{"slug":"ico-cyber-caseload-tracker-2026","study":"The ICO cyber caseload: the published outcome of 956 closed cyber investigations, 2021 to 2026","question":"When the Information Commissioner's Office closes a cyber investigation and publishes it, what outcome does that case carry - and how often is that outcome a monetary penalty?","short_answer":"10 of the 956 cyber investigations the ICO closed and published between January 2021 and March 2026 ended on the penalty track - 1.05%, or one in 96. 23 ended in a reprimand (2.41%). The remaining 923 (96.55%) ended in neither. Read that with the concentration beside it: 502 of these 956 closures (52.51%) fall in the single quarter Jan-Mar 2021, which contains no penalty-track case and no reprimand. Excluding that quarter the penalty rate is 2.2% of 454 (one in 45); excluding all of calendar 2021 it is 4.76% of 168 (one in 21).","publisher":"Servnet","built":"2026-09-29T08:07:35Z","snapshot_as_at":"2026-09-29","snapshot_utc":"2026-09-29T06:57:09Z","as_at_line":"Figures computed on 2026-09-29 from the 41 quarterly CSV files the ICO had published at that date, covering closures from January 2021 to March 2026.","population":{"n":956,"unit":"one closed, published ICO cyber investigation","definition":"Every case row in the ICO's 21 quarterly 'Cyber investigations' CSVs, Jan-Mar 2021 to Jan-Mar 2026. Defined by the regulator's own publication.","companion_n":796,"total_cases":1752,"flow_not_stock":true},"definitions":{"penalty track":"Our label for the published outcome strings that record a monetary penalty issued, pursued, under appeal, or issued and not recovered: 'appeal', 'civil monetary penalty pursued', 'fine - higher tier', 'not recoverable', 'paid in full'. The grouping is Bristows', extended by one string.","reprimand":"The published outcome string 'Reprimand'. The ICO's draft enforcement procedural guidance (v0.8, 31 October 2025, at https://ico.org.uk/media2/jakfp5aw/enforcement-prod-guidance-consultation-20251031.pdf; consultation closed 23 January 2026) states that a reprimand 'makes a finding that the controller or processor has infringed data protection legislation, but it does not impose any legally binding obligations'. Quoted as the draft that was consulted on; we did not verify whether a final version has since been published.","neither":"Every other published outcome string, including no action, advice, no personal data and the administrative closures.","published caseload":"The cases the ICO chose to publish in these quarterly files. Not every case the regulator handled.","RAP":"The ICO's Regulatory Action Policy of November 2018 (https://ico.org.uk/media2/about-the-ico/documents/2259467/regulatory-action-policy.pdf), the policy the outcome string 'in line with RAP' refers to. It was in force across the data period except that its penalty-notice sections were replaced by the Data Protection Fining Guidance published on 18 March 2024, inside the January 2021 to March 2026 window.","why_this_is_not_a_security_measure":"A case closed with no action is not a finding that the organisation was secure, and a reprimand is not a finding that it was not.","no_organisation_is_named":"No organisation is named anywhere in the published dataset, the README or this page, other than where the ICO has already published an enforcement action or a reprimand of its own."},"preRegisteredMetrics":[{"id":"denominator","statement":"The ICO closed and published 956 cyber investigations across the 21 quarterly files covering Jan-Mar 2021 to Jan-Mar 2026.","value":956,"denominator":956,"denominator_label":"itself - this is the denominator every other figure uses","how_to_recompute":"Count rows in ico-cyber-caseload-tracker-2026.csv where case_type == 'investigations'.","tolerance":"exact"},{"id":"penalty_track_pooled","statement":"10 of those 956 closed cyber investigations - 1.05%, one in 96 - ended on the penalty track.","value":10,"value_pct":1.05,"denominator":956,"denominator_label":"all 956 closed cyber investigations published by the ICO over 21 quarters","how_to_recompute":"Count rows where case_type == 'investigations' and outcome_track_house_coding == 'penalty_track'.","tolerance":"exact"},{"id":"reprimand_pooled","statement":"23 of 956 - 2.41% - ended in a reprimand.","value":23,"value_pct":2.41,"denominator":956,"denominator_label":"all 956 closed cyber investigations published by the ICO over 21 quarters","how_to_recompute":"Count rows where case_type == 'investigations' and outcome_family == 'Reprimand'.","tolerance":"exact"},{"id":"neither_pooled","statement":"923 of 956 - 96.55% - ended in neither a penalty nor a reprimand.","value":923,"value_pct":96.55,"denominator":956,"denominator_label":"all 956 closed cyber investigations published by the ICO over 21 quarters","how_to_recompute":"Count rows where case_type == 'investigations' and outcome_track_house_coding == 'neither'.","tolerance":"exact"},{"id":"first_quarter_concentration","statement":"502 of the 956 closures - 52.51% - fall in the single quarter Jan-Mar 2021.","value":502,"value_pct":52.51,"denominator":956,"denominator_label":"all 956 closed cyber investigations published by the ICO over 21 quarters","how_to_recompute":"Count investigation rows where closure_quarter == '2021Q1'.","tolerance":"exact"},{"id":"penalty_track_ex_first_quarter","statement":"Excluding that quarter, 10 of 454 - 2.2%, one in 45 - ended on the penalty track.","value":10,"value_pct":2.2,"denominator":454,"denominator_label":"the 454 closures outside Jan-Mar 2021","how_to_recompute":"Count investigation rows where closure_quarter != '2021Q1', then the penalty_track subset of those.","tolerance":"exact"},{"id":"penalty_track_ex_2021","statement":"Excluding all of calendar 2021, 8 of 168 - 4.76%, one in 21 - ended on the penalty track.","value":8,"value_pct":4.76,"denominator":168,"denominator_label":"the 168 closures from January 2022 onwards","how_to_recompute":"Count investigation rows where closure_year != '2021', then the penalty_track subset of those.","tolerance":"exact"},{"id":"recency","statement":"Only 31 of the 956 closures - 3.24% - fall in the nine most recent published quarters, Jan-Mar 2024 (Q1) to Jan-Mar 2026 (Q1).","value":31,"value_pct":3.24,"denominator":956,"denominator_label":"all 956 closed cyber investigations published by the ICO over 21 quarters","how_to_recompute":"Sum closed_cases over the last nine quarters of the investigations series, 2024Q1, 2024Q2, 2024Q3, 2024Q4, 2025Q1, 2025Q2, 2025Q3, 2025Q4, 2026Q1. Note 2025Q1 is a published file with zero closures and must stay in the window as a zero.","tolerance":"exact"},{"id":"incidents_context","statement":"The companion cyber incidents data set contributes a further 796 closed cases, giving 1752 cases in all. It is context only.","value":796,"denominator":1752,"denominator_label":"all 1752 closed cyber cases in both data sets","how_to_recompute":"Count rows where case_type == 'incidents'.","tolerance":"exact"}],"page":{"title":"The ICO cyber caseload: the published outcome of 956 closed cyber investigations, 2021 to 2026","standfirst":"The published trackers of ICO enforcement count the actions the Information Commissioner's Office takes. None of the trackers we could read carries the cyber caseload those actions came out of, because the enforcement register does not contain it; one, behind a subscription, we could not read at all; the closest prior work, Bristows in 2023, computed a caseload denominator for one year on a mixed population. This study computes it from the regulator's own 21 quarterly cyber-investigation files - 41 files in all once the companion incidents series is included - as the complete outcome distribution of 956 closed cyber investigations published between January 2021 and March 2026.","headline":"10 of the 956 cyber investigations the ICO closed and published between January 2021 and March 2026 ended on the penalty track - 1.05%, or one in 96. 23 ended in a reprimand (2.41%). The remaining 923 (96.55%) ended in neither.","headline_qualifier":"Read that with the concentration beside it: 52.51% of these closures fall in the single quarter Jan-Mar 2021. Excluding that quarter the penalty rate is 2.2% (one in 45, n=454); excluding all of calendar 2021 it is 4.76% (one in 21, n=168). The pooled figure describes 2021 more than it describes 2026.","as_at_line":"Figures computed on 2026-09-29 from the 41 quarterly CSV files the ICO had published at that date, covering closures from January 2021 to March 2026.","wording_rules":["British English. Plain and factual. No superlatives.","Never 'first', 'only' or 'nobody has ever'. Bristows published an adjacent headline in April 2023 and is credited by name in the opening section.","Always 'published caseload', never 'caseload'.","Always 'organisations reported to the UK regulator', not 'UK organisations'.","Descriptive throughout. This is what the published caseload looks like - never that the regulator lets attackers off, and never a security-purchase argument built on the numbers.","Every percentage carries its denominator in the same sentence or the sentence before it.","No percentage on n below 10; report the count and say why.","The pooled headline never appears without the figures excluding Jan-Mar 2021 in the same block."],"headlines":[{"metric":"Closed cyber investigations published","value":"956","denominator":"21 quarterly files, Jan-Mar 2021 to Jan-Mar 2026","source":"ICO Cyber investigations data sets"},{"metric":"Ended on the penalty track","value":"10 (1.05%, one in 96)","denominator":"of 956 closed cyber investigations","source":"ICO Cyber investigations data sets"},{"metric":"Ended in a reprimand","value":"23 (2.41%)","denominator":"of 956 closed cyber investigations","source":"ICO Cyber investigations data sets"},{"metric":"Ended in neither","value":"923 (96.55%)","denominator":"of 956 closed cyber investigations","source":"ICO Cyber investigations data sets"},{"metric":"Penalty rate excluding Jan-Mar 2021, the first published quarter","value":"2.2% (one in 45)","denominator":"of 454 closures outside Jan-Mar 2021","source":"ICO Cyber investigations data sets"},{"metric":"Penalty rate excluding all of calendar 2021","value":"4.76% (one in 21)","denominator":"of 168 closures from January 2022 onwards","source":"ICO Cyber investigations data sets"}],"sections":[{"id":"the-denominator","heading":"The denominator the fine trackers do not carry","lead":"Trackers of ICO enforcement count actions taken. The ICO's own enforcement register lists penalties, enforcement notices, reprimands and prosecutions; the published trackers built on it count the same things. None of the ones we could read carries the published caseload those actions came out of, because the register does not contain it. Bristows computed a caseload denominator from these same ICO data sets in 2023, for one calendar year and with civil and cyber investigations pooled; it is credited in full below. The ICO