Preventing Malware and Ransomware Attacks in Your Business
Malware and ransomware prevention requires overlapping layers of technical controls — no single tool provides complete protection. This guide covers the attack pathways attackers use, the controls that block each pathway and the backup and response practices that limit damage when prevention fails.
Nathan Hill-Haimes
Technical Director
*Nathan Hill-Haimes, Technical Director · 10 min read · Updated June 2026*
How do malware and ransomware get into a business network?
Most incidents trace back to a handful of entry points, not exotic zero-days. Phishing email, unpatched internet-facing systems and stolen credentials account for the overwhelming majority of malware and ransomware affecting UK SMEs. Knowing the pathways tells you where to spend your defensive effort first.
Phishing remains the single most common breach type identified by UK businesses, according to the government's Cyber Security Breaches Survey 2025. The routes attackers actually use:
- Phishing emails — malicious links or attachments that socially engineer a user into clicking, downloading, or entering credentials on a fake login page. Still the most common delivery mechanism.
- Unpatched vulnerabilities — VPN appliances, remote desktop (RDP), Exchange and other internet-facing systems with known flaws are scanned and exploited within days of public disclosure.
- Compromised credentials — stolen logins (from phishing, breach dumps or brute-forcing weak passwords) used against VPN, RDP or Microsoft 365 give direct access with no malware needed.
- Drive-by downloads — visiting a compromised or malicious website installs malware, especially on unpatched browsers or legacy systems running Java or Flash.
- USB and removable media — less common in offices, but still relevant in manufacturing and industrial settings.
The NCSC's guidance on mitigating malware and ransomware maps controls to each of these pathways. The sections below follow the same logic.
How do you reduce the attack surface attackers can reach?
The first layer shrinks what an attacker can even touch before exploitation is possible. You patch fast, take remote access off the public internet, filter email, and block malicious domains at the DNS level. Each control removes a category of opportunity rather than waiting to catch an attack in progress.
- Patch management — apply critical and high-severity patches within 14 days, prioritising internet-facing systems, VPN appliances and remote access. Automated tooling (Windows Update for Business, RMM agents) keeps the workload manageable.
- Disable unnecessary services — RDP should never face the internet directly. If remote desktop is needed, expose it only through VPN or Zero Trust network access, never a public port. Audit internet-facing services regularly.
- Email filtering — anti-spam, sandboxed attachment detonation and time-of-click URL scanning cut the volume of malicious content reaching inboxes. This is core to AMVIA's phishing protection approach.
- DNS filtering — block connections to known-bad domains so malware that lands on a device cannot call home or pull down a second-stage payload.
Why is endpoint detection and response the core control?
When something bypasses email and network filters, the endpoint is where you catch it. Endpoint detection and response (EDR) watches behaviour rather than signatures — flagging ransomware-style file encryption, process injection and living-off-the-land techniques even when the specific malware is brand new and unknown to any antivirus database.
| Capability | Traditional antivirus | Endpoint detection & response (EDR) |
|---|---|---|
| Detection method | Known signatures | Behavioural analysis |
| Catches novel/unknown malware | No | Yes |
| Automated isolation of a host | Rare | Standard |
| Forensic timeline of an attack | No | Yes |
| Value without monitoring | Limited | Limited — alerts must be actioned |
EDR technology on its own is not enough. Alerts that sit unreviewed never turn into containment, and ransomware commonly detonates overnight and at weekends. That is why AMVIA delivers endpoint detection and response as a monitored service — Microsoft Defender for Endpoint watched by an in-house 24/7 SOC, so detections are acted on around the clock.
How do identity and access controls stop the spread?
Many infections spread by credential, not by malware file. An attacker who lands on one machine steals credentials and reuses them to move laterally. Tightening identity controls — MFA, least privilege and protected admin accounts — denies that lateral movement and contains the blast radius of any single compromise.
- MFA on every account — stops compromised credentials from authenticating to cloud services or VPN. Non-negotiable for Microsoft 365.
- Least privilege — users should not hold local administrator rights unless their role genuinely requires it. Local admin is what most malware needs to install and persist.
- Privileged access workstations — IT admins should run privileged tasks from a dedicated, hardened device, not a general-purpose laptop that also reads email.
- Credential Guard — Windows Defender Credential Guard protects credential material in memory, blunting the harvesting tools used for lateral movement.
These controls layer directly onto a hardened Microsoft tenant. See AMVIA's wider managed detection and response service for how identity signals feed the same monitoring pipeline.
How do backups decide whether ransomware costs you everything?
