Ransomware shows the cost of weak cyber policy and poor enforcement

Author: Guy Bewsher

03 Sep 2025

It should come as no surprise that the UK is second only to the US in terms of ransomware victims. Nor is it unexpected that the National Cyber Security Strategy has lost its way. The problem is not a lack of policy; it is a lack of practice and enforcement. As the RUSI report says, criminals and state actors are still able to rely on the same tactics they used when ransomware began to surge in 2019. That is because the fundamentals of our preparedness and behaviours have not changed.  

The gap between policy and reality 

Government policy sets a low bar. Cyber Essentials, while well-intentioned, often becomes a tick-box exercise. And with few controls over who can call themselves a “cyber security consultant”, many organisations receive advice that is superficial at best. Even when given sound advice, organisations are often slow to follow through with recommended remediations.  

Initiatives such as Secure by Design (SbD) and Zero Trust Architecture (ZTA) are welcome steps forward, but only on paper. SbD tells you what  to trust; ZTA tells you how  to trust. Yet neither has real enforcement. A supplier can claim to apply these approaches, but how does a customer know that is true? Even large primes admit to “re-badging” staff as SbD experts when clients demand it. Without a clear definition of expertise, the value of the label diminishes and without consistent standards and implementation, the overall initiative is weakened. 

Secure by Design is not a badge 

At Nexor, with more than thirty years’ experience in building secure architectures for cross domain solutions, we know that security must be designed from first principles. 

Every solution starts with a series of fundamental questions: 

  • What is the threat? 

  • What is the organisation’s risk appetite? 

  • What posture is required according to NCSC patterns? 

The architecture is designed to compartmentalise, enforce business rules, prevent unauthorised transfer, block malware ingress and data exfiltration, and provide logging that not only detects and alerts to suspicious activity but also contains it, while the component hardware and software are chosen to meet both the security and business needs of the customer, because we don’t just advise, we deliver 

This is what SbD means in practice, not a badge, but an outcome-driven mindset. 

Enforcement and accountability 

The situation is worsened by a lack of enforcement. Over half of all ransomware victims pay up, according to a survey by Cohesity in its Global cyber resilience report 2024. Those who refuse risk severe disruption or collapse, as happened to haulage firm Knights of Old. In the UK, paying a ransom is not illegal, unlike in the US. Meanwhile, insurers and city firms may see ransomware insurance as good business, which reduces pressure for reform. 

The victims of poor cyber resilience are rarely executives. They are shareholders who lose value - as Marks & Spencer’s investors did, with £300 million wiped off profits, or employees who lose their jobs, as at Knights of Old. That is not bad luck. It is the result of weak governance and preventable mistakes. 

The Ministry of Defence, facing millions of hostile attempts each year, considers itself perpetually ‘in contact’ in the cyber domain, and has long recognised that breaches are inevitable. Its answer is defence in depth, education, compartmentalisation, and consequence management. By contrast, most of the industry has yet to adopt this approach. 

Raising the bar 

There are steps that could be taken. For example, requiring companies to report their cyber security posture in annual reports. Or introducing a graduated scale of assurance, ranging from “Bronze” Cyber Essentials through to “Platinum”, where systems are architected on NCSC patterns with guards and gateways like those used to protect data of national importance. That might sound expensive, but the alternative is often worse. 

Enforcement must also extend to those in positions of responsibility. The charging of the SolarWinds CISO with fraud in 2023 was a wake-up call in the US. It forced boards to take cyber risk more seriously and required CISOs to ensure the board understood the stakes. A similar approach in the UK could drive better governance, whether that is greater personal accountability for directors or restrictions on future appointments where governance failures are proven. 

Making security a way of life 

The lesson from ransomware is simple: security is not something to claim, it is something to nurture and prove. Policies and frameworks are only meaningful when they are adopted, enforced and embedded.

At Nexor, we believe Secure by Design is not a badge; it is a way of life. By enforcing business rules, compartmentalising architectures, and adopting approved security patterns, organisations can build resilience that reduces the impact of inevitable attacks. 

Until the UK closes the gap between policy, practice, and enforcement, ransomware will remain a profitable enterprise for attackers and a costly one for victims. 

Read more posts on

About the author

Guy Bewsher has been at the forefront of technological innovation, combining deep expertise with a forward-thinking approach. In 1996, he worked as a contractor for DERA, exploring the potential of synthetic environments; now known as AI; to streamline and enhance military decision-making processes. This research contributed to advancements like the Single Information Environment (SInfoE) MVP, driven by Dstl’s SIE and Comms and Nets programs. Through a series of four blogs, Guy will delve into the impact of AI on the battlespace and explain how the SInfoE is central to achieving the Integrated Force vision.

Guy Bewsher on Linkedin

Read more posts by Guy Bewsher