OneClickComply
    Back to BlogCyber Defense

    What the UK Government’s “Lock the Door” Cyber Campaign Means for Your Business

    Rutuja Tilekar
    25 February 2026

    Last week, the UK Government launched a major campaign urging businesses to “lock the door” on cyber criminals. Appearing across social media, podcasts and radio, the message is simple: cyber risk is now a core business risk, just like fire or theft, and basic cyber security is no longer optional.

    For many businesses, especially SMEs, that message makes sense in principle, but the next question is usually the same: what does “locking the door” actually look like in practice?

    The answer sits in the Government’s own Cyber Essentials scheme.


    So What is the “Lock the Door” Campaign?

    Launched by the Department for Science, Innovation and Technology (DSIT) and the National Cyber Security Centre (NCSC), this campaign is a direct response to the eye-watering £14.7 billion that cyber threats cost UK businesses annually. When speaking about the new campaign, Cyber Security Minister Baroness Lloyd warned that “no business is out of reach from cyber criminals…The reality is criminals look for easy opportunities, and without basic protections in place, any business of any size can become a target.”

    Recent data shows that 50% of small businesses have suffered some kind of breach or attack in the last 12 months, with a single significant cyber incident now costing businesses an average of £195,000. The majority of these attacks are not sophisticated, targeted operations, but rather crimes of opportunity, where attackers use automated tools to find businesses with basic weaknesses they can easily exploit.

    That is exactly why the campaign focuses on simple, foundational protections. It encourages businesses to improve their cyber hygiene and take action through Cyber Essentials, the UK Government-backed certification scheme for baseline cyber security.

    In other words, the campaign is not asking businesses to become cyber security experts overnight. It is encouraging them to put the basic protections in place that make them a much harder target.


    What is Cyber Essentials?

    Cyber Essentials is a government backed certification designed to protect your organisation against approximately 80% of common internet based threats. Think of it as a digital MOT - a verified checklist that ensures your ‘digital windows and doors’ are bolted shut.

    The scheme is built on five core pillars:

    • Firewalls: Firewalls act as a barrier between your business systems and the internet. They help block unauthorised access and reduce the chances of attackers reaching your devices and services.
    • Secure Configuration: Devices and software are not always secure by default. This area focuses on things like changing default passwords, removing unnecessary software, and turning off risky features that attackers often look for.
    • User Access Control: Not everyone in a business needs access to everything. This control helps ensure people only have access to the systems and data required for their role, which limits the impact if an account is compromised.
    • Malware Protection: This covers the measures used to prevent malicious software, such as ransomware, spyware and viruses, from running on your systems.
    • Security Update Management (patching): Attackers often exploit known vulnerabilities in outdated software. This control focuses on keeping systems and applications up to date so those weaknesses are addressed quickly.

    Why Businesses Should Take Cyber Essentials Seriously?

    Whether you are a two-person start-up or a corporation with thousands of employees, the logic is the same; if your business depends on digital systems, cyber security is not a nice-to-have.

    Cyber Essentials matters because it helps businesses put proven basics in place, rather than relying on point-in-time fixes after something goes wrong. It turns cyber security from an abstract idea into a manageable set of actions and requirements.

    It also brings wider business benefits beyond technical protection:

    • Builds trust: Cyber Essentials certification shows customers, partners and suppliers that you take cyber security seriously and have taken independent steps to put core protections in place.
    • Improves resilience: A significant cyber incident can interrupt operations, damage your reputation, and create costs that smaller businesses can struggle to absorb. Cyber Essentials helps reduce exposure to many common, preventable threats.
    • Supports commercial growth: Cyber Essentials is often required for certain public sector contracts and is increasingly recognised in procurement processes more widely. For some organisations, certification is not just a security decision, but a commercial one.
    • Can support insurance outcomes: Certified businesses may benefit from improved insurance outcomes, and eligible UK organisations can access free cyber insurance through the scheme.

    How OneClickComply Makes Cyber Essentials Simpler

    At OneClickComply, we know you want protection, not paperwork. Achieving Cyber Essentials standard doesn’t have to be a headache. We have recently streamlined our process to make it the easiest for users to achieve CE on the market.

    Our platform is designed to simplify the process from end to end:

    Unified Core Controls: Instead of working through a long list of disconnected checks and then trying to complete the Cyber Essentials questionnaire, OneClickComply helps you manage the process through a clearer, more structured set of controls and tasks inside the platform. Once completed, you can automatically generate a completed questionnaire that can be submitted to your assessor of choice.

    OneClickFix & AutoComplete: With our OneClickFix technology, eligible technical issues can be remediated directly through the platform, helping teams close gaps faster without unnecessary back-and-forth. And with our AutoComplete feature, policy and documentation tasks become far easier to manage, instantly generating content that matches your real-world setup, all in a single click.

    Automatic Evidence gathering: Without any human intervention, our platform automatically gathers the technical evidence required to prove implementation, so you are not manually chasing screenshots or trying to work backwards after making a change.

    The result is a Cyber Essentials process that is clearer, faster and far less stressful, especially for teams that do not have deep in-house cyber expertise. Rather than treating certification as a one-off paperwork exercise, OneClickComply helps you build the baseline properly and maintain confidence in it over time.


    Don’t Leave the Door Unlocked

    As the Government’s “Lock the Door” campaign gains visibility across the country, baseline cyber security will become an increasingly expected standard for UK businesses.

    This change is a positive one. Cyber Essentials is not about fear or box-ticking. It is about taking practical, proportionate steps to reduce common risks and protect the business you have worked hard to build.

    For customers, partners and suppliers, certification signals responsibility and trust. For your team, it creates a clearer foundation for secure day-to-day operations. And for your business as a whole, it strengthens resilience in a world where digital trust matters more than ever.

    If you are ready to make Cyber Essentials straightforward, OneClickComply can help you move from uncertainty to audit readiness with a simpler, more automated path to certification.


    Want to see OneClickComply in action?

    Book a demo and see how we automate compliance for organisations like yours.

    Book a Demo