What Is Ransomware? A Guide for UK Businesses

Ransomware is malicious software that encrypts your files and demands payment for the decryption key. It is the most financially damaging cyber threat facing UK businesses, with attacks increasing in frequency and sophistication year on year.

Quick answer

Ransomware is malicious software that encrypts your files and demands a payment — usually in cryptocurrency — in exchange for the decryption key. Modern strains add "double extortion": attackers steal your data before encrypting it, then threaten to leak it. For UK businesses, layered prevention is far cheaper than recovery, which is why AMVIA runs security-first managed cybersecurity.

How to Protect Your Business from Ransomware

Effective ransomware protection requires multiple layers working together.

Email Security

Phishing emails are the most common delivery mechanism for ransomware. Advanced email filtering and DMARC/SPF/DKIM authentication reduce the risk significantly.

Endpoint Detection (EDR)

EDR monitors device behaviour in real time, catching ransomware before it can encrypt files — even if the malware is brand new and unknown to signature-based tools.

Tested Backups

Immutable, air-gapped backups that are regularly tested are your last line of defence. If ransomware gets through, backups let you recover without paying.

Staff Awareness

Training staff to recognise phishing emails and suspicious links reduces the likelihood of ransomware gaining initial access.

Patch Management

Keeping software and operating systems updated closes the vulnerabilities that ransomware exploits to spread across networks.

24/7 Monitoring

Security Operations Centre monitoring detects ransomware activity in its early stages — before encryption begins — enabling rapid containment.

Ransomware Response: Pay vs Recover vs Prevent

The cost and outcome of different approaches to ransomware.

Feature
Pay Ransom£50K–£500K+
Recover (No Backup)£20K–£200K+
Prevent (Managed)£15–£25/user/moRecommended
Data recoveredMaybe (no guarantee)PartialN/A (attack prevented)
DowntimeDays to weeksDays to weeksMinimal
Legal/regulatory riskHighHighLow
Reputational damageSignificantSignificantNone
Funds future attacks

Ransom amounts and recovery costs vary significantly based on business size and attack severity.

How does ransomware actually work?

Ransomware works in stages: it gains access, spreads quietly, then encrypts. Once inside a network it locates valuable files — documents, databases, backups — encrypts them with a key only the attacker holds, and drops a ransom note. Double-extortion strains exfiltrate that data first, so paying never guarantees it stays private.

The mechanics matter because they tell you where to break the chain. The earlier you detect the intrusion, the cheaper it is to stop. By the time files are being encrypted, you are already in incident-response territory rather than prevention. That is the entire argument for continuous monitoring through endpoint detection and response rather than relying on antivirus alone.

How does ransomware get into a UK business network?

The most common entry points are phishing emails with malicious attachments or links, exposed Remote Desktop Protocol (RDP) services, and unpatched software vulnerabilities. Phishing dominates: 85% of businesses that experienced a breach identified phishing as the attack vector (Cyber Security Breaches Survey 2025), which is why email is the single most important control to harden.

That makes email security your first line of defence. AMVIA combines Microsoft Defender with the Barracuda email suite to filter malicious attachments and links before they reach an inbox, backed by DMARC, SPF and DKIM authentication to block spoofing. According to the NCSC, keeping software patched and disabling unused remote-access services closes the other two main routes attackers use.

  • Phishing emails — malicious links and attachments delivered to staff inboxes.
  • Exposed RDP — internet-facing remote desktop with weak or reused passwords.
  • Unpatched software — known vulnerabilities attackers scan for and exploit.
  • Stolen credentials — reused passwords bought on criminal marketplaces.

How bad is the ransomware threat to UK businesses?

Ransomware is rising sharply. Among UK businesses it more than doubled from less than 0.5% to 1% — approximately 19,000 businesses affected. Encryption outcomes are getting worse too: 70% of UK ransomware attacks resulted in data being encrypted, up from 46% in 2024 (2025 UK market data). The trend line is the point — this is no longer a large-enterprise problem.

The financial impact lands hardest on smaller organisations without tested recovery. The average cost of the most disruptive breach is £3,550 (DSIT 2025), but a full ransomware event — downtime, recovery, lost revenue, regulatory exposure — runs far higher. The Cyber Security Breaches Survey 2025 shows phishing and ransomware remain the dominant threats facing UK businesses of every size.

How do you protect your business from ransomware?

Effective ransomware protection is layered — no single control is enough. The goal is defence in depth: stop most attacks at the email gateway, detect the rest at the endpoint, and guarantee recovery with backups you have actually tested. AMVIA delivers all of this from one accountable provider.

  • Email security — advanced filtering plus DMARC/SPF/DKIM authentication cuts the most common delivery route. See email security.
  • Endpoint detection (EDR) — Microsoft Defender for Endpoint watches device behaviour in real time, catching ransomware before it encrypts, even when the malware is brand new.
  • Tested, immutable backups — air-gapped backups, tested regularly, are your last line of defence. Microsoft 365 backup protects cloud data that native retention does not.
  • Staff awareness — training people to spot phishing reduces the chance of initial access.
  • Patch management — updating software and operating systems closes the vulnerabilities ransomware uses to spread.
  • 24/7 monitoring — AMVIA's in-house SOC detects ransomware activity in its early stages, before encryption begins, enabling rapid managed detection and response.

Should you pay a ransomware demand? Pay vs recover vs prevent

You should not pay. UK law enforcement and the NCSC advise against paying ransoms — payment does not guarantee recovery, funds criminal groups, and marks you as a willing payer for future attacks. The economics are stark once you compare paying, recovering without backups, and preventing the attack outright.

FactorPay Ransom £50K–£500K+Recover (No Backup) £20K–£200K+Prevent (Managed) £15–£25/user/month
Data recoveredMaybe (no guarantee)PartialN/A — attack prevented
DowntimeDays to weeksDays to weeksMinimal
Legal/regulatory riskHighHighLow
Reputational damageSignificantSignificantNone
Funds future attacksYesNoNo

Note: ransom amounts and recovery costs vary significantly with business size and attack severity. The managed-prevention figure is the only one you control in advance — and it is a fraction of the alternatives.

What should you do if you are hit by ransomware?

Isolate first, then escalate. Disconnect affected devices from the network to stop the spread, but do not power them off — volatile memory can hold evidence. Engage incident response specialists immediately, preserve logs, and begin recovery from your most recent tested backup rather than negotiating with attackers.

Reporting matters too. UK businesses should report ransomware to Action Fraud and the NCSC, and notify the ICO within 72 hours if personal data is affected. A rehearsed plan turns a crisis into a procedure — which is exactly what AMVIA's 24/7 SOC and incident-response process exist to provide.

Frequently Asked Questions

Protect Your Business from Ransomware

A free security assessment identifies your ransomware risk and recommends practical improvements.