In October 2023, the Rhysida ransomware group infiltrated the British Library, one of the world's largest libraries, holding over 170 million items including irreplaceable manuscripts, historical records, and national archives.
The attackers exfiltrated approximately 600 gigabytes of internal data, including staff HR records, internal system data, and user information. When the British Library refused to pay the ransom demand of approximately 20 Bitcoin, Rhysida published the stolen data online. Recovery took months. Digital services, including the online catalogue used by researchers worldwide, were severely disrupted through early 2024. The total recovery cost exceeded £7 million, a significant sum for a publicly funded institution operating on a fixed budget.
The British Library is not a commercial organisation with a large security team and a well-funded technology estate. It is a public institution whose primary function is the preservation and provision of knowledge. It held sensitive staff data, operational systems, and internal records that had real value to an attacker willing to encrypt and extort. The gap between what it held and what it could afford to protect was significant and well known.
That gap is real and worth addressing. But the recovery cost and the disruption were not primarily consequences of the initial intrusion. They were consequences of what happened after the intrusion - the data exfiltration and the ransomware deployment - neither of which required a confirmed human authority decision before executing.
A public institution with constrained resources cannot be expected to maintain enterprise-grade security across every layer of its infrastructure. That is a genuine problem that goes beyond any single product. But the execution boundary is different. GoFirm does not require a large security team or complex infrastructure. It requires the organisation to identify its high-consequence actions - bulk data exports, infrastructure-level changes, privileged access escalations - and configure a named authority for each. The SDK embeds in three lines of code. The admin panel is operational same day.
For the British Library, that means: before 600GB of internal data leaves the network, a named authority receives a confirmation request on their registered personal device. They confirm or the export stops. Before ransomware can encrypt production systems, the infrastructure access that enables it requires the same confirmation. An attacker who has successfully entered the network still cannot produce it.
The £7 million recovery cost, the months of disruption to researchers and institutions worldwide, the publication of staff personal data - all of it followed from actions that executed without confirmed human authority. GoFirm does not require a large budget to deploy. It requires a decision to put a gate at the execution boundary before the damage happens rather than after.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.
References
1. Depth Security, Inside the Biggest Cybersecurity Breaches of 2023–2025: What They Reveal About Modern Security Gaps, October 2025
