Article Details

Scrape Timestamp (UTC): 2025-05-01 10:18:05.897

Source: https://www.theregister.com/2025/05/01/ico_brit_library/

Original Article Text

Click to Toggle View

Data watchdog will leave British Library alone – further probes 'not worth our time'. No MFA? No problem – as long as you show you’ve learned your lesson. The UK's data protection overlord is not going to pursue any further investigation into the British Library's 2023 ransomware attack. The Information Commissioner's Office (ICO) said it doesn't think its resources would be best spent on UK's national library, even though it was such a disaster due to MFA not being applied on an admin account. Time to examine the anatomy of the British Library ransomware nightmare "Having carefully considered this particular case, the Information Commissioner decided that, due to our current priorities, further investigation would not be the most effective use of our resources," a statement read. "We have provided guidance to the British Library, which has reassured us about its commitment to continue to review and ensure that appropriate security measures are in place to protect people's data." In the short post on the matter, the ICO – like many others in the cybersecurity community have done since the digital break in – lauded the British Library for its stellar approach to responsibly disclosing the ransomware attack. From the start, the library issued regular, comprehensive updates about its recovery status, and in March 2024 it published a full review of the attack, outlining in depth the institution's IT weaknesses and the lessons it learned. The ICO commended the British Library for its crisis comms, which major organizations are still struggling to emulate years later. "Following the incident, the British Library published a cyber incident review in March 2024, which provided an overview of the cyber-attack and key lessons learnt to help other organisations that may experience similar incidents.   "We commend the British Library for being open and transparent about its system vulnerabilities that contributed to the incident, the impact it has had, and the improvements made so far to protect people's personal information. " The ICO's decision to leave the library in peace is taken at a time when internal resource constraints have contributed to performances that break the wrong records. Earlier this month, the regulator revealed that it missed its complaint response targets by the biggest margin since it started tracking them, and due to current staffing levels, its performance is expected to decline further.  Illustrating the size of the backlog, it said the goal is to respond to all complaints within 90 days, however, only 12.3 percent of complaints from the latest quarter were thoroughly assessed. For context, the ICO has a lot on its plate. For a small-ish team operating out of a modest office in Wilmslow, a small English town in Cheshire East, it received more than 10,000 complaints during the most recent quarter, an increase of 746 compared to the three months prior. The ICO confirmed it was hiring for various roles and "significant digital and process changes" were on the way, with the aim of easing the burden.

Daily Brief Summary

RANSOMWARE // British Library's Ransomware Disclosure Approach Praised by ICO

The UK's Information Commissioner's Office (ICO) has opted not to pursue further investigation into the British Library's 2023 ransomware attack.

The decision was made based on current priorities and resource allocation, despite the severity of the incident caused by a lack of Multi-Factor Authentication (MFA) on an admin account.

The British Library was commended for its transparency and comprehensive communication during the recovery process from the ransomware attack.

In March 2024, the library published an in-depth review of the attack, sharing valuable insights about its IT vulnerabilities and the corrective steps taken post-incident.

The ICO has expressed approval of the Library's ongoing efforts to enhance data security and their proactive measures to educate other organizations on cybersecurity.

Meanwhile, the ICO is facing internal challenges with resource constraints and a significant backlog in complaint resolutions, impacting overall performance.

The ICO is currently hiring and implementing significant digital and process changes to improve efficiency and response times to complaints.