The ICO cyber caseload: the published outcome of 956 closed cyber investigations, 2021 to 2026
The published trackers of ICO enforcement count the actions the Information Commissioner's Office takes. None of the trackers we could read carries the cyber caseload those actions came out of, because the enforcement register does not contain it; one, behind a subscription, we could not read at all; the closest prior work, Bristows in 2023, computed a caseload denominator for one year on a mixed population. This study computes it from the regulator's own 21 quarterly cyber-investigation files - 41 files in all once the companion incidents series is included - as the complete outcome distribution of 956 closed cyber investigations published between January 2021 and March 2026.
Updated 29 September 2026 · 41 ICO quarterly data sets, retrieved 29 September 2026 · method and dataset below
One in 96 pooled, one in 45 once the first published quarter is set aside, one in 21 from 2022
10 of the 956 cyber investigations the ICO closed and published between January 2021 and March 2026 ended on the penalty track - 1.05%, or one in 96. 23 ended in a reprimand (2.41%). The remaining 923 (96.55%) ended in neither.
Read that with the concentration beside it: 52.51% of these closures fall in the single quarter Jan-Mar 2021. Excluding that quarter the penalty rate is 2.2% (one in 45, n=454); excluding all of calendar 2021 it is 4.76% (one in 21, n=168). The pooled figure describes 2021 more than it describes 2026.
Figures computed on 2026-09-29 from the 41 quarterly CSV files the ICO had published at that date, covering closures from January 2021 to March 2026.
What these figures are, and what they are not
- This is a FLOW of cases the ICO closed and published each quarter, not a STOCK of every cyber case the regulator has ever handled. It cannot tell you how many cyber cases are open.
- Say 'published caseload', not 'caseload'. These quarterly data sets are a publication, and what goes into them is a choice the regulator makes. The ICO does not usually announce individual decisions to take no further action.
- 502 of the 956 closures - 52.51% - fall in one quarter, Jan-Mar 2021, and 788 of the 956 - 82.43% - fall in calendar 2021 as a whole.
- The headline roughly doubles when the first published quarter, Jan-Mar 2021, is removed (1.05% of 956 to 2.2% of 454) and roughly quadruples when all of calendar 2021 is removed (4.76% of 168). All three are published together for that reason.
- Descriptive, not a criticism of the regulator. This page counts published outcome strings; it makes no claim about why any case ended where it did, and no claim about whether the pattern is or is not in line with the ICO’s Regulatory Action Policy. Nothing here is an argument that the regulator should fine more often, and nothing here is an argument for buying anything.
- Small n. From 2024 the yearly denominators fall to double and single figures. Any year with n below 50 is too small to rank and any year with n below 10 is reported as a count only. A single case moves those rates by tens of percentage points.
- 'Penalty track' is a definition, not a field in the data. It means the published outcome records a monetary penalty issued, pursued, under appeal, or issued and not recovered. Four defensible codings were computed and they give between 8 and 11 cases out of 956; the published figure is 10. The headline does not turn on the coding.
- The penalty grouping is Bristows', extended by one outcome string. They published the grouping in April 2023; we add 'Not recoverable', which they place in their Closed/Other group. On their grouping unchanged the figure is 9 of 956 rather than 10, and both are printed. Nothing here is a first.
- NOT a measure of how often UK organisations are fined for cyber attacks in general. It measures what happened to the cases the ICO itself closed and published in these two data sets.
- NOT a measure of security. A case closed with no action is not a finding that the organisation was secure, and a reprimand is not a finding that it was not.
- Population is UK-jurisdiction, not UK-domiciled. Non-UK entities appear because the ICO regulates controllers processing UK personal data. The right phrase is 'organisations reported to the UK regulator', not 'UK organisations'.
- No organisation is named anywhere in the dataset. Counted as distinct strings, the organisation and controller columns of the source files carry 921 values in the 21 investigations files and 1688 across all 41 - upper bounds on the number of organisations, because the column is not a clean register. None of those strings appears in any published file here, and the emitter refuses to write a row containing one.
- The source's controller column is a case-title field, not a clean organisation register: it carries entries such as an ICO case title rather than a company name, a bare initialism, and a group name where the ICO's published action names a subsidiary. Any organisation named in the page text must be taken from the ICO's published enforcement or reprimand page, never from this column.
The remaining 9 limits are printed in full in the method section, alongside the dropped-row register and the points where our figures depart from the study brief. All 22 are also in the machine-readable file.
