UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Servnet Research · Regulatory data · Open Government Licence

The ICO cyber caseload: the published outcome of 956 closed cyber investigations, 2021 to 2026

The published trackers of ICO enforcement count the actions the Information Commissioner's Office takes. None of the trackers we could read carries the cyber caseload those actions came out of, because the enforcement register does not contain it; one, behind a subscription, we could not read at all; the closest prior work, Bristows in 2023, computed a caseload denominator for one year on a mixed population. This study computes it from the regulator's own 21 quarterly cyber-investigation files - 41 files in all once the companion incidents series is included - as the complete outcome distribution of 956 closed cyber investigations published between January 2021 and March 2026.

956
Closed cyber investigations published, 21 quarterly files, Jan-Mar 2021 to Jan-Mar 2026
10 (1.05%, one in 96)
Ended on the penalty track, of 956 closed cyber investigations
23 (2.41%)
Ended in a reprimand, of 956 closed cyber investigations
2.2% (one in 45)
Penalty rate excluding Jan-Mar 2021, the first published quarter, of 454 closures outside Jan-Mar 2021
4.76% (one in 21)
Penalty rate excluding all of calendar 2021, of 168 closures from January 2022 onwards

Updated 29 September 2026 · 41 ICO quarterly data sets, retrieved 29 September 2026 · method and dataset below

The finding

One in 96 pooled, one in 45 once the first published quarter is set aside, one in 21 from 2022

10 of the 956 cyber investigations the ICO closed and published between January 2021 and March 2026 ended on the penalty track - 1.05%, or one in 96. 23 ended in a reprimand (2.41%). The remaining 923 (96.55%) ended in neither.

Read that with the concentration beside it: 52.51% of these closures fall in the single quarter Jan-Mar 2021. Excluding that quarter the penalty rate is 2.2% (one in 45, n=454); excluding all of calendar 2021 it is 4.76% (one in 21, n=168). The pooled figure describes 2021 more than it describes 2026.

Figures computed on 2026-09-29 from the 41 quarterly CSV files the ICO had published at that date, covering closures from January 2021 to March 2026.

Read this first

What these figures are, and what they are not

  • This is a FLOW of cases the ICO closed and published each quarter, not a STOCK of every cyber case the regulator has ever handled. It cannot tell you how many cyber cases are open.
  • Say 'published caseload', not 'caseload'. These quarterly data sets are a publication, and what goes into them is a choice the regulator makes. The ICO does not usually announce individual decisions to take no further action.
  • 502 of the 956 closures - 52.51% - fall in one quarter, Jan-Mar 2021, and 788 of the 956 - 82.43% - fall in calendar 2021 as a whole.
  • The headline roughly doubles when the first published quarter, Jan-Mar 2021, is removed (1.05% of 956 to 2.2% of 454) and roughly quadruples when all of calendar 2021 is removed (4.76% of 168). All three are published together for that reason.
  • Descriptive, not a criticism of the regulator. This page counts published outcome strings; it makes no claim about why any case ended where it did, and no claim about whether the pattern is or is not in line with the ICO’s Regulatory Action Policy. Nothing here is an argument that the regulator should fine more often, and nothing here is an argument for buying anything.
  • Small n. From 2024 the yearly denominators fall to double and single figures. Any year with n below 50 is too small to rank and any year with n below 10 is reported as a count only. A single case moves those rates by tens of percentage points.
  • 'Penalty track' is a definition, not a field in the data. It means the published outcome records a monetary penalty issued, pursued, under appeal, or issued and not recovered. Four defensible codings were computed and they give between 8 and 11 cases out of 956; the published figure is 10. The headline does not turn on the coding.
  • The penalty grouping is Bristows', extended by one outcome string. They published the grouping in April 2023; we add 'Not recoverable', which they place in their Closed/Other group. On their grouping unchanged the figure is 9 of 956 rather than 10, and both are printed. Nothing here is a first.
  • NOT a measure of how often UK organisations are fined for cyber attacks in general. It measures what happened to the cases the ICO itself closed and published in these two data sets.
  • NOT a measure of security. A case closed with no action is not a finding that the organisation was secure, and a reprimand is not a finding that it was not.
  • Population is UK-jurisdiction, not UK-domiciled. Non-UK entities appear because the ICO regulates controllers processing UK personal data. The right phrase is 'organisations reported to the UK regulator', not 'UK organisations'.
  • No organisation is named anywhere in the dataset. Counted as distinct strings, the organisation and controller columns of the source files carry 921 values in the 21 investigations files and 1688 across all 41 - upper bounds on the number of organisations, because the column is not a clean register. None of those strings appears in any published file here, and the emitter refuses to write a row containing one.
  • The source's controller column is a case-title field, not a clean organisation register: it carries entries such as an ICO case title rather than a company name, a bare initialism, and a group name where the ICO's published action names a subsidiary. Any organisation named in the page text must be taken from the ICO's published enforcement or reprimand page, never from this column.

The remaining 9 limits are printed in full in the method section, alongside the dropped-row register and the points where our figures depart from the study brief. All 22 are also in the machine-readable file.

The denominator

The denominator the fine trackers do not carry

Trackers of ICO enforcement count actions taken. The ICO's own enforcement register lists penalties, enforcement notices, reprimands and prosecutions; the published trackers built on it count the same things. None of the ones we could read carries the published caseload those actions came out of, because the register does not contain it. Bristows computed a caseload denominator from these same ICO data sets in 2023, for one calendar year and with civil and cyber investigations pooled; it is credited in full below. The ICO publishes the caseload separately, as quarterly CSV files of closed cyber cases. This study is a census of those files: 956 closed cyber investigations across 21 consecutive quarterly publications, with the outcome recorded on every one of them.

