routine government spreadsheet leak turns into a two-year covert court order? How about why the police might feel your mother-in-law’s contact details were key to national security? Have you ever pondered how many working weeks it takes to read a cookie banner? Whether Wall Street knows about your last GP visit? Or if you’re in Australia (g’day) why an AI is sending notes on your worst rashes to faraway cloud servers?

Read about all this and more in our latest DPAS Data Protection Bulletin.

Read More »
Alex Haslam

Root Cause Analysis: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »
Alex Haslam

How to Report a Data Breach: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »
Jack Penaligon

How to Respond to a Data Breach: A Practical Guide

This blog provides an overview of the practical steps organisations can take to reduce the impact of a data breach once it has been identified. It focuses on the actions that should be taken during the early stages of an incident to contain the breach, protect affected individuals, and meet regulatory requirements.

The article discusses a range of mitigation measures, including contacting unintended recipients of personal data, securing the deletion or recovery of exposed information, isolating compromised systems, and maintaining clear records of actions taken. It also explores the challenges posed by both digital and physical data breaches, highlighting the importance of balancing operational needs with data protection obligations.

Finally, the blog emphasises the value of preparation, explaining how established procedures, communication templates, and predefined response plans can help organisations respond more effectively and demonstrate accountability during a regulatory investigation.

Read More »

Get a Free Consultation