The denominator the fine trackers do not carry
Trackers of ICO enforcement count actions taken. The ICO's own enforcement register lists penalties, enforcement notices, reprimands and prosecutions; the published trackers built on it count the same things. None of the ones we could read carries the published caseload those actions came out of, because the register does not contain it. Bristows computed a caseload denominator from these same ICO data sets in 2023, for one calendar year and with civil and cyber investigations pooled; it is credited in full below. The ICO publishes the caseload separately, as quarterly CSV files of closed cyber cases. This study is a census of those files: 956 closed cyber investigations across 21 consecutive quarterly publications, with the outcome recorded on every one of them.
| What was counted | Value |
|---|---|
| Closed cyber investigations published, Jan 2021 to Mar 2026 | 956 |
| Quarterly CSV files read | 41 |
| Cases with a published outcome | 100.00% of 956 |
| Distinct case references (investigations) | 956 |
| Duplicate case references (investigations) | 0 |
| Closed cyber incidents, carried as context only | 796 |
| Rows in the published dataset | 1,752 |
Scroll the table sideways to see every column →
Every figure on this page is a count of all 956 closed cyber investigations published by the ICO over 21 quarters, except where a different denominator is printed beside it. “Penalty track” is our label, not a field in the source: Our label for the published outcome strings that record a monetary penalty issued, pursued, under appeal, or issued and not recovered: 'appeal', 'civil monetary penalty pursued', 'fine - higher tier', 'not recoverable', 'paid in full'. The grouping is Bristows', extended by one string.
What the 956 closed investigations ended in
Every one of the 956 cases carries a published outcome - coverage is 100.0%. Just under four fifths of the published caseload - 756 of 956, 79.08% - ends in one of two strings: 'No action for DC' and 'Advice provided'.
Scroll the chart sideways to see all of it →
Source: ICO Cyber investigations quarterly data sets (OGL v3.0), retrieved 29 September 2026. Bars are counts on a linear scale, so the small categories are hairlines; read the printed figure. Amber = penalty track, violet = reprimand, grey = neither.
| Published outcome | Cases | Share of 956 | Track |
|---|---|---|---|
| No action for DC | 518 | 54.18% | Neither |
| Advice provided | 238 | 24.90% | Neither |
| No further action | 72 | 7.53% | Neither |
| No Personal Data | 69 | 7.22% | Neither |
| Reprimand | 23 | 2.41% | Reprimand |
| Closed - duplicate | 10 | 1.05% | Neither |
| Closed after intervention - in line with RAP | 10 | 1.05% | Neither |
| Paid in full | 5 | 0.52% | Penalty track |
| NFA - ICO not LSA | 3 | 0.31% | Neither |
| Civil monetary penalty pursued | 2 | 0.21% | Penalty track |
| Appeal | 1 | 0.10% | Penalty track |
| Closed - Documents pasted into existing case | 1 | 0.10% | Neither |
| Fine - higher tier | 1 | 0.10% | Penalty track |
| MPN not issued | 1 | 0.10% | Neither |
| NFA - Created in error | 1 | 0.10% | Neither |
| Not recoverable | 1 | 0.10% | Penalty track |
| Total | 956 | 99.98% |
Scroll the table sideways to see every column →
Outcome strings are counted as the ICO published them. Only spelling, wording and encoding variants of one outcome are folded together: the family “Closed after intervention - in line with RAP” is “Closed after intervention–in line with RAP” (6), “Closed after intervention and in line with RAP” (1), “Closed after intervention–in line with RAP” (3). Each raw string and its count is preserved in the dataset beside the family. Shares are rounded to two decimals, so the column sums to 99.98% rather than exactly 100%.
The three tracks, and how sensitive they are to the definition
10 of 956 closed investigations (1.05%) reached the penalty track, 23 (2.41%) ended in a reprimand, and 923 (96.55%) in neither. Every rate in this section is pooled across all 956 closures: outside Jan–Mar 2021 the same 10 penalty-track cases are 2.20% of 454, and the 8 closed from January 2022 onwards are 4.76% of 168. 'Penalty track' is our label for a group of published outcome strings, not a field in the data. Four defensible codings were computed. Across all four, the count moves between 8 and 11 cases out of 956, so the pooled figure does not turn on which one a reader prefers.
| Coding of the penalty track | Outcome strings it counts | Cases | Share of 956 | About one in |
|---|---|---|---|---|
| Published here | Paid in full, Civil monetary penalty pursued, Fine - higher tier, Appeal, Not recoverable. A penalty was issued, pursued, under appeal, or issued and not recovered. | 10 | 1.05% | 96 |
| Strictest | Paid in full, Civil monetary penalty pursued, Fine - higher tier only. | 8 | 0.84% | 120 |
| Bristows’ published grouping | Bristows' published grouping, verbatim: Appeal; Civil monetary penalty pursued; fine - higher tier; and Paid in full. Not recoverable sits in their Closed/Other group. | 9 | 0.94% | 106 |
| Broadest | The house coding plus MPN not issued, which records a penalty considered and not issued. | 11 | 1.15% | 87 |
Scroll the table sideways to see every column →
And the denominator, tested the other way. The four codings stress-test the numerator. The denominator is stress-tested once, the other way: 81 of the 956 rows (8.47%) carry an outcome that records an administrative closure rather than a worked case. Removing them raises the penalty rate from 1.05% of 956 to 1.14% (10 of 875, one in 88), so the headline does not turn on whether they are counted. The cut that does move it is the period: 2.20% of the 454 closures outside Jan-Mar 2021, and 4.76% of the 168 from January 2022 onwards. The 81 are 'Closed - Documents pasted into existing case', 'Closed - duplicate', 'NFA - Created in error', 'No Personal Data'.