What was countedValue
Closed cyber investigations published, Jan 2021 to Mar 2026956
Quarterly CSV files read41
Cases with a published outcome100.00% of 956
Distinct case references (investigations)956
Duplicate case references (investigations)0
Closed cyber incidents, carried as context only796
Rows in the published dataset1,752

Scroll the table sideways to see every column →

Every figure on this page is a count of all 956 closed cyber investigations published by the ICO over 21 quarters, except where a different denominator is printed beside it. “Penalty track” is our label, not a field in the source: Our label for the published outcome strings that record a monetary penalty issued, pursued, under appeal, or issued and not recovered: 'appeal', 'civil monetary penalty pursued', 'fine - higher tier', 'not recoverable', 'paid in full'. The grouping is Bristows', extended by one string.

Outcomes

What the 956 closed investigations ended in

Every one of the 956 cases carries a published outcome - coverage is 100.0%. Just under four fifths of the published caseload - 756 of 956, 79.08% - ends in one of two strings: 'No action for DC' and 'Advice provided'.

Published outcome of every closed cyber investigation, 956 cases
No action for DCNo action for DC: 518 of 956 closed investigations (54.18%)518 · 54.18%Advice providedAdvice provided: 238 of 956 closed investigations (24.90%)238 · 24.90%No further actionNo further action: 72 of 956 closed investigations (7.53%)72 · 7.53%No Personal DataNo Personal Data: 69 of 956 closed investigations (7.22%)69 · 7.22%ReprimandReprimand: 23 of 956 closed investigations (2.41%)23 · 2.41%Closed - duplicateClosed - duplicate: 10 of 956 closed investigations (1.05%)10 · 1.05%Closed after intervention - in line with RAPClosed after intervention - in line with RAP: 10 of 956 closed investigations (1.05%)10 · 1.05%Paid in fullPaid in full: 5 of 956 closed investigations (0.52%)5 · 0.52%NFA - ICO not LSANFA - ICO not LSA: 3 of 956 closed investigations (0.31%)3 · 0.31%Civil monetary penalty pursuedCivil monetary penalty pursued: 2 of 956 closed investigations (0.21%)2 · 0.21%AppealAppeal: 1 of 956 closed investigations (0.10%)1 · 0.10%Closed - Documents pasted into existing caseClosed - Documents pasted into existing case: 1 of 956 closed investigations (0.10%)1 · 0.10%Fine - higher tierFine - higher tier: 1 of 956 closed investigations (0.10%)1 · 0.10%MPN not issuedMPN not issued: 1 of 956 closed investigations (0.10%)1 · 0.10%NFA - Created in errorNFA - Created in error: 1 of 956 closed investigations (0.10%)1 · 0.10%Not recoverableNot recoverable: 1 of 956 closed investigations (0.10%)1 · 0.10%0130259389518Closed cyber investigations (of 956)
Penalty trackReprimandNeither

Scroll the chart sideways to see all of it →

Source: ICO Cyber investigations quarterly data sets (OGL v3.0), retrieved 29 September 2026. Bars are counts on a linear scale, so the small categories are hairlines; read the printed figure. Amber = penalty track, violet = reprimand, grey = neither.

Published outcomeCasesShare of 956Track
No action for DC51854.18%Neither
Advice provided23824.90%Neither
No further action727.53%Neither
No Personal Data697.22%Neither
Reprimand232.41%Reprimand
Closed - duplicate101.05%Neither
Closed after intervention - in line with RAP101.05%Neither
Paid in full50.52%Penalty track
NFA - ICO not LSA30.31%Neither
Civil monetary penalty pursued20.21%Penalty track
Appeal10.10%Penalty track
Closed - Documents pasted into existing case10.10%Neither
Fine - higher tier10.10%Penalty track
MPN not issued10.10%Neither
NFA - Created in error10.10%Neither
Not recoverable10.10%Penalty track
Total95699.98%

Scroll the table sideways to see every column →

Outcome strings are counted as the ICO published them. Only spelling, wording and encoding variants of one outcome are folded together: the family “Closed after intervention - in line with RAP” is “Closed after intervention–in line with RAP” (6), “Closed after intervention and in line with RAP” (1), “Closed after intervention–in line with RAP” (3). Each raw string and its count is preserved in the dataset beside the family. Shares are rounded to two decimals, so the column sums to 99.98% rather than exactly 100%.

The three tracks, and how sensitive they are to the definition

10 of 956 closed investigations (1.05%) reached the penalty track, 23 (2.41%) ended in a reprimand, and 923 (96.55%) in neither. Every rate in this section is pooled across all 956 closures: outside Jan–Mar 2021 the same 10 penalty-track cases are 2.20% of 454, and the 8 closed from January 2022 onwards are 4.76% of 168. 'Penalty track' is our label for a group of published outcome strings, not a field in the data. Four defensible codings were computed. Across all four, the count moves between 8 and 11 cases out of 956, so the pooled figure does not turn on which one a reader prefers.

