A man started a new job at Herefordshire Council, in the directorate that handles children and young people — the files on families in the care system, safeguarding assessments, the most sensitive records a local authority holds. Within days, over a four-day stretch, he used his brand-new access to open around 490 records and download 94 documents. Not case files he was assigned. The records of family members and families he personally knew. Medical records, social worker reports, child and family assessments.

Geoffrey Smith, 31, pleaded guilty to an offence under the Computer Misuse Act and, on 17 July, was sentenced at Worcester Magistrates' Court to two months' imprisonment, suspended for twelve months, plus 120 hours of unpaid work and £2,154 in costs and surcharge. The headline, inevitably, is that he was spared prison.

The sentence is the least interesting thing about this case. For anyone who runs an organisation that holds personal data — which is all of them — the story is everything that happened before the courtroom, and what it tells you about the defences you are actually relying on.

The breach nobody budgets for

We spend our security budgets on the outside: the firewall, the phishing filter, the endpoint agent watching for the intruder trying to get in. This was not that. There was no intruder. There was an employee, correctly logged in, using access he had been legitimately granted, for a purpose he had not. No malware, no exploit, no exfiltration infrastructure — just a person and a curiosity.

This is the insider snoop, and it is simultaneously the most common form of data misuse in any organisation holding interesting records and the least defended against, precisely because it does not look like an attack. Nobody breaks anything. The logs, if anyone reads them, show a valid user opening records they had the technical right to open. It is the security failure that hides inside normal behaviour, and it is endemic in exactly the places that hold the most harmful data to misuse: councils, the NHS, the police. The Register's own list of related cases — a stranger treating a patient on an NHS ward, police visiting the wrong child's school, a maternity data leak I wrote about a fortnight ago — is a portrait of a public sector where the threat is very often already on the inside, holding a valid pass.

The controls failed long before the law was needed

Here is the finding I would put in front of a board, and it has nothing to do with the sentence. A brand-new starter was able to reach roughly 490 sensitive safeguarding records — about people entirely unconnected to his actual work — and download ninety-four of them, across four days, before anything or anyone stopped him.

Sit with each half of that. The access is the first failure: a new employee's account should be provisioned to the records their role requires, not to the directorate's entire store. Least privilege is not an exotic control; it is the oldest one there is, and it is the difference between a nosy employee being able to look up their own caseload and being able to look up half the county. The second failure is detection. Four days of one new user ranging across hundreds of unrelated, highly sensitive records is not subtle. It is one of the most detectable patterns in security — anomalous volume, anomalous breadth, downloads — and the systems either were not watching for it or nobody was reading what they saw. The misuse ended because it was eventually noticed, but "eventually," here, was 490 records too late.

So the question the Herefordshire case actually poses to your organisation is not "would we prosecute." It is: could a new joiner this week open several hundred of your most sensitive records and download a hundred of them, and if they did, how long would it take you to notice? For a great many organisations the honest answers are "yes" and "far too long." That is the vulnerability. The court case is just the aftermath.

Even the tough tool ends in a suspended sentence

Now the sentence, because there is a real lesson in it — just not the one the headline reaches for.

Notice which law was used. The ICO prosecuted Smith under Section 1 of the Computer Misuse Act 1990 — unauthorised access to computer material — not under Section 170 of the Data Protection Act, the more obvious "unlawfully obtaining personal data" offence I discussed in the Forth Valley piece. That choice is deliberate and increasingly common, and the reason is simple: Section 170 is a fine-only offence, while the Computer Misuse Act carries the possibility of imprisonment. The regulator reached for the tougher statute specifically so that prison was on the table, to signal that insider snooping is a crime and not merely a disciplinary matter.

And with that tougher tool, against a guilty plea, the outcome was a two-month sentence, suspended, plus unpaid work and costs. I am not arguing the sentence was wrong — magistrates weigh a guilty plea, a first offence and personal mitigation, and that is their job. I am arguing about what it means for your planning. If any part of your defence against the curious insider rests on the deterrent power of prosecution, this case shows you what "prosecuted with the most serious available charge" actually looks like in practice: a suspended sentence and 120 hours of community work. That is a real consequence. It is not a wall that will stop a tempted employee at the moment of temptation, because the moment of temptation is a quiet afternoon at a desk, and the court is a distant abstraction.

The deterrent that actually works on the insider is not the far-off possibility of a magistrate. It is the near-certainty of being caught quickly, by their own employer, because the access is logged and the logs are watched — and knowing that in advance.

Why "no money was taken" is the wrong comfort

One more thing, because it matters and it is easy to miss. Nobody defrauded anyone here. No bank details were sold. By the metric a lot of breach statements reach for — "no financial or payment information was affected" — you might call this minor.

It is not minor. The records were children's social-work files, family assessments, medical histories — information about vulnerable people in the care system, read by an acquaintance with no right to it. The harm is not a fraud loss you can reimburse. It is the violation itself, and the safeguarding risk of the most private facts about a family being in the hands of someone who knows them. When the data is this, "no money was taken" is not reassurance. It is a category error. The ICO's Andy Curry was right to call the sensitivity of a Children and Young People directorate's records exactly what makes this "particularly serious."

What actually protects the family whose file is one click away

None of the fixes are exotic, and all of them sit inside the organisation rather than the courtroom.

Provision access to the role, not the system. A new starter — anyone — should be able to reach the records their job requires and not the rest. Most staff having standing access to hundreds of unrelated sensitive files is the vulnerability; role-based access, granted on a proper joiners process, is the fix.

Log every access to sensitive records, and actually watch the logs. Alert on the patterns that gave this away too late: bulk access, downloads, a user opening records unconnected to their caseload, a new account ranging widely. Detection should be measured in hours, not in "when someone eventually noticed." For the most sensitive records, a reason-for-access prompt — a break-glass step that makes the user state why — both deters the casual snoop and builds the audit trail.

And tell your people, plainly, that access is logged and reviewed. The single most effective deterrent against insider snooping is not the distant threat of court; it is the near-certain, quick, internal consequence, and the knowledge beforehand that it is coming. A workforce that knows every look is recorded snoops far less than one that assumes nobody is watching.

The part worth remembering

The sentence will get the argument — too soft, too harsh, the usual. It is the least useful thing to argue about. The useful fact is that a man days into a new job could open the safeguarding files of nearly five hundred people and walk out with copies of a hundred of them before his employer's systems caught it, and that the criminal law — even at its most serious, even with a guilty plea — is what you are left holding when your own controls have already lost.

If your protection against the curious insider is "they could be prosecuted," Herefordshire has shown you precisely what that is worth. Build the controls that make the snooping visible and certain to be caught inside your own walls. That, and not the magistrate, is the thing standing between a bored new starter and the most private records of a family who will never know how close it came.