The weakness, stated up front: this describes 2021
52.51% of the closures in this population - 502 of 956 - fall in one quarter, Jan-Mar 2021, the first quarter the ICO published, and 788 of 956 - 82.43% - fall in calendar 2021 as a whole. That quarter contains no penalty-track case and no reprimand at all. The pooled rate is therefore dominated by a single quarter, and every cut is published rather than one. Why that quarter is so large is not something the published data answers, and no explanation is asserted here.
Scroll the chart sideways to see all of it →
Source: ICO Cyber investigations quarterly data sets (OGL v3.0). Each row is a different population; its n is printed beside the label. Upper bar = penalty track (amber), lower bar = reprimand (violet).
| Population | Closed cases (n) | Penalty track | Reprimand | Neither |
|---|---|---|---|---|
| All closed cyber investigations, Jan-Mar 2021 to Jan-Mar 2026 | 956 | 10 (1.05%) | 23 (2.41%) | 923 (96.55%) |
| Closures in Jan-Mar 2021 only | 502 | 0 (0.00%) | 0 (0.00%) | 502 (100.00%) |
| Excluding Jan-Mar 2021, the first published quarter | 454 | 10 (2.20%) | 23 (5.07%) | 421 (92.73%) |
| Closures in calendar 2021 only | 788 | 2 (0.25%) | 5 (0.63%) | 781 (99.11%) |
| Excluding all of calendar 2021 | 168 | 8 (4.76%) | 18 (10.71%) | 142 (84.52%) |
Scroll the table sideways to see every column →
502 of the 956 closures (52.51%) fall in Jan–Mar 2021, the first quarter the ICO published, and that quarter contains 0 penalty-track cases and 0 reprimands. Only 31 closures (3.24%) fall in the nine most recent published quarters. The pooled rate is therefore a description of 2021 with a thin tail attached, which is why all five populations are printed rather than one.
Why that quarter is large is not something this page claims to know. The nearest thing to evidence about that quarter, published rather than left out: 287 of its 502 closures (57.17%) carry a case reference whose four-digit year is earlier than the year the case closed, against 25 of 231 (10.82%) in the next quarter. The ICO does not publish what that year means, so this is a description of the reference strings. It is consistent with the first published quarter clearing older cases and is not proof of it, and the quarter is named by its date everywhere on this page rather than labelled a backlog.
By year of closure, with each year’s own denominator
From 2024 the yearly denominators fall below 50 and then below 10. Years with n below 10 are reported as counts with no percentage. No year in this table is a trend.
| Year the ICO published the closure | Closed cases (n) | Penalty track | Reprimand | Neither |
|---|---|---|---|---|
| Closed in 2021 | 788 | 2 (0.25%) | 5 (0.63%) | 781 (99.11%) |
| Closed in 2022 | 40 | 4 (10.00%) | 6 (15.00%) | 30 (75.00%) |
| Closed in 2023 | 97 | 0 (0.00%) | 9 (9.28%) | 88 (90.72%) |
| Closed in 2024 | 18 | 0 (0.00%) | 3 (16.67%) | 15 (83.33%) |
| Closed in 2025 | 8 | 2 (n<10, no %) | 0 (n<10, no %) | 6 |
| Closed in 2026 (Jan-Mar only) | 5 | 2 (n<10, no %) | 0 (n<10, no %) | 3 |
Scroll the table sideways to see every column →
n is below 10, so counts only are reported: a single case would move any percentage by more than ten points. No year in this table is a trend, and no year is ranked against another.
Closures per quarter
A bare sourced count of cases closed and published per quarter, with no trend read into it. The published data cannot distinguish the ICO closing fewer cases from the ICO publishing fewer, so no such claim is made.
Scroll the chart sideways to see all of it →
Source: ICO Cyber investigations quarterly data sets (OGL v3.0). Jan-Mar 2025 (Q1) had a file published with no closure in it and is drawn as a marked zero rather than omitted. The quarter comes from the ICO's own publication file, not from any date in the row. The two agree on every case: the calendar quarter of the published closure date matches the quarter of the file it appears in for all 956 investigations (verified).
No trend is read into this shape. 502 of the 956closures land in Jan–Mar 2021, the first quarter published, and the published data cannot separate the regulator closing fewer cases from the regulator publishing fewer of them.
The incidents file, as context only
The ICO publishes a second quarterly series, of closed cyber incidents: 796 cases across 20 files. It is shown here for scale and is not part of the denominator.