publishes the caseload separately, as quarterly CSV files of closed cyber cases. This study is a census of those files: 956 closed cyber investigations across 21 consecutive quarterly publications, with the outcome recorded on every one of them.","findings":{"closed_cyber_investigations":956,"closed_cyber_incidents_context_only":796,"total_cases":1752,"quarterly_files":41,"distinct_case_references":956,"duplicate_case_references":0,"outcome_coverage_pct":100,"denominator_label":"all 956 closed cyber investigations published by the ICO over 21 quarters"}},{"id":"outcomes","heading":"What the 956 closed investigations ended in","lead":"Every one of the 956 cases carries a published outcome - coverage is 100.0%. Just under four fifths of the published caseload - 756 of 956, 79.08% - ends in one of two strings: 'No action for DC' and 'Advice provided'.","denominator":956,"denominator_label":"all 956 closed cyber investigations published by the ICO over 21 quarters","census":[{"outcome_family":"No action for DC","n":518,"share_pct":54.18,"track_house_coding":"neither","raw_strings_as_published":{"No action for DC":518}},{"outcome_family":"Advice provided","n":238,"share_pct":24.9,"track_house_coding":"neither","raw_strings_as_published":{"Advice provided":238}},{"outcome_family":"No further action","n":72,"share_pct":7.53,"track_house_coding":"neither","raw_strings_as_published":{"No further action":72}},{"outcome_family":"No Personal Data","n":69,"share_pct":7.22,"track_house_coding":"neither","raw_strings_as_published":{"No Personal Data":69}},{"outcome_family":"Reprimand","n":23,"share_pct":2.41,"track_house_coding":"reprimand","raw_strings_as_published":{"Reprimand":23}},{"outcome_family":"Closed - duplicate","n":10,"share_pct":1.05,"track_house_coding":"neither","raw_strings_as_published":{"Closed - duplicate":10}},{"outcome_family":"Closed after intervention - in line with RAP","n":10,"share_pct":1.05,"track_house_coding":"neither","raw_strings_as_published":{"Closed after intervention–in line with RAP":6,"Closed after intervention and in line with RAP":1,"Closed after interventionâ€“in line with RAP":3}},{"outcome_family":"Paid in full","n":5,"share_pct":0.52,"track_house_coding":"penalty_track","raw_strings_as_published":{"Paid in full":5}},{"outcome_family":"NFA - ICO not LSA","n":3,"share_pct":0.31,"track_house_coding":"neither","raw_strings_as_published":{"NFA - ICO not LSA":3}},{"outcome_family":"Civil monetary penalty pursued","n":2,"share_pct":0.21,"track_house_coding":"penalty_track","raw_strings_as_published":{"Civil monetary penalty pursued":2}},{"outcome_family":"Appeal","n":1,"share_pct":0.1,"track_house_coding":"penalty_track","raw_strings_as_published":{"Appeal":1}},{"outcome_family":"Closed - Documents pasted into existing case","n":1,"share_pct":0.1,"track_house_coding":"neither","raw_strings_as_published":{"Closed - Documents pasted into existing case":1}},{"outcome_family":"Fine - higher tier","n":1,"share_pct":0.1,"track_house_coding":"penalty_track","raw_strings_as_published":{"Fine - higher tier":1}},{"outcome_family":"MPN not issued","n":1,"share_pct":0.1,"track_house_coding":"neither","raw_strings_as_published":{"MPN not issued":1}},{"outcome_family":"NFA - Created in error","n":1,"share_pct":0.1,"track_house_coding":"neither","raw_strings_as_published":{"NFA - Created in error":1}},{"outcome_family":"Not recoverable","n":1,"share_pct":0.1,"track_house_coding":"penalty_track","raw_strings_as_published":{"Not recoverable":1}}],"tracks":{"penalty_track":10,"penalty_track_pct":1.05,"reprimand":23,"reprimand_pct":2.41,"neither":923,"neither_pct":96.55},"coding_note":"'Penalty track' is our label for a group of published outcome strings, not a field in the data. Four defensible codings were computed.","codings":{"house_published":{"definition":"Paid in full, Civil monetary penalty pursued, Fine - higher tier, Appeal, Not recoverable. A penalty was issued, pursued, under appeal, or issued and not recovered.","penalty_track_n":10,"denominator":956,"pct":1.05,"one_in":96},"strictest_issued_or_pursued":{"definition":"Paid in full, Civil monetary penalty pursued, Fine - higher tier only.","penalty_track_n":8,"denominator":956,"pct":0.84,"one_in":120},"bristows_monetary_penalty_group":{"definition":"Bristows' published grouping, verbatim: Appeal; Civil monetary penalty pursued; fine - higher tier; and Paid in full. Not recoverable sits in their Closed/Other group.","penalty_track_n":9,"denominator":956,"pct":0.94,"one_in":106},"broadest_touched_the_penalty_process":{"definition":"The house coding plus MPN not issued, which records a penalty considered and not issued.","penalty_track_n":11,"denominator":956,"pct":1.15,"one_in":87}},"denominator_sensitivity":{"administrative_closures":{"definition":"Published outcome strings that record the regulator closing a record it had decided was not a case: 'Closed - Documents pasted into existing case', 'Closed - duplicate', 'NFA - Created in error', 'No Personal Data'.","n":81,"share_of_denominator_pct":8.47},"excluding_administrative_closures":{"label":"Excluding the administrative closures","n":875,"denominator_label":"the 875 closed investigations left once the 81 administrative closures are removed","penalty_track":10,"penalty_track_pct":1.14,"penalty_track_one_in":88,"reprimand":23,"reprimand_pct":2.63,"neither":842,"neither_pct":96.23,"n_too_small_for_a_percentage":false,"small_n_note":null}},"denominator_sensitivity_note":"The four codings stress-test the numerator. The denominator is stress-tested once, the other way: 81 of the 956 rows (8.47%) carry an outcome that records an administrative closure rather than a worked case. Removing them raises the penalty rate from 1.05% of 956 to 1.14% (10 of 875, one in 88), so the headline does not turn on whether they are counted. The cut that does move it is the period: 2.20% of the 454 closures outside Jan-Mar 2021, and 4.76% of the 168 from January 2022 onwards."},{"id":"the-concentration","heading":"The weakness, stated up front: this describes 2021","lead":"52.51% of the closures in this population - 502 of 956 - fall in one quarter, Jan-Mar 2021, the first quarter the ICO published, and 788 of 956 - 82.43% - fall in calendar 2021 as a whole. That quarter contains no penalty-track case and no reprimand at all. The pooled rate is therefore dominated by a single quarter, and every cut is published rather than one. Why that quarter is so large is not something the published data answers, and no explanation is asserted here.","cuts":{"pooled":{"label":"All closed cyber investigations, Jan-Mar 2021 to Jan-Mar 2026","n":956,"denominator_label":"all 956 closed cyber investigations published by the ICO over 21 quarters","penalty_track":10,"penalty_track_pct":1.05,"penalty_track_one_in":96,"reprimand":23,"reprimand_pct":2.41,"neither":923,"neither_pct":96.55,"n_too_small_for_a_percentage":false,"small_n_note":null},"first_quarter_only":{"label":"Closures in Jan-Mar 2021 only","n":502,"denominator_label":"the 502 cases closed in the single quarter Jan-Mar 2021","penalty_track":0,"penalty_track_pct":0,"penalty_track_one_in":null,"reprimand":0,"reprimand_pct":0,"neither":502,"neither_pct":100,"n_too_small_for_a_percentage":false,"small_n_note":null},"excluding_first_quarter":{"label":"Excluding Jan-Mar 2021, the first published quarter","n":454,"denominator_label":"the 454 closures outside Jan-Mar 2021","penalty_track":10,"penalty_track_pct":2.2,"penalty_track_one_in":45,"reprimand":23,"reprimand_pct":5.07,"neither":421,"neither_pct":92.73,"n_too_small_for_a_percentage":false,"small_n_note":null},"calendar_2021_only":{"label":"Closures in calendar 2021 only","n":788,"denominator_label":"the 788 cases closed during calendar 2021","penalty_track":2,"penalty_track_pct":0.25,"penalty_track_one_in":394,"reprimand":5,"reprimand_pct":0.63,"neither":781,"neither_pct":99.11,"n_too_small_for_a_percentage":false,"small_n_note":null},"excluding_calendar_2021":{"label":"Excluding all of calendar 2021","n":168,"denominator_label":"the 168 closures from January 2022 onwards","penalty_track":8,"penalty_track_pct":4.76,"penalty_track_one_in":21,"reprimand":18,"reprimand_pct":10.71,"neither":142,"neither_pct":84.52,"n_too_small_for_a_percentage":false,"small_n_note":null}},"reference_vintage":{"what_it_is":"The ICO's case references end in a four-digit year (INV/nnnn/yyyy). The ICO does not publish what that year means, so this is a description of the references, not a dated record of when a case was opened.","first_quarter_n":502,"first_quarter_reference_year_earlier_than_closure_year":287,"first_quarter_pct":57.17,"next_quarter_n":231,"next_quarter_reference_year_earlier_than_closure_year":25,"next_quarter_pct":10.82,"reading":"Consistent with the first published quarter clearing older cases; not proof of it. No causal claim is made from it, and the quarter is named by its date throughout."},"reference_vintage_note":"The nearest thing to evidence about that quarter, published rather than left out: 287 of its 502 closures (57.17%) carry a case reference whose four-digit year is earlier than the year the case closed, against 25 of 231 (10.82%) in the next quarter. The ICO does not publish what that year means, so this is a description of the reference strings. It is consistent with the first published quarter clearing older cases and is not proof of it, and the quarter is named by its date everywhere on this page rather than labelled a backlog.","by_closure_year":[{"label":"Closed in 2021","n":788,"denominator_label":"the 788 cyber investigations the ICO closed and published in 2021","penalty_track":2,"penalty_track_pct":0.25,"penalty_track_one_in":394,"reprimand":5,"reprimand_pct":0.63,"neither":781,"neither_pct":99.11,"n_too_small_for_a_percentage":false,"small_n_note":null},{"label":"Closed in 2022","n":40,"denominator_label":"the 40 cyber investigations the ICO closed and published in 2022","penalty_track":4,"penalty_track_pct":10,"penalty_track_one_in":10,"reprimand":6,"reprimand_pct":15,"neither":30,"neither_pct":75,"n_too_small_for_a_percentage":false,"small_n_note":null},{"label":"Closed in 2023","n":97,"denominator_label":"the 97 cyber investigations the ICO closed and published in 2023","penalty_track":0,"penalty_track_pct":0,"penalty_track_one_in":null,"reprimand":9,"reprimand_pct":9.28,"neither":88,"neither_pct":90.72,"n_too_small_for_a_percentage":false,"small_n_note":null},{"label":"Closed in 2024","n":18,"denominator_label":"the 18 cyber investigations the ICO closed and published in 2024","penalty_track":0,"penalty_track_pct":0,"penalty_track_one_in":null,"reprimand":3,"reprimand_pct":16.67,"neither":15,"neither_pct":83.33,"n_too_small_for_a_percentage":false,"small_n_note":null},{"label":"Closed in 2025","n":8,"denominator_label":"the 8 cyber investigations the ICO closed and published in 2025","penalty_track":2,"penalty_track_pct":null,"penalty_track_one_in":null,"reprimand":0,"reprimand_pct":null,"neither":6,"neither_pct":null,"n_too_small_for_a_percentage":true,"small_n_note":"n is below 10, so counts only are reported: a single case would move any percentage by more than ten points"},{"label":"Closed in 2026 (Jan-Mar only)","n":5,"denominator_label":"the 5 cyber investigations the ICO closed and published in 2026 (Jan-Mar only)","penalty_track":2,"penalty_track_pct":null,"penalty_track_one_in":null,"reprimand":0,"reprimand_pct":null,"neither":3,"neither_pct":null,"n_too_small_for_a_percentage":true,"small_n_note":"n is below 10, so counts only are reported: a single case would move any percentage by more than ten points"}],"small_n_warning":"From 2024 the yearly denominators fall below 50 and then below 10. Years with n below 10 are reported as counts with no percentage. No year in this table is a trend."