TL;DR:

  • The NCSC and DSIT have launched a “Lock the Door” cyber campaign targeting UK SMEs, backed by new free toolkits and guidance specifically written for small business owners rather than IT professionals
  • Ransomware has doubled since 2024 and is now the NCSC’s top-rated threat to UK businesses, with AI-generated phishing making credential theft faster and more convincing
  • The five things the campaign prioritises — software updates, strong authentication, backups, staff awareness, and knowing who to call — are unglamorous but genuinely effective

There’s a particular type of government cyber campaign that looks good in a press release and achieves nothing. Then there’s the kind that’s actually grounded in what attackers are doing and what small businesses can realistically act on with no dedicated IT budget. The NCSC’s “Lock the Door” campaign, launched in coordination with DSIT, lands closer to the second category.

The name is intentional. The NCSC’s messaging throughout the campaign uses the physical security analogy explicitly: you wouldn’t leave your shop with the door unlocked, the alarm off, and your cash till visible from the window. Most small businesses are doing exactly this equivalent digitally, and a lot of the attacks succeeding against UK SMEs aren’t sophisticated — they’re opportunistic. An unlocked digital door is enough.

What the Campaign Is Actually Saying

The toolkit the NCSC released alongside the campaign isn’t new guidance, exactly — it builds on the Cyber Aware and Small Business Guide material they’ve published for years. What’s new is the framing and the targeting. The content is now written explicitly for a business owner without an IT background, not for a security professional. That sounds obvious, but most official guidance reads like it was written for the latter and politely hoped the former would figure it out.

The five areas the campaign focuses on are:

Keep software up to date. This is still the most impactful single control for most small businesses. The vast majority of successful ransomware intrusions exploit known vulnerabilities with available patches that weren’t applied. Automatic updates on Windows, macOS, and iOS resolve most of this without requiring any active effort. The campaign points specifically to enabling auto-updates on devices, browsers, and applications — and checking that your router firmware is also up to date, which many businesses forget.

Use strong, unique passwords with multi-factor authentication. The campaign doesn’t recommend specific password managers, but it does endorse the use of any password manager over remembered passwords or reused passwords. MFA is framed as non-negotiable for email, banking, and any cloud service. Microsoft and Google both provide free MFA via their authenticator apps for business accounts.

Back up your data. The emphasis here is on the 3-2-1 rule — three copies, on two different media, with one offsite or in the cloud — and on testing that the backup actually restores. A backup that exists but has never been tested is common and useless in a real incident.

Stay alert to phishing. The campaign acknowledges that AI-generated phishing has made the “look for spelling mistakes” heuristic almost useless. Attackers are now generating convincing, personalised spear-phishing emails at scale with no grammatical tells. The practical advice shifts towards scepticism about unexpected requests rather than grammar-checking — verify unusual payment requests or login prompts through a separate channel, not by clicking the link in the email.

Know where to turn. This is the part that often gets left out of security guidance. The campaign specifically directs small businesses to Action Fraud (0300 123 2040) for reporting incidents, NCSC’s online incident reporting for cyber attacks, and Cyber Incident Response providers listed on the NCSC’s website. Knowing this before an incident happens is genuinely valuable — after a ransomware attack is not the time to be googling “what do I do.”

What AI-Powered Attacks Mean in Practice

The NCSC’s threat intelligence is clear that AI tools are now used extensively in attack campaigns. This isn’t AI creating novel attacks — it’s AI accelerating the commodity ones. Voice cloning allows vishing calls from a number you recognise, speaking in a voice that sounds like someone you know, asking you to transfer money or reset a password. Email generation at scale means the same convincing message can reach 10,000 targets in the time it previously took to write one manually.

The defence against this isn’t better phishing filters, though those help at the margins. It’s process: out-of-band verification for financial requests, call-back procedures using numbers you look up rather than numbers the caller provides, and scepticism as a learned habit rather than a technical control.

Taking This Seriously Without Spending Much

To be honest, the most valuable thing most small businesses can do after reading this isn’t to buy a security product. It’s to spend two hours working through the NCSC’s free Cyber Action Plan (available at ncsc.gov.uk), enable MFA on your Microsoft 365 or Google Workspace account today, and make sure you know what your backup situation actually looks like — not what you think it looks like.

The NCSC estimates that roughly 42% of UK small businesses experienced a cyber attack or breach in the past year. That number would drop significantly if every business on that list had MFA, patched software, and a tested backup. The “Lock the Door” framing is right: most of the problem is an unlocked door, not a technically sophisticated attacker.