Scroll the chart sideways to see all of it →
Source: ICO Cyber incidents quarterly data sets (OGL v3.0). Apr-Jun 2025 (Q2) had a file published with no closure in it and is drawn as a marked zero rather than omitted. There is no Jan-Mar 2021 cyber incidents file: the ICO states on the landing page that no relevant cases were held for that period. 21 investigations files against 20 incidents files is therefore not a gap in collection.
| Published outcome | Cases | Share of 796 |
|---|---|---|
| No further action | 728 | 91.46% |
| Closed after intervention - in line with RAP | 34 | 4.27% |
| No Personal Data Involved | 22 | 2.76% |
| Advice provided | 7 | 0.88% |
| Does not meet threshold | 4 | 0.50% |
| No UK Jurisdiction | 1 | 0.13% |
Scroll the table sideways to see every column →
Why no escalation rate. Dividing 956 closed investigations by 796 closed incidents would produce something that looks like an escalation rate. It is not one, and it is not published here. The two are separate publications with different inclusion rules; the incidents series has no Jan-Mar 2021 file at all; and neither file records whether a given incident later became an investigation. The ICO states that the cases on the incidents data sets "are those which were considered but not progressed to a full Investigation", so the two files are the two outcomes of one triage step rather than a pool and the share of it that escalated. The ratio would measure ICO publication practice, not case escalation. Bristows published an escalation rate for 2022 (9% of the cyber incidents in their 2022 population); we do not repeat it, for these reasons.
Repeated references on this side. The zero-duplicates figure on the denominator is a statement about the 956 investigations. The incidents side carries 2 repeated references out of 796 rows and they are reported rather than removed: IC/0018/2024 appears in 4030363__cyber-crimson-incidents-q4-2023-24.csv; IC/0028/2024 appears in 4031244__cyber-incidents-2024-25-q1-closed-datasets.csv and pwghpy4r__cyber-incidents-q2-2025-26.csv. One is an exact duplicate row inside a single ICO file; the other is the same reference closed twice, in two different files, with two different outcomes. Both are left in the dataset as published.
What was already known, and what this adds
Bristows published the adjacent analysis in April 2023: Marc Dautlich, 'The ICO's complaints and concerns data sets', covering calendar 2022 only, with civil and cyber investigations pooled, n = 311. They reported 2% monetary penalty, 14% reprimand, 17% advice, 67% no action. They also built the penalty grouping this study extends, and they excluded the 2021 data sets on purpose, because in their words those files "suggested a marked change in approach to Cyber Investigations between 2021 and 2022".
What this study adds
- 21 consecutive quarters rather than one calendar year.
- Cyber only, rather than cyber and civil investigations pooled.
- The complete outcome distribution - every published outcome string with its count - rather than four summary percentages.
- The sensitivity analysis: pooled, excluding the first published quarter and excluding all of 2021 side by side, plus a by-year table with its small-n warning.
- A published, per-row dataset with the source file, URL and hash on every row.
What it does not claim. Not a first. Bristows published an adjacent headline three years earlier, on a population that overlaps this one for 2022, and the penalty grouping is theirs, extended here by one outcome string ('Not recoverable'). On their grouping unchanged the figure is 9 of 956 rather than 10, and both are printed in the codings table above.
Two halves, and both are stated. Our cyber-only 2022 reprimand rate is 6 of 40 (15.0%) against their 14% on 311 mixed cases - close enough to be worth a sentence as a consistency check, and no more than that. The penalty rates do not agree: 4 of 40 (10.0%) here against their 2%, and 4 cases in 40 is not a stable estimate of anything.
The published fine trackers all count actions, not cases: Bridewell (58 monetary penalties, 49 enforcement notices, 65 reprimands and 3 prosecutions published between 2023 and 2026, extracted from the ICO Enforcement Register on 11 May 2026), URM Consulting for 2024 and for 2025, BDO's rolling action counts, and the GDPR Enforcement Tracker operated by CMS, whose stated scope is that only GDPR fines are listed. None publishes a denominator, because the enforcement register does not contain one. All four are listed in the sources table below, cited and not reused.
Practical Law (Thomson Reuters) publishes an 'ICO civil penalties: tracker'. It returned HTTP 403 to an identified bot and is subscription-only, so it is not quoted, not counted and not replaced with a weaker source. Prior art in full: Bristows LLP (Inquisitive Minds) - 'The ICO's complaints and concerns data sets', Marc Dautlich, 26 April 2023.
What was measured, when, and how
How these figures were produced
- The published outcome of every cyber case the Information Commissioner's Office closed and published in its own quarterly 'Cyber investigations' and 'Cyber incidents' data sets, from Jan-Mar 2021 to Jan-Mar 2026.
- The 41 CSV files were retrieved once each on 2026-09-29, starting 2026-09-29T06:57:09Z, at the 6-second crawl delay ico.org.uk publishes. Analysis is offline and makes no network request.
- All 41 CSVs were downloaded once each, single-threaded, at the 6-second Crawl-delay ico.org.uk/robots.txt sets, with an identifying User-Agent, and stored byte-identical with a sha256 per file. No authenticated access and no scanning of any kind.
- Each file is decoded utf-8-sig first and cp1252 on failure. Mojibake is repaired per field, not per file, because one file is genuinely mixed; the string as read is preserved in the dataset beside the repaired one.
