Ransomware is malicious software that encrypts your files — and increasingly your backups, cloud data and customer information — then demands payment to restore access. In 2026, it's no longer a 'big company' problem. UK SMEs are squarely in scope.
How a modern ransomware attack unfolds
- Initial access — usually a phishing email, a stolen password, or an unpatched internet-facing service.
- Quiet expansion — the attacker spends days or weeks mapping your network, finding admin accounts, locating backups.
- Data theft — files are quietly exfiltrated to the attacker's infrastructure.
- Encryption — at a chosen moment, files are encrypted across every reachable machine and shared drive.
- Extortion — a ransom note appears. Pay to decrypt; pay again to stop your data being published.
Why SMEs are the perfect target
- Smaller security teams (often no dedicated security team at all).
- Flat networks where one compromised laptop reaches everything.
- Backups that turn out to be online, mounted and encryptable.
- Cyber insurance that makes payment feel viable.
- Sensitive client data that creates leverage for double extortion.
What an attack actually looks like
From the inside, it usually starts with a normal Monday. Files won't open. Shared drives show strange extensions. A README file appears on every desktop. Office 365 logs show logins from countries no one's visited. By the time anyone notices, the attacker has been inside for two to three weeks.
What stops it
- MFA everywhere (especially on remote access and email).
- Modern EDR that detects the quiet expansion phase, not just the encryption.
- Patched, hardened internet-facing services.
- Backups that are offline, immutable and tested.
- 24/7 monitoring so alerts don't sit overnight or over a weekend.
Next step
If you're not sure whether your business would survive a ransomware incident, book a free 30-minute review. We'll walk through your current defences and give you a plain-English risk picture.

