It'd be reasonable to think that the most troubling part of a phishing attack is your valuable data being stolen. But did you know your business could also be at risk of serious fines if your data protection security was substandard to begin with?
Earlier this year, the Information Commissioner’s Office (ICO) found fault with the cybersecurity of South Staffordshire Plc and South Staffordshire Water Plc (together ‘South Staffordshire’), issuing the organisation with a fine of almost £1 million after a major cyber-attack led to a data breach.
Rhiannon Hastings, solicitor in Muckle LLP’s commercial team, considers what businesses should do to effectively protect their data, mitigate cyber threats and prevent serious fines now and in the future.
Think before you click
Over a third of small British businesses were hit by a cyber attack in the past year, costing them almost £27,000 each.
Phishing remains the most prevalent form of cyberattack, with 38% of businesses falling victim to the scams in 2025.
But what can happen if your business is caught out by malicious hackers?
In 2020, South Staffordshire fell victim to a phishing email, which allowed attackers to infiltrate the organisation’s systems. Almost two years later, in May 2022, undetected, the attackers granted themselves domain administrator privileges – the highest level of access.
The breach wasn’t identified until July 2022, triggering an internal investigation. Towards the end of July 2022, South Staffordshire reported a personal data breach to the ICO and two days later, discovered a ransom note from the hackers.
Unfortunately, South Staffordshire’s personal information, including the addresses, dates of birth, telephone numbers, national insurance numbers, passwords and bank account details of 633,887 people was published to the dark web.
The case is a cruel reminder of how simple it is for skilled attackers to access private data. But, as the ICO also fined South Staffordshire years down the line for having poor cybersecurity, it also emphasises that lost data shouldn’t be the only concern for businesses exploited by cybercriminals.
Significant fines can also be on the table if your business isn’t demonstrating compliance with UK data protection laws, so it’s vital to have robust protection in place.
Safeguarding your company’s reputation
Your business can quite literally pay the price if the ICO finds that your data wasn’t secure under UK data protection law.
In 2022, the ICO’s investigation into South Staffordshire found it had failed to implement appropriate security controls as required under UK data protection law. They identified obsolete, unsupported software on some devices and insufficient vulnerability management measures, including the lack of regular security scans.
As South Staffordshire had been cooperative, admitted its failings early and outlined measures to prevent recurrences, the ICO applied a 40% reduction to the fine, leaving South Staffordshire to pay £963,900. However, this is still a significant financial hit for any business neglecting its responsibilities under UK data protection law.
Prioritising cybersecurity
The case serves as a cautionary tale for all businesses and reinforces that the ICO won’t turn a blind eye to poor cybersecurity and resilience.
Businesses should always consider whether:
1. They have adequate controls in place, ensuring that only those who need to access certain data are authorised to do so and that they don’t have access to more information than necessary
2. They have suitable logging and monitoring controls in place to identify and manage threats early on
3. Staff are properly trained to identify and deal with threats
4. They are regularly updating their software and using compatible devices
5. They are deploying regular internal and external scanning to identify threats and system compromises
For guidance on how to prevent data breaches in your business, please contact Rhiannon Hastings via rhiannon.hastings@muckle-llp.com or 0191 211 7891.

