Ransomware is no longer the lone-hacker story it was a decade ago. In 2026, it's an industry — well-funded groups, affiliate programmes, leak sites and negotiation specialists. UK SMEs are squarely in the firing line because they have enough money to pay and rarely have a full-time security team.
The good news: the controls that stop almost every ransomware attack are well understood. None of them are exotic. This guide explains them in plain English, in priority order, so you know exactly where to spend your next pound of effort.
How modern ransomware actually unfolds
Almost every ransomware incident we see follows the same script:
- Initial access — usually a phishing email, a stolen password reused from a breach, or an exposed remote service.
- Quiet foothold — the attacker installs a remote-access tool and waits, sometimes for weeks, scoping the environment.
- Privilege escalation — they hunt for admin credentials and map out file shares, backups and cloud storage.
- Data theft — they quietly copy your most sensitive data to use as leverage, before any encryption.
- Detonation — out of hours, they encrypt everything they can reach and drop a ransom note.
Stop them at step 1 or 2 and you have a near-miss. Catch them at step 5 and you have a crisis.
The 8 controls that stop most attacks
In rough priority order for a typical UK SME:
1. Multi-factor authentication on everything
MFA on email, remote access, admin accounts and any cloud service holding business data. Stolen passwords are the most common entry point — MFA alone defeats the majority of opportunistic attacks. Where you can, move admins to phishing-resistant MFA (passkeys or hardware keys).
2. Modern endpoint protection (EDR), not just antivirus
Traditional signature-based antivirus is no longer enough. Endpoint Detection and Response watches behaviour — unusual processes, suspicious PowerShell, mass file changes — and can automatically isolate a device the moment it sees ransomware-like activity.
Related service
Add EDR/MDR threat protection
24/7 monitored endpoint protection with rapid containment — the single biggest reduction in ransomware risk.
Explore Add EDR/MDR threat protection3. Patching, automated and measured
Apply high and critical security updates within 14 days, every time. Manual patching almost never holds the line. Automate via Intune, RMM or equivalent and report monthly on compliance.
4. Backups your attacker can't reach
Backups are your last line of defence — and the first thing modern ransomware groups try to destroy. You need: offline or immutable copies, separate credentials from your production environment, and a restore that you've actually tested in the last 90 days. Untested backups are wishful thinking.
5. Phishing-resistant email and trained people
Most ransomware starts with a phishing email. A modern email gateway that inspects links at click-time, plus regular, realistic phishing simulation, dramatically reduces successful initial access.
Related service
Run realistic phishing simulations
Find out who would click — before an attacker does. Then turn it into 5 minutes of training.
Explore Run realistic phishing simulations6. Least privilege and no standing admin rights
Day-to-day accounts should not be local admins. Separate admin accounts, used only when needed. This single change limits the blast radius of almost every intrusion.
7. Network segmentation
Flat networks are a ransomware paradise — one compromised laptop reaches every server, every share, every backup. Segment by function, restrict server-to-server traffic, and put critical systems behind their own controls.
8. 24/7 detection and response
Attackers love evenings, weekends and bank holidays — that's when in-house IT is offline and response is slowest. Managed Detection and Response (MDR) puts a human analyst on your alerts around the clock, ready to contain a threat in minutes rather than the next morning.
What an actual incident looks like (and what saves you)
In a recent case, a UK professional services firm had an attacker land via a phished email. EDR fired an alert at 9:47pm. The MDR analyst isolated the endpoint within four minutes, force-signed-out the user's cloud sessions, and audited mailbox rules across the tenant. Total business impact: one laptop offline overnight and a tightened MFA policy. Without EDR and 24/7 response, this would have been a multi-day encryption event.
If the worst happens
Have a written incident response plan that names the first three people to call, where your backups live, and which suppliers (insurer, IT, legal, PR) need to be notified. Print it. The one time you'll need it is the one time your systems are down.
Related service
Get a ransomware readiness assessment
An honest, prioritised view of where ransomware would land in your business — and what to fix first.
Explore Get a ransomware readiness assessmentWhere to start this week
If you do nothing else this month: confirm MFA is on every email and admin account, confirm a backup restore was tested in the last 90 days, and confirm you have modern EDR (not just antivirus) on every laptop and server. Those three controls alone close the door on most attacks.
Next step
Want a clear, prioritised view of where ransomware would most likely land in your business — and what it would cost to close the gaps? Book a free 30-minute review with a UK specialist. No obligation, no scare tactics, just plain-English answers.

