What Is Ransomware? A Guide for UK Businesses
Ransomware is malicious software that encrypts your files and demands payment for the decryption key. It is the most financially damaging cyber threat facing UK businesses, with attacks increasing in frequency and sophistication year on year.
Quick answer
Ransomware is malicious software that encrypts your files and demands a payment — usually in cryptocurrency — in exchange for the decryption key. Modern strains add "double extortion": attackers steal your data before encrypting it, then threaten to leak it. For UK businesses, layered prevention is far cheaper than recovery, which is why AMVIA runs security-first managed cybersecurity.
How to Protect Your Business from Ransomware
Effective ransomware protection requires multiple layers working together.
Email Security
Phishing emails are the most common delivery mechanism for ransomware. Advanced email filtering and DMARC/SPF/DKIM authentication reduce the risk significantly.
Endpoint Detection (EDR)
EDR monitors device behaviour in real time, catching ransomware before it can encrypt files — even if the malware is brand new and unknown to signature-based tools.
Tested Backups
Immutable, air-gapped backups that are regularly tested are your last line of defence. If ransomware gets through, backups let you recover without paying.
Staff Awareness
Training staff to recognise phishing emails and suspicious links reduces the likelihood of ransomware gaining initial access.
Patch Management
Keeping software and operating systems updated closes the vulnerabilities that ransomware exploits to spread across networks.
24/7 Monitoring
Security Operations Centre monitoring detects ransomware activity in its early stages — before encryption begins — enabling rapid containment.
Ransomware Response: Pay vs Recover vs Prevent
The cost and outcome of different approaches to ransomware.
| Feature | Pay Ransom£50K–£500K+ | Recover (No Backup)£20K–£200K+ | Prevent (Managed)£15–£25/user/moRecommended |
|---|---|---|---|
| Data recovered | Maybe (no guarantee) | Partial | N/A (attack prevented) |
| Downtime | Days to weeks | Days to weeks | Minimal |
| Legal/regulatory risk | High | High | Low |
| Reputational damage | Significant | Significant | None |
| Funds future attacks |
Ransom amounts and recovery costs vary significantly based on business size and attack severity.
How does ransomware actually work?
Ransomware works in stages: it gains access, spreads quietly, then encrypts. Once inside a network it locates valuable files — documents, databases, backups — encrypts them with a key only the attacker holds, and drops a ransom note. Double-extortion strains exfiltrate that data first, so paying never guarantees it stays private.
The mechanics matter because they tell you where to break the chain. The earlier you detect the intrusion, the cheaper it is to stop. By the time files are being encrypted, you are already in incident-response territory rather than prevention. That is the entire argument for continuous monitoring through endpoint detection and response rather than relying on antivirus alone.
How does ransomware get into a UK business network?
The most common entry points are phishing emails with malicious attachments or links, exposed Remote Desktop Protocol (RDP) services, and unpatched software vulnerabilities. Phishing dominates: 85% of businesses that experienced a breach identified phishing as the attack vector (Cyber Security Breaches Survey 2025), which is why email is the single most important control to harden.
That makes email security your first line of defence. AMVIA combines Microsoft Defender with the Barracuda email suite to filter malicious attachments and links before they reach an inbox, backed by DMARC, SPF and DKIM authentication to block spoofing. According to the NCSC, keeping software patched and disabling unused remote-access services closes the other two main routes attackers use.
- Phishing emails — malicious links and attachments delivered to staff inboxes.
- Exposed RDP — internet-facing remote desktop with weak or reused passwords.
- Unpatched software — known vulnerabilities attackers scan for and exploit.
- Stolen credentials — reused passwords bought on criminal marketplaces.
How bad is the ransomware threat to UK businesses?
Ransomware is rising sharply. Among UK businesses it more than doubled from less than 0.5% to 1% — approximately 19,000 businesses affected. Encryption outcomes are getting worse too: 70% of UK ransomware attacks resulted in data being encrypted, up from 46% in 2024 (2025 UK market data). The trend line is the point — this is no longer a large-enterprise problem.
The financial impact lands hardest on smaller organisations without tested recovery. The average cost of the most disruptive breach is £3,550 (DSIT 2025), but a full ransomware event — downtime, recovery, lost revenue, regulatory exposure — runs far higher. The Cyber Security Breaches Survey 2025 shows phishing and ransomware remain the dominant threats facing UK businesses of every size.
How do you protect your business from ransomware?
