Avoiding DIY pitfalls and lessons from recent ICO fines and cyber attacks
Imagine stepping into a courtroom as your own defence lawyer. The stakes are high, the pressure is palpable, and you are armed with nothing more than borrowed law books and an unwavering belief that you can "figure things out." You begin your argument, hoping that your cobbled-together knowledge from late-night research can withstand the scrutiny of seasoned lawyers and a no-nonsense judge. But with every question, the gaps in your understanding become painfully clear. Mistakes you never saw coming. Vulnerabilities that could have been avoided with expert guidance. Before long, your defence crumbles, and the verdict is delivered. Your DIY approach has cost you more than you ever anticipated.
This courtroom analogy is a stark reminder of the hidden dangers of attempting Secure by Design without expert oversight. While keeping security in-house may seem appealing, especially when cost-saving measures are at the top of most organisations' minds, the reality is far more complex and riskier than most organisations anticipate. Just like defending yourself in court, cybersecurity demands specialised expertise, the ability to foresee potential threats, and the foresight to implement resilience before attacks strike. Without these skills, businesses expose themselves to breaches, regulatory fines, and severe reputational damage.
Lessons from recent ICO fines and cyber-attacks demonstrate the consequences of neglecting Secure by Design. Advanced Computer Software Group Ltd faced a £3.07 million fine in March 2024 following a ransomware attack that exposed sensitive information belonging to over 79,000 individuals and disrupted NHS 111 services. The ICO investigation revealed basic security failures, including the absence of multi-factor authentication, poor vulnerability management, and inadequate patching. A Secure by Design approach could have prevented these weaknesses. Similarly, DPP Law Ltd was fined £60,000 in April 2025 after a cyber-attack resulted in the theft of highly sensitive legal information. Their failure to secure administrator accounts with multi-factor authentication exposed critical data, highlighting the need for fundamental security measures.
The M&S Scattered Spider attack in April 2025 further underscores the risks of inadequate security planning. Attackers exploited privileged account compromises and multi-factor authentication fatigue tactics to infiltrate critical systems. While M&S's response has been commendable, the absence of Secure by Design principles such as Zero Trust architecture, strong identity verification, and micro-segmentation allowed the attackers greater access than necessary. Had these security strategies been embedded from the outset, the adversary would have faced significant resistance.
Secure by Design is not just a framework. It is a mindset that prioritises security at every stage of development and operation. It integrates threat modelling, rigorous access controls, continuous security testing, and best practices tailored to an organisation's unique risk landscape. Implementing these measures proactively saves organisations from the financial, reputational, and operational devastation that follows security failures. Secure by Design consultants function as seasoned defence lawyers, bringing years of specialised knowledge to anticipate challenges and build a security posture that withstands scrutiny from regulators, cybercriminals, and industry compliance bodies. When a breach occurs, organisations must justify their security choices, and those that relied on DIY strategies instead of expert-led Secure by Design approaches will struggle to mitigate the fallout.
A failure to implement Secure by Design does not just expose vulnerabilities, it can completely derail a business-critical programme. Imagine spending months or even years developing a project, investing substantial resources, only to discover security flaws that make it unfit for deployment. The financial toll is immediate, from remediation costs and regulatory penalties to reputational damage and lost revenue. Customer trust deteriorates, investor confidence falters, and operational disruptions consume bandwidth that should be dedicated to innovation rather than recovering from failure.
At Nexor, cyber security is not just a compliance requirement. It is the foundation of operational success and resilience. Organisations must be prepared to win day one of the war against cyber threats, not react after the damage is done. If your Secure by Design programme feels more like a DIY effort than the work of seasoned security practitioners, reach out to us. Whether you need an initial discussion to share lessons learned or Nexor leading your Secure by Design initiatives with an outcome-driven approach, we are ready to support you. Investing in expertise today ensures your business is secure, trusted, and ready for the future.