BITS Group
The breach that hid for 20 months: what the South Staffordshire Water fine means for your business

The breach that hid for 20 months: what the South Staffordshire Water fine means for your business

One employee opened a phishing email in 2020. The attachment they clicked installed malware inside South Staffordshire Water's systems. Nobody noticed, for the next 20 months, that malware quietly worked its way through the network, harvesting data. By August 2022, the personal and banking details of 633,887 customers and employees had been published on the dark web. This month, the ICO issued a fine of just under £1 million.

The fine got coverage. But the bit that should make most business owners sit up isn't the penalty, it's the 20 months.

Why a 20-month gap is more common than it sounds

When business owners hear about a breach, the instinct is to think about prevention: a stronger firewall, better spam filters, tighter passwords. Prevention matters. But the South Staffordshire Water case is really a story about detection, and detection is the thing most businesses don't have a clear plan for.

The ICO's investigation found that at the time of the attack, only 5% of South Staffordshire's IT environment was actively monitored. That's not a failure you'd spot on a normal Tuesday morning. It's the kind of gap that builds up quietly, because monitoring costs effort and money, because nobody asks for a report on it, and because it tends to get deprioritised until it's too late.

For most UK SMEs, the picture isn't dramatically different. According to the UK Government's Cyber Security Breaches Survey 2025/2026, just 25% of businesses have a formal incident response plan. Without that plan, an intrusion can sit inside your systems for weeks, months, or longer before anyone recognises what they're looking at.

The attack started with a phishing email.

The survey also found that phishing remains the most common entry point for breaches, affecting 38% of UK businesses. This isn't a technical vulnerability in the traditional sense. It's a human one. Someone received a convincing-looking email, opened an attachment, and that was enough.

The NCSC has been clear on this: it's not just large retailers and utilities that are targets. In their recent blog post on incidents impacting UK organisations, the NCSC noted that criminal groups have shifted to "ransomware as a service," lowering the barrier to entry so that attackers with little technical skill can launch effective campaigns using ready-made tools. The organisations getting hit span every sector and every size.

For an SME, this matters because the instinct is to assume you're too small to be a worthwhile target. You're not. You're often easier to get into.

What the South Staffordshire case actually teaches us

Three failures sat behind this breach. They're worth naming plainly, because they're failures we see in organisations across the UK, often without anyone realising.

Monitoring coverage was too thin. Only 5% of the IT environment was being watched for unusual activity. When an attacker gets inside, the question is no longer "how do we stop them?" but "how quickly do we know they're there?" That question only has a good answer if you have eyes on your systems.

Patching and vulnerability management had gaps. The investigation found unpatched critical systems and no regular security scanning. Patches feel like housework. They're easy to deprioritise when everyone's busy. But unpatched systems are open doors, and criminal tools are designed to find them automatically.

There was no early detection mechanism. Because monitoring was inadequate, there was no alert, no trip-wire, no report that said "something looks wrong." The attack progressed for nearly two years without a human noticing.

None of these is exotic. None requires a nation-state actor or a sophisticated zero-day exploit. They're operational gaps in an otherwise functioning organisation.

Five things worth doing now

If you're an SME business owner or MD, here's where to focus:

  1. Ask who's monitoring your network, and how much of it. If the answer is "our IT provider checks if things are working," that's maintenance, not security monitoring. You need active detection across your environment, not just uptime checks.

  2. Check your patching status. When were your servers, devices, and software last patched? If nobody can answer that confidently within a week, it's worth getting a clear picture.

  3. Test your phishing resilience. The South Staffordshire attack started with one person clicking one attachment. Phishing simulation exercises, run as part of awareness training, are one of the most effective ways to find out where your team's weak points are before an attacker does.

  4. Build a basic incident response plan. It doesn't have to be complex. "Who do we call if we think we've been breached, what do we turn off, and who needs to know?" answered in writing is better than most businesses have.

  5. Consider Cyber Essentials. The scheme exists specifically to close the foundational gaps: patching, access controls, malware protection, secure configuration, and network boundaries. It's proportionate, affordable, and increasingly expected by insurers and larger clients.

We help our clients work through these checks as part of regular IT health reviews. If you'd like to know how your current setup stacks up, get in touch and we can talk through where to start.

Need IT Support?

Contact us today for a free consultation and discover how we can help your business.

Get Started Today