},{"id":"series","heading":"Closures per quarter","lead":"A bare sourced count of cases closed and published per quarter, with no trend read into it. The published data cannot distinguish the ICO closing fewer cases from the ICO publishing fewer, so no such claim is made.","investigations":[{"quarter":"2021Q1","label":"Jan-Mar 2021 (Q1)","closed_cases":502,"file_published":true},{"quarter":"2021Q2","label":"Apr-Jun 2021 (Q2)","closed_cases":231,"file_published":true},{"quarter":"2021Q3","label":"Jul-Sep 2021 (Q3)","closed_cases":35,"file_published":true},{"quarter":"2021Q4","label":"Oct-Dec 2021 (Q4)","closed_cases":20,"file_published":true},{"quarter":"2022Q1","label":"Jan-Mar 2022 (Q1)","closed_cases":11,"file_published":true},{"quarter":"2022Q2","label":"Apr-Jun 2022 (Q2)","closed_cases":8,"file_published":true},{"quarter":"2022Q3","label":"Jul-Sep 2022 (Q3)","closed_cases":6,"file_published":true},{"quarter":"2022Q4","label":"Oct-Dec 2022 (Q4)","closed_cases":15,"file_published":true},{"quarter":"2023Q1","label":"Jan-Mar 2023 (Q1)","closed_cases":41,"file_published":true},{"quarter":"2023Q2","label":"Apr-Jun 2023 (Q2)","closed_cases":11,"file_published":true},{"quarter":"2023Q3","label":"Jul-Sep 2023 (Q3)","closed_cases":21,"file_published":true},{"quarter":"2023Q4","label":"Oct-Dec 2023 (Q4)","closed_cases":24,"file_published":true},{"quarter":"2024Q1","label":"Jan-Mar 2024 (Q1)","closed_cases":6,"file_published":true},{"quarter":"2024Q2","label":"Apr-Jun 2024 (Q2)","closed_cases":6,"file_published":true},{"quarter":"2024Q3","label":"Jul-Sep 2024 (Q3)","closed_cases":5,"file_published":true},{"quarter":"2024Q4","label":"Oct-Dec 2024 (Q4)","closed_cases":1,"file_published":true},{"quarter":"2025Q1","label":"Jan-Mar 2025 (Q1)","closed_cases":0,"file_published":true},{"quarter":"2025Q2","label":"Apr-Jun 2025 (Q2)","closed_cases":1,"file_published":true},{"quarter":"2025Q3","label":"Jul-Sep 2025 (Q3)","closed_cases":3,"file_published":true},{"quarter":"2025Q4","label":"Oct-Dec 2025 (Q4)","closed_cases":4,"file_published":true},{"quarter":"2026Q1","label":"Jan-Mar 2026 (Q1)","closed_cases":5,"file_published":true}],"quarter_assignment":"The quarter comes from the ICO's own publication file, not from any date in the row. The two agree on every case: the calendar quarter of the published closure date matches the quarter of the file it appears in for all 956 investigations (verified).","zero_quarters":["Jan-Mar 2025 (Q1)"]},{"id":"incidents","heading":"The incidents file, as context only","lead":"The ICO publishes a second quarterly series, of closed cyber incidents: 796 cases across 20 files. It is shown here for scale and is not part of the denominator.","denominator":796,"denominator_label":"all 796 closed cyber incidents published across 20 quarterly files","census":[{"outcome_family":"No further action","n":728,"share_pct":91.46},{"outcome_family":"Closed after intervention - in line with RAP","n":34,"share_pct":4.27},{"outcome_family":"No Personal Data Involved","n":22,"share_pct":2.76},{"outcome_family":"Advice provided","n":7,"share_pct":0.88},{"outcome_family":"Does not meet threshold","n":4,"share_pct":0.5},{"outcome_family":"No UK Jurisdiction","n":1,"share_pct":0.13}],"series":[{"quarter":"2021Q2","label":"Apr-Jun 2021 (Q2)","closed_cases":24,"file_published":true},{"quarter":"2021Q3","label":"Jul-Sep 2021 (Q3)","closed_cases":87,"file_published":true},{"quarter":"2021Q4","label":"Oct-Dec 2021 (Q4)","closed_cases":74,"file_published":true},{"quarter":"2022Q1","label":"Jan-Mar 2022 (Q1)","closed_cases":118,"file_published":true},{"quarter":"2022Q2","label":"Apr-Jun 2022 (Q2)","closed_cases":88,"file_published":true},{"quarter":"2022Q3","label":"Jul-Sep 2022 (Q3)","closed_cases":53,"file_published":true},{"quarter":"2022Q4","label":"Oct-Dec 2022 (Q4)","closed_cases":103,"file_published":true},{"quarter":"2023Q1","label":"Jan-Mar 2023 (Q1)","closed_cases":56,"file_published":true},{"quarter":"2023Q2","label":"Apr-Jun 2023 (Q2)","closed_cases":51,"file_published":true},{"quarter":"2023Q3","label":"Jul-Sep 2023 (Q3)","closed_cases":39,"file_published":true},{"quarter":"2023Q4","label":"Oct-Dec 2023 (Q4)","closed_cases":15,"file_published":true},{"quarter":"2024Q1","label":"Jan-Mar 2024 (Q1)","closed_cases":16,"file_published":true},{"quarter":"2024Q2","label":"Apr-Jun 2024 (Q2)","closed_cases":26,"file_published":true},{"quarter":"2024Q3","label":"Jul-Sep 2024 (Q3)","closed_cases":7,"file_published":true},{"quarter":"2024Q4","label":"Oct-Dec 2024 (Q4)","closed_cases":5,"file_published":true},{"quarter":"2025Q1","label":"Jan-Mar 2025 (Q1)","closed_cases":11,"file_published":true},{"quarter":"2025Q2","label":"Apr-Jun 2025 (Q2)","closed_cases":0,"file_published":true},{"quarter":"2025Q3","label":"Jul-Sep 2025 (Q3)","closed_cases":3,"file_published":true},{"quarter":"2025Q4","label":"Oct-Dec 2025 (Q4)","closed_cases":5,"file_published":true},{"quarter":"2026Q1","label":"Jan-Mar 2026 (Q1)","closed_cases":15,"file_published":true}],"distinct_case_references":794,"duplicate_case_references":2,"duplicate_case_reference_detail":{"IC/0018/2024":[{"closed_date_raw":"20/02/2024","outcome_family":"No further action","source_file":"4030363__cyber-crimson-incidents-q4-2023-24.csv"},{"closed_date_raw":"20/02/2024","outcome_family":"No further action","source_file":"4030363__cyber-crimson-incidents-q4-2023-24.csv"}],"IC/0028/2024":[{"closed_date_raw":"19/04/2024","outcome_family":"No further action","source_file":"4031244__cyber-incidents-2024-25-q1-closed-datasets.csv"},{"closed_date_raw":"30/07/2025","outcome_family":"Does not meet threshold","source_file":"pwghpy4r__cyber-incidents-q2-2025-26.csv"}]},"duplicate_case_reference_note":"The zero-duplicates figure on the denominator is a statement about the 956 investigations. The incidents side carries 2 repeated references out of 796 rows and they are reported rather than removed: IC/0018/2024 appears in 4030363__cyber-crimson-incidents-q4-2023-24.csv; IC/0028/2024 appears in 4031244__cyber-incidents-2024-25-q1-closed-datasets.csv and pwghpy4r__cyber-incidents-q2-2025-26.csv. One is an exact duplicate row inside a single ICO file; the other is the same reference closed twice, in two different files, with two different outcomes. Both are left in the dataset as published.","why_no_escalation_rate":"Dividing 956 closed investigations by 796 closed incidents would produce something that looks like an escalation rate. It is not one, and it is not published here. The two are separate publications with different inclusion rules; the incidents series has no Jan-Mar 2021 file at all; and neither file records whether a given incident later became an investigation. The ICO states that the cases on the incidents data sets \"are those which were considered but not progressed to a full Investigation\", so the two files are the two outcomes of one triage step rather than a pool and the share of it that escalated. The ratio would measure ICO publication practice, not case escalation. Bristows published an escalation rate for 2022 (9% of the cyber incidents in their 2022 population); we do not repeat it, for these reasons."},{"id":"prior-art","heading":"What was already known, and what this adds","lead":"Bristows published the adjacent analysis in April 2023: Marc Dautlich, 'The ICO's complaints and concerns data sets', covering calendar 2022 only, with civil and cyber investigations pooled, n = 311. They reported 2% monetary penalty, 14% reprimand, 17% advice, 67% no action. They also built the penalty grouping this study extends, and they excluded the 2021 data sets on purpose, because in their words those files \"suggested a marked change in approach to Cyber Investigations between 2021 and 2022\".","what_this_adds":["21 consecutive quarters rather than one calendar year.","Cyber only, rather than cyber and civil investigations pooled.","The complete outcome distribution - every published outcome string with its count - rather than four summary percentages.","The sensitivity analysis: pooled, excluding the first published quarter and excluding all of 2021 side by side, plus a by-year table with its small-n warning.","A published, per-row dataset with the source file, URL and hash on every row."],"what_this_does_not_claim":"Not a first. Bristows published an adjacent headline three years earlier, on a population that overlaps this one for 2022, and the penalty grouping is theirs, extended here by one outcome string ('Not recoverable'). On their grouping unchanged the figure is 9 of 956 rather than 10, and both are printed in the codings table above.","consistency_check":"Two halves, and both are stated. Our cyber-only 2022 reprimand rate is 6 of 40 (15.0%) against their 14% on 311 mixed cases - close enough to be worth a sentence as a consistency check, and no more than that. The penalty rates do not agree: 4 of 40 (10.0%) here against their 2%, and 4 cases in 40 is not a stable estimate of anything.","numerator_only_trackers":"The published fine trackers all count actions, not cases: Bridewell (58 monetary penalties, 49 enforcement notices, 65 reprimands and 3 prosecutions published between 2023 and 2026, extracted from the ICO Enforcement Register on 11 May 2026), URM Consulting for 2024 and for 2025, BDO's rolling action counts, and the GDPR Enforcement Tracker operated by CMS, whose stated scope is that only GDPR fines are listed. None publishes a denominator, because the enforcement register does not contain one. All four are listed in the sources table below, cited and not reused.","unverifiable_source":"Practical Law (Thomson Reuters) publishes an 'ICO civil penalties: tracker'. It returned HTTP 403 to an identified bot and is subscription-only, so it is not quoted, not counted and not replaced with a weaker source."