- A row counts as a case only where its case-reference column matches an ICO case reference of the form INV/nnnn/yyyy or IC/nnnn/yyyy. That one objective rule isolates the non-case rows: 4 across all 41 files, listed individually with file and line number in the dropped-row register below.
- The quarter of each case comes from the ICO's own publication file via a hard-coded, auditable 41-row table, never inferred from a date. ICO financial quarters run Q1 = Apr-Jun to Q4 = Jan-Mar, so 'q4-2025-26' is Jan-Mar 2026. As a check, the calendar quarter of each case's published closure date was compared with the quarter of the file it appears in: they agree on every case.
- Outcome strings are counted exactly as published. Only spelling, wording and encoding variants of one outcome are folded into a family - one family folds a published string in which the word 'and' stands where the others carry a dash - and each family lists the raw strings and counts that make it up.
- The controller / organisation columns were read only to set a boolean and to build a blocklist. The emitter checks every value of every row against that blocklist and refuses to write the file if an organisation name reaches it.
What was deliberately not computed
- An escalation rate from incidents to investigations - an unbounded publication artefact. Reason on the page.
- Any sector league table - sector is present on only 11.72% of investigations.
- Any duration or 'the ICO took N days' metric - the Crimson start date is present on only 17.57% of investigations. The closure date is present on 100.0%; the drop is about start-date coverage.
- Any pound figure - 'Final Value' is 0 or blank on 956 of 956 investigations and on all 10 penalty-track rows.
- Any claim that the ICO is investigating more or less than before.
- Any naming of an organisation that suffered a cyber attack.
Limits
- It measures a publication. What the ICO chooses to publish in these files is a regulatory decision, and the files' coverage can change without the underlying caseload changing.
- It is heavily weighted to 2021. See the concentration figures above.
- It is cyber only. Civil investigations are published separately and are not included.
- It is a flow of closures, not a stock of cases.
The remaining caveats, in full
Every caveat this study wrote is on this page. These are the 9 that are about how the files are built rather than about what the figures mean; the other 13 are in Read this first.
- Series break, explained by the publisher. From Q4 2022-23 the ICO joins its two case systems - ICE360 for complaints and breach reports, Crimson for cyber investigations - so files from that quarter carry ICE_ and CRIMSON_ prefixes while earlier files use a flat 4-6 column schema. That is the main reason there are 19 distinct header shapes as published (18 once trailing whitespace in header names is trimmed).
- Encoding. Three of the 41 files are not valid UTF-8 and need a cp1252 fallback. One of them is genuinely mixed - UTF-8 byte sequences inside an otherwise cp1252 file - so a whole-file cp1252 read mangles an en-dash that is not damaged at source. Repair is done per field, and the string as read is preserved in the dataset beside the repaired one.
- Quarters with a file and no cases. 21 quarterly investigation files were published but only 20 quarters contain a closure; Jan-Mar 2025 (Q1) is annotation-only. It stays in the series as an explicit zero, because dropping it shortens the series and inflates the recent-quarters share.
- The incidents data set has no Jan-Mar 2021 file at all: the ICO states on the landing page that no relevant cases were held for that period. The two series do not cover the same span.
- Coverage of the fields we do not use: sector is present on 11.72% of investigations and the Crimson start date on 17.57%. The closure date is present on 100.0%. Those coverage figures are why the sector breakdown and every duration metric are dropped - the drop is about start-date coverage, not closure-date coverage.
- No pound figure is derivable. 'Final Value' is 0 or blank on 956 of 956 investigations, including all 10 penalty-track rows.
- Denominator sensitivity. 81 of the 956 rows (8.47%) record an administrative closure rather than a worked case - no personal data, a duplicate record, documents pasted into an existing case, or a record created in error. Excluding all four the penalty rate is 10 of 875 (1.14%) rather than 1.05%, so the headline does not turn on whether they are counted.
- No escalation rate. Dividing closed investigations by closed incidents would look like one and is not: the two are separate publications with different inclusion rules, the incidents series is missing its first quarter entirely, and neither file records whether a given incident later became an investigation. Any such ratio measures ICO publication practice, not case escalation. Bristows published one (9% of 2022 cyber incidents); we do not repeat it, and this is why.
- No trend claim. The published data cannot distinguish the ICO handling fewer cases from the ICO publishing fewer cases, so no statement about enforcement rising or falling is made here.
