IT & SupportIT SupportMicrosoft 365Server SolutionsVirtualisationCyber SecurityCyber SecuritySavvy SecureEmail SolutionsAccess ControlCCTVConnectivity & CommsBusiness Phone SystemsProfessional CommunicationNetwork & WiFiMobile ConnectivityBroadband CheckerWeb & DigitalWeb DesignAll servicesCompanyLocationsKnowledge HubGuidesFAQsAboutContactGet a Quote
Cyber Security

What is ransomware and how do UK small businesses get hit?

Business computer displaying a cyber security warning

This is for UK small business owners who want a realistic view of ransomware rather than a horror story. It explains what attackers do, how they usually get in, why paying is a poor recovery plan, and which few controls cut the most risk.

What ransomware does

Ransomware is malicious software used to stop you accessing systems or data, usually by encrypting files so they will not open. The criminals then demand payment for a decryption key. Modern attacks may also copy data before encryption and threaten to publish it if the victim does not pay. That turns an IT outage into a confidentiality and reputational problem too.

The first sign can be a ransom note on a screen, strange file names on a shared drive, or staff reporting that documents will not open. By that point the activity may have started hours or days earlier. Attackers often spend time looking around first, finding backups, administrator accounts and valuable data before they make themselves known.

A small business is not too small to be affected. Many attacks are automated or opportunistic. Criminals look for an exposed remote login, a reused password or a user who can be persuaded to run something. They are not necessarily choosing businesses because they are famous; they are choosing the easiest route to money.

The realistic ways it gets in

Phishing remains a common starting point. An email may pretend to be an invoice, shared document, voicemail or Microsoft sign-in alert. It tries to collect a password or persuade somebody to open a harmful attachment. The message does not have to be perfect. It only needs to reach one busy person at the wrong moment.

Stolen remote-access credentials are another route. If a remote desktop service, VPN or cloud account is protected only by a password, a password found in an old breach can be enough. MFA makes this substantially harder, which is why it should protect email, remote access and administrator accounts. See our plain-English guide to multi-factor authentication.

Unpatched systems give attackers a door. Old operating systems, neglected servers, network appliances and third-party software sometimes contain known weaknesses. Attackers can scan the internet for them. Applying security updates promptly is not glamorous, but it removes many avoidable opportunities.

Trusted tools can be misused. A criminal with valid access may use normal remote-management, scripting or backup tools rather than an obvious virus. That is one reason behaviour-based monitoring matters. Our EDR and antivirus comparison explains the difference.

Why paying is a bad plan

Paying does not guarantee that you will receive a working decryption key, that every file will recover, or that copied data will be deleted. You are dealing with criminals who may have made several demands already. Even when a decryption tool arrives, restoring a large environment can be slow and technically difficult.

Payment can also create legal, insurance and reputational issues. Your insurer or incident-response adviser may need to be involved immediately, and some payments can raise sanctions concerns. Do not make a rushed transfer because someone says there is a countdown on screen. Preserve evidence and get appropriate professional, legal and insurance advice for your situation.

The harder truth is that a business without usable backups or a recovery plan may feel it has no choice. That is why the time to prepare is before an incident. Insurance can help with some costs, but it is not a substitute for prevention or recovery capability; our cyber insurance explainer sets out the limits.

What recovery really involves

The first job is containment. Disconnect affected devices from the network, but do not immediately wipe or restart everything. You need to stop spread while preserving clues about how the attacker entered. Tell your IT support provider, insurer and any agreed incident contacts as soon as possible.

Recovery is more than restoring the last backup. Someone must identify the entry point, reset compromised credentials, remove persistence, check other devices and confirm backups are clean before bringing systems back. If the attacker copied personal or customer data, you may also need to assess notification obligations. Rushing a restore without removing the cause can put you straight back where you started.

A good backup plan follows the idea of separate copies with one kept away from normal day-to-day access. It also includes regular restore tests. The business data backup guide explains what to test, from individual files to a whole server or Microsoft 365 account.

The controls that make the biggest difference

  • Turn on MFA: particularly for email, remote access, cloud administration and finance systems.
  • Patch promptly: include computers, servers, routers, firewalls and the software that people forget is there.
  • Use endpoint protection and monitoring: make sure alerts lead to action, not an unread inbox.
  • Keep tested backups: separate them from normal access and make sure you can restore what matters.
  • Limit administrator access: staff should not use powerful accounts for ordinary work.
  • Teach people to pause: a short, repeated reminder about phishing is more useful than a once-a-year lecture.

These are not exotic controls. They are the foundations often expected by Cyber Essentials and by larger customers reviewing a supplier. Our Cyber Essentials overview explains how the baseline fits together for a small business.

If an incident is happening now, treat it as urgent. Isolate affected equipment, speak to your IT support provider and insurer, and avoid communicating through a possibly compromised business email account. Use a known safe phone or personal method agreed by your team.

What to do next

Ask one direct question: if our main files and email were unavailable this afternoon, who would do what first? Then test the answer. TSS can help you review the gaps in a free, no-obligation chat and prioritise practical changes without turning the conversation into a scare tactic.

Worried about ransomware exposure?

Book a free, no-obligation chat and we will help you focus on the controls that reduce real risk.

Call us Get a quote