Backups do not prevent infection — they decide whether an infection becomes a catastrophe. If you can restore clean data quickly, ransom pressure evaporates. The 3-2-1 rule is the floor: three copies, on two media types, with one copy offline or immutable so ransomware cannot reach it.
What makes a backup genuinely ransomware-resilient:
- Immutable or offline copies — cloud backup with object lock, or offline media, cannot be encrypted by an attacker who reaches your live environment.
- Separate credentials — backup systems must not share admin accounts with production. A compromised domain admin should not also be able to delete your backups.
- Tested restores — most failed backups are discovered during a live incident. Test restoration on a schedule, not in a crisis.
- Microsoft 365 is not backed up by Microsoft — Microsoft provides data-centre resilience, not a backup service. A third-party Microsoft 365 backup for Exchange, SharePoint and OneDrive is necessary, as Microsoft's own shared responsibility documentation makes clear.
What should you do when prevention fails?
No stack is 100% effective, so rehearse the response. When malware is confirmed, the priority order is isolate, contain, preserve, communicate, recover — in that sequence. Acting in the wrong order, especially reimaging a machine before evidence is captured, destroys the information you need to understand the breach.
1. Isolate — disconnect the affected device immediately: WiFi, Ethernet and any VPN. This limits lateral spread. 2. Contain — identify other affected devices through EDR telemetry or network traffic analysis. 3. Preserve — do not reimage before forensic evidence is collected; it determines how the attacker got in. 4. Communicate — notify your IT or MDR provider, your cyber insurer, and — if personal data may be affected — begin the GDPR breach assessment with the ICO. 5. Recover — restore from clean backups once the initial vector and scope are understood.
Reduce your ransomware exposure before an attacker finds the gap
Most breaches exploit a control you already meant to fix. AMVIA reviews your current malware and ransomware defences — email filtering, patching, EDR, identity and backups — and returns a prioritised remediation plan that closes the gaps most likely to be exploited.
One provider. Security-first. Microsoft-certified. Start with a free, no-obligation review: book your free security audit.
Related Reading
How Many Prevention Layers Do You Have in Place?
AMVIA can assess your current malware and ransomware prevention controls and identify the gaps most likely to be exploited — providing a prioritised remediation plan.
Frequently Asked Questions
There is no single most important control — ransomware prevention needs overlapping layers. If forced to prioritise, the combination of MFA (blocks credential-based access), fast patching (removes known exploitation routes) and managed EDR (detects what bypasses preventive controls) delivers the biggest risk reduction for most UK SMEs. Ransomware affecting UK businesses roughly doubled through 2025 (DSIT Cyber Security Breaches Survey 2025), which is why detection matters as much as prevention.
The NCSC and UK law enforcement recommend against paying. Payment does not guarantee recovery — many victims pay and receive non-functional decryptors — it funds criminal groups and marks you as a soft target for repeat attacks. The case against paying is strongest when you hold clean offline backups. Recovery costs land on you whether or not you pay: the government's Cyber Security Breaches Survey 2025 put the average cost of the most disruptive breach at £3,550 for UK businesses reporting a financial outcome, covering downtime, lost business and repairs.
Once detonated, modern ransomware can encrypt files across a network in 30 minutes to a few hours. The earlier access-to-detonation period is usually far longer — attackers often spend days or weeks establishing persistence and exfiltrating data first. That dwell time is your window to detect and contain before the damaging encryption phase, which is why 24/7 monitoring is decisive.
Microsoft provides data-centre resilience, not a backup service. It does not guarantee recovery beyond standard retention windows (typically 90 days for deleted items) and does not protect against an attacker who encrypts OneDrive files or mass-deletes SharePoint content with stolen credentials. A third-party Microsoft 365 backup is necessary for full data protection.
A drive-by download installs malware simply because a user visited a malicious or compromised website — no clicking required beyond loading the page. Prevent it by keeping browsers and extensions fully patched, using DNS or content filtering to block known-bad domains, and running EDR that flags suspicious processes spawned from the browser.
Cyber Essentials covers the five technical controls most relevant to malware: firewalls, secure configuration, user access control, malware protection and patch management. It is a strong baseline rather than a complete defence — it does not include 24/7 detection or backup resilience. AMVIA holds Cyber Essentials Plus and builds detection and recovery on top of that baseline.
Related Reading
What Is Ransomware? | Plain English Guide for Business
How ransomware works, real UK examples and the full picture of what a ransomware incident involves.
Ransomware Protection for UK Businesses | AMVIA Guide
Backups, endpoint security, email filtering and response planning for ransomware protection.
Phishing Protection for UK Businesses | AMVIA Guide
Phishing controls that address the most common initial access vector for malware and ransomware.
Protect your business → Get Cybersecurity Assessment