Effective ransomware protection is layered — no single control is enough. The goal is defence in depth: stop most attacks at the email gateway, detect the rest at the endpoint, and guarantee recovery with backups you have actually tested. AMVIA delivers all of this from one accountable provider.
- Email security — advanced filtering plus DMARC/SPF/DKIM authentication cuts the most common delivery route. See email security.
- Endpoint detection (EDR) — Microsoft Defender for Endpoint watches device behaviour in real time, catching ransomware before it encrypts, even when the malware is brand new.
- Tested, immutable backups — air-gapped backups, tested regularly, are your last line of defence. Microsoft 365 backup protects cloud data that native retention does not.
- Staff awareness — training people to spot phishing reduces the chance of initial access.
- Patch management — updating software and operating systems closes the vulnerabilities ransomware uses to spread.
- 24/7 monitoring — AMVIA's in-house SOC detects ransomware activity in its early stages, before encryption begins, enabling rapid managed detection and response.
Should you pay a ransomware demand? Pay vs recover vs prevent
You should not pay. UK law enforcement and the NCSC advise against paying ransoms — payment does not guarantee recovery, funds criminal groups, and marks you as a willing payer for future attacks. The economics are stark once you compare paying, recovering without backups, and preventing the attack outright.
| Factor | Pay Ransom £50K–£500K+ | Recover (No Backup) £20K–£200K+ | Prevent (Managed) £15–£25/user/month |
|---|---|---|---|
| Data recovered | Maybe (no guarantee) | Partial | N/A — attack prevented |
| Downtime | Days to weeks | Days to weeks | Minimal |
| Legal/regulatory risk | High | High | Low |
| Reputational damage | Significant | Significant | None |
| Funds future attacks | Yes | No | No |
Note: ransom amounts and recovery costs vary significantly with business size and attack severity. The managed-prevention figure is the only one you control in advance — and it is a fraction of the alternatives.
What should you do if you are hit by ransomware?
Isolate first, then escalate. Disconnect affected devices from the network to stop the spread, but do not power them off — volatile memory can hold evidence. Engage incident response specialists immediately, preserve logs, and begin recovery from your most recent tested backup rather than negotiating with attackers.
Reporting matters too. UK businesses should report ransomware to Action Fraud and the NCSC, and notify the ICO within 72 hours if personal data is affected. A rehearsed plan turns a crisis into a procedure — which is exactly what AMVIA's 24/7 SOC and incident-response process exist to provide.
Frequently Asked Questions
No. The NCSC and UK law enforcement advise against paying. Payment does not guarantee data recovery, funds criminal organisations, and marks your business as a willing payer for future attacks. Focus instead on restoring from tested backups and engaging incident-response specialists — a tested recovery plan is far more reliable than attacker cooperation.
The most common entry points are phishing emails with malicious attachments or links, exposed Remote Desktop Protocol (RDP) services, and unpatched software vulnerabilities. With 85% of businesses that experienced a breach identifying phishing as the attack vector (Cyber Security Breaches Survey 2025), email security and staff awareness training are your most important preventive controls.
Tested, immutable backups stored separately from your production network are the primary recovery mechanism after an attack. Without them, businesses face paying the ransom or permanently losing data. Backups must be tested regularly — untested backups frequently fail during real recovery. Organisations with verified backups recover faster and at lower cost.
No. Traditional signature-based antivirus only recognises known threats, and modern ransomware is often brand new or modified to evade signatures. Endpoint detection and response (EDR) monitors device behaviour in real time, catching the encryption activity itself rather than waiting to match a signature. EDR plus email filtering is the practical baseline.
Double-extortion ransomware steals your data before encrypting it, then threatens to publish the stolen information if you do not pay — even if you can restore from backup. It defeats a backup-only strategy because the data exposure has already happened. This is why prevention and early detection, not just recovery, are essential.
Yes. Attackers automate scanning for exposed services and weak credentials, so smaller organisations with limited defences are frequently hit precisely because they are easier to compromise. The Cyber Security Breaches Survey 2025 shows ransomware affecting businesses of every size, and smaller firms without tested backups feel the impact hardest.
Protect Your Business from Ransomware
A free security assessment identifies your ransomware risk and recommends practical improvements.
Related Resources
Managed Cybersecurity
How managed cybersecurity defends UK businesses against ransomware.
Incident Response
What to do if you are attacked.
EDR vs Antivirus
Why traditional antivirus misses ransomware.
24/7 Security Monitoring
Detect threats before they cause damage.
Protect your business → Get Cybersecurity Assessment