GoFirm
Back to Blog
Threat Landscape·3 min read

The UK Government Is Right to Lock the Door. The Vault Needs a Different Lock.

By GoFirm

In February 2026, the UK government launched a campaign urging businesses to “lock the door” on cyber criminals. The campaign promotes Cyber Essentials, the NCSC’s baseline certification scheme, and the numbers behind it are striking. Cyber threats cost UK businesses £14.71 billion annually. Half of all small businesses suffered a breach or attack in the last twelve months. And organisations with Cyber Essentials in place made 92% fewer insurance claims than those without.¹

Cyber Essentials is worth having. The five controls it mandates, firewalls, secure configuration, software updates, user access control, and malware protection, address the most common attack vectors that opportunistic criminals use to gain entry. For an SME that has not yet implemented the basics, getting certified is a meaningful and immediate risk reduction. The insurance figure alone makes the case.

But the campaign’s own headline tells you where the limit is. “Lock the door” is the right metaphor for what Cyber Essentials achieves. It hardens the perimeter. It makes opportunistic entry harder. It closes the gaps that unsophisticated attackers exploit.

It does not address what happens when the door is opened legitimately.

The government’s own Cyber Security Longitudinal Survey, published alongside the campaign, found that 82% of medium and large businesses suffered a cyber incident in the past year. Those organisations are not failing to implement firewalls or malware protection. They are experiencing incidents that go through the door correctly, using valid credentials, legitimate access paths, and authorised-looking instructions that bypass perimeter controls entirely.

A finance employee who authorises a transfer following a convincing deepfake video call has not failed to lock the door. The door was locked. The attacker knocked and was let in. A phishing email that leads to a credential compromise and a bulk data extraction did not exploit a firewall misconfiguration. It exploited a human, and the human had the key. An AI agent that executes a destructive command because it found an over-scoped credential in a developer’s environment was not stopped by malware protection because it was not malware. It was a legitimate process acting on legitimate credentials.

The £14.71 billion annual cost of cybercrime to UK businesses is not primarily the cost of attacks that broke down the door. It is the cost of attacks that walked through it. Stolen credentials. Social engineering. Insider actions. AI-assisted manipulation. Rogue agents. Every one of those vectors bypasses the five Cyber Essentials controls by design, because those controls secure the boundary between inside and outside, not the actions that take place once someone is inside.

The lock the door metaphor actually points to what is missing. A locked door protects what is behind it from unauthorised entry. It does not protect what is inside from someone who has a key. For the assets that matter most, the crown jewels, financial transfers, bulk data, infrastructure configuration, privileged access, the relevant control is not the door lock. It is the vault lock. The control that requires confirmed authority before the most consequential actions execute, regardless of how the person got into the building.

Cyber Essentials raises the floor. Every UK business should have it. But the £14.71 billion annual loss figure will not move materially until the industry also addresses what happens when the door is opened correctly by the wrong person, or by a system acting without verified human authority.

Lock the door. Then put a vault lock on what matters most inside it.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. UK Government / NCSC, Businesses urged to “lock the door” on cyber criminals as new government campaign launches, February 2026, https://www.gov.uk/government/news/businesses-urged-to-lock-the-door-on-cyber-criminals-as-new-government-campaign-launches

Share this article