Coding of the penalty trackOutcome strings it countsCasesShare of 956About one in
Published herePaid in full, Civil monetary penalty pursued, Fine - higher tier, Appeal, Not recoverable. A penalty was issued, pursued, under appeal, or issued and not recovered.101.05%96
StrictestPaid in full, Civil monetary penalty pursued, Fine - higher tier only.80.84%120
Bristows’ published groupingBristows' published grouping, verbatim: Appeal; Civil monetary penalty pursued; fine - higher tier; and Paid in full. Not recoverable sits in their Closed/Other group.90.94%106
BroadestThe house coding plus MPN not issued, which records a penalty considered and not issued.111.15%87

Scroll the table sideways to see every column →

And the denominator, tested the other way. The four codings stress-test the numerator. The denominator is stress-tested once, the other way: 81 of the 956 rows (8.47%) carry an outcome that records an administrative closure rather than a worked case. Removing them raises the penalty rate from 1.05% of 956 to 1.14% (10 of 875, one in 88), so the headline does not turn on whether they are counted. The cut that does move it is the period: 2.20% of the 454 closures outside Jan-Mar 2021, and 4.76% of the 168 from January 2022 onwards. The 81 are 'Closed - Documents pasted into existing case', 'Closed - duplicate', 'NFA - Created in error', 'No Personal Data'.

The central weakness

The weakness, stated up front: this describes 2021

52.51% of the closures in this population - 502 of 956 - fall in one quarter, Jan-Mar 2021, the first quarter the ICO published, and 788 of 956 - 82.43% - fall in calendar 2021 as a whole. That quarter contains no penalty-track case and no reprimand at all. The pooled rate is therefore dominated by a single quarter, and every cut is published rather than one. Why that quarter is so large is not something the published data answers, and no explanation is asserted here.

Penalty-track and reprimand rates on five populations drawn from the same 956 cases
All 21 quarters, 2021 to 2026n = 956All 21 quarters, 2021 to 2026: 10 of 956 (1.05%)1.05% (10)All 21 quarters, 2021 to 2026: 23 of 956 (2.41%)2.41% (23)Jan–Mar 2021 only (the first published quarter)n = 502Jan–Mar 2021 only (the first published quarter): 0 of 502 (0.00%)0.00% (0)Jan–Mar 2021 only (the first published quarter): 0 of 502 (0.00%)0.00% (0)Excluding Jan–Mar 2021n = 454Excluding Jan–Mar 2021: 10 of 454 (2.20%)2.20% (10)Excluding Jan–Mar 2021: 23 of 454 (5.07%)5.07% (23)Calendar 2021 onlyn = 788Calendar 2021 only: 2 of 788 (0.25%)0.25% (2)Calendar 2021 only: 5 of 788 (0.63%)0.63% (5)From January 2022 onwardsn = 168From January 2022 onwards: 8 of 168 (4.76%)4.76% (8)From January 2022 onwards: 18 of 168 (10.71%)10.71% (18)0%3%6%9%12%Share of that population’s closed investigations

Scroll the chart sideways to see all of it →

Source: ICO Cyber investigations quarterly data sets (OGL v3.0). Each row is a different population; its n is printed beside the label. Upper bar = penalty track (amber), lower bar = reprimand (violet).

PopulationClosed cases (n)Penalty trackReprimandNeither
All closed cyber investigations, Jan-Mar 2021 to Jan-Mar 202695610 (1.05%)23 (2.41%)923 (96.55%)
Closures in Jan-Mar 2021 only5020 (0.00%)0 (0.00%)502 (100.00%)
Excluding Jan-Mar 2021, the first published quarter45410 (2.20%)23 (5.07%)421 (92.73%)
Closures in calendar 2021 only7882 (0.25%)5 (0.63%)781 (99.11%)
Excluding all of calendar 20211688 (4.76%)18 (10.71%)142 (84.52%)

Scroll the table sideways to see every column →

502 of the 956 closures (52.51%) fall in Jan–Mar 2021, the first quarter the ICO published, and that quarter contains 0 penalty-track cases and 0 reprimands. Only 31 closures (3.24%) fall in the nine most recent published quarters. The pooled rate is therefore a description of 2021 with a thin tail attached, which is why all five populations are printed rather than one.

Why that quarter is large is not something this page claims to know. The nearest thing to evidence about that quarter, published rather than left out: 287 of its 502 closures (57.17%) carry a case reference whose four-digit year is earlier than the year the case closed, against 25 of 231 (10.82%) in the next quarter. The ICO does not publish what that year means, so this is a description of the reference strings. It is consistent with the first published quarter clearing older cases and is not proof of it, and the quarter is named by its date everywhere on this page rather than labelled a backlog.

By year of closure, with each year’s own denominator

From 2024 the yearly denominators fall below 50 and then below 10. Years with n below 10 are reported as counts with no percentage. No year in this table is a trend.

Year the ICO published the closureClosed cases (n)Penalty trackReprimandNeither
Closed in 20217882 (0.25%)5 (0.63%)781 (99.11%)
Closed in 2022404 (10.00%)6 (15.00%)30 (75.00%)
Closed in 2023970 (0.00%)9 (9.28%)88 (90.72%)
Closed in 2024180 (0.00%)3 (16.67%)15 (83.33%)
Closed in 202582 (n<10, no %)0 (n<10, no %)6
Closed in 2026 (Jan-Mar only)52 (n<10, no %)0 (n<10, no %)3

Scroll the table sideways to see every column →

n is below 10, so counts only are reported: a single case would move any percentage by more than ten points. No year in this table is a trend, and no year is ranked against another.

The series

Closures per quarter

A bare sourced count of cases closed and published per quarter, with no trend read into it. The published data cannot distinguish the ICO closing fewer cases from the ICO publishing fewer, so no such claim is made.

Cyber investigations closed and published, by quarter (956 cases across 21 quarterly files)
Closed cases0150300450600Jan-Mar 2021 (Q1): 502502Q1Apr-Jun 2021 (Q2): 231231Q2Jul-Sep 2021 (Q3): 3535Q3Oct-Dec 2021 (Q4): 2020Q4Jan-Mar 2022 (Q1): 1111Q1Apr-Jun 2022 (Q2): 88Q2Jul-Sep 2022 (Q3): 66Q3Oct-Dec 2022 (Q4): 1515Q4Jan-Mar 2023 (Q1): 4141Q1Apr-Jun 2023 (Q2): 1111Q2Jul-Sep 2023 (Q3): 2121Q3Oct-Dec 2023 (Q4): 2424Q4Jan-Mar 2024 (Q1): 66Q1Apr-Jun 2024 (Q2): 66Q2Jul-Sep 2024 (Q3): 55Q3Oct-Dec 2024 (Q4): 11Q4Jan-Mar 2025 (Q1): 0 (file published, no closure in it)0Q1Apr-Jun 2025 (Q2): 11Q2Jul-Sep 2025 (Q3): 33Q3Oct-Dec 2025 (Q4): 44Q4Jan-Mar 2026 (Q1): 55Q1202120222023202420252026Quarter in which the ICO published the closure

Scroll the chart sideways to see all of it →

Source: ICO Cyber investigations quarterly data sets (OGL v3.0). Jan-Mar 2025 (Q1) had a file published with no closure in it and is drawn as a marked zero rather than omitted. The quarter comes from the ICO's own publication file, not from any date in the row. The two agree on every case: the calendar quarter of the published closure date matches the quarter of the file it appears in for all 956 investigations (verified).

No trend is read into this shape. 502 of the 956closures land in Jan–Mar 2021, the first quarter published, and the published data cannot separate the regulator closing fewer cases from the regulator publishing fewer of them.

Context

The incidents file, as context only

The ICO publishes a second quarterly series, of closed cyber incidents: 796 cases across 20 files. It is shown here for scale and is not part of the denominator.

Cyber incidents closed and published, by quarter (796 cases across 20 quarterly files)
Closed cases050100150200Apr-Jun 2021 (Q2): 2424Q2Jul-Sep 2021 (Q3): 8787Q3Oct-Dec 2021 (Q4): 7474Q4Jan-Mar 2022 (Q1): 118118Q1Apr-Jun 2022 (Q2): 8888Q2Jul-Sep 2022 (Q3): 5353Q3Oct-Dec 2022 (Q4): 103103Q4Jan-Mar 2023 (Q1): 5656Q1Apr-Jun 2023 (Q2): 5151Q2Jul-Sep 2023 (Q3): 3939Q3Oct-Dec 2023 (Q4): 1515Q4Jan-Mar 2024 (Q1): 1616Q1Apr-Jun 2024 (Q2): 2626Q2Jul-Sep 2024 (Q3): 77Q3Oct-Dec 2024 (Q4): 55Q4Jan-Mar 2025 (Q1): 1111Q1Apr-Jun 2025 (Q2): 0 (file published, no closure in it)0Q2Jul-Sep 2025 (Q3): 33Q3Oct-Dec 2025 (Q4): 55Q4Jan-Mar 2026 (Q1): 1515Q1202120222023202420252026Quarter in which the ICO published the closure

Scroll the chart sideways to see all of it →

Source: ICO Cyber incidents quarterly data sets (OGL v3.0). Apr-Jun 2025 (Q2) had a file published with no closure in it and is drawn as a marked zero rather than omitted. There is no Jan-Mar 2021 cyber incidents file: the ICO states on the landing page that no relevant cases were held for that period. 21 investigations files against 20 incidents files is therefore not a gap in collection.

Published outcomeCasesShare of 796
No further action72891.46%
Closed after intervention - in line with RAP344.27%
No Personal Data Involved222.76%
Advice provided70.88%
Does not meet threshold40.50%
No UK Jurisdiction10.13%

Scroll the table sideways to see every column →

Why no escalation rate. Dividing 956 closed investigations by 796 closed incidents would produce something that looks like an escalation rate. It is not one, and it is not published here. The two are separate publications with different inclusion rules; the incidents series has no Jan-Mar 2021 file at all; and neither file records whether a given incident later became an investigation. The ICO states that the cases on the incidents data sets "are those which were considered but not progressed to a full Investigation", so the two files are the two outcomes of one triage step rather than a pool and the share of it that escalated. The ratio would measure ICO publication practice, not case escalation. Bristows published an escalation rate for 2022 (9% of the cyber incidents in their 2022 population); we do not repeat it, for these reasons.

Repeated references on this side. The zero-duplicates figure on the denominator is a statement about the 956 investigations. The incidents side carries 2 repeated references out of 796 rows and they are reported rather than removed: IC/0018/2024 appears in 4030363__cyber-crimson-incidents-q4-2023-24.csv; IC/0028/2024 appears in 4031244__cyber-incidents-2024-25-q1-closed-datasets.csv and pwghpy4r__cyber-incidents-q2-2025-26.csv. One is an exact duplicate row inside a single ICO file; the other is the same reference closed twice, in two different files, with two different outcomes. Both are left in the dataset as published.

Prior art

What was already known, and what this adds

Bristows published the adjacent analysis in April 2023: Marc Dautlich, 'The ICO's complaints and concerns data sets', covering calendar 2022 only, with civil and cyber investigations pooled, n = 311. They reported 2% monetary penalty, 14% reprimand, 17% advice, 67% no action. They also built the penalty grouping this study extends, and they excluded the 2021 data sets on purpose, because in their words those files "suggested a marked change in approach to Cyber Investigations between 2021 and 2022".

What this study adds

  • 21 consecutive quarters rather than one calendar year.
  • Cyber only, rather than cyber and civil investigations pooled.
  • The complete outcome distribution - every published outcome string with its count - rather than four summary percentages.
  • The sensitivity analysis: pooled, excluding the first published quarter and excluding all of 2021 side by side, plus a by-year table with its small-n warning.
  • A published, per-row dataset with the source file, URL and hash on every row.

What it does not claim. Not a first. Bristows published an adjacent headline three years earlier, on a population that overlaps this one for 2022, and the penalty grouping is theirs, extended here by one outcome string ('Not recoverable'). On their grouping unchanged the figure is 9 of 956 rather than 10, and both are printed in the codings table above.

Two halves, and both are stated. Our cyber-only 2022 reprimand rate is 6 of 40 (15.0%) against their 14% on 311 mixed cases - close enough to be worth a sentence as a consistency check, and no more than that. The penalty rates do not agree: 4 of 40 (10.0%) here against their 2%, and 4 cases in 40 is not a stable estimate of anything.

The published fine trackers all count actions, not cases: Bridewell (58 monetary penalties, 49 enforcement notices, 65 reprimands and 3 prosecutions published between 2023 and 2026, extracted from the ICO Enforcement Register on 11 May 2026), URM Consulting for 2024 and for 2025, BDO's rolling action counts, and the GDPR Enforcement Tracker operated by CMS, whose stated scope is that only GDPR fines are listed. None publishes a denominator, because the enforcement register does not contain one. All four are listed in the sources table below, cited and not reused.

Practical Law (Thomson Reuters) publishes an 'ICO civil penalties: tracker'. It returned HTTP 403 to an identified bot and is subscription-only, so it is not quoted, not counted and not replaced with a weaker source. Prior art in full: Bristows LLP (Inquisitive Minds) - 'The ICO's complaints and concerns data sets', Marc Dautlich, 26 April 2023.

Method

What was measured, when, and how

How these figures were produced

  • The published outcome of every cyber case the Information Commissioner's Office closed and published in its own quarterly 'Cyber investigations' and 'Cyber incidents' data sets, from Jan-Mar 2021 to Jan-Mar 2026.
  • The 41 CSV files were retrieved once each on 2026-09-29, starting 2026-09-29T06:57:09Z, at the 6-second crawl delay ico.org.uk publishes. Analysis is offline and makes no network request.
  • All 41 CSVs were downloaded once each, single-threaded, at the 6-second Crawl-delay ico.org.uk/robots.txt sets, with an identifying User-Agent, and stored byte-identical with a sha256 per file. No authenticated access and no scanning of any kind.
  • Each file is decoded utf-8-sig first and cp1252 on failure. Mojibake is repaired per field, not per file, because one file is genuinely mixed; the string as read is preserved in the dataset beside the repaired one.
  • A row counts as a case only where its case-reference column matches an ICO case reference of the form INV/nnnn/yyyy or IC/nnnn/yyyy. That one objective rule isolates the non-case rows: 4 across all 41 files, listed individually with file and line number in the dropped-row register below.
  • The quarter of each case comes from the ICO's own publication file via a hard-coded, auditable 41-row table, never inferred from a date. ICO financial quarters run Q1 = Apr-Jun to Q4 = Jan-Mar, so 'q4-2025-26' is Jan-Mar 2026. As a check, the calendar quarter of each case's published closure date was compared with the quarter of the file it appears in: they agree on every case.
  • Outcome strings are counted exactly as published. Only spelling, wording and encoding variants of one outcome are folded into a family - one family folds a published string in which the word 'and' stands where the others carry a dash - and each family lists the raw strings and counts that make it up.
  • The controller / organisation columns were read only to set a boolean and to build a blocklist. The emitter checks every value of every row against that blocklist and refuses to write the file if an organisation name reaches it.

What was deliberately not computed

  • An escalation rate from incidents to investigations - an unbounded publication artefact. Reason on the page.
  • Any sector league table - sector is present on only 11.72% of investigations.
  • Any duration or 'the ICO took N days' metric - the Crimson start date is present on only 17.57% of investigations. The closure date is present on 100.0%; the drop is about start-date coverage.
  • Any pound figure - 'Final Value' is 0 or blank on 956 of 956 investigations and on all 10 penalty-track rows.
  • Any claim that the ICO is investigating more or less than before.
  • Any naming of an organisation that suffered a cyber attack.

Limits

  • It measures a publication. What the ICO chooses to publish in these files is a regulatory decision, and the files' coverage can change without the underlying caseload changing.
  • It is heavily weighted to 2021. See the concentration figures above.
  • It is cyber only. Civil investigations are published separately and are not included.
  • It is a flow of closures, not a stock of cases.

The remaining caveats, in full

Every caveat this study wrote is on this page. These are the 9 that are about how the files are built rather than about what the figures mean; the other 13 are in Read this first.

