Ransomware Protection for UK Businesses: A Practical Guide
Ransomware remains the most damaging cyber threat facing UK SMEs. This practical guide covers the controls that matter most — offline backups, endpoint protection, email filtering, access management — the response steps that limit damage when ransomware does detonate.
AMVIA Team
Editorial
This guide covers the controls that matter most, the way ransomware really gets in, and the response steps that limit damage when an attack does land. If you want a single accountable provider managing the lot, start with our managed cybersecurity service.
How big is the ransomware threat to UK businesses?
Ransomware is the most damaging cyber threat facing UK SMEs, and it is not slowing down. The National Cyber Security Centre managed 20 ransomware incidents in 2024, 13 of which were classified as nationally significant — up from 10 the year before. Small businesses are squarely in scope, not collateral.
The "we're too small to be a target" assumption is demonstrably false. Ransomware groups run a Ransomware-as-a-Service (RaaS) model: affiliates use automated tooling to scan for vulnerable systems and deploy payloads at scale, hitting businesses of every size. SMEs are attractive precisely because they typically have less defensive capability than large enterprises while still holding valuable, ransomable data.
- In 2024, 39% of UK businesses identified a cyber attack (DSIT Cyber Security Breaches Survey), with ransomware behind a large share of the most costly incidents
- The average UK data breach cost reached £3.58 million in 2024
- For ransomware specifically, recovery costs — forensics, remediation, downtime, regulatory exposure — frequently exceed that figure
The escalation in incidents handled at national level is documented in the NCSC Annual Review, and the wider business attack rate is tracked in the government's Cyber Security Breaches Survey.
How does ransomware get into your business?
Ransomware infections follow predictable patterns. The three most common initial access routes for UK SME incidents are phishing, exploitation of unpatched internet-facing systems, and the use of stolen credentials. Understanding these three narrows where your prevention budget should actually go.
- Phishing emails: malicious attachments or links that deliver the initial payload or harvest credentials for later access. Cut this off with managed phishing protection.
- Unpatched internet-facing systems: VPN appliances, Remote Desktop Protocol (RDP), Microsoft Exchange and edge devices carrying unpatched critical vulnerabilities.
- Compromised credentials: logins stolen via phishing or pulled from breach data, then replayed against VPN, RDP or cloud services.
The takeaway is blunt: prioritise patch management for anything internet-facing, email security on every inbox, and MFA on every remote access method. The NCSC's ransomware guidance reinforces this same short list.
Which five controls cut ransomware risk the most?
Five controls do most of the heavy lifting. None of them are exotic, and together they break the chain at every stage — initial access, execution, encryption and recovery. This is the baseline AMVIA deploys for clients, not a wishlist.
| Control | What it stops | Why it matters |
|---|---|---|
| Offline / immutable backups | Loss of data leverage | Clean restore removes ransom pressure |
| Endpoint detection & response (EDR) | Execution and encryption | Auto-isolates devices in seconds |
| Email security | Phishing-borne access | Filters most malicious content before delivery |
| MFA on all accounts | Credential replay | Blocks the vast majority of automated logins |
| Patch management | Exploitation of edge systems | Closes internet-facing vulnerabilities fast |
1. Offline and immutable backups
If ransomware encrypts your data, a clean backup is the difference between a straightforward recovery and a ransom negotiation. Modern ransomware actively hunts backups — deleting shadow copies and encrypting any connected backup drive. Backups must be offline or air-gapped (tape, object storage with object lock, air-gapped replication), tested at least quarterly, and protected with credentials separate from your Active Directory domain.
Microsoft 365 data needs its own backup too. Exchange, SharePoint and OneDrive resilience does not protect you against account-level deletion or encryption — that is what dedicated Microsoft 365 backup is for.
2. Endpoint detection and response (EDR)
EDR detects ransomware behaviour — mass file encryption, shadow copy deletion, anomalous process activity — and can kill processes and isolate devices automatically, often before encryption completes. Consumer antivirus cannot do this. AMVIA delivers this through endpoint detection and response built on Microsoft Defender for Endpoint, monitored by our in-house 24/7 SOC.
3. Email security
Anti-phishing filtering — Safe Attachments, Safe Links and impersonation detection — strips most malicious content before it reaches a user. DMARC, DKIM and SPF block domain spoofing. Because most ransomware starts in the inbox, email security is one of the highest-yield controls you can deploy.
