ICO CYBER CASELOAD TRACKER 2026 The published outcome of every cyber case the ICO closed and published, Jan-Mar 2021 to Jan-Mar 2026 ==================================================================================================== FILE ico-cyber-caseload-tracker-2026.csv ROWS 1752 data rows plus one header row UNIT one closed ICO cyber case 956 closed cyber investigations (the headline denominator) 796 closed cyber incidents (context only, not part of the denominator) SNAPSHOT source files retrieved 2026-09-29 (first request 2026-09-29T06:57:09Z) BUILT BY scripts/research/ico-cyber-caseload-tracker-2026/analyse.py - offline, no network request at analysis time ---------------------------------------------------------------------------------------------------- WHAT THIS MEASURES ---------------------------------------------------------------------------------------------------- The outcome the Information Commissioner's Office recorded when it closed a cyber case, as published in the regulator's own quarterly 'Cyber investigations' and 'Cyber incidents' CSV data sets. It is a census of a publication: a FLOW of cases closed in each quarter, not a STOCK of every cyber case the ICO holds. It is NOT a measure of how often UK organisations are fined for cyber attacks in general, NOT a measure of anyone's security, and NOT a sample of cyber attacks or of breach reports. No organisation is named. ---------------------------------------------------------------------------------------------------- HEADLINE FIGURES, EACH WITH ITS DENOMINATOR ---------------------------------------------------------------------------------------------------- Closed cyber investigations published, 21 quarterly files .................. 956 ended on the penalty track ............................................... 10 of 956 = 1.05% (one in 96) ended in a reprimand ..................................................... 23 of 956 = 2.41% ended in neither ......................................................... 923 of 956 = 96.55% SENSITIVITY - read the headline only with these beside it: closures in the first published quarter, Jan-Mar 2021 ................... 502 of 956 = 52.51% penalty track excluding that quarter ..................................... 10 of 454 = 2.2% (one in 45) penalty track excluding all of calendar 2021 ............................. 8 of 168 = 4.76% (one in 21) closures in the nine most recent published quarters ...................... 31 of 956 = 3.24% penalty track excluding the 81 administrative closures ................... 10 of 875 = 1.14% (one in 88) Jan-Mar 2021 is named by its date, never called a backlog quarter: the published data does not say why it is large. As the nearest available evidence, 287 of its 502 closures (57.17%) carry a case reference whose four-digit year is earlier than the year the case closed, against 25 of 231 (10.82%) in the next quarter. That is consistent with a clearance of older cases and is not proof of one. DUPLICATE CASE REFERENCES. The 956 investigations carry 956 distinct references and no duplicate. The 796 incidents carry 794 distinct references: 2 references appear twice and are reported rather than removed. IC/0018/2024 20/02/2024 / No further action / 4030363__cyber-crimson-incidents-q4-2023-24.csv; 20/02/2024 / No further action / 4030363__cyber-crimson-incidents-q4-2023-24.csv IC/0028/2024 19/04/2024 / No further action / 4031244__cyber-incidents-2024-25-q1-closed-datasets.csv; 30/07/2025 / Does not meet threshold / pwghpy4r__cyber-incidents-q2-2025-26.csv ---------------------------------------------------------------------------------------------------- COLUMNS ---------------------------------------------------------------------------------------------------- case_reference The ICO's own case reference, e.g. INV/0105/2020 or IC/0092/2021. Not a person. case_type investigations (the denominator) or incidents (context only). published_quarter The ICO quarterly file this case was published in, as a calendar quarter key. published_quarter_label The same quarter in words. closed_date_raw The closure date exactly as published (dd/mm/yyyy). closed_date_iso The same date as yyyy-mm-dd. closure_quarter Calendar quarter of the closure date. closure_year Calendar year of the closure date. outcome_raw The outcome string exactly as it decodes from the published file, mojibake included. outcome_repaired The same string with per-field mojibake repair applied. outcome_family The repaired string, with spelling and encoding variants of one outcome folded. outcome_track_house_coding penalty_track, reprimand or neither, under the coding this study publishes. sector_raw ICE sector where the file carries one; blank otherwise. Sparse - see the limits. crimson_start_date_raw Crimson start date where published; blank otherwise. Sparse - see the limits. final_value_raw The 'Final Value' field as published. It is 0 or blank throughout. controller_named_in_source yes/no. Whether the source file carried an organisation or controller name for this row; the column name varies ('Organisation' before 2023, 'CRIMSON Data Controller' after). It is 'yes' on all rows. The name itself is never published. source_file The ICO CSV this row came from, as stored in the snapshot. source_url The URL that file was downloaded from. source_sha256 sha256 of that file as downloaded, so any revision is detectable. NO PERSONAL DATA. Counted as distinct strings, the organisation and controller columns of the source files carry 921 values in the 21 investigations files and 1688 across all 41 - upper bounds on the number of organisations, because the column is not a clean register. No organisation name, individual name or contact detail appears in this file. The controller columns were read only to set controller_named_in_source, and the writer refuses to emit a row containing a controller string. The pre-2023 column headed 'Name' holds a case reference, not a person; this was checked at source. ---------------------------------------------------------------------------------------------------- METHOD ---------------------------------------------------------------------------------------------------- 1. All 41 published CSVs were downloaded once each on 2026-09-29, single-threaded, at the 6-second Crawl-delay ico.org.uk/robots.txt sets, with an identifying User-Agent, and stored byte-identical with a sha256 per file. No authenticated access, no scanning, no scraping of anything else. 2. Each file is decoded utf-8-sig first, cp1252 on failure (3 of 41 files need the fallback). One file is genuinely mixed, so mojibake is repaired per field rather than per file; 3 rows are affected and the string as read is kept in outcome_raw beside the repair in outcome_repaired. 3. A row counts as a case only where its case-reference column holds an ICO case reference of the form INV/nnnn/yyyy or IC/nnnn/yyyy. That single objective rule drops 4 non-case rows across all 41 files - two all-blank spacer rows and two ICO annotation lines - and lands on 956 and 796 exactly. 4. The quarter comes from the ICO's own publication file via a hard-coded 41-row table, never inferred from a date. ICO financial quarters run Q1 = Apr-Jun to Q4 = Jan-Mar, so 'q4-2025-26' is Jan-Mar 2026. As a check, the calendar quarter of each closure date was compared with the quarter of its file: they agree on every case. 5. Outcome strings are counted exactly as published. Only spelling, wording and encoding variants of one outcome are folded into a family; one family folds a published string in which the word 'and' stands where the others carry a dash. Every raw string and its count is kept beside the family. SERIES BREAK. From Q4 2022-23 the ICO joins its ICE360 and Crimson case systems, so files from that quarter carry ICE_ and CRIMSON_ prefixes while earlier files use a flat 4-6 column schema. There are 19 distinct header shapes as published, 18 once trailing whitespace in header names is trimmed. QUARTERS WITH A FILE AND NO CASES: Jan-Mar 2025 (Q1). It stays in the series as an explicit zero. There is no Jan-Mar 2021 incidents file at all; the ICO states no relevant cases were held for that period. ---------------------------------------------------------------------------------------------------- DELIBERATELY NOT COMPUTED ---------------------------------------------------------------------------------------------------- * An escalation rate from incidents to investigations. The two are separate publications with different inclusion rules, the incidents series is missing its first quarter, and neither file records whether an incident later became an investigation. The ICO states that the cases on the incidents data sets "are those which were considered but not progressed to a full Investigation", so the two files are the two outcomes of one triage step rather than a pool and the share of it that escalated. Any ratio would measure publication practice, not escalation. * Any sector breakdown. Sector is present on only 11.72% of investigations. * Any duration metric. The Crimson start date is present on only 17.57% of investigations (the closure date is present on 100.0%; the drop is about start-date coverage). * Any pound figure. 'Final Value' is 0 or blank on 956 of 956 investigations and on all 10 penalty-track rows. * Any claim that the ICO is investigating more or less than before. * Any naming of an organisation that suffered a cyber attack. ---------------------------------------------------------------------------------------------------- PRIOR ART ---------------------------------------------------------------------------------------------------- Bristows LLP (Marc Dautlich), 'The ICO's complaints and concerns data sets', 26 April 2023, analysed the same ICO data sets for calendar 2022, with civil and cyber investigations pooled, n = 311, and reported 2% monetary penalty, 14% reprimand, 17% advice and 67% no action. The penalty grouping used here is theirs, extended by one outcome string ('Not recoverable', which they place in their Closed/Other group); on their grouping unchanged the figure is 9 of 956 rather than 10. They excluded the 2021 data sets on purpose, because in their words those files "suggested a marked change in approach to Cyber Investigations between 2021 and 2022". This study covers 21 consecutive quarters rather than one year, cyber only rather than pooled, publishes the complete outcome distribution rather than four summary percentages, and publishes the per-row dataset. It is not a first and does not claim to be one. https://inquisitiveminds.bristows.com/post/102idmi/the-icos-complaints-and-concerns-data-sets ---------------------------------------------------------------------------------------------------- LICENCE AND ATTRIBUTION ---------------------------------------------------------------------------------------------------- SOURCE DATA: Open Government Licence v3.0. Commercial re-use permitted. ATTRIBUTION TO USE when re-using this data, with the name and date of publication filled in as the ICO's condition requires: "Information Commissioner's Office, Cyber investigations and Cyber incidents quarterly data sets, published January 2021 to March 2026, licensed under the Open Government Licence." The ICO states the condition as a template, verbatim from https://ico.org.uk/global/copyright-and-re-use-of-materials/ : "Information Commissioner's Office, [name and date of publication], licensed under the Open Government Licence." The square brackets are the ICO's; the line above them is that template filled in. Licence deed: https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/ The ICO's grant covers text content and excludes images; no ICO image, chart or screenshot is reproduced. THIS DERIVED DATASET: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/), carrying the ICO attribution above verbatim. Please cite as: Servnet, "The ICO cyber caseload: the published outcome of 956 closed cyber investigations, 2021 to 2026", 2026-09-29, https://www.servnetuk.com/research/ico-cyber-caseload-tracker-2026 Contains public sector information licensed under the Open Government Licence v3.0. ---------------------------------------------------------------------------------------------------- HOW TO CHECK THIS ---------------------------------------------------------------------------------------------------- Re-run scripts/research/ico-cyber-caseload-tracker-2026/analyse.py. It makes no network request and rewrites all three outputs. Re-download any of the 41 source CSVs and compare its sha256 with the source_sha256 column. The ICO's quarterly files are static once published, so a mismatch means a revision and the study should be re-run. Every headline above can be recomputed from this CSV alone; lib/research/ico-cyber-caseload-tracker-2026.json carries the pre-registered metrics with a how_to_recompute line on each.