  • Series break, explained by the publisher. From Q4 2022-23 the ICO joins its two case systems - ICE360 for complaints and breach reports, Crimson for cyber investigations - so files from that quarter carry ICE_ and CRIMSON_ prefixes while earlier files use a flat 4-6 column schema. That is the main reason there are 19 distinct header shapes as published (18 once trailing whitespace in header names is trimmed).
  • Encoding. Three of the 41 files are not valid UTF-8 and need a cp1252 fallback. One of them is genuinely mixed - UTF-8 byte sequences inside an otherwise cp1252 file - so a whole-file cp1252 read mangles an en-dash that is not damaged at source. Repair is done per field, and the string as read is preserved in the dataset beside the repaired one.
  • Quarters with a file and no cases. 21 quarterly investigation files were published but only 20 quarters contain a closure; Jan-Mar 2025 (Q1) is annotation-only. It stays in the series as an explicit zero, because dropping it shortens the series and inflates the recent-quarters share.
  • The incidents data set has no Jan-Mar 2021 file at all: the ICO states on the landing page that no relevant cases were held for that period. The two series do not cover the same span.
  • Coverage of the fields we do not use: sector is present on 11.72% of investigations and the Crimson start date on 17.57%. The closure date is present on 100.0%. Those coverage figures are why the sector breakdown and every duration metric are dropped - the drop is about start-date coverage, not closure-date coverage.
  • No pound figure is derivable. 'Final Value' is 0 or blank on 956 of 956 investigations, including all 10 penalty-track rows.
  • Denominator sensitivity. 81 of the 956 rows (8.47%) record an administrative closure rather than a worked case - no personal data, a duplicate record, documents pasted into an existing case, or a record created in error. Excluding all four the penalty rate is 10 of 875 (1.14%) rather than 1.05%, so the headline does not turn on whether they are counted.
  • No escalation rate. Dividing closed investigations by closed incidents would look like one and is not: the two are separate publications with different inclusion rules, the incidents series is missing its first quarter entirely, and neither file records whether a given incident later became an investigation. Any such ratio measures ICO publication practice, not case escalation. Bristows published one (9% of 2022 cyber incidents); we do not repeat it, and this is why.
  • No trend claim. The published data cannot distinguish the ICO handling fewer cases from the ICO publishing fewer cases, so no statement about enforcement rising or falling is made here.

Rows dropped, listed one by one

A row counts as a case only where its case-reference column holds an ICO case reference. That rule removed 4 rows from all 41 files, and every one of them is printed here rather than summarised.

Source fileLineWhy it is not a caseThe row as published
4020217__202101-202103-cyber-investigations.csv2all-blank row,,,,
4020224__202104-202106-cyber-investigations.csv2all-blank row,,,,
sf4ptnae__cyber-incidents-q1-2025-26.csv2reference column holds no ICO case reference - not a case row* NB no relevent incident cases concluded in this quarter,,,
wpfdra4w__q4-2024-2025-cyber-investigations-final.csv2reference column holds no ICO case reference - not a case row* NB no relevent investigations cases concluded in this quarter,,,,,,,,,,,,,

Scroll the table sideways to see every column →

From Q4 2022-23 the ICO joins ICE360 and Crimson, so the file schema changes. 19 distinct header shapes as published, 18 trimmed. The outcome column is named 'Investigation Outcome Desc', 'CRIMSON_InvestigationOutcome' or 'CRIMSON Investigation Outcome' depending on the quarter. 3 files decoded as cp1252; 38 files decoded as utf-8-sig. Repair is per field, not per file: 3 rows carry one mojibaked outcome string, read as “Closed after intervention–in line with RAP” and repaired to “Closed after intervention–in line with RAP”, with both kept in the dataset. The ICO's quarterly files are static once published. Every row of the published dataset carries the sha256 of the file it came from, so a revision is detectable rather than silent. If a hash stops matching, the study is re-run and re-dated rather than patched.

Where this page departs from what we set out to publish, reported rather than reconciled

The “study brief” and the working notes below are Servnet’s own unpublished planning documents for this study, written before the files were parsed. They are not a source and are not published; they are named here only so that the changes made after the data came back are on the record rather than quietly absorbed.

PointWhat we set out to publishWhat the files showHow it was handled
Naive investigation row countThe study brief said a naive parse gives 958 investigation rows.Parsing all 21 investigation files here gives 959 body rows.Reported as measured rather than forced. The brief's arithmetic does not close either: 958 minus 3 non-case rows would give 955, not 956. 959 body rows minus the 3 non-case rows gives 956, the headline denominator, exactly.
Position of the two blank investigation rowsThe brief described them as trailing rows.Both are the first body row, immediately under the header, in the Jan-Mar 2021 and Apr-Jun 2021 files. Both files end on a real case row.Corrected here; see the dropped-row register, which prints file and line number.
Number of distinct header shapesThe brief said 19.19 comparing header cells exactly as published, 18 after trimming whitespace from header names.Both are published and the page says which convention it is using. The difference is a trailing space in one column name in two files.
MojibakeThe brief said three cp1252 files produce three mojibaked outcome strings.Three files need a cp1252 fallback, but only one produces mojibake, and it produces one distinct mojibaked string appearing on 3 rows.The accurate wording is 'three rows carrying one mojibaked string'.
'21 consecutive quarters, no gaps'True of the files.Not true of the closures: 20 quarters contain at least one closure, because Jan-Mar 2025 (Q1) is annotation-only.The page says '21 consecutive quarterly files, 20 quarters with at least one closure'.
Which outcomes belong on the penalty trackThe brief includes 'Not recoverable' and excludes 'MPN not issued'.Bristows' published grouping includes neither 'Not recoverable' nor 'MPN not issued', giving 9.All four codings are published. They span 8 to 11 cases out of 956; the headline figure is 10 and the conclusion does not turn on the choice.
Where the penalty-track cases fall by yearAn earlier internal coding of ours put one penalty-track case in 2023 and one in 2026.Recomputed here: none in 2023 and two in 2026. The two tables differ by exactly one case in each year and both total 10.The difference is entirely the coding. That working file counted 'MPN not issued' (closed 11 January 2023) as penalty track and excluded 'Not recoverable' (closed 9 February 2026); this study does the reverse, following the definition it publishes. Both give 10 overall. The by-year table here uses the published coding, and the codings block lets a reader rebuild either.
How much of the denominator closed in 2021An earlier internal working figure of ours put it at 733 of 956, 78%.Recomputed here from the closure dates: 788 of 956, 82.43%.The figure computed from the published dataset is the one used. It can be recomputed from the CSV by counting investigation rows with closure_year == '2021'.
The study titleOur own planning note titled this 'what actually happens after a UK cyber attack is reported'.That frames the population as reported cyber attacks. The population measured is the cases the ICO closed and published, which is neither a sample of cyber attacks nor a sample of reports made to the regulator.Retitled to the population actually measured. The original phrasing is not used anywhere on the page.