4. MFA on all accounts and remote access
MFA stops compromised credentials being replayed against VPN, RDP or cloud services. It is the single highest-impact control against credential-based access — Microsoft's telemetry shows MFA blocks over 99.99% of automated credential attacks. Get it deployed across every account with MFA for Microsoft 365. Microsoft documents the underlying numbers across its security research.
5. Patch management
Apply critical and high-severity patches within 14 days — the NCSC baseline that also underpins Cyber Essentials. Prioritise internet-facing systems: VPN appliances, Exchange, web-facing applications and remote access infrastructure. Automated patching removes the operational drag and stops fixes slipping indefinitely.
What should you do in the first 60 minutes of a ransomware attack?
If ransomware detonates, the first hour decides the scope of the damage. Move in a fixed order: contain the spread, preserve evidence, get expert help, and protect your legal and insurance position before you make any payment decision. Speed of containment matters more than anything else.
1. Isolate immediately: disconnect affected machines — pull Ethernet, kill WiFi, drop VPN. Stop the spread before you investigate. 2. Do not reimage: preserve forensic evidence so you understand how the attackers got in before you rebuild and re-expose the same hole. 3. Engage incident response: call your IT partner or MDR provider. AMVIA's managed detection and response clients have a dedicated 24/7 emergency contact for exactly this. 4. Notify your cyber insurer: most policies require prompt notification; delay can affect coverage. 5. Assess GDPR obligations: if personal data was encrypted or exfiltrated, start the 72-hour ICO breach notification assessment. 6. Do not pay immediately: understand the scope first, and involve law enforcement and legal counsel before any payment decision.
A rehearsed plan beats an improvised one every time. Building one with us is part of structured incident response.
Could Your Business Recover From a Ransomware Attack Today?
AMVIA can assess your current ransomware defences and backup resilience — giving you a clear answer to that question, and a plan to address any gaps.
Frequently Asked Questions
Yes. Ransomware-as-a-Service has industrialised attacks — affiliates use automated tools to scan for vulnerable systems and deploy ransomware at scale, hitting businesses of every size. Small firms are attractive because they typically have weaker defences than large enterprises while still holding valuable data. NCSC data consistently shows SMEs make up a significant share of UK ransomware victims.
Costs vary enormously with the scope of encryption, downtime, recovery capability and whether data was stolen. The average UK data breach cost reached £3.58 million in 2024, and for SMEs, significant incidents commonly run £50,000–£500,000 (typical UK 2026 range) once forensics, IT recovery, business interruption and penalties are counted. Broader industry estimates (market rates as of 2026) put average recovery — excluding the ransom — at around $2.58 million for larger incidents. Firms with tested offline backups consistently spend far less.
Double extortion means attackers both encrypt your data and exfiltrate a copy first, then threaten to publish it on a leak site unless you pay. That pressures even organisations with clean backups, because refusing to pay still risks sensitive data being leaked. Preventing exfiltration needs EDR and network monitoring that can detect unusual large outbound transfers before the data leaves.
It is worth having, but not as a substitute for prevention. Insurance covers incident response, business interruption and third-party liability, and sometimes ransom payment subject to conditions. Premiums have risen and insurers increasingly require evidence of baseline controls — MFA and tested backups — as a condition of cover, so good security lowers both your risk and your premium.
No. Offline, immutable backups are the single most important recovery control, but they only help after an attack and do nothing against double extortion, where stolen data is leaked regardless. Backups must sit alongside EDR, email security, MFA and patching so the attack is more likely to fail before encryption ever starts.
Modern EDR responds in seconds. It detects ransomware behaviour — mass file encryption, shadow copy deletion, anomalous processes — and can terminate the process and isolate the device automatically, often before encryption completes. With a 24/7 SOC watching, suspicious activity is investigated and contained around the clock rather than waiting for someone to notice in the morning.
Related Reading
What Is Ransomware? | Plain English Guide for Business
How ransomware works, how attacks unfold and what the consequences look like for affected businesses.
Preventing Malware & Ransomware Attacks | Business Guide
The attack pathways attackers use and the prevention controls that block each one.
Ransomware Protection | Safeguarding Business in 2025
The evolving ransomware threat landscape in 2025 and how managed security protects UK businesses.
Protect your business → Get Cybersecurity Assessment