
Ransomware is back in the headlines for a simple reason: too many organisations are still being forced into impossible decisions after an attack has already happened.
Proofpoint’s 2026 ransomware research found that 58% of affected UK organisations paid a ransom, despite official advice not to. It also found that 22% of those that paid were hit with a second extortion demand. Paying can feel like the quickest route back to normal, but it does not guarantee recovery and it can leave a business exposed to more pressure.
For small and medium-sized businesses, the real lesson is not “never get attacked”. That is not realistic. The better question is: if your files, email, accounts system or client data became unavailable tomorrow morning, how quickly could you recover without needing to negotiate with criminals?
Ransomware is a recovery problem, not just a security problem
Good cyber security reduces the chance of an attack getting through. Good cyber resilience reduces the damage if one does.
That distinction matters. A business can have antivirus, firewalls and email filtering in place, but still struggle badly if backups are not tested, admin accounts are overused, or nobody knows who makes decisions during an incident.
The National Cyber Security Centre and UK government continue to advise organisations not to pay ransoms. The practical reason is simple: payment does not guarantee a working decryptor, does not guarantee stolen data will be deleted, and does not remove the original weakness that let the attacker in.
Start with backups you have actually tested
A backup is only useful if it can be restored quickly when you need it. That means backups should be separated from the systems attackers can reach, protected with strong access controls, and tested on a regular schedule.
It is not enough to know that a backup job says “successful”. Businesses should know what can be restored, how long it takes, who can access the backup platform, and what happens if the main server, Microsoft 365 tenant or local network is unavailable.
Protect the accounts attackers want first
Many ransomware incidents begin with phishing, stolen credentials, malicious links or compromised email accounts. The UK government’s Cyber Security Breaches Survey 2025/2026 found that phishing remains the most common type of breach or attack identified by businesses.
Multi-factor authentication, strong password controls, least-privilege admin access and sensible monitoring make a real difference. If an attacker gets one password, they should not be able to walk through the whole business.
Patch the obvious doors before they are used against you
Attackers look for old software, exposed remote access, weak passwords and unmanaged devices. These are not glamorous fixes, but they close the doors criminals try first.
Every business should know which devices it owns, which systems are business-critical, which applications need regular patching, and which suppliers can access the environment. If nobody has that picture, recovery becomes slower and more expensive.
Have the incident plan before the incident
During a ransomware incident, time gets very expensive. People need to know who disconnects affected devices, who contacts the IT provider, who speaks to staff, and who checks legal, insurance or reporting obligations.
Clear decisions made calmly in advance are much better than rushed decisions during downtime. Even a short one-page incident plan is better than relying on memory when systems are offline.
What UK businesses should do now
- Check that important data is backed up and restorable
- Turn on multi-factor authentication for Microsoft 365 and other key systