Notice
The Ladies' College ordered to improve security measures following breach (2025-12-04)
Issued 2025-12-04View on ODPA's website Source document
Summary
This is a public enforcement notice from Guernsey's Office of the Data Protection Authority (ODPA) concerning a ransomware attack on The Ladies' College discovered on 24 June 2024. The Authority investigated and found the College in breach of the Data Protection (Bailiwick of Guernsey) Law, 2017 due to inadequate security monitoring, a weak unprotected administrator account, and exposed remote access. The College has already completed all remedial actions ordered by the Authority.
- Root causes identified: Suspicious authentication activity was detected by systems but not monitored or escalated; an administrator account used a weak password without Multi-Factor Authentication (MFA), enabling a brute force attack; remote access to network computers was not properly secured, exposing them to compromised credentials.
- Impact: Systems were encrypted by ransomware; most affected data was not personal data and none related to students, but some limited personal data was impacted. No evidence of data exfiltration was found.
- Regulatory outcome: The Authority found a breach of the Data Protection Law and imposed an order requiring The Ladies' College to take specific security improvement actions, all of which have since been completed.
- General lessons for organisations: Implement processes to ensure security alerts are seen and actioned promptly (e.g. via email alerts); use strong passwords (NCSC recommends the 'three random words' approach); implement MFA across accounts where possible; disable Remote Desktop Protocol (RDP) access where not needed, or strictly control it with firewall rules, strong passwords and MFA.
The notice is primarily retrospective and informational for the College involved, but the Authority frames its findings as general guidance for all data controllers on expected security safeguards.
Key obligations
- Organisations must put in place processes to ensure security monitoring alerts are identified and actioned in a timely manner
- Organisations must ensure appropriate (strong) passwords are used to mitigate unauthorised account access
- Organisations should implement Multi-Factor Authentication (MFA) across accounts to the extent possible
- Organisations must ensure Remote Desktop Protocol access to devices is disabled if not required, or otherwise strictly controlled with firewall rules, strong passwords and MFA
- The Ladies' College was ordered to undertake specific security improvement actions following the breach finding (since completed)
Applies to
data controllers, organisations processing personal data, educational institutions/schools