Skip to main content

There is a question I have started asking people about contactless security, and the answer usually tells me more than any statistic: what would have to happen before you protected the contactless cards and credentials you carry?

Would it take an unexplained payment? A card clash at a station gate? A lost phone containing your digital wallet and your physical backup card? Or an unshielded backup card carried in the back of the phone cover exposed to accidental payment or eSkimming while you still have the phone? Or would even one of those events be dismissed as an inconvenience rather than a reason to change a habit?

Contactless payment is no longer a niche behaviour. UK Finance says 19.2 billion contactless debit and credit card payments were made in the UK in 2025, worth £311 billion. It also says the average contactless payment was just under £18. [1] When a technology becomes that normal, we stop noticing the technology and concentrate on the task: getting through the barrier, paying for coffee, checking into a hotel or entering a building.

That is a success story. It also creates a blind spot. Familiarity can become a substitute for understanding. We may know how to tap, but not which card is responding, when a reader is active, what happens when more than one credential is presented, or what remains exposed while our cards sit unused in a pocket, bag or phone case.

I am not arguing that everyone should be frightened of contactless. That would be irresponsible. UK Finance describes the fraud rate on contactless cards as very low and confirms that customers retain protection against unauthorised fraud. [1] A trustworthy conversation has to include that fact.

But a refund is not the same thing as prevention. Nor does a low statistical risk mean that every avoidable disruption is irrelevant. Replacing a card, checking transactions, disputing a fare or losing both a phone and the backup carried with it all consume time and attention. Personal security is often less about expecting disaster and more about removing unnecessary points of failure.

My own view is that contactless apathy is rarely stupidity. It is usually the result of three beliefs: “it probably will not happen to me”, “my bank will sort it out”, and “protection sounds inconvenient”. Those beliefs deserve to be discussed honestly, because the third one can now be challenged. Physical shielding can be built into the things we already carry.

At Blocktek, we think of this as the physical edge of cyber safety. Our approach is a Cyber Safety Toolkit: use the right shielded format for the credential and the situation, while keeping access simple when you intentionally want to tap. The purpose is not to make everyday life feel dangerous. It is to make protection an ordinary habit.

So I will return to the opening question. What would have to happen before you acted—and if protection created no extra daily effort, would you act before that event rather than after it?

Rob Rostron
Owner and Managing Director
Blocktek Ltd

Leave a Reply