When “It’s Just a Data Breach” Becomes a NIS Problem: What Operators of Essential Services Should Learn from South Staffordshire Water

When “It’s Just a Data Breach” Becomes a NIS Problem: What Operators of Essential Services Should Learn from South Staffordshire Water

Arcanum Technical Director, Lawrie Abercrombie, outlines how the recent data breach suffered by South Staffordshire Water can be assessed through a compliance and regulatory lens – and what other organisations working in Critical National Infrastructure should take from this case study.

In May 2026, the Information Commissioner’s Office (ICO) fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 following a cyber-attack that resulted in the personal information of 633,887 people being extracted and later published on the dark web. That enforcement action was taken under UK GDPR, focused on the confidentiality and integrity of personal data.  

But for Operators of Essential Services (OES), the more uncomfortable question is this:

If this can happen to a regulated utility, how would a NIS Competent Authority assess it, using the NCSC Cyber Assessment Framework (CAF) and what would the enforcement risk look like?

This article answers that question in NIS language: how the case maps to CAF outcomes, what a regulator is likely to conclude about “appropriate and proportionate” measures and the practical control improvements that shift you from “explainable incident” to “defensible compliance posture.” The water sector is used as the anchor, but the lessons apply across OES sectors.

The case in brief – why it matters to OES

According to the ICO’s public account, the attack began with a phishing email in September 2020, enabling malware installation that remained undetected for around 20 months. In May 2022, the attacker moved through the network and obtained domain administrator privileges and the breach was only identified after IT performance issues triggered investigation in mid-July 2022.  

The ICO and reporting outlets highlighted concrete security failings that will sound familiar to every assessor who has run a CAF-aligned inspection:

  • Limited controls enabling privilege escalation to admin 
  • Inadequate monitoring/logging, with only ~5% of the IT environment monitored 
  • Legacy/unsupported software (including Windows Server 2003) 
  • Inadequate vulnerability management, critical systems unpatched and no regular scanning 

In a NIS context, these are not “nice-to-haves.” They are the foundations of the “appropriate and proportionate” baseline.

Who regulates what under NIS and why “the ICO already fined us” isn’t a shield

NIS enforcement is carried out by sector-specific Competent Authorities.  The ICO explicitly notes that NIS is overseen by different competent authorities across sectors and describes enforcement tools including information notices, enforcement notices and monetary penalties (up to statutory maxima).  [msn.com]

For the water sector in England and Wales, the Drinking Water Inspectorate (DWI) publishes its NIS enforcement policy, explaining that the NIS Regulations identify drinking water supply and distribution as an essential service and that the DWI is nominated to exercise the operational function and regulatory activity of the Competent Authority. 

The key implication for OES boards and CISOs is straightforward:

  • UK GDPR enforcement addresses personal data harms. 
  • NIS enforcement addresses the security and resilience of the network and information systems on which the essential service depends. 

These regimes can overlap in a single incident, but they do not merge into one regulatory outcome.

How a NIS regulator is likely to assess this using the NCSC CAF (A–D)

The CAF gives regulators a consistent way to assess whether OES have taken “appropriate and proportionate” measures. Water sector enforcement policy emphasises exactly that duty, appropriate and proportionate technical and organisational measures to manage risks to essential-service systems. The table below is an explicit CAF mapping based on publicly stated facts of the incident.

Screenshot 2026 07 10 at 09.39.15

What enforcement risk looks like in practice under NIS 

The “appropriate and proportionate” test

DWI’s enforcement policy is explicit that NIS expects appropriate and proportionate measures and that where compliance is not achieved, enforcement action may be required.  

In CAF terms, the South Staffordshire Water facts strongly suggest systemic shortfalls across A, B and C, with D compromised by the absence of timely detection. This matters because NIS enforcement is rarely about a single missing control, it’s about whether the organisation can demonstrate a credible, risk-based, continuously improving management system for cyber resilience.  

Why OES should assume “dual scrutiny”

The ICO’s NIS guidance explains that NIS is overseen by multiple competent authorities and that entities can be in scope for NIS while also being subject to data protection requirements. Practically, a major incident can trigger: NIS regulatory assurance activity (evidence gathering, inspection, mandated improvements).

  • UK GDPR enforcement where personal data is involved (as in this case) Penalties are not the only (or even primary) lever

Even where regulators have the ability to issue monetary penalties, enforcement in many sectors often begins with:

  • Formal evidence requests (information notices),
  • Improvement requirements (enforcement notices) and
  • Independent audits/inspections.

The ICO’s NIS enforcement overview confirms these tools exist within the NIS regime.  The DWI policy also emphasises that guidance and advice are preferred, but enforcement may be needed to secure compliance.  

The point for OES leadership:

A CAF “Not Achieved” in core areas can become a multi-year supervisory burden even where the incident did not cause catastrophic service outage.

South Staffordshire Water Graphic

What “good” looks like and what moves the CAF needle

Here are the control outcomes that most directly address the gaps evidenced in this case, written in CAF-aligned language and prioritised as an OES improvement plan.

