The Information Commissioner's Office (ICO) has warned that complacency is a bigger risk than hackers as UK construction giant Interserve is issued a fine of £4.4 million following a data breach,
The ICO has warned that companies are leaving themselves open to cyber attack by ignoring crucial measures like updating software and training staff.
Berkshire-based construction company, Interserve Group, was fined for failing to keep personal information of its staff secure – a breach of data protection law.
The ICO found that the company failed to put appropriate security measures in place to prevent a cyber attack, which enabled hackers to access the personal data of up to 113,000 employees through a phishing email.
The compromised data included personal information such as contact details, national insurance numbers, and bank account details, as well as special category data including ethnic origin, religion, details of any disabilities, sexual orientation, and health information.
John Edwards, UK Information Commissioner, said: "The biggest cyber risk businesses face is not from hackers outside of their company, but from complacency within their company. If your business doesn't regularly monitor for suspicious activity in its systems and fails to act on warnings, or doesn't update software and fails to provide training to staff, you can expect a similar fine from my office.
"Leaving the door open to cyber attackers is never acceptable, especially when dealing with people's most sensitive information. This data breach had the potential to cause real harm to Interserve's staff, as it left them vulnerable to the possibility of identity theft and financial fraud.
"Cyber attacks are a global concern, and businesses around the world need to take steps to guard against complacency. The ICO and NCSC already work together to offer advice and support to businesses, and this week I will be meeting with regulators from around the world, to work towards consistent international cyber guidance so that people's data is protected wherever a company is based."
• Details of the Interserve data breach
An Interserve employee forwarded a phishing email, which was not quarantined or blocked by the Interserve's system, to another employee who opened it and downloaded its content. This resulted in the installation of malware onto the employee's workstation.
The company's anti-virus quarantined the malware and sent an alert, but Interserve failed to thoroughly investigate the suspicious activity. If they had done so, Interserve would have found that the attacker still had access to the company's systems.
The attacker subsequently compromised 283 systems and 16 accounts, as well as uninstalling the company's anti-virus solution. Personal data of up to 113,000 current and former employees was encrypted and rendered unavailable.
The ICO investigation found that Interserve failed to follow-up on the original alert of a suspicious activity, used outdated software systems and protocols, and had a lack of adequate staff training and insufficient risk assessments, which ultimately left them vulnerable to a cyber attack.
Interserve broke data protection law by failing to put appropriate technical and organisational measures in place to prevent the unauthorised access of people's information.
The ICO issued Interserve with a 'notice of intent' - a legal document that precedes a potential fine. The provisional fine amount was set at £4.4million. Having carefully considered representations from Interserve, no reductions were made to the final fine amount.
Construction News
25/10/2022
ICO: 'Complacency Greater Risk Than Hackers'


16/04/2025
Construction work on the £5 million repair and refurbishment project at the Loch Centre in Tranent is scheduled to commence in June 2026.
East Lothian Council has announced the anticipated start date for the significant upgrade to the well-used community facility.
Under the current timetable, the

16/04/2025
A £636,000 project to install solar panels at the Gorbals water pumping station in South Ayrshire has been successfully completed.
The scheme aims to provide a renewable energy source for pumping water to thousands of customers in the region.
The project involved the installation of 793 solar pan

16/04/2025
A planning application has been lodged with Glasgow City Council by The JR Group, acting on behalf of Wheatley Group, for the construction of 29 much-needed affordable homes in the Baillieston area of the city.
The proposed development on Caledonia Road will offer a mix of one- and two-bedroom apa

16/04/2025
Residents in 20 blocks of flats across Coatbridge are already experiencing the positive impacts of a recently completed, ambitious energy efficiency refurbishment project.
The extensive construction work has delivered significant improvements to the properties, including the installation of cavity

16/04/2025
Ground investigation works are commencing this month at the proposed site for Orkney Islands Council’s Scapa Deep Water Quay at Deepdale in Holm.
These initial investigations will be followed by marine-based site investigation works scheduled to begin in June.
These works form part of the Pre-Con

16/04/2025
Construction work has been finalised on a significant new housing development in Motherwell town centre, delivering 42 newly built, highly energy-efficient flats alongside the respectful conversion of the B-Listed YMCA building into a further six homes. The project, part of North Lanarkshire Council

16/04/2025
The Construction Industry Training Board (CITB) has today released its year-end performance data for its New Entrant Support Team (NEST), revealing a significant increase in apprenticeship starts. During the financial year 2024-25, NEST supported 4,128 individuals in commencing apprenticeships, a su

16/04/2025
A water-powered mill in Angus is set to grind grain once again after receiving a record-breaking donation to fund its restoration.
The National Trust for Scotland has announced that a long-time member of the conservation charity has gifted an incredible £2.4 million, one of the largest single dona

15/04/2025
Construction of a £70 million student accommodation development at 292-298 St Vincent Street in Glasgow has reached a significant milestone, with the building now visibly rising from the ground.
Drone footage has captured the progress of the project, which is a partnership between developer Artisa

15/04/2025
Energy regulator Ofgem is expected to confirm today (April 15) its finalised Connections Reform process, designed to expedite grid connections for renewable energy projects that are ready and crucial for achieving the UK's clean power targets for 2030 and beyond.
The new connections system, anticip