On the 10th of March, UK criminal defence law firm Tuckers Solicitors was fined £98,000 by the Information Commissioners Office (ICO).

The fine was released after a ransomware attack saw 60 court documents, including medical statements and witness statements, being published on the Dark Web in 2020.

In their ruling, the ICO found that Tuckers had broken the General Data Protection Regulation 2016 by not introducing multi-factor authentication for remote-access users. This is a responsibility for any business but this was a significant error on the part of a national law firm that holds highly sensitive and private data. Regarding this, the ICO stated, “Had MFA been used, it could have substantially supported Tuckers in preventing access to its network”.

The firm also delayed patching a critical vulnerability, believed to be in Citrix Application Delivery Controller (ADC). Citrix provided a patch for this vulnerability on the 19th of January, but Tuckers only installed it on June 2020, five months after it was released, and three months after the NCSC announced that organisations were required to install it.

NCSC ‘Cyber Essentials‘, for which TecSec is a Certification body, requires patches that are rated as ‘high’ or ‘critical’ should be applied within 14 days of the release of the patch. As Tuckers had failed to install a critical patch within 5 months of it being released, this represents a clear cyber security failure.

These were not the only failures cited by the ICO, as personal data stored on Tuckers’ archive server was not encrypted, and was later seized in the ransomware attack. Their statement was that “The Commissioner accepts that encryption of the personal data may not have prevented the ransomware attack. However, it would have mitigated some of the risks this attack posed to the affected data subjects.”

The criminal law firm failed a Cyber Essentials assessment in October 2019. The ICO stated that “Given the personal data that Tuckers should have not only have met, but surpassed the basic requirements of Cyber Essentials. The fact that some 10 months after failing Cyber Essentials it had still not resolved this issue is, in the Commissioner’s view, sufficient to constitute a negligent approach to data security obligations”.

Other practices that the ICO have deemed negligent on the part of Tuckers includes their processing of personal data on an operating system which ended mainstream support in 2015 and extended support in January 2020. The only comparable software that meets these requirements is Windows 7.

Another practice is their storage of court bundles after the required seven-year retention period, some of which were lost to the ransomware attack. A failure to adhere to or justify departures from its retention practices creates concerns about their compliance with Article S(I)(e) GDPR, which requires personal data to be “kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed,” the ICO found.

In order to mitigate the fine, Tuckers have engaged with third-party experts to implement measures to increase the security of its systems. These measures include updating its infrastructure and implementing MFA. Tuckers have also instructed an outside vendor to take care of updating and patching its core infrastructure and software. It has engaged with Cyber Griffin and agreed to let Cyber Griffin audit its security procedures before applying for Cyber Essentials and then Cyber Essentials Plus. The Law firm has automated the deletion of personal data in its case management system on the expiry of the retention period and for personal data outside of the CMS, and is using an external consultant to identify tools that will support the classification and automated deletion of personal data.

Had Tuckers employed the services of a suitably qualified IT and Risk Management company from the outset they could have prevented much if not all of the attack and the consequences outlined.

In a statement regarding the ransomware attack and the ICO’s decision, Tuckers stated “Tuckers Solicitors takes data privacy and trust very seriously. We are disappointed in this initial finding from the ICO, relative to an international criminal organisations attack on our system and theft of data that was already publicly available“.

They went on to add, “We have cooperated in full with the ICO and City of London Police in their investigation. The commissioner makes clear that he accepts that primary culpability for this incident rests with the attacker. But for the attacker’s criminal actions, regardless of the state of the security, the breach would not have occurred. Following the attack, we have successfully implemented a broad range of measures to prevent the recurrence of such criminal incidents and the ICO acknowledges the strengthened procedures which are now in place as we operate from a state of the art system“.


This fine could easily have been avoided and this incident should serve as a good reminder to all firms and businesses that they should be employing the services of a suitably qualified I.T. firm, and where possible one that is a Certification Body for Cyber Essentials and CE+.

Had Tuckers used a firm such as TecSec Services to deliver not only their IT but also to help them to achieve the CE standards, it is likely they would have avoided the cost and damage to reputation commonly associated with such an incident.

For more information on our Cyber Essentials assessments, view our page here.