There's no single silver bullet for ransomware. There is, however, a well-understood stack of controls that — when combined — stops the overwhelming majority of attacks targeting UK SMEs.
Identity (stop them getting in)
- MFA on every account, no exceptions.
- Phishing-resistant MFA for admins (passkeys / FIDO2).
- Conditional Access: block legacy auth, enforce compliant devices.
Endpoints (catch them early)
- Modern EDR on every laptop, desktop and server — not legacy AV.
- 24/7 monitored alerts (MDR) so detection doesn't wait until Monday.
- Automated patching for OS, browsers and key apps within 14 days.
Network and access
- No internet-exposed RDP. VPN or ZTNA only, behind MFA.
- Segmentation: finance, ops and admin tooling on separate VLANs/identities.
- Removal of standing local admin rights.
Data and recovery
- Backups that are offline or immutable, plus a copy off-site.
- Restore tests at least quarterly — backups are only real once you've restored from them.
- A written incident response plan, with named owners and out-of-band contact details.
How to phase it
If you're starting from scratch, sequence is everything. A realistic order of operations:
- Month 1: MFA, EDR, patching, RDP off the internet.
- Month 2: MDR/monitoring, segmentation, admin rights cleanup.
- Month 3: backup hardening, restore testing, IR plan and tabletop.
The business case in one line
The average UK SME ransomware incident now costs more than five years of a managed security subscription. The maths is no longer subtle.
Next step
Book a free 30-minute review and we'll show you which of these 12 controls you already have, which need work, and what a realistic 90-day plan looks like for your business.