Rows dropped, listed one by one
A row counts as a case only where its case-reference column holds an ICO case reference. That rule removed 4 rows from all 41 files, and every one of them is printed here rather than summarised.
| Source file | Line | Why it is not a case | The row as published |
|---|---|---|---|
| 4020217__202101-202103-cyber-investigations.csv | 2 | all-blank row | ,,,, |
| 4020224__202104-202106-cyber-investigations.csv | 2 | all-blank row | ,,,, |
| sf4ptnae__cyber-incidents-q1-2025-26.csv | 2 | reference column holds no ICO case reference - not a case row | * NB no relevent incident cases concluded in this quarter,,, |
| wpfdra4w__q4-2024-2025-cyber-investigations-final.csv | 2 | reference column holds no ICO case reference - not a case row | * NB no relevent investigations cases concluded in this quarter,,,,,,,,,,,,, |
Scroll the table sideways to see every column →
From Q4 2022-23 the ICO joins ICE360 and Crimson, so the file schema changes. 19 distinct header shapes as published, 18 trimmed. The outcome column is named 'Investigation Outcome Desc', 'CRIMSON_InvestigationOutcome' or 'CRIMSON Investigation Outcome' depending on the quarter. 3 files decoded as cp1252; 38 files decoded as utf-8-sig. Repair is per field, not per file: 3 rows carry one mojibaked outcome string, read as “Closed after intervention–in line with RAP” and repaired to “Closed after intervention–in line with RAP”, with both kept in the dataset. The ICO's quarterly files are static once published. Every row of the published dataset carries the sha256 of the file it came from, so a revision is detectable rather than silent. If a hash stops matching, the study is re-run and re-dated rather than patched.
Where this page departs from what we set out to publish, reported rather than reconciled
The “study brief” and the working notes below are Servnet’s own unpublished planning documents for this study, written before the files were parsed. They are not a source and are not published; they are named here only so that the changes made after the data came back are on the record rather than quietly absorbed.
| Point | What we set out to publish | What the files show | How it was handled |
|---|---|---|---|
| Naive investigation row count | The study brief said a naive parse gives 958 investigation rows. | Parsing all 21 investigation files here gives 959 body rows. | Reported as measured rather than forced. The brief's arithmetic does not close either: 958 minus 3 non-case rows would give 955, not 956. 959 body rows minus the 3 non-case rows gives 956, the headline denominator, exactly. |
| Position of the two blank investigation rows | The brief described them as trailing rows. | Both are the first body row, immediately under the header, in the Jan-Mar 2021 and Apr-Jun 2021 files. Both files end on a real case row. | Corrected here; see the dropped-row register, which prints file and line number. |
| Number of distinct header shapes | The brief said 19. | 19 comparing header cells exactly as published, 18 after trimming whitespace from header names. | Both are published and the page says which convention it is using. The difference is a trailing space in one column name in two files. |
| Mojibake | The brief said three cp1252 files produce three mojibaked outcome strings. | Three files need a cp1252 fallback, but only one produces mojibake, and it produces one distinct mojibaked string appearing on 3 rows. | The accurate wording is 'three rows carrying one mojibaked string'. |
| '21 consecutive quarters, no gaps' | True of the files. | Not true of the closures: 20 quarters contain at least one closure, because Jan-Mar 2025 (Q1) is annotation-only. | The page says '21 consecutive quarterly files, 20 quarters with at least one closure'. |
| Which outcomes belong on the penalty track | The brief includes 'Not recoverable' and excludes 'MPN not issued'. | Bristows' published grouping includes neither 'Not recoverable' nor 'MPN not issued', giving 9. | All four codings are published. They span 8 to 11 cases out of 956; the headline figure is 10 and the conclusion does not turn on the choice. |
| Where the penalty-track cases fall by year | An earlier internal coding of ours put one penalty-track case in 2023 and one in 2026. | Recomputed here: none in 2023 and two in 2026. The two tables differ by exactly one case in each year and both total 10. | The difference is entirely the coding. That working file counted 'MPN not issued' (closed 11 January 2023) as penalty track and excluded 'Not recoverable' (closed 9 February 2026); this study does the reverse, following the definition it publishes. Both give 10 overall. The by-year table here uses the published coding, and the codings block lets a reader rebuild either. |
| How much of the denominator closed in 2021 | An earlier internal working figure of ours put it at 733 of 956, 78%. | Recomputed here from the closure dates: 788 of 956, 82.43%. | The figure computed from the published dataset is the one used. It can be recomputed from the CSV by counting investigation rows with closure_year == '2021'. |
| The study title | Our own planning note titled this 'what actually happens after a UK cyber attack is reported'. | That frames the population as reported cyber attacks. The population measured is the cases the ICO closed and published, which is neither a sample of cyber attacks nor a sample of reports made to the regulator. | Retitled to the population actually measured. The original phrasing is not used anywhere on the page. |
Scroll the table sideways to see every column →
Sources
| Source | Publisher | What was taken | Licence |
|---|---|---|---|
