08/09/2026
The Information Commissioner’s Office has changed gear. In the first half of 2025 it collected around seven times more in fines than in the whole of 2024, and the average penalty jumped from roughly £150,000 to over £2.8 million. The striking thing is not the size of the fines, though. It is what causes them. Almost every one traces back to a basic security failure that would have been cheap to fix.
For a small or medium business, the lesson is not “we might get a huge fine”, because you almost certainly will not be fined millions. It is that the same failures that cost big organisations millions are the exact ones that let attackers into small ones, with the same painful results.
Big fines, basic failures
Look at the recent cases and a pattern jumps out:
- Advanced Computer Software (£3.07m). Attackers got in through a customer account that had no multi-factor authentication, then launched ransomware that disrupted healthcare services for tens of thousands of people.
The ICO's biggest fines nearly all trace back to missing basics like MFA. What UK SMEs should learn, and why Cyber Essentials is the baseline that prevents them.