Monitoring and detection coverage (CAF C1/C2)

Target outcome: material increase in monitored estate coverage; detection of attacker behaviour, not just malware signatures.

What to implement

  • Central logging with defined minimum log sources (AD, endpoints, servers, VPN/RDP, privileged actions)
  • Detection engineering for privilege escalation, lateral movement, anomalous admin use
  • 24/7 monitoring for critical systems; at minimum, robust on-call and triage SLAs

Why: Monitoring coverage of only ~5% is structurally incompatible with CAF C1.  

Privileged access control and identity hardening (CAF B2)

Target outcome: prevent/contain escalation to domain admin; reduce blast radius of credential compromise.

What to implement

  • Enforced least privilege and role-based access
  • Privileged access workstations (PAWs) / tiered admin model
  • MFA everywhere for privileged accounts; remove legacy auth paths
  • Continuous review of privileged group membership and admin rights

Why: Domain admin compromise is effectively enterprise compromise. 

Vulnerability management and patch assurance (CAF A2/B4)

Target outcome: demonstrable, repeatable vulnerability lifecycle, identify, prioritise, remediate, verify.

What to implement

  • Regular internal and external scanning; defined cadence and exception management
  • “Known exploited vulnerabilities” prioritisation
  • Patch SLAs tied to essential-service criticality
  • Independent verification and reporting to governance forums

Why: The case explicitly referenced unpatched critical systems and lack of regular scanning.  

Legacy and unsupported technology strategy (CAF A3/B4)

Target outcome: unsupported platforms are removed, isolated, or wrapped in compensating controls.

What to implement

  • Asset inventory with lifecycle status
  • End-of-life eradication programme (or strong containment/segmentation)
  • Compensating controls for residual legacy (network isolation, strict allowlisting, jump hosts)

Why: Unsupported software (e.g., Windows Server 2003) featured prominently in public reporting.  

Network segmentation and resilience engineering (CAF B5/D1)

Target outcome: compromise of one zone does not enable enterprise-wide lateral movement; essential service remains deliverable.

What to implement

  • Segmentation between user, server and management planes
  • Restrict RDP; use controlled management paths
  • Recovery design: golden images, immutable backups, tested restores
  • OT/IT separation where applicable, with monitored, controlled interconnects

Why: Lateral movement and persistence were key characteristics of the attack timeline.  

Arcanum’s view: how to make CAF defensible, not just “compliant on paper”

The hidden risk for OES isn’t simply a fine, it’s failing to demonstrate to a Competent Authority that you have:

  • A credible understanding of risk (Objective A),
  • Controls that are actually effective and technically robust (Objective B) and
  • Visibility that would detect a real attacker (Objective C) with  
  • Practised response and recovery (Objective D). 

At Arcanum, we see the same pattern repeatedly: organisations are often reasonable at policy and weak at evidence. Regulators assess what you can demonstrate, not what you can assert.

What “market-leading” looks like in practice for OES

A strong CAF posture is built through:

  • CAF-aligned assurance that tests real-world effectiveness (not checkbox audit)
  • Evidence packs prepared the way regulators actually request them (asset scope, risk method, control test results, incident learnings)
  • Prioritised remediation roadmaps that show proportionate decision-making (what you fixed, why and what remains with compensating controls)
  • Executive governance that connects cyber risk to essential service continuity and investment decisions

This is precisely where specialist consultancies add value: not by writing another policy, but by helping you operationalise controls, build evidence and stand up to scrutiny.

A practical “next 30/60/90 days” plan for OES leaders

If you’re an OES leader reading this and thinking “we’re probably not far off that baseline,” here’s a pragmatic way to start:

Next 30 days, establish the truth

  • Quantify monitoring coverage (what % of estate; what critical systems; what log sources) 
  • Identify legacy/unsupported platforms and where they sit in the service chain 
  • Review privileged access paths and domain admin exposure 60 days, fix the highest-risk control gaps
  • Expand logging for identity, endpoints and admin actions
  • Implement MFA and tiered admin controls
  • Start vulnerability scanning cadence and remediation SLAs 

90 days, build CAF evidence and assurance

  • Document CAF outcome ratings with evidence
  • Run a table-top + technical exercise to validate detection and response
  • Produce an OES regulator-ready pack aligned to your Competent Authority’s expectations 

Closing thought: CAF isn’t a framework, it’s how regulators think

South Staffordshire Water’s case is a reminder that a cyber incident is rarely judged solely on sophistication. Regulators look for whether basic, known-effective controls were in place, proportionate to the risk and the essential nature of the service. 

If your estate has low monitoring coverage, weak privileged controls, unmanaged vulnerabilities and legacy systems, you don’t just have “security debt”, you have CAF gaps and those translate directly into NIS enforcement exposure.

If your organisation needs help to get CAF aligned, get in touch with us today for an introductory call to outline how we can help to make the process a fast and efficient one. Contact us.