Ransomware and UK Small Businesses: How Firms Get Hit and How to Stop It
Ransomware locks up your files and demands payment to release them. Small UK firms are hit not because they are targeted, but because they are easy. A short list of controls, tested backups, multi-factor authentication, prompt patching and basic staff awareness, prevents the vast majority of attacks. This article explains how firms get caught and what actually works.
Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.
What ransomware does, and why small firms get hit
Ransomware is malicious software that scrambles all the files it can reach, your quotes, invoices, customer records, everything, and then demands a payment to unlock them. Increasingly, attackers also steal a copy of your data first and threaten to publish it if you do not pay. For a small business, the result can be days of downtime, lost trust and, in the worst cases, closure.
The biggest misunderstanding is thinking you are too small to be a target. Most ransomware attacks are not targeted at all. Criminals run automated tools that scan the whole internet looking for weaknesses, an out-of-date server, a remote login with a weak password, a mailbox with no multi-factor authentication, and they attack whatever they find. You do not need to be famous to be caught. You just need to be reachable and unprotected.
Ransomware rarely picks its victims. It finds the unlocked door, and a small business with no backups and no multi-factor authentication is an unlocked door.
How a typical attack unfolds
Real incidents against small firms tend to follow a handful of routes in.
- A phishing email. Someone receives a convincing message and either opens a booby-trapped attachment or types their password into a fake login page. The attacker now has a foothold or a working set of credentials.
- Weak or stolen remote access. Many firms opened up remote access for staff to work from home and never locked it down. A guessable password, reused from another site and already leaked, is all it takes.
- Unpatched software. A known flaw in software that was never updated gives the attacker a way in without needing anyone to click anything.
Once inside, attackers often wait. They quietly look around, work out where your important data lives, and, crucially, try to find and destroy your backups first. Then they trigger the encryption, usually out of hours so it is well underway before anyone notices. By Monday morning, the files are locked and a ransom note is waiting.
Understanding this sequence matters, because every stage is a chance to stop it.
The handful of controls that actually work
You do not need an enormous security budget to defend against the vast majority of ransomware. You need a small number of controls done properly and kept in place.
1. Backups you have actually tested
This is the single most important defence. If you can restore your systems from a recent backup, ransomware becomes an expensive inconvenience rather than a catastrophe. The key details:
- Keep at least one backup copy that is offline or otherwise isolated, so an attacker who gets into your network cannot reach and delete it.
- Back up often enough that losing everything since the last backup would not seriously hurt.
- Test a restore regularly. A backup you have never tried to restore is a guess, not a safety net. Plenty of businesses discover their backups were broken only after they needed them.
2. Multi-factor authentication (MFA)
MFA means a stolen password is not enough on its own, because logging in also needs a code or approval on a separate device. It is one of the most effective controls you can turn on, and it directly shuts down the stolen-credential route that so many attacks rely on. Put it on email, remote access and any cloud system that supports it. A password manager such as Proton Pass makes it realistic to give every account a long, unique password as well, so one leaked password does not unlock everything.
3. Prompt patching
Keep operating systems and software updated, and turn on automatic updates where you can. Most attacks that exploit software flaws use holes that were fixed long ago, they only work on machines that never applied the update. Retire software that is no longer supported and can no longer be patched.
4. Staff awareness
Your team is not the weak link, they are the front line, but only if they know what to look for. Short, regular, blame-free training on how to spot a suspicious email and what to do about it pays for itself many times over. People who feel safe reporting a mistake quickly give you the chance to contain an incident before it spreads.
Have a plan for the bad day
Even with strong defences, you should know what you would do if the worst happened. Who do you call? How do you restore from backup? How would you keep serving customers while systems are down? Writing this down while calm is far easier than improvising in a crisis. And if you are hit, UK guidance from the NCSC is clear: do not pay the ransom. There is no guarantee you get your data back, it marks you as a business that pays, and it funds more crime. Good backups are what let you say no.
Where Dacros fits in
The controls above are exactly what we put in place and, just as importantly, keep in place for the businesses we look after across Leeds and Yorkshire. As part of managed IT support we run monitored backups and test restores, roll out multi-factor authentication, keep systems patched and train your staff, so protection does not quietly decay the moment things get busy. Sectors that hold sensitive records, such as healthcare and care homes, have the most to lose and benefit most from getting this right.
If you are not confident your backups would survive a ransomware attack, or that they even work, book a free IT and security review. We will check your defences honestly and tell you where the real risks are. You can also learn more about our approach to cyber security.
Frequently asked questions
What is ransomware?
Ransomware is malicious software that scrambles your files so you cannot open them, then demands a payment, usually in cryptocurrency, in return for unlocking them. Many attacks now also steal a copy of your data and threaten to publish it unless you pay.
Should we pay the ransom if we get hit?
UK authorities, including the NCSC, advise against paying. There is no guarantee you will get your data back, it marks you as a business that pays, and it funds further crime. Reliable, tested backups mean you should not have to pay, because you can restore your systems yourself.
What is the single best defence against ransomware?
Backups you have actually tested. If you can restore your systems from a recent, offline or otherwise isolated backup, ransomware becomes an expensive nuisance rather than a business-ending event. Pair backups with multi-factor authentication for the strongest effect.
How does ransomware usually get in?
Most commonly through a phishing email that tricks someone into opening an attachment or entering their password on a fake page, through stolen or weak login details on remote access, or through software that has not been kept up to date.
Do small businesses really get targeted?
They rarely get singled out. Instead, automated attacks scan the internet for easy targets, and small firms with weak controls get caught. Being an easy target, not a famous one, is what puts you at risk.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.