| ICO - Cyber investigations and Cyber incidents quarterly data sets (41 CSV files) | Information Commissioner's Office | Every published row of all 41 quarterly CSVs, Jan-Mar 2021 to Jan-Mar 2026. The controller / organisation columns were read only to set a boolean and to build a blocklist that the emitter checks against; no organisation name appears in any output. | Open Government Licence v3.0 |
| ICO - Copyright and re-use of materials | Information Commissioner's Office | The licence grant and the exact attribution wording, quoted verbatim. | Open Government Licence v3.0 |
| Open Government Licence v3.0 | The National Archives | Nothing. Linked as the licence deed only. | — |
| Bristows LLP (Inquisitive Minds) - 'The ICO's complaints and concerns data sets', Marc Dautlich, 26 April 2023 | Bristows LLP | Prior art. Cited, not reused. | All rights reserved. Quoted briefly for attribution and comparison. |
| ICO - Regulatory Action Policy, November 2018 | Information Commissioner's Office | The policy the data's own 'in line with RAP' outcome string refers to. In force across the data period except that its penalty-notice sections were replaced by the Data Protection Fining Guidance on 18 March 2024. | Open Government Licence v3.0 |
| ICO - Data protection fining guidance, 18 March 2024 | Information Commissioner's Office | Evidence for the date on which the Regulatory Action Policy's penalty-notice sections were replaced, inside this study's data window. Quoted: it 'replaces the sections about penalty notices in the Regulatory Action Policy published in November 2018'. | Open Government Licence v3.0 |
| ICO - draft Data Protection Enforcement Procedural Guidance v0.8, 31 October 2025 | Information Commissioner's Office | Quoted for the ICO's own description of what a reprimand is. Draft, not final: the consultation closed on 23 January 2026 and we did not check whether a final version has since been published. | Open Government Licence v3.0 |
| Bridewell - 'Average value of ICO monetary penalties up 370 percent since 2023' | Bridewell | Cited, not reused. A numerator-only tracker. Its counts are of records published between 2023 and 2026, extracted from the ICO Enforcement Register on 11 May 2026. | All rights reserved. Figures quoted briefly for comparison. |
| URM Consulting - analyses of ICO enforcement action, 2024 and 2025 | URM Consulting | Cited, not reused. Numerator-only trackers. The 2024 analysis is at https://www.urmconsulting.com/blog/analysis-of-fines-imposed-by-the-information-commissioners-office-in-2024 | All rights reserved. Named, no figure reproduced. |
| BDO - 'Trends in recent ICO enforcement action' | BDO LLP | Cited, not reused. A numerator-only tracker. Named, no figure reproduced. | All rights reserved. |
| GDPR Enforcement Tracker, operated by CMS | CMS Legal Services EEIG | Cited, not reused. A numerator-only tracker. Its own stated scope is that only GDPR fines are listed, which is why it carries no caseload denominator. | All rights reserved. |
Scroll the table sideways to see every column →
Attribution, as required by the licence: “Information Commissioner's Office, Cyber investigations and Cyber incidents quarterly data sets, published January 2021 to March 2026, licensed under the Open Government Licence.” The ICO's grant covers text content and refuses image re-use. No ICO image, chart or screenshot is reproduced. The Open Government Licence deed itself was linked and never fetched, because The National Archives publishes a signal asking that its pages are not used as AI input. Downloads: CSV, 1,752 rows · README and attribution · JSON. The dataset contains no organisation names, individual names, contact details or any other personal data.
Questions about the ICO cyber caseload
How often does an ICO cyber investigation end in a fine?
On the published record it is uncommon, and the rate depends heavily on the period you take. Of the 956 cyber investigations the Information Commissioner's Office closed and published in its own quarterly data sets between January 2021 and March 2026, 10 (1.05%, about one in 96) carry an outcome recording a monetary penalty issued, pursued, under appeal, or issued and not recovered — not all of which are fines. The grouping is Bristows' (April 2023), extended here by one outcome string; four defensible codings of it give between 8 and 11 of the 956, and 10 is the coding published here. That pooled rate is weighted by one very large quarter: the same 10 cases are 2.20% of the 454 closures outside January to March 2021. Narrowing further, 8 penalty-track cases fall among the 168 closures published from January 2022 onwards (4.76%); the other 2 closed during 2021.
How many ICO cyber investigations end in a reprimand?
23 of the 956 cyber investigations the ICO closed and published between January 2021 and March 2026, which is 2.41%. Excluding January to March 2021, the first published quarter, it is 23 of 454 (5.07%); from January 2022 onwards it is 18 of 168 (10.71%).
What is the most common outcome of an ICO cyber investigation?
Across the 956 closed cyber investigations the ICO published from January 2021 to March 2026, the two largest published outcome strings are "No action for DC" on 518 cases (54.18%) and "Advice provided" on 238 (24.90%). Together they account for 79.08% of that published caseload. Outside January to March 2021 the neither-outcome share is 421 of 454 (92.73%), and from January 2022 onwards 142 of 168 (84.52%). 923 of the 956 (96.55%) ended in neither a penalty nor a reprimand.
Does a cyber case closed with no action mean the organisation was secure?
No, and the published data does not support reading it that way. A case closed with no action is not a finding that the organisation was secure, and a reprimand is not a finding that it was not. Of the 956 closed cyber investigations published between January 2021 and March 2026, 518 carry the outcome "No action for DC"; that is a record of what the regulator did next, not an assessment of the organisation's security.