},{"id":"related","heading":"Cases, not reports","lead_before_link":"This study counts cases the regulator worked and closed. For the other side of the same pipeline - the personal data breach reports organisations made to the ICO - see ","lead_link_text":"our study of the ICO's data security incident trends","lead_after_link":". The two count different things - reports received against cases closed - but they are not disjoint sets, and we do not claim they are. The ICO says of the cyber files that \"cyber investigations usually originate from a data protection complaint or self-reported data breach case\", and that from Q4 2022-23 those files carry the originating ICE360 record alongside the Crimson one, so a case counted here may also sit inside the breach reports counted there, and we have not measured how often. The ICO separately says of the breach-report data that \"under specific circumstances some cases are transferred to a separate system for review\" and \"are not included within this data\". It does not name that system in the same place; treating it as Crimson, the system these cyber files come from, is our reading and not an ICO statement.","lead":"This study counts cases the regulator worked and closed. For the other side of the same pipeline - the personal data breach reports organisations made to the ICO - see our study of the ICO's data security incident trends. The two count different things - reports received against cases closed - but they are not disjoint sets, and we do not claim they are. The ICO says of the cyber files that \"cyber investigations usually originate from a data protection complaint or self-reported data breach case\", and that from Q4 2022-23 those files carry the originating ICE360 record alongside the Crimson one, so a case counted here may also sit inside the breach reports counted there, and we have not measured how often. The ICO separately says of the breach-report data that \"under specific circumstances some cases are transferred to a separate system for review\" and \"are not included within this data\". It does not name that system in the same place; treating it as Crimson, the system these cyber files come from, is our reading and not an ICO statement.","links":[{"anchor":"UK data breach statistics 2026: seven years of reports to the ICO","href":"/research/uk-data-breach-statistics-2026","relationship":"Reciprocal. That page counts reports received; this one counts cases closed. One link each way, no link stacking."}]}],"caveats":["This is a FLOW of cases the ICO closed and published each quarter, not a STOCK of every cyber case the regulator has ever handled. It cannot tell you how many cyber cases are open.","Say 'published caseload', not 'caseload'. These quarterly data sets are a publication, and what goes into them is a choice the regulator makes. The ICO does not usually announce individual decisions to take no further action.","502 of the 956 closures - 52.51% - fall in one quarter, Jan-Mar 2021, and 788 of the 956 - 82.43% - fall in calendar 2021 as a whole.","The headline roughly doubles when the first published quarter, Jan-Mar 2021, is removed (1.05% of 956 to 2.2% of 454) and roughly quadruples when all of calendar 2021 is removed (4.76% of 168). All three are published together for that reason.","Descriptive, not a criticism of the regulator. This page counts published outcome strings; it makes no claim about why any case ended where it did, and no claim about whether the pattern is or is not in line with the ICO’s Regulatory Action Policy. Nothing here is an argument that the regulator should fine more often, and nothing here is an argument for buying anything.","Small n. From 2024 the yearly denominators fall to double and single figures. Any year with n below 50 is too small to rank and any year with n below 10 is reported as a count only. A single case moves those rates by tens of percentage points.","'Penalty track' is a definition, not a field in the data. It means the published outcome records a monetary penalty issued, pursued, under appeal, or issued and not recovered. Four defensible codings were computed and they give between 8 and 11 cases out of 956; the published figure is 10. The headline does not turn on the coding.","The penalty grouping is Bristows', extended by one outcome string. They published the grouping in April 2023; we add 'Not recoverable', which they place in their Closed/Other group. On their grouping unchanged the figure is 9 of 956 rather than 10, and both are printed. Nothing here is a first.","NOT a measure of how often UK organisations are fined for cyber attacks in general. It measures what happened to the cases the ICO itself closed and published in these two data sets.","NOT a measure of security. A case closed with no action is not a finding that the organisation was secure, and a reprimand is not a finding that it was not.","Population is UK-jurisdiction, not UK-domiciled. Non-UK entities appear because the ICO regulates controllers processing UK personal data. The right phrase is 'organisations reported to the UK regulator', not 'UK organisations'.","No organisation is named anywhere in the dataset. Counted as distinct strings, the organisation and controller columns of the source files carry 921 values in the 21 investigations files and 1688 across all 41 - upper bounds on the number of organisations, because the column is not a clean register. None of those strings appears in any published file here, and the emitter refuses to write a row containing one.","The source's controller column is a case-title field, not a clean organisation register: it carries entries such as an ICO case title rather than a company name, a bare initialism, and a group name where the ICO's published action names a subsidiary. Any organisation named in the page text must be taken from the ICO's published enforcement or reprimand page, never from this column.","Series break, explained by the publisher. From Q4 2022-23 the ICO joins its two case systems - ICE360 for complaints and breach reports, Crimson for cyber investigations - so files from that quarter carry ICE_ and CRIMSON_ prefixes while earlier files use a flat 4-6 column schema. That is the main reason there are 19 distinct header shapes as published (18 once trailing whitespace in header names is trimmed).","Encoding. Three of the 41 files are not valid UTF-8 and need a cp1252 fallback. One of them is genuinely mixed - UTF-8 byte sequences inside an otherwise cp1252 file - so a whole-file cp1252 read mangles an en-dash that is not damaged at source. Repair is done per field, and the string as read is preserved in the dataset beside the repaired one.","Quarters with a file and no cases. 21 quarterly investigation files were published but only 20 quarters contain a closure; Jan-Mar 2025 (Q1) is annotation-only. It stays in the series as an explicit zero, because dropping it shortens the series and inflates the recent-quarters share.","The incidents data set has no Jan-Mar 2021 file at all: the ICO states on the landing page that no relevant cases were held for that period. The two series do not cover the same span.","Coverage of the fields we do not use: sector is present on 11.72% of investigations and the Crimson start date on 17.57%. The closure date is present on 100.0%. Those coverage figures are why the sector breakdown and every duration metric are dropped - the drop is about start-date coverage, not closure-date coverage.","No pound figure is derivable. 'Final Value' is 0 or blank on 956 of 956 investigations, including all 10 penalty-track rows.","Denominator sensitivity. 81 of the 956 rows (8.47%) record an administrative closure rather than a worked case - no personal data, a duplicate record, documents pasted into an existing case, or a record created in error. Excluding all four the penalty rate is 10 of 875 (1.14%) rather than 1.05%, so the headline does not turn on whether they are counted.","No escalation rate. Dividing closed investigations by closed incidents would look like one and is not: the two are separate publications with different inclusion rules, the incidents series is missing its first quarter entirely, and neither file records whether a given incident later became an investigation. Any such ratio measures ICO publication practice, not case escalation. Bristows published one (9% of 2022 cyber incidents); we do not repeat it, and this is why.","No trend claim. The published data cannot distinguish the ICO handling fewer cases from the ICO publishing fewer cases, so no statement about enforcement rising or falling is made here."],"method":{"what_was_measured":"The published outcome of every cyber case the Information Commissioner's Office closed and published in its own quarterly 'Cyber investigations' and 'Cyber incidents' data sets, from Jan-Mar 2021 to Jan-Mar 2026.","when":"The 41 CSV files were retrieved once each on 2026-09-29, starting 2026-09-29T06:57:09Z, at the 6-second crawl delay ico.org.uk publishes. Analysis is offline and makes no network request.","population":{"n":956,"unit":"one cyber investigation the ICO opened, worked, closed and published","definition":"Every row of the 21 quarterly 'Cyber investigations' CSVs whose case-reference column holds an ICO case reference. A population of the publication, not a sample of it.","flow_not_stock":"These are cases CLOSED in each quarter. The files do not report open cases, so nothing here is a count of cyber cases the ICO holds.","not_a_sample_of":"cyber attacks on UK organisations, or reports made to the ICO. Neither of those populations is measured here.","companion":"796 closed cyber incidents from the 20 'Cyber incidents' CSVs, carried as context only, giving 1752 cases in all."},"how":["All 41 CSVs were downloaded once each, single-threaded, at the 6-second Crawl-delay ico.org.uk/robots.txt sets, with an identifying User-Agent, and stored byte-identical with a sha256 per file. No authenticated access and no scanning of any kind.","Each file is decoded utf-8-sig first and cp1252 on failure. Mojibake is repaired per field, not per file, because one file is genuinely mixed; the string as read is preserved in the dataset beside the repaired one.","A row counts as a case only where its case-reference column matches an ICO case reference of the form INV/nnnn/yyyy or IC/nnnn/yyyy. That one objective rule isolates the non-case rows: 4 across all 41 files, listed individually with file and line number in the dropped-row register below.","The quarter of each case comes from the ICO's own publication file via a hard-coded, auditable 41-row table, never inferred from a date. ICO financial quarters run Q1 = Apr-Jun to Q4 = Jan-Mar, so 'q4-2025-26' is Jan-Mar 2026. As a check, the calendar quarter of each case's published closure date was compared with the quarter of the file it appears in: they agree on every case.","Outcome strings are counted exactly as published. Only spelling, wording and encoding variants of one outcome are folded into a family - one family folds a published string in which the word 'and' stands where the others carry a dash - and each family lists the raw strings and counts that make it up.","The controller / organisation columns were read only to set a boolean and to build a blocklist. The emitter checks every value of every row against that blocklist and refuses to write the file if an organisation name reaches it."],"what_was_deliberately_not_computed":["An escalation rate from incidents to investigations - an unbounded publication artefact. Reason on the page.","Any sector league table - sector is present on only 11.72% of investigations.","Any duration or 'the ICO took N days' metric - the Crimson start date is present on only 17.57% of investigations. The closure date is present on 100.0%; the drop is about start-date coverage.","Any pound figure - 'Final Value' is 0 or blank on 956 of 956 investigations and on all 10 penalty-track rows.","Any claim that the ICO is investigating more or less than before.","Any naming of an organisation that suffered a cyber attack."],"limits":["It measures a publication. What the ICO chooses to publish in these files is a regulatory decision, and the files' coverage can change without the underlying caseload changing.","It is heavily weighted to 2021. See the concentration figures above.","It is cyber only. Civil investigations are published separately and are not included.","It is a flow of closures, not a stock of cases."]