How to prevent ransomware from ending your business
The five defences that stop most attacks, and what to do in the first hour if one gets through.
Ransomware locks your files and demands payment to get them back, and recovering without preparation is slow and expensive. This guide covers how attacks start, the five defences that stop most of them, and the first steps to take if you are ever hit.
Ask us about ransomware protection
Enter your details and we will call you back to talk through backups, security and staff training for your business.
You will speak to our Brighton-based team, rated 4.9 stars on Google.
What a ransomware attack looks like now
A ransomware attack used to mean one thing: your files were encrypted and a payment was demanded for the key. Most attacks now run double extortion. Before encrypting anything, the attackers quietly steal a copy of your data, known as exfiltration, then threaten to publish it, personal data and all, if you refuse to pay. Backups get your systems back, but they do not get the stolen copy back, which is why prevention matters more than it ever has.
Attackers automate their scanning, so a ten-person firm gets probed by the same tools as a bank. The National Cyber Security Centre (NCSC) treats ransomware as one of the most serious cyber threats facing UK organisations, and its guidance shapes the advice on this page.
How ransomware gets in
Almost every attack arrives through one of three doors.
The five defences that stop most attacks
None of these are exotic. Most ransomware prevention comes down to the basics, done properly and checked, and together they prevent ransomware attacks more reliably than any single product.
Firewalls, security software and monitoring that detects ransomware early still matter, and they work best on top of these five. The five map directly to the NCSC’s guidance on mitigating malware and ransomware attacks.
If you are being attacked right now
Move fast and keep the order. A ransomware infection spreads while you wait.
1. Disconnect affected machines from the network, but leave them switched on. Pulling the network cable or Wi-Fi stops the spread and helps limit the impact; powering off destroys evidence that helps recovery.
2. Call for help. Our emergency cyber security line is 01273 806211, open 8am to 6pm, Monday to Friday, and we respond within 15 minutes. That page also has a fuller while-you-wait checklist.
3. Tell your cyber insurance provider early, if you have one. Many policies require it before any recovery work starts.
4. Do not pay, and do not reply to the attacker. The NCSC and UK law enforcement advise against paying: there is no guarantee you get your data back, and payment funds the next attack.
5. Report it. Report the attack to Action Fraud, and use the NCSC’s ransomware hub for what to expect next.
Ransomware's relatives, in one minute
Ransomware is one type of malware, which is the umbrella word for malicious software. Three relatives come up in most conversations about it.
The five defences above protect your business against all of them.
Frequently asked questions
Should we ever pay the ransom?
No. The NCSC and UK law enforcement advise against paying. There is no guarantee you will get a working key, the stolen copy of your data stays stolen, payment funds the next wave of cyber attacks, and where the gang is under sanctions, paying can itself be unlawful. Put the money into recovery instead.
Does cyber insurance cover ransomware?
Often partly, and the detail varies a lot between policies. Check what yours says about ransom payments, recovery costs and business interruption. Insurers increasingly treat MFA, tested backups and patching as required best practices before they will pay a claim, so the five defences protect your cover as well as your systems.
How much does ransomware protection cost?
For most small businesses the controls that protect against ransomware are not five separate products. Backups, MFA, patching and sensible access controls are part of how a well-run IT provider manages your systems, included in the monthly support price rather than sold back as extras. Costs rise with the amount of data you back up and any round-the-clock cybersecurity monitoring of your devices (endpoint detection and response) you add. Ask any provider to show, in writing and in pounds, which of the five their standard price includes.
Can we recover without paying?
Yes. Recovering without paying a ransom is exactly what backups are for, if they are intact, recent and tested, which is why the gangs hunt for them before they encrypt your data. An offline or otherwise unreachable copy exists for this moment.
How long does recovery take?
Recovering from a ransomware attack takes longer than most people expect. Even with good backups, incident response takes days rather than hours: rebuilding systems, restoring data and checking nothing hostile remains. Without backups, some businesses never get their data back at all.
Get new guides by email
One short email when a new guide goes live, and nothing else.