Is this the number of UK organisations fined after a cyber attack?
No. It counts only what happened to the 956 cyber investigations the ICO itself closed and published in its quarterly "Cyber investigations" data sets between January 2021 and March 2026, of which 10 reached the penalty track — and over half those closures fall in the single quarter Jan–Mar 2021, which contains none of them. Cases the regulator has not closed, has not published in these files, or handled as civil rather than cyber investigations are outside the population, and the ICO's jurisdiction covers any controller processing UK personal data, so not every organisation counted is UK-domiciled.
What source is this built from, and when was it collected?
The 41 quarterly CSV files the Information Commissioner's Office publishes as its "Cyber investigations" and "Cyber incidents" data sets, covering January 2021 to March 2026, each downloaded once on 29 September 2026 and stored with a SHA-256 hash. They yield 956 closed cyber investigations and 796 closed cyber incidents, 1,752 cases in all. The source is licensed under the Open Government Licence v3.0; the derived dataset is published under CC BY 4.0 and contains no organisation or individual names.
Why is there no escalation rate from cyber incidents to cyber investigations?
Because the two published files will not support one. Dividing 956 closed investigations by 796 closed incidents would produce something that looks like an escalation rate. It is not one, and it is not published here. The two are separate publications with different inclusion rules; the incidents series has no Jan-Mar 2021 file at all; and neither file records whether a given incident later became an investigation. The ICO states that the cases on the incidents data sets "are those which were considered but not progressed to a full Investigation", so the two files are the two outcomes of one triage step rather than a pool and the share of it that escalated. The ratio would measure ICO publication practice, not case escalation. Bristows published an escalation rate for 2022 (9% of the cyber incidents in their 2022 population); we do not repeat it, for these reasons.
Has anyone published this before?
An adjacent analysis exists and is credited here. Bristows (Marc Dautlich, 26 April 2023) analysed the ICO's investigation data sets for calendar 2022 only, with civil and cyber investigations pooled, n = 311, and reported 2% monetary penalty and 14% reprimand. This study covers 21 consecutive quarterly files rather than one year, counts cyber investigations only, publishes the complete outcome distribution of all 956 closed cases rather than four summary percentages, and adds the sensitivity to the first published quarter. The penalty grouping is Bristows', extended by one outcome string ("Not recoverable", which they place in their Closed/Other group); on their grouping unchanged the figure is 9 of 956 rather than 10.
Cases, not reports
This study counts cases the regulator worked and closed. For the other side of the same pipeline - the personal data breach reports organisations made to the ICO - see our study of the ICO's data security incident trends. The two count different things - reports received against cases closed - but they are not disjoint sets, and we do not claim they are. The ICO says of the cyber files that "cyber investigations usually originate from a data protection complaint or self-reported data breach case", and that from Q4 2022-23 those files carry the originating ICE360 record alongside the Crimson one, so a case counted here may also sit inside the breach reports counted there, and we have not measured how often. The ICO separately says of the breach-report data that "under specific circumstances some cases are transferred to a separate system for review" and "are not included within this data". It does not name that system in the same place; treating it as Crimson, the system these cyber files come from, is our reading and not an ICO statement.
Servnet Research publishes dated observations from public sources for information only. It is not legal, security, financial or investment advice, and data are provided without warranty. Spotted an error, or want something re-measured or reviewed? See our corrections and takedown policy.
More Servnet research · Corrections and takedown policy
About this study
- What it is: a census of the 41 quarterly “Cyber investigations” and “Cyber incidents” CSV files the Information Commissioner’s Office had published as at 29 September 2026, covering closures from January 2021 to March 2026. It reports the published outcome of 956 closed cyber investigations and 796 closed cyber incidents. It is a flow of cases the regulator closed and published, not a stock of cases it holds, and it is not a measure of any organisation’s security.
- Licence and attribution: contains public sector information licensed under the Open Government Licence v3.0 — “Information Commissioner's Office, Cyber investigations and Cyber incidents quarterly data sets, published January 2021 to March 2026, licensed under the Open Government Licence.”. Servnet’s derived dataset and analysis are free to reuse under CC BY 4.0, carrying that attribution and crediting “Servnet: the ICO cyber caseload 2026” with a link to this page. The ICO’s grant covers text and excludes images, so no ICO chart or screenshot is reproduced here.
- Third-party names: Bristows, Inquisitive Minds, Thomson Reuters, Practical Law, Bridewell, URM Consulting, BDO, CMS and GDPR Enforcement Tracker are trade marks of their respective owners, used only to identify products and organisations. Servnet is not affiliated with, endorsed by or acting for them.
- Our interest: Servnet sells and maintains IT hardware and services. This study measures a regulator’s published caseload, not a product Servnet sells, and nothing here is a security recommendation or an argument for buying anything. No organisation paid for, sponsored or approved it.
- Errors and takedown: tell us at webmaster@servnetuk.com and we will check it; see the corrections and takedown policy.
Talk to a UK specialist
Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.