},"sources":[{"name":"ICO - Cyber investigations and Cyber incidents quarterly data sets (41 CSV files)","publisher":"Information Commissioner's Office","url":"https://ico.org.uk/action-weve-taken/complaints-and-concerns-data-sets/cyber-investigations/","what_was_taken":"Every published row of all 41 quarterly CSVs, Jan-Mar 2021 to Jan-Mar 2026. The controller / organisation columns were read only to set a boolean and to build a blocklist that the emitter checks against; no organisation name appears in any output.","retrieved":"2026-09-29T06:57:09Z","files":41,"licence":"Open Government Licence v3.0","licence_url":"https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/","licence_evidence":"https://ico.org.uk/global/copyright-and-re-use-of-materials/","required_attribution_verbatim":"Information Commissioner's Office, [name and date of publication], licensed under the Open Government Licence.","commercial_reuse":"Permitted under the OGL.","images_excluded":"The same ICO page refuses image re-use outright. Every figure on this page is our own rendering; no ICO chart or screenshot is reproduced.","robots":"ico.org.uk/robots.txt (206 bytes) sets Crawl-delay: 6 for User-agent: * and disallows only /private and /restricted, plus a separate block disallowing the 'deepcrawl' agent. Neither /action-weve-taken/ nor /media2/ is disallowed. The 6-second delay was honoured single-threaded throughout: 44 requests in the data-collection pass (41 CSVs plus robots.txt, the copyright page and the landing page) and 25 further ICO pages and PDFs for the evidence pack, 69 ICO requests in all."},{"name":"ICO - Copyright and re-use of materials","publisher":"Information Commissioner's Office","url":"https://ico.org.uk/global/copyright-and-re-use-of-materials/","what_was_taken":"The licence grant and the exact attribution wording, quoted verbatim.","licence":"Open Government Licence v3.0","note":"https://ico.org.uk/global/copyright/ returns HTTP 404; this is the live path."},{"name":"Open Government Licence v3.0","publisher":"The National Archives","url":"https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/","what_was_taken":"Nothing. Linked as the licence deed only.","note":"www.nationalarchives.gov.uk/robots.txt carries Content-Signal: ai-train=no, ai-input=no. The deed was therefore linked and never fetched or reproduced. The licence grant is evidenced from the ICO's own copyright page instead."},{"name":"Bristows LLP (Inquisitive Minds) - 'The ICO's complaints and concerns data sets', Marc Dautlich, 26 April 2023","publisher":"Bristows LLP","url":"https://inquisitiveminds.bristows.com/post/102idmi/the-icos-complaints-and-concerns-data-sets","role":"Prior art. Cited, not reused.","what_they_did":"Calendar 2022 only; civil and cyber investigations pooled; n = 311. They reported 2% monetary penalty, 14% reprimand, 17% advice, 67% no action.","what_we_take_from_them":"The penalty grouping. Their published 'Monetary Penalty' group is Appeal; Civil monetary penalty pursued; fine - higher tier; and Paid in full. Our penalty track is that grouping plus 'Not recoverable'. The grouping is theirs and is credited as theirs.","licence":"All rights reserved. Quoted briefly for attribution and comparison."},{"name":"ICO - Regulatory Action Policy, November 2018","publisher":"Information Commissioner's Office","url":"https://ico.org.uk/media2/about-the-ico/documents/2259467/regulatory-action-policy.pdf","role":"The policy the data's own 'in line with RAP' outcome string refers to. In force across the data period except that its penalty-notice sections were replaced by the Data Protection Fining Guidance on 18 March 2024.","licence":"Open Government Licence v3.0","note":"The legacy /media/ path 301-redirects; the /media2/ path above is the live one."},{"name":"ICO - Data protection fining guidance, 18 March 2024","publisher":"Information Commissioner's Office","url":"https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/","role":"Evidence for the date on which the Regulatory Action Policy's penalty-notice sections were replaced, inside this study's data window. Quoted: it 'replaces the sections about penalty notices in the Regulatory Action Policy published in November 2018'.","licence":"Open Government Licence v3.0"},{"name":"ICO - draft Data Protection Enforcement Procedural Guidance v0.8, 31 October 2025","publisher":"Information Commissioner's Office","url":"https://ico.org.uk/media2/jakfp5aw/enforcement-prod-guidance-consultation-20251031.pdf","role":"Quoted for the ICO's own description of what a reprimand is. Draft, not final: the consultation closed on 23 January 2026 and we did not check whether a final version has since been published.","licence":"Open Government Licence v3.0"},{"name":"Bridewell - 'Average value of ICO monetary penalties up 370 percent since 2023'","publisher":"Bridewell","url":"https://www.bridewell.com/insights/blogs/detail/average-value-of-ico-monetary-penalties-up-370-percent-since-2023","role":"Cited, not reused. A numerator-only tracker. Its counts are of records published between 2023 and 2026, extracted from the ICO Enforcement Register on 11 May 2026.","retrieved":"2026-09-29","licence":"All rights reserved. Figures quoted briefly for comparison."},{"name":"URM Consulting - analyses of ICO enforcement action, 2024 and 2025","publisher":"URM Consulting","url":"https://www.urmconsulting.com/blog/analysis-of-enforcement-action-by-the-ico-in-2025-actions-way-down-security-data-breach-fines-way-up","role":"Cited, not reused. Numerator-only trackers. The 2024 analysis is at https://www.urmconsulting.com/blog/analysis-of-fines-imposed-by-the-information-commissioners-office-in-2024","retrieved":"2026-09-29","licence":"All rights reserved. Named, no figure reproduced."},{"name":"BDO - 'Trends in recent ICO enforcement action'","publisher":"BDO LLP","url":"https://www.bdo.co.uk/en-gb/insights/advisory/risk-and-advisory-services/trends-in-recent-ico-enforcement-action","role":"Cited, not reused. A numerator-only tracker. Named, no figure reproduced.","retrieved":"2026-09-29","licence":"All rights reserved."},{"name":"GDPR Enforcement Tracker, operated by CMS","publisher":"CMS Legal Services EEIG","url":"https://www.enforcementtracker.com/","role":"Cited, not reused. A numerator-only tracker. Its own stated scope is that only GDPR fines are listed, which is why it carries no caseload denominator.","retrieved":"2026-09-29","licence":"All rights reserved."}],"disagreements":[{"about":"Naive investigation row count","claim_a":"The study brief said a naive parse gives 958 investigation rows.","claim_b":"Parsing all 21 investigation files here gives 959 body rows.","resolution":"Reported as measured rather than forced. The brief's arithmetic does not close either: 958 minus 3 non-case rows would give 955, not 956. 959 body rows minus the 3 non-case rows gives 956, the headline denominator, exactly."},{"about":"Position of the two blank investigation rows","claim_a":"The brief described them as trailing rows.","claim_b":"Both are the first body row, immediately under the header, in the Jan-Mar 2021 and Apr-Jun 2021 files. Both files end on a real case row.","resolution":"Corrected here; see the dropped-row register, which prints file and line number."},{"about":"Number of distinct header shapes","claim_a":"The brief said 19.","claim_b":"19 comparing header cells exactly as published, 18 after trimming whitespace from header names.","resolution":"Both are published and the page says which convention it is using. The difference is a trailing space in one column name in two files."},{"about":"Mojibake","claim_a":"The brief said three cp1252 files produce three mojibaked outcome strings.","claim_b":"Three files need a cp1252 fallback, but only one produces mojibake, and it produces one distinct mojibaked string appearing on 3 rows.","resolution":"The accurate wording is 'three rows carrying one mojibaked string'."},{"about":"'21 consecutive quarters, no gaps'","claim_a":"True of the files.","claim_b":"Not true of the closures: 20 quarters contain at least one closure, because Jan-Mar 2025 (Q1) is annotation-only.","resolution":"The page says '21 consecutive quarterly files, 20 quarters with at least one closure'."},{"about":"Which outcomes belong on the penalty track","claim_a":"The brief includes 'Not recoverable' and excludes 'MPN not issued'.","claim_b":"Bristows' published grouping includes neither 'Not recoverable' nor 'MPN not issued', giving 9.","resolution":"All four codings are published. They span 8 to 11 cases out of 956; the headline figure is 10 and the conclusion does not turn on the choice."},{"about":"Where the penalty-track cases fall by year","claim_a":"An earlier internal coding of ours put one penalty-track case in 2023 and one in 2026.","claim_b":"Recomputed here: none in 2023 and two in 2026. The two tables differ by exactly one case in each year and both total 10.","resolution":"The difference is entirely the coding. That working file counted 'MPN not issued' (closed 11 January 2023) as penalty track and excluded 'Not recoverable' (closed 9 February 2026); this study does the reverse, following the definition it publishes. Both give 10 overall. The by-year table here uses the published coding, and the codings block lets a reader rebuild either."},{"about":"How much of the denominator closed in 2021","claim_a":"An earlier internal working figure of ours put it at 733 of 956, 78%.","claim_b":"Recomputed here from the closure dates: 788 of 956, 82.43%.","resolution":"The figure computed from the published dataset is the one used. It can be recomputed from the CSV by counting investigation rows with closure_year == '2021'."