Scroll the table sideways to see every column →

Sources

SourcePublisherWhat was takenLicence
ICO - Cyber investigations and Cyber incidents quarterly data sets (41 CSV files)Information Commissioner's OfficeEvery published row of all 41 quarterly CSVs, Jan-Mar 2021 to Jan-Mar 2026. The controller / organisation columns were read only to set a boolean and to build a blocklist that the emitter checks against; no organisation name appears in any output.Open Government Licence v3.0
ICO - Copyright and re-use of materialsInformation Commissioner's OfficeThe licence grant and the exact attribution wording, quoted verbatim.Open Government Licence v3.0
Open Government Licence v3.0The National ArchivesNothing. Linked as the licence deed only.—
Bristows LLP (Inquisitive Minds) - 'The ICO's complaints and concerns data sets', Marc Dautlich, 26 April 2023Bristows LLPPrior art. Cited, not reused.All rights reserved. Quoted briefly for attribution and comparison.
ICO - Regulatory Action Policy, November 2018Information Commissioner's OfficeThe policy the data's own 'in line with RAP' outcome string refers to. In force across the data period except that its penalty-notice sections were replaced by the Data Protection Fining Guidance on 18 March 2024.Open Government Licence v3.0
ICO - Data protection fining guidance, 18 March 2024Information Commissioner's OfficeEvidence for the date on which the Regulatory Action Policy's penalty-notice sections were replaced, inside this study's data window. Quoted: it 'replaces the sections about penalty notices in the Regulatory Action Policy published in November 2018'.Open Government Licence v3.0
ICO - draft Data Protection Enforcement Procedural Guidance v0.8, 31 October 2025Information Commissioner's OfficeQuoted for the ICO's own description of what a reprimand is. Draft, not final: the consultation closed on 23 January 2026 and we did not check whether a final version has since been published.Open Government Licence v3.0
Bridewell - 'Average value of ICO monetary penalties up 370 percent since 2023'BridewellCited, not reused. A numerator-only tracker. Its counts are of records published between 2023 and 2026, extracted from the ICO Enforcement Register on 11 May 2026.All rights reserved. Figures quoted briefly for comparison.
URM Consulting - analyses of ICO enforcement action, 2024 and 2025URM ConsultingCited, not reused. Numerator-only trackers. The 2024 analysis is at https://www.urmconsulting.com/blog/analysis-of-fines-imposed-by-the-information-commissioners-office-in-2024All rights reserved. Named, no figure reproduced.
BDO - 'Trends in recent ICO enforcement action'BDO LLPCited, not reused. A numerator-only tracker. Named, no figure reproduced.All rights reserved.
GDPR Enforcement Tracker, operated by CMSCMS Legal Services EEIGCited, not reused. A numerator-only tracker. Its own stated scope is that only GDPR fines are listed, which is why it carries no caseload denominator.All rights reserved.

Scroll the table sideways to see every column →

Attribution, as required by the licence: “Information Commissioner's Office, Cyber investigations and Cyber incidents quarterly data sets, published January 2021 to March 2026, licensed under the Open Government Licence.” The ICO's grant covers text content and refuses image re-use. No ICO image, chart or screenshot is reproduced. The Open Government Licence deed itself was linked and never fetched, because The National Archives publishes a signal asking that its pages are not used as AI input. Downloads: CSV, 1,752 rows · README and attribution · JSON. The dataset contains no organisation names, individual names, contact details or any other personal data.

FAQ

Questions about the ICO cyber caseload

How often does an ICO cyber investigation end in a fine?

On the published record it is uncommon, and the rate depends heavily on the period you take. Of the 956 cyber investigations the Information Commissioner's Office closed and published in its own quarterly data sets between January 2021 and March 2026, 10 (1.05%, about one in 96) carry an outcome recording a monetary penalty issued, pursued, under appeal, or issued and not recovered — not all of which are fines. The grouping is Bristows' (April 2023), extended here by one outcome string; four defensible codings of it give between 8 and 11 of the 956, and 10 is the coding published here. That pooled rate is weighted by one very large quarter: the same 10 cases are 2.20% of the 454 closures outside January to March 2021. Narrowing further, 8 penalty-track cases fall among the 168 closures published from January 2022 onwards (4.76%); the other 2 closed during 2021.

How many ICO cyber investigations end in a reprimand?

23 of the 956 cyber investigations the ICO closed and published between January 2021 and March 2026, which is 2.41%. Excluding January to March 2021, the first published quarter, it is 23 of 454 (5.07%); from January 2022 onwards it is 18 of 168 (10.71%).

What is the most common outcome of an ICO cyber investigation?

Across the 956 closed cyber investigations the ICO published from January 2021 to March 2026, the two largest published outcome strings are "No action for DC" on 518 cases (54.18%) and "Advice provided" on 238 (24.90%). Together they account for 79.08% of that published caseload. Outside January to March 2021 the neither-outcome share is 421 of 454 (92.73%), and from January 2022 onwards 142 of 168 (84.52%). 923 of the 956 (96.55%) ended in neither a penalty nor a reprimand.

Does a cyber case closed with no action mean the organisation was secure?

No, and the published data does not support reading it that way. A case closed with no action is not a finding that the organisation was secure, and a reprimand is not a finding that it was not. Of the 956 closed cyber investigations published between January 2021 and March 2026, 518 carry the outcome "No action for DC"; that is a record of what the regulator did next, not an assessment of the organisation's security.

