It should come as no surprise that the UK is second only to the US in terms of ransomware victims. Nor is it unexpected that the National Cyber Security Strategy has lost its way. The problem is not a lack of policy; it is a lack of practice and enforcement. As the RUSI report says, criminals and state actors are still able to rely on the same tactics they used when ransomware began to surge in 2019. That is because the fundamentals of our preparedness and behaviours have not changed.
The gap between policy and reality
Government policy sets a low bar. Cyber Essentials, while well-intentioned, often becomes a tick-box exercise. And with few controls over who can call themselves a “cyber security consultant”, many organisations receive advice that is superficial at best. Even when given sound advice, organisations are often slow to follow through with recommended remediations.
Initiatives such as Secure by Design (SbD) and Zero Trust Architecture (ZTA) are welcome steps forward, but only on paper. SbD tells you what to trust; ZTA tells you how to trust. Yet neither has real enforcement. A supplier can claim to apply these approaches, but how does a customer know that is true? Even large primes admit to “re-badging” staff as SbD experts when clients demand it. Without a clear definition of expertise, the value of the label diminishes and without consistent standards and implementation, the overall initiative is weakened.
Secure by Design is not a badge
At Nexor, with more than thirty years’ experience in building secure architectures for cross domain solutions, we know that security must be designed from first principles.
Every solution starts with a series of fundamental questions:
What is the threat?
What is the organisation’s risk appetite?
What posture is required according to NCSC patterns?
The architecture is designed to compartmentalise, enforce business rules, prevent unauthorised transfer, block malware ingress and data exfiltration, and provide logging that not only detects and alerts to suspicious activity but also contains it, while the component hardware and software are chosen to meet both the security and business needs of the customer, because we don’t just advise, we deliver
This is what SbD means in practice, not a badge, but an outcome-driven mindset.
Enforcement and accountability
The situation is worsened by a lack of enforcement. Over half of all ransomware victims pay up, according to a survey by Cohesity in its Global cyber resilience report 2024. Those who refuse risk severe disruption or collapse, as happened to haulage firm Knights of Old. In the UK, paying a ransom is not illegal, unlike in the US. Meanwhile, insurers and city firms may see ransomware insurance as good business, which reduces pressure for reform.
The victims of poor cyber resilience are rarely executives. They are shareholders who lose value - as Marks & Spencer’s investors did, with £300 million wiped off profits, or employees who lose their jobs, as at Knights of Old. That is not bad luck. It is the result of weak governance and preventable mistakes.
The Ministry of Defence, facing millions of hostile attempts each year, considers itself perpetually ‘in contact’ in the cyber domain, and has long recognised that breaches are inevitable. Its answer is defence in depth, education, compartmentalisation, and consequence management. By contrast, most of the industry has yet to adopt this approach.
Raising the bar
There are steps that could be taken. For example, requiring companies to report their cyber security posture in annual reports. Or introducing a graduated scale of assurance, ranging from “Bronze” Cyber Essentials through to “Platinum”, where systems are architected on NCSC patterns with guards and gateways like those used to protect data of national importance. That might sound expensive, but the alternative is often worse.
Enforcement must also extend to those in positions of responsibility. The charging of the SolarWinds CISO with fraud in 2023 was a wake-up call in the US. It forced boards to take cyber risk more seriously and required CISOs to ensure the board understood the stakes. A similar approach in the UK could drive better governance, whether that is greater personal accountability for directors or restrictions on future appointments where governance failures are proven.
Making security a way of life
The lesson from ransomware is simple: security is not something to claim, it is something to nurture and prove. Policies and frameworks are only meaningful when they are adopted, enforced and embedded.
At Nexor, we believe Secure by Design is not a badge; it is a way of life. By enforcing business rules, compartmentalising architectures, and adopting approved security patterns, organisations can build resilience that reduces the impact of inevitable attacks.
Until the UK closes the gap between policy, practice, and enforcement, ransomware will remain a profitable enterprise for attackers and a costly one for victims.