},{"about":"The study title","claim_a":"Our own planning note titled this 'what actually happens after a UK cyber attack is reported'.","claim_b":"That frames the population as reported cyber attacks. The population measured is the cases the ICO closed and published, which is neither a sample of cyber attacks nor a sample of reports made to the regulator.","resolution":"Retitled to the population actually measured. The original phrasing is not used anywhere on the page."}],"dataset":{"csv":"/research/ico-cyber-caseload-tracker-2026.csv","readme":"/research/ico-cyber-caseload-tracker-2026-README.txt","rows":1752,"unit":"one closed ICO cyber case","columns":["case_reference","case_type","published_quarter","published_quarter_label","closed_date_raw","closed_date_iso","closure_quarter","closure_year","outcome_raw","outcome_repaired","outcome_family","outcome_track_house_coding","sector_raw","crimson_start_date_raw","final_value_raw","controller_named_in_source","source_file","source_url","source_sha256"],"source_licence":"Open Government Licence v3.0","source_attribution_required":"Information Commissioner's Office, Cyber investigations and Cyber incidents quarterly data sets, published January 2021 to March 2026, licensed under the Open Government Licence.","source_attribution_template_as_the_ico_publishes_it":"Information Commissioner's Office, [name and date of publication], licensed under the Open Government Licence.","derived_licence":"CC BY 4.0","derived_licence_url":"https://creativecommons.org/licenses/by/4.0/","contains_no":"organisation names, individual names, contact details or any other personal data"}},"verification":{"rule":"Any pre-registered headline that does not reproduce exactly is cut, not caveated.","no_network_at_analysis_time":true,"how_to_check":["Re-run scripts/research/ico-cyber-caseload-tracker-2026/analyse.py against the stored snapshot in data/research/ico-cyber-caseload-tracker-2026/. It makes no network request. All three outputs should be rewritten byte-identical apart from the 'built' timestamp in the JSON.","Verify each of the 41 source CSVs against the sha256 recorded on its row in public/research/ico-cyber-caseload-tracker-2026.csv and in the source_files block of this JSON. A fresh download should match: the ICO's quarterly files are static once published, so any mismatch means the ICO has revised a file and the study must be re-run and re-dated.","Recompute every pre-registered metric from ico-cyber-caseload-tracker-2026.csv alone, using the how_to_recompute string on each one. The CSV is sufficient for all of them.","Check the census sums: the outcome families listed in the outcomes section must sum to 956, and penalty_track + reprimand + neither must equal 956.","Check that every investigation row has a non-empty outcome_family (coverage must be 100%), and that the 956 case references are distinct with no duplicates.","Check the four penalty codings by counting outcome_raw strings directly: they should span 8 to 11 cases and the published figure should be 10.","Check the recent-quarters window includes Jan-Mar 2025 (Q1) as an explicit zero. Dropping the zero quarter changes the answer and would be wrong.","Check that the published dataset contains no organisation name: grep it for any controller string from the raw files. The emitter asserts this, but it should be checked independently."],"expected_values":{"closed_cyber_investigations":956,"closed_cyber_incidents":796,"total_rows_in_published_csv":1752,"penalty_track":10,"penalty_track_pct":1.05,"reprimand":23,"reprimand_pct":2.41,"neither":923,"neither_pct":96.55,"first_published_quarter_closures":502,"first_published_quarter_share_pct":52.51,"ex_first_quarter_n":454,"ex_first_quarter_penalty_pct":2.2,"ex_calendar_2021_n":168,"ex_calendar_2021_penalty_pct":4.76,"closures_in_most_recent_nine_quarters":31,"share_in_most_recent_nine_quarters_pct":3.24,"distinct_case_references":956,"duplicate_case_references":0,"header_shapes_as_published":19,"header_shapes_whitespace_trimmed":18,"cp1252_files":3,"mojibaked_rows":3,"non_case_rows_dropped":4},"csv_sha256":"2f0610d763951bc7592de5fbfab32b581942cc388f7f9c39c10ce0eaf39ba0b4","readme_sha256":"e6ca13e0a4d3e769636c536fd04975002f50f3a54f76e2e46490d09c164dd64a"},"series_and_revisions":{"series_break":"From Q4 2022-23 the ICO joins ICE360 and Crimson, so the file schema changes. 19 distinct header shapes as published, 18 trimmed. The outcome column is named 'Investigation Outcome Desc', 'CRIMSON_InvestigationOutcome' or 'CRIMSON Investigation Outcome' depending on the quarter.","zero_case_quarters_investigations":["Jan-Mar 2025 (Q1)"],"zero_case_quarters_incidents":["Apr-Jun 2025 (Q2)"],"missing_file":"There is no Jan-Mar 2021 cyber incidents file: the ICO states on the landing page that no relevant cases were held for that period. 21 investigations files against 20 incidents files is therefore not a gap in collection.","revision_policy":"The ICO's quarterly files are static once published. Every row of the published dataset carries the sha256 of the file it came from, so a revision is detectable rather than silent. If a hash stops matching, the study is re-run and re-dated rather than patched.","header_shapes_as_published":["ICE Case Reference|ICE Sector|ICE SubSector|ICE Function Type|ICE Decision|ICE Legislation|ICE Received Date|ICE Completed Date|CRIMSON Case Reference|CRIMSON Start Date|CRIMSON Closed Date|CRIMSON Investigation Outcome|CRIMSON Data Controller|Final Value","ICE Case Reference|ICE_Sector|ICE_SubSector|ICE_FunctionType|ICE_Decision|ICE_Legislation|ICE_Received Datetime|ICE_Completed DateTime|CRIMSON Case Reference|CRIMSON Incident Outcome|CRIMSON Received Date|CRIMSON Closed Date|CRIMSON Data Controller","ICE_Case Reference|ICE_Sector|ICE_SubSector|ICE_FunctionType|ICE_Decision|ICE_Legislation|ICE_Completed DateTime|CRIMSON_CaseReference|CRIMSON_StartDate|CRIMSON_ClosedDate|CRIMSON_InvestigationOutcome|CRIMSON_FinalValue|CRIMSON_DataController","ICE_Case Reference|ICE_Sector|ICE_SubSector|ICE_FunctionType|ICE_Decision|ICE_Legislation|ICE_Received Datetime|ICE_Completed DateTime|CRIMSON_CaseReference|CRIMSON_IncidentOutcome|CRIMSON_ClosedDate|CRIMSON_DataController","ICE_Case Reference|ICE_Sector|ICE_SubSector|ICE_FunctionType|ICE_Decision|ICE_Legislation|ICE_Received Datetime|ICE_Completed DateTime|CRIMSON_CaseReference|CRIMSON_IncidentOutcome|CRIMSON_ReceivedDate|CRIMSON_ClosedDate|CRIMSON_DataController","ICE_Case Reference|ICE_Sector|ICE_SubSector|ICE_FunctionType|ICE_Decision|ICE_Legislation|ICE_Received Datetime|ICE_Completed DateTime|CRIMSON_CaseReference|CRIMSON_ReceivedDate|CRIMSON_ClosedDate|CRIMSON_IncidentOutcome|CRIMSON_DataController","ICE_Case Reference|ICE_Sector|ICE_SubSector|ICE_FunctionType|ICE_Decision|ICE_Legislation|ICE_Received Datetime|ICE_Completed DateTime|CRIMSON_CaseReference|CRIMSON_StartDate|CRIMSON_ClosedDate|CRIMSON_InvestigationOutcome|CRIMSON_DataController","ICE_Case Reference|ICE_Sector|ICE_SubSector|ICE_FunctionType|ICE_Decision|ICE_Legislation|ICE_Received Datetime|ICE_Completed DateTime|CRIMSON_CaseReference|CRIMSON_StartDate|CRIMSON_ClosedDate|CRIMSON_InvestigationOutcome|CRIMSON_DataController|Final Value","ICE_Case Reference|ICE_Sector|ICE_SubSector|ICE_FunctionType|ICE_Decision|ICE_Legislation|ICE_Received Datetime|ICE_Completed DateTime|CRIMSON_CaseReference|CRIMSON_StartDate|CRIMSON_ClosedDate|CRIMSON_InvestigationOutcome|Final Value|CRIMSON_DataController","ICE_Case Reference|ICE_Sector|ICE_SubSector|ICE_FunctionType|ICE_Decision|ICE_Legislation|ICE_Received Date|ICE_Completed Date|CRIMSON_CaseReference|CRIMSON_IncidentOutcome|CRIMSON_ReceivedDate|CRIMSON_ClosedDate|CRIMSON_DataController","ICE_Case Reference|ICE_Sector|ICE_SubSector|ICE_FunctionType|ICE_Decision|ICE_Legislation|ICE_Received Date|ICE_Completed Date|CRIMSON_CaseReference|CRIMSON_StartDate|CRIMSON_ClosedDate|CRIMSON_InvestigationOutcome|CRIMSON_DataController","ICE_Case Reference|ICE_Sector|ICE_SubSector|ICE_FunctionType|ICE_Decision|ICE_Legislation|ICE_Received Date|ICE_Completed Date|CRIMSON_CaseReference|CRIMSON_StartDate|CRIMSON_ClosedDate|CRIMSON_InvestigationOutcome|CRIMSON_DataController|Final Value","ICE_Case Reference|ICE_Sector|ICE_SubSector|ICE_Submitted About Account|ICE_CaseStatus|ICE_FunctionType|ICE_Decision|ICE_Legislation|ICE_Received Datetime|ICE_Completed DateTime|CRIMSON_CaseReference|CRIMSON_StartDate|CRIMSON_ClosedDate|CRIMSON_InvestigationOutcome|CRIMSON_DataController|Crimson Final Value","ICE_Case Reference|ICE_Sector|ICE_SubSector|ICE_Submitted About Account|ICE_FunctionType|ICE_Decision|ICE_Legislation|ICE_Received Datetime|ICE_Completed DateTime|CRIMSON_CaseReference|CRIMSON_IncidentOutcome|CRIMSON_ReceivedDate|CRIMSON_ClosedDate|CRIMSON_DataController","Name|Organisation|Final Value|Date Closed|Investigation Outcome Desc","Name|Start Date|Organisation |Date Closed|Final Value|Investigation Outcome Desc","Name|Start Date|Organisation|Date Closed|Final Value|Investigation Outcome Desc","Ref Number|Data Controller|Closure Date|Incident Outcome Desc","Ref Number|Organisation|Closure Date|Incident Outcome Desc"]},"source_files":[{"file":"4020217__202101-202103-cyber-investigations.csv","case_type":"investigations","published_quarter":"2021Q1","published_quarter_label":"Jan-Mar 2021 (Q1)","source_url":"https://ico.org.uk/media2/migrated/4020217/202101-202103-cyber-investigations.csv","retrieved_utc":"2026-09-29T06:59:12+00:00","http_status":200,"bytes":36039,"sha256":"6e2e9274d27fcdcc6e324dbf24be380e2d64650af1f00396e6ef0dbdbb7e5078","encoding_used":"cp1252","columns":5,"body_rows":503,"cases_kept":502,"non_case_rows_dropped":1},{"file":"4020224__202104-202106-cyber-investigations.csv","case_type":"investigations","published_quarter":"2021Q2","published_quarter_label":"Apr-Jun 2021 (Q2)","source_url":"https://ico.org.uk/media2/migrated/4020224/202104-202106-cyber-investigations.csv","retrieved_utc":"2026-09-29T06:59:06+00:00","http_status":200,"bytes":16712,"sha256":"bd447f0781658ff739e81a7a8acc1b68844a4d83b56fd20db14144da27486656","encoding_used":"utf-8-sig","columns":5,"body_rows":232,"cases_kept":231,"non_case_rows_dropped":1},{"file":"4021268__cyber-investigations-202110-202112.csv","case_type":"investigations","published_quarter":"2021Q4","published_quarter_label":"Oct-Dec 2021 (Q4)","source_url":"https://ico.org.uk/media2/migrated/4021268/cyber-investigations-202110-202112.csv","retrieved_utc":"2026-09-29T06:58:54+00:00","http_status":200,"bytes":1538,"sha256":"96a412716cea242fc911efaf17b9e0f60a2b53939196c378dcd1759eeaea0ee5","encoding_used":"utf-8-sig","columns":5,"body_rows":20,"cases_kept":20,"non_case_rows_dropped":0},{"file":"4021269__cyber-investigations-202107-202109.csv","case_type":"investigations","published_quarter":"2021Q3","published_quarter_label":"Jul-Sep 2021 (Q3)","source_url":"https://ico.org.uk/media2/migrated/4021269/cyber-investigations-202107-202109.csv","retrieved_utc":"2026-09-29T06:59:00+00:00","http_status":200,"bytes":2505,"sha256":"c12905b95d5cb438c26a68a223c480d25c6d9f97b7d83513750f45c4f7d5417e","encoding_used":"utf-8-sig","columns":5,"body_rows":35,"cases_kept":35,"non_case_rows_dropped":0},{"file":"4021270__cyber-incidents-202110-202112.csv","case_type":"incidents","published_quarter":"2021Q4","published_quarter_label":"Oct-Dec 