Is this the number of UK organisations fined after a cyber attack?

No. It counts only what happened to the 956 cyber investigations the ICO itself closed and published in its quarterly "Cyber investigations" data sets between January 2021 and March 2026, of which 10 reached the penalty track — and over half those closures fall in the single quarter Jan–Mar 2021, which contains none of them. Cases the regulator has not closed, has not published in these files, or handled as civil rather than cyber investigations are outside the population, and the ICO's jurisdiction covers any controller processing UK personal data, so not every organisation counted is UK-domiciled.

What source is this built from, and when was it collected?

The 41 quarterly CSV files the Information Commissioner's Office publishes as its "Cyber investigations" and "Cyber incidents" data sets, covering January 2021 to March 2026, each downloaded once on 29 September 2026 and stored with a SHA-256 hash. They yield 956 closed cyber investigations and 796 closed cyber incidents, 1,752 cases in all. The source is licensed under the Open Government Licence v3.0; the derived dataset is published under CC BY 4.0 and contains no organisation or individual names.

Why is there no escalation rate from cyber incidents to cyber investigations?

Because the two published files will not support one. Dividing 956 closed investigations by 796 closed incidents would produce something that looks like an escalation rate. It is not one, and it is not published here. The two are separate publications with different inclusion rules; the incidents series has no Jan-Mar 2021 file at all; and neither file records whether a given incident later became an investigation. The ICO states that the cases on the incidents data sets "are those which were considered but not progressed to a full Investigation", so the two files are the two outcomes of one triage step rather than a pool and the share of it that escalated. The ratio would measure ICO publication practice, not case escalation. Bristows published an escalation rate for 2022 (9% of the cyber incidents in their 2022 population); we do not repeat it, for these reasons.

Has anyone published this before?

An adjacent analysis exists and is credited here. Bristows (Marc Dautlich, 26 April 2023) analysed the ICO's investigation data sets for calendar 2022 only, with civil and cyber investigations pooled, n = 311, and reported 2% monetary penalty and 14% reprimand. This study covers 21 consecutive quarterly files rather than one year, counts cyber investigations only, publishes the complete outcome distribution of all 956 closed cases rather than four summary percentages, and adds the sensitivity to the first published quarter. The penalty grouping is Bristows', extended by one outcome string ("Not recoverable", which they place in their Closed/Other group); on their grouping unchanged the figure is 9 of 956 rather than 10.

Related

Cases, not reports

This study counts cases the regulator worked and closed. For the other side of the same pipeline - the personal data breach reports organisations made to the ICO - see our study of the ICO's data security incident trends. The two count different things - reports received against cases closed - but they are not disjoint sets, and we do not claim they are. The ICO says of the cyber files that "cyber investigations usually originate from a data protection complaint or self-reported data breach case", and that from Q4 2022-23 those files carry the originating ICE360 record alongside the Crimson one, so a case counted here may also sit inside the breach reports counted there, and we have not measured how often. The ICO separately says of the breach-report data that "under specific circumstances some cases are transferred to a separate system for review" and "are not included within this data". It does not name that system in the same place; treating it as Crimson, the system these cyber files come from, is our reading and not an ICO statement.

UK data breach statistics 2026: seven years of reports to the ICOThe other side of the same pipeline: the personal data breach reports organisations made to the ICO, 2019 to 2025.Open →Who holds a current NHS data-security assessmentA census of the DSP Toolkit register, counted the same way: a population, not a league table.Open →What CISA’s own ransomware advisories nameThe nearest sibling of this study: a census of what a regulator-adjacent body publishes, counted the same way.Open →UK public sector email security census 2026A measured census of 907 public sector bodies against the government’s own email security standard.Open →Windows 10 security fixes missed since end of supportA dated count of the fixes an unsupported Windows 10 estate has not received.Open →

Servnet Research publishes dated observations from public sources for information only. It is not legal, security, financial or investment advice, and data are provided without warranty. Spotted an error, or want something re-measured or reviewed? See our corrections and takedown policy.

More Servnet research · Corrections and takedown policy

About this study

  • What it is: a census of the 41 quarterly “Cyber investigations” and “Cyber incidents” CSV files the Information Commissioner’s Office had published as at 29 September 2026, covering closures from January 2021 to March 2026. It reports the published outcome of 956 closed cyber investigations and 796 closed cyber incidents. It is a flow of cases the regulator closed and published, not a stock of cases it holds, and it is not a measure of any organisation’s security.
  • Licence and attribution: contains public sector information licensed under the Open Government Licence v3.0 — “Information Commissioner's Office, Cyber investigations and Cyber incidents quarterly data sets, published January 2021 to March 2026, licensed under the Open Government Licence.”. Servnet’s derived dataset and analysis are free to reuse under CC BY 4.0, carrying that attribution and crediting “Servnet: the ICO cyber caseload 2026” with a link to this page. The ICO’s grant covers text and excludes images, so no ICO chart or screenshot is reproduced here.
  • Third-party names: Bristows, Inquisitive Minds, Thomson Reuters, Practical Law, Bridewell, URM Consulting, BDO, CMS and GDPR Enforcement Tracker are trade marks of their respective owners, used only to identify products and organisations. Servnet is not affiliated with, endorsed by or acting for them.
  • Our interest: Servnet sells and maintains IT hardware and services. This study measures a regulator’s published caseload, not a product Servnet sells, and nothing here is a security recommendation or an argument for buying anything. No organisation paid for, sponsored or approved it.
  • Errors and takedown: tell us at webmaster@servnetuk.com and we will check it; see the corrections and takedown policy.

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111