Nothing Says “Secure Digital Future”, Like Another Data Breach

The UK government’s recent King’s Speech outlined plans to introduce a new digital identity framework designed to make accessing services easier, faster and more modern.

On paper, that sounds sensible enough.

Less paperwork. Less waiting around. Fewer passwords scribbled on post-its, or envelopes beside the router.

But there’s one tiny issue nobody seems keen to discuss:

The organisations responsible for managing the vast amounts of sensitive data, already struggle to protect the information they have now.

Which does raise the obvious question:

Should the people repeatedly locking their keys inside the car really be handed responsibility for the national key cabinet?

The dream vs the reality

The idea behind digital identity systems is straightforward.

One secure identity. One login. One trusted system. Access to services without constantly proving who you are.

In theory, it’s clean, efficient and modern.

In reality, many of the same organisations involved in handling sensitive data are still:

  • running legacy systems older than some interns
  • outsourcing critical infrastructure to the lowest bidder
  • treating cybersecurity as an annual compliance exercise
  • emailing spreadsheets around departments labelled “FINAL_v2_USE_THIS_ONE.xlsx”

And this is before we even mention the regular stream of:

  • ransomware attacks
  • leaked databases
  • phishing breaches
  • exposed customer records
  • “technical incidents”
  • systems mysteriously going offline on Friday afternoons

Apparently the future is digital. The error messages certainly are.

Confidence inspired by absolutely nothing

Every few months, another major organisation announces that customer information may have been “accessed by an unauthorised third party” – which is corporate language for:

“Someone has wandered off with the data and we’d appreciate everyone remaining calm.”

But come-on, “information may have been accessed by an unauthorised third party”, it either was accessed, or it was not – there is no “may have been”. I love it when folks in charge, attempt to bamboozle the public with nonsense.

Saying that, data breaches have become so common they barely register as news.

A million records exposed? Standard Tuesday.

A contractor accidentally leaving sensitive files unsecured? Classic Wednesday behaviour.

Entire systems unavailable because someone clicked a suspicious PDF attachment? Thursday again already?

At this point, modern cybersecurity often feels less like a highly coordinated defence strategy and more like trying to stop floodwater using a roll of kitchen towel and a strongly worded email.

The “state of the art” systems

One of the strange things about government technology projects is that they’re always described as:

  • cutting-edge
  • revolutionary
  • world-leading
  • transformational

Yet many users still experience the digital equivalent of trying to renew a passport using a fax machine connected to a microwave.

Anyone who has interacted with large public or enterprise systems knows the reality:

  • forgotten legacy software
  • temporary fixes that became permanent in 2014
  • password policies so complicated they actively encourage unsafe behaviour
  • departments using entirely different systems that refuse to speak to each other

Some infrastructure is held together with the IT equivalent of duct tape, hope and a single developer who left three years ago but still occasionally receives panicked phone calls.

And into this environment we’re introducing centralised digital identity systems tied to sensitive personal data.

What could possibly go wrong?

The problem isn’t digital identity

To be fair, digital identity itself is not the issue.

Most people already use digital systems daily:

  • banking apps
  • online payments
  • government portals
  • healthcare services
  • multi-factor authentication

The real issue is trust.

Because trust isn’t built through press releases, glossy launch videos or ministers using phrases like “world-class digital transformation”.

Trust is built through competence. And….. competence, is not something you can download during a procurement meeting.

Security theatre

Modern cybersecurity sometimes feels suspiciously similar to airport security.

Lots of procedures.
Lots of buzzwords.
Lots of expensive contracts.

Meanwhile, the danger often comes from:

  • weak passwords
  • unpatched systems
  • human error
  • rushed deployments
  • poor oversight
  • exhausted teams
  • and Dave from Accounts clicking “Enable Macros”, for the fifth time this month.

You can have the most advanced identity platform in the world, but if the surrounding systems are chaotic, outdated or poorly managed, the entire thing becomes a very expensive digital padlock attached to a shed with no walls.

A modest proposal

Perhaps before building massive interconnected identity systems, we should ensure:

  • existing systems are secure
  • organisations can manage data responsibly
  • infrastructure is modernised properly
  • cybersecurity is funded beyond the annual panic budget
  • and nobody is still storing critical information in spreadsheets called “new_final_REAL.xlsx”

I don’t know – just a thought.

Final thoughts

Digital identity will probably become part of everyday life eventually.

That’s not science fiction anymore.

But asking the public to trust large-scale identity systems while data breaches continue appearing with the regularity of weather forecasts is a difficult sell.

Technology isn’t really the problem. Trust is.

And trust is much harder to rebuild once someone’s left the national key cabinet open again.

To top