The UK government has launched a new cybersecurity campaign urging businesses to “lock the door” against online criminals. The message is simple: too many organisations still haven’t put even basic protections in place.
According to the latest Cyber Security Longitudinal Survey, 82% of businesses and 77% of charities reported experiencing some form of cyber incident in the past year. In other words, digital break-ins are no longer rare events. They’re routine.
Yet only 30% of businesses and 28% of charities currently hold the government-backed Cyber Essentials certification.
That gap is exactly what the new campaign is trying to close. Because when organisations fail to lock their digital doors, it is your personal data sitting behind them.
When cyber risk becomes normalised
The survey paints a concerning picture. More than half of organisations (54%) report similar incidents across multiple years. That suggests many businesses are not learning from attacks or investing in stronger defences.
Cybersecurity minister Baroness Lloyd has warned that criminals are looking for easy opportunities such as:
- Unpatched software
- Weak passwords
- Poor access controls
- Outdated systems.
In real terms that means personal data left exposed — often through entirely preventable failures.
Why this campaign should matter to consumers
The government’s campaign focuses on businesses adopting Cyber Essentials, a certification scheme designed to protect organisations against the most common cyber threats, backed by practical support from the National Cyber Security Centre.
None of this is cutting-edge. It is basic digital housekeeping.
The fact that seven in ten organisations still do not follow it should worry everyone.
Over the past few years, we have seen repeated examples of large-scale breaches affecting millions of people. These data breaches are rarely caused by sophisticated Hollywood-style hacks. More often, they stem from simple, preventable failures. And when organisations cut corners, it is ordinary people who deal with the fallout.
Anxiety. Fraud risk. Endless password resets. Hours on the phone to banks.
Our digital ID pledge
As more of our personal information is stored and shared digitally, one basic question becomes unavoidable: Are the systems holding that data genuinely secure?
If a significant number of organisations are still experiencing incidents each year, and most are not meeting even baseline standards, trust cannot simply be assumed.
At Join the Claim, we support the Government’s latest campaign. But we’re also calling on every organisation that uses digital identity data — public or private — to back a five-point pledge that puts protection, transparency and accountability first.
That means:
- Full transparency over where data is stored
- Immediate and full disclosure of any breach attempts
- Independent annual audits of system security and resilience
- Strict limits on data sharing, including a total ban on commercial profiling
- Clear accountability for any organisation handling Digital ID data.
Because digital security should not be optional. And neither should accountability.
To stand with us and call for tougher protections, share your support using #ProtectOurDigitalID.
Has your data been breached?
If your data has been exposed because an organisation failed to implement basic protections, you have legal rights.
Explore current data breach claims and wider consumer actions on our website, and register your interest if you believe you have been affected.
Join the Claim connects consumers with SRA-regulated lawyers. Keep an eye out for updates on any potential claim and possible eligibility checks/registration opportunities.