While the threat of a cyber-attack now features prominently on most U.K. company risk registers, regulatory action so far has been fairly low-key. But a recent case has shown that U.K. enforcement agencies are prepared to show their bite when necessary—and that organisations should take heed.