2021 (Q4)","source_url":"https://ico.org.uk/media2/migrated/4021270/cyber-incidents-202110-202112.csv","retrieved_utc":"2026-09-29T07:01:02+00:00","http_status":200,"bytes":5095,"sha256":"fed04d183be359c3d0867333ab91653390f0907071fbee29a89644bd6f406ff6","encoding_used":"utf-8-sig","columns":4,"body_rows":74,"cases_kept":74,"non_case_rows_dropped":0},{"file":"4021271__cyber-incidents-202107-202109.csv","case_type":"incidents","published_quarter":"2021Q3","published_quarter_label":"Jul-Sep 2021 (Q3)","source_url":"https://ico.org.uk/media2/migrated/4021271/cyber-incidents-202107-202109.csv","retrieved_utc":"2026-09-29T07:01:08+00:00","http_status":200,"bytes":6012,"sha256":"73b0641b5fc442298f9e83ab3486118ade68f7f992cc7390f625ddbb730381b0","encoding_used":"utf-8-sig","columns":4,"body_rows":87,"cases_kept":87,"non_case_rows_dropped":0},{"file":"4021272__cyber-incidents-202104-202106.csv","case_type":"incidents","published_quarter":"2021Q2","published_quarter_label":"Apr-Jun 2021 (Q2)","source_url":"https://ico.org.uk/media2/migrated/4021272/cyber-incidents-202104-202106.csv","retrieved_utc":"2026-09-29T07:01:14+00:00","http_status":200,"bytes":1713,"sha256":"593cb9907de0be96e806781b1bf1565bf1dc81d4c455434c5c5969aaa6a1e012","encoding_used":"utf-8-sig","columns":4,"body_rows":24,"cases_kept":24,"non_case_rows_dropped":0},{"file":"4022963__cyber-investigations-q4-2021-2022.csv","case_type":"investigations","published_quarter":"2022Q1","published_quarter_label":"Jan-Mar 2022 (Q1)","source_url":"https://ico.org.uk/media2/migrated/4022963/cyber-investigations-q4-2021-2022.csv","retrieved_utc":"2026-09-29T06:58:48+00:00","http_status":200,"bytes":957,"sha256":"bfd179d676894d40989fd057ee945fc29d76fc21ec3b9e672de5237263509f92","encoding_used":"utf-8-sig","columns":6,"body_rows":11,"cases_kept":11,"non_case_rows_dropped":0},{"file":"4022964__cyber-investigations-q1-2022-2023.csv","case_type":"investigations","published_quarter":"2022Q2","published_quarter_label":"Apr-Jun 2022 (Q2)","source_url":"https://ico.org.uk/media2/migrated/4022964/cyber-investigations-q1-2022-2023.csv","retrieved_utc":"2026-09-29T06:58:41+00:00","http_status":200,"bytes":747,"sha256":"fdb656ffa1aee2335e74ee7a747715e0de41ee58b9d57260865e9f0ccf928531","encoding_used":"utf-8-sig","columns":6,"body_rows":8,"cases_kept":8,"non_case_rows_dropped":0},{"file":"4022965__cyber-incidents-q4-2021-2022.csv","case_type":"incidents","published_quarter":"2022Q1","published_quarter_label":"Jan-Mar 2022 (Q1)","source_url":"https://ico.org.uk/media2/migrated/4022965/cyber-incidents-q4-2021-2022.csv","retrieved_utc":"2026-09-29T07:00:56+00:00","http_status":200,"bytes":8262,"sha256":"e3c6b788169cda15e0f4004f99264ffe7b24c7e2c19da2b76bbd102f9c1af43a","encoding_used":"utf-8-sig","columns":4,"body_rows":118,"cases_kept":118,"non_case_rows_dropped":0},{"file":"4022966__cyber-incidents-q1-2022-2023.csv","case_type":"incidents","published_quarter":"2022Q2","published_quarter_label":"Apr-Jun 2022 (Q2)","source_url":"https://ico.org.uk/media2/migrated/4022966/cyber-incidents-q1-2022-2023.csv","retrieved_utc":"2026-09-29T07:00:49+00:00","http_status":200,"bytes":6142,"sha256":"352657fbcc2ee80a2414e97510db0e7a2a14cced3e8bdaa613af08897f45e03e","encoding_used":"utf-8-sig","columns":4,"body_rows":88,"cases_kept":88,"non_case_rows_dropped":0},{"file":"4024654__cyber-incidents-q2-2022-2023.csv","case_type":"incidents","published_quarter":"2022Q3","published_quarter_label":"Jul-Sep 2022 (Q3)","source_url":"https://ico.org.uk/media2/migrated/4024654/cyber-incidents-q2-2022-2023.csv","retrieved_utc":"2026-09-29T07:00:43+00:00","http_status":200,"bytes":3739,"sha256":"d6202eb1e93dc4500f6ae3922dcf18b29451a3bbc5e64b28b9e21cc86ffd87e4","encoding_used":"utf-8-sig","columns":4,"body_rows":53,"cases_kept":53,"non_case_rows_dropped":0},{"file":"4024655__cyber-incidents-q3-2022-2023.csv","case_type":"incidents","published_quarter":"2022Q4","published_quarter_label":"Oct-Dec 2022 (Q4)","source_url":"https://ico.org.uk/media2/migrated/4024655/cyber-incidents-q3-2022-2023.csv","retrieved_utc":"2026-09-29T07:00:37+00:00","http_status":200,"bytes":7097,"sha256":"563e9d9aa94157f2a4297e627ee76aebbfc6c2f900456c6e81de382b0c61f2c0","encoding_used":"cp1252","columns":4,"body_rows":103,"cases_kept":103,"non_case_rows_dropped":0},{"file":"4024656__cyber-investigations-q2-2022-2023.csv","case_type":"investigations","published_quarter":"2022Q3","published_quarter_label":"Jul-Sep 2022 (Q3)","source_url":"https://ico.org.uk/media2/migrated/4024656/cyber-investigations-q2-2022-2023.csv","retrieved_utc":"2026-09-29T06:58:35+00:00","http_status":200,"bytes":509,"sha256":"e8128ab10e844056f450e17ce58328008d4c9ee7899655d36d173c2485db080d","encoding_used":"utf-8-sig","columns":6,"body_rows":6,"cases_kept":6,"non_case_rows_dropped":0},{"file":"4024657__cyber-investigations-q3-2022-2023.csv","case_type":"investigations","published_quarter":"2022Q4","published_quarter_label":"Oct-Dec 2022 (Q4)","source_url":"https://ico.org.uk/media2/migrated/4024657/cyber-investigations-q3-2022-2023.csv","retrieved_utc":"2026-09-29T06:58:29+00:00","http_status":200,"bytes":1252,"sha256":"73d47dc64e40de209336f16e842bca4c832bf6d6bf33f3d3ad7e04504f22aa7b","encoding_used":"utf-8-sig","columns":6,"body_rows":15,"cases_kept":15,"non_case_rows_dropped":0},{"file":"4026222__cyber-incidents-q4-2022-2023.csv","case_type":"incidents","published_quarter":"2023Q1","published_quarter_label":"Jan-Mar 2023 (Q1)","source_url":"https://ico.org.uk/media2/migrated/4026222/cyber-incidents-q4-2022-2023.csv","retrieved_utc":"2026-09-29T07:00:31+00:00","http_status":200,"bytes":11393,"sha256":"75254883e18f1f9719ca18761a58feea9c919c3288be9ecf6934985cead63d0c","encoding_used":"utf-8-sig","columns":13,"body_rows":56,"cases_kept":56,"non_case_rows_dropped":0},{"file":"4026223__cyber-investigations-q4-2022-2023.csv","case_type":"investigations","published_quarter":"2023Q1","published_quarter_label":"Jan-Mar 2023 (Q1)","source_url":"https://ico.org.uk/media2/migrated/4026223/cyber-investigations-q4-2022-2023.csv","retrieved_utc":"2026-09-29T06:58:23+00:00","http_status":200,"bytes":8103,"sha256":"64f68014410029383cd04b318edcf999f1544f6dfaf326883db09fafd178c13d","encoding_used":"utf-8-sig","columns":14,"body_rows":41,"cases_kept":41,"non_case_rows_dropped":0},{"file":"4026897__q1-202324-cyber-incidents.csv","case_type":"incidents","published_quarter":"2023Q2","published_quarter_label":"Apr-Jun 2023 (Q2)","source_url":"https://ico.org.uk/media2/migrated/4026897/q1-202324-cyber-incidents.csv","retrieved_utc":"2026-09-29T07:00:25+00:00","http_status":200,"bytes":10235,"sha256":"855e30eea2f5635592eeee2af0a44bd790f393eb9ca5081c43e2a9987d66771b","encoding_used":"utf-8-sig","columns":12,"body_rows":51,"cases_kept":51,"non_case_rows_dropped":0},{"file":"4026898__q1-202324-cyber-investigations.csv","case_type":"investigations","published_quarter":"2023Q2","published_quarter_label":"Apr-Jun 2023 (Q2)","source_url":"https://ico.org.uk/media2/migrated/4026898/q1-202324-cyber-investigations.csv","retrieved_utc":"2026-09-29T06:58:16+00:00","http_status":200,"bytes":2547,"sha256":"f18c6bb10ad27e0f61203c9a639ee8a48993c710102326899bd600f934ed5b3d","encoding_used":"utf-8-sig","columns":14,"body_rows":11,"cases_kept":11,"non_case_rows_dropped":0},{"file":"4027749__cyber-incidents-datasets-with-ice-data-q2-202324.csv","case_type":"incidents","published_quarter":"2023Q3","published_quarter_label":"Jul-Sep 2023 (Q3)","source_url":"https://ico.org.uk/media2/migrated/4027749/cyber-incidents-datasets-with-ice-data-q2-202324.csv","retrieved_utc":"2026-09-29T07:00:19+00:00","http_status":200,"bytes":8224,"sha256":"1a6c8b5a233f3f75eabf8926fbd0f63e097010c69bb71e4e32d85761c74b2b97","encoding_used":"utf-8-sig","columns":13,"body_rows":39,"cases_kept":39,"non_case_rows_dropped":0},{"file":"4027750__cyber-investigations-datasets-with-ice-data-q2-202324.csv","case_type":"investigations","published_quarter":"2023Q3","published_quarter_label":"Jul-Sep 2023 (Q3)","source_url":"https://ico.org.uk/media2/migrated/4027750/cyber-investigations-datasets-with-ice-data-q2-202324.csv","retrieved_utc":"2026-09-29T06:58:10+00:00","http_status":200,"bytes":4600,"sha256":"84fe3633812b757648e645e8de9c500410cac5163a29f69586bc61b94d64b621","encoding_used":"utf-8-sig","columns":14,"body_rows":21,"cases_kept":21,"non_case_rows_dropped":0},{"file":"4029137__cyber-incidents-q3-2023-24.csv","case_type":"incidents","published_quarter":"2023Q4","published_quarter_label":"Oct-Dec 2023 (Q4)","source_url":"https://ico.org.uk/media2/migrated/4029137/cyber-incidents-q3-2023-24.csv","retrieved_utc":"2026-09-29T07:00:13+00:00","http_status":200,"bytes":3212,"sha256":"a1f22fe28e25ec3b58c5ef37b9aec1f05fd45b40a5efa347e365487ad2ba9419","encoding_used":"utf-8-sig","columns":13,"body_rows":15,"cases_kept":15,"non_case_rows_dropped":0},{"file":"4029138__cyber-investigations-q3-2023-24.csv","case_type":"investigations","published_quarter":"2023Q4","published_quarter_label":"Oct-Dec 2023 (Q4)","source_url":"https://ico.org.uk/media2/migrated/4029138/cyber-investigations-q3-2023-24.csv","retrieved_utc":"2026-09-29T06:58:04+00:00","http_status":200,"bytes":5023,"sha256":"e87508ed6a7c3a3d67770738517728c20b4ed394e445c3757b7d6496daad1ede","encoding_used":"utf-8-sig","columns":14,"body_rows":24,"cases_kept":24,"non_case_rows_dropped":0},{"file":"4030362__cyber-crimson-investigations-q4-2023-24.csv","case_type":"investigations","published_quarter":"2024Q1","published_quarter_label":"Jan-Mar 2024 (Q1)","source_url":"https://ico.org.uk/media2/migrated/4030362/cyber-crimson-investigations-q4-2023-24.csv","retrieved_utc":"2026-09-29T06:57:58+00:00","http_status":200,"bytes":1459,"sha256":"b4c4e5afd01f6f49bde1511c789288d3e4ce9b32403a0258e37a610f79504e42","encoding_used":"utf-8-sig","columns":14,"body_rows":6,"cases_kept":6,"non_case_rows_dropped":0},{"file":"4030363__cyber-crimson-incidents-q4-2023-24.csv","case_type":"incidents","published_quarter":"2024Q1","published_quarter_label":"Jan-Mar 2024 (Q1)","source_url":"https://ico.org.uk/media2/migrated/4030363/cyber-crimson-incidents-q4-2023-24.csv","retrieved_utc":"2026-09-29T07:00:07+00:00","http_status":200,"bytes":3388,"sha256":"555600b06561e15766ee1536385939f6c3079a35a7a8d17f665852622c573e59","encoding_used":"utf-8-sig","columns":13,"body_rows":16,"cases_kept":16,"non_case_rows_dropped":0},{"file":"4031243__cyber-investigations-202425-q1-closed-datasets.csv","case_type":"investigations","published_quarter":"2024Q2","published_quarter_label":"Apr-Jun 2024 (Q2)","source_url":"https://ico.org.uk/media2/migrated/4031243/cyber-investigations-202425-q1-closed-datasets.csv","retrieved_utc":"2026-09-29T06:57:52+00:00","http_status":200,"bytes":1372,"sha256":"61dcd5d0a54d720d6329dddcedec51f2fb35b788528dfbaf1cf00fac3b679852","encoding_used":"utf-8-sig","columns":14,"body_rows":6,"cases_kept":6,"non_case_rows_dropped":0},{"file":"4031244__cyber-incidents-2024-25-q1-closed-datasets.csv","case_type":"incidents","published_quarter":"2024Q2","published_quarter_label":"Apr-Jun 2024 (Q2)","source_url":"https://ico.org.uk/media2/migrated/4031244/cyber-incidents-2024-25-q1-closed-datasets.csv","retrieved_utc":"2026-09-29T07:00:01+00:00","http_status":200,"bytes":5580,"sha256":"e7c1969464adf554de915fad2baa0788eb68c9048e02fd5aca5b2d4439092577","encoding_used":"utf-8-sig","columns":13,"body_rows":26,"cases_kept":26,"non_case_rows_dropped":0},{"file":"4032161__cyber-202425-q2-closed-datasets-investigations.csv","case_type":"investigations","published_quarter":"2024Q3","published_quarter_label":"Jul-Sep 2024 (Q3)","source_url":"https://ico.org.uk/media2/migrated/4032161/cyber-202425-q2-closed-datasets-investigations.csv","retrieved_utc":"2026-09-29T06:57:46+00:00","http_status":200,"bytes":1321,"sha256":"430b891147be84a2ad2b476ba550b858582ff1024887d2ea83ba2ea950d4a68c","encoding_used":"utf-8-sig","columns":14,"body_rows":5,"cases_kept":5,"non_case_rows_dropped":0},{"file":"4032162__cyber-202425-q2-closed-datasets-incident.csv","case_type":"incidents","published_quarter":"2024Q3","published_quarter_label":"Jul-Sep 2024 (Q3)","source_url":"https://ico.org.uk/media2/migrated/4032162/cyber-202425-q2-closed-datasets-incident.csv","retrieved_utc":"2026-09-29T06:59:55+00:00","http_status":200,"bytes":1696,"sha256":"0c78f22243ed87cc29ba70d80b756e34d5bbfe6aa71324c3021c03940eb553ef","encoding_used":"utf-8-sig","columns":13,"body_rows":7,"cases_kept":7,"non_case_rows_dropped":0},{"file":"555h4vsg__cyber-investigations-202526-q3.csv","case_type":"investigations","published_quarter":"2025Q4","published_quarter_label":"Oct-Dec 2025 (Q4)","source_url":"https://ico.org.uk/media2/555h4vsg/cyber-investigations-202526-q3.csv","retrieved_utc":"2026-09-29T06:57:16+00:00","http_status":200,"bytes":1086,"sha256":"7089808b7bc67445d5a2f54dc102303b0e6eaef0e96df1f428e0f80fe1825633","encoding_used":"utf-8-sig","columns":13,"body_rows":4,"cases_kept":4,"non_case_rows_dropped":0},{"file":"ikzdgce4__cyber-investigations-q3-2024-2025.csv","case_type":"investigations","published_quarter":"2024Q4","published_quarter_label":"Oct-Dec 2024 (Q4)","source_url":"https://ico.org.uk/media2/ikzdgce4/cyber-investigations-q3-2024-2025.csv","retrieved_utc":"2026-09-29T06:57:40+00:00","http_status":200,"bytes":473,"sha256":"fd1f5fa7199e32d9d0cfda51f42ac37682d234d402d20f882ad94a6bf5a90351","encoding_used":"utf-8-sig","columns":14,"body_rows":1,"cases_kept":1,"non_case_rows_dropped":0},{"file":"jnmeneke__cyber-investigations-q1-2025-26.csv","case_type":"investigations","published_quarter":"2025Q2","published_quarter_label":"Apr-Jun 2025 (Q2)","source_url":"https://ico.org.uk/media2/jnmeneke/cyber-investigations-q1-2025-26.csv","retrieved_utc":"2026-09-29T06:57:28+00:00","http_status":200,"bytes":574,"sha256":"b54e4cd4954d236a59e0582d1b2dee4339cb3c5fd213ff2f251915ed4b8275bc","encoding_used":"utf-8-sig","columns":16,"body_rows":1,"cases_kept":1,"non_case_rows_dropped":0},{"file":"paygmcfh__q4-2024-2025-cyber-incidents-final.csv","case_type":"incidents","published_quarter":"2025Q1","published_quarter_label":"Jan-Mar 2025 (Q1)","source_url":"https://ico.org.uk/media2/paygmcfh/q4-2024-2025-cyber-incidents-final.csv","retrieved_utc":"2026-09-29T06:59:42+00:00","http_status":200,"bytes":2836,"sha256":"cd4941d73aa025010f9c5b929b001c35fc22559ff87f78006c9a164e4551832c","encoding_used":"utf-8-sig","columns":13,"body_rows":11,"cases_kept":11,"non_case_rows_dropped":0},{"file":"pwghpy4r__cyber-incidents-q2-2025-26.csv","case_type":"incidents","published_quarter":"2025Q3","published_quarter_label":"Jul-Sep 2025 (Q3)","source_url":"https://ico.org.uk/media2/pwghpy4r/cyber-incidents-q2-2025-26.csv","retrieved_utc":"2026-09-29T06:59:30+00:00","http_status":200,"bytes":857,"sha256":"78373fe1f80f20ebc826abd342fdd4c7b5316488e05e3c6fafea9b2a226b88f1","encoding_used":"utf-8-sig","columns":14,"body_rows":3,"cases_kept":3,"non_case_rows_dropped":0},{"file":"sf4ptnae__cyber-incidents-q1-2025-26.csv","case_type":"incidents","published_quarter":"2025Q2","published_quarter_label":"Apr-Jun 2025 (Q2)","source_url":"https://ico.org.uk/media2/sf4ptnae/cyber-incidents-q1-2025-26.csv","retrieved_utc":"2026-09-29T06:59:36+00:00","http_status":200,"bytes":125,"sha256":"cdd4fb235da5f6fad8660660dfc9bd67e07882aadb92e030f696818129034b39","encoding_used":"utf-8-sig","columns":4,"body_rows":1,"cases_kept":0,"non_case_rows_dropped":1},{"file":"uyoop3it__cyber-incidents-q4-2025-26.csv","case_type":"incidents","published_quarter":"2026Q1","published_quarter_label":"Jan-Mar 2026 (Q1)","source_url":"https://ico.org.uk/media2/uyoop3it/cyber-incidents-q4-2025-26.csv","retrieved_utc":"2026-09-29T06:59:18+00:00","http_status":200,"bytes":3252,"sha256":"600175d14373e173cd33c7ea95644fb2a86bef5ea1bc8241178207c41ae9351d","encoding_used":"utf-8-sig","columns":13,"body_rows":15,"cases_kept":15,"non_case_rows_dropped":0},{"file":"w4ilzayr__cyber-incidents-q3-2024-2025.csv","case_type":"incidents","published_quarter":"2024Q4","published_quarter_label":"Oct-Dec 2024 (Q4)","source_url":"https://ico.org.uk/media2/w4ilzayr/cyber-incidents-q3-2024-2025.csv","retrieved_utc":"2026-09-29T06:59:48+00:00","http_status":200,"bytes":1356,"sha256":"2bb6e069a772f3e97b97aa2d6a93fb9f9a0144baff36a56e91ead29f2b4dc7c3","encoding_used":"utf-8-sig","columns":13,"body_rows":5,"cases_kept":5,"non_case_rows_dropped":0},{"file":"wpfdra4w__q4-2024-2025-cyber-investigations-final.csv","case_type":"investigations","published_quarter":"2025Q1","published_quarter_label":"Jan-Mar 2025 (Q1)","source_url":"https://ico.org.uk/media2/wpfdra4w/q4-2024-2025-cyber-investigations-final.csv","retrieved_utc":"2026-09-29T06:57:34+00:00","http_status":200,"bytes":337,"sha256":"8fec602ee7b135d3f2759c3427675f4d32e9e959978a38f8cd0da665e53e3ce7","encoding_used":"utf-8-sig","columns":14,"body_rows":1,"cases_kept":0,"non_case_rows_dropped":1},{"file":"ycjlg3ye__cyber-investigations-q2-2025-26.csv","case_type":"investigations","published_quarter":"2025Q3","published_quarter_label":"Jul-Sep 2025 (Q3)","source_url":"https://ico.org.uk/media2/ycjlg3ye/cyber-investigations-q2-2025-26.csv","retrieved_utc":"2026-09-29T06:57:22+00:00","http_status":200,"bytes":718,"sha256":"5805db58f0816fc88e66a66e10d6b2b499aea330c92c50e1825643ba36dd40cb","encoding_used":"cp1252","columns":13,"body_rows":3,"cases_kept":3,"non_case_rows_dropped":0},{"file":"yxtbixl0__cyber-incidents-202526-q3.csv","case_type":"incidents","published_quarter":"2025Q4","published_quarter_label":"Oct-Dec 2025 (Q4)","source_url":"https://ico.org.uk/media2/yxtbixl0/cyber-incidents-202526-q3.csv","retrieved_utc":"2026-09-29T06:59:24+00:00","http_status":200,"bytes":1271,"sha256":"6cb701edfdba2e458784c5a71e313a523859a0b7ec0ca8ba05e165febff9aa7d","encoding_used":"utf-8-sig","columns":13,"body_rows":5,"cases_kept":5,"non_case_rows_dropped":0},{"file":"zcul1eg3__cyber-investigations-q4-2025-26.csv","case_type":"investigations","published_quarter":"2026Q1","published_quarter_label":"Jan-Mar 2026 (Q1)","source_url":"https://ico.org.uk/media2/zcul1eg3/cyber-investigations-q4-2025-26.csv","retrieved_utc":"2026-09-29T06:57:09+00:00","http_status":200,"bytes":1256,"sha256":"0e817752c64f67c622e00cc59b79d99f63b733b7207522558752f6490c453125","encoding_used":"utf-8-sig","columns":13,"body_rows":5,"cases_kept":5,"non_case_rows_dropped":0}],"dropped_rows":[{"file":"4020217__202101-202103-cyber-investigations.csv","line":2,"reason":"all-blank row","verbatim":",,,,"},{"file":"4020224__202104-202106-cyber-investigations.csv","line":2,"reason":"all-blank row","verbatim":",,,,"},{"file":"sf4ptnae__cyber-incidents-q1-2025-26.csv","line":2,"reason":"reference column holds no ICO case reference - not a case row","verbatim":"* NB no relevent incident cases concluded in this quarter,,,"},{"file":"wpfdra4w__q4-2024-2025-cyber-investigations-final.csv","line":2,"reason":"reference column holds no ICO case reference - not a case row","verbatim":"* NB no relevent investigations cases concluded in this quarter,,,,,,,,,,,,,"}],"mojibake_register":[{"file":"ycjlg3ye__cyber-investigations-q2-2025-26.csv","line":2,"as_read":"Closed after interventionâ€“in line with RAP","repaired":"Closed after intervention–in line with RAP"},{"file":"ycjlg3ye__cyber-investigations-q2-2025-26.csv","line":3,"as_read":"Closed after interventionâ€“in line with RAP","repaired":"Closed after intervention–in line with RAP"},{"file":"ycjlg3ye__cyber-investigations-q2-2025-26.csv","line":4,"as_read":"Closed after interventionâ€“in line with RAP","repaired":"Closed after intervention–in line with RAP"}],"encodings":{"cp1252":3,"utf-8-sig":38},"licence":{"source":"Open Government Licence v3.0","source_url":"https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/","source_evidence":"https://ico.org.uk/global/copyright-and-re-use-of-materials/","required_attribution_template_verbatim":"Information Commissioner's Office, [name and date of publication], licensed under the Open Government Licence.","required_attribution_verbatim":"Information Commissioner's Office, [name and date of publication], licensed under the Open Government Licence.","attribution_as_used":"Information Commissioner's Office, Cyber investigations and Cyber incidents quarterly data sets, published January 2021 to March 2026, licensed under the Open Government Licence.","attribution_note":"The string above with the square brackets is the ICO's template as published on its copyright page, kept here as evidence of the condition. The attribution actually used on the page, in the README and in the derived dataset is attribution_as_used, with the name and the date of publication filled in as the condition requires.","commercial_reuse":"Permitted.","images_excluded":"The ICO's grant covers text content and refuses image re-use. No ICO image, chart or screenshot is reproduced.","derived":"CC BY 4.0, carrying the ICO attribution above verbatim."},"open_questions":["Whether the fall in published closures after 2021 reflects fewer cases or a change in what the ICO publishes. The data cannot tell them apart and no claim is made.","Whether the 'MPN not issued' and 'Not recoverable' strings mean what they appear to mean. The ICO publishes no definition of its outcome taxonomy other than in draft guidance, so both codings are published rather than one being asserted.","Whether any of the 41 files has been revised since retrieval. Re-hashing answers it.","Whether the ICO has published a final version of the Data Protection Enforcement Procedural Guidance since the consultation closed on 23 January 2026. The draft v0.8 is quoted here for the ICO's own description of a reprimand; we did not check for a final version and make no claim that none exists."],"url":"https://www.servnetuk.com/research/ico-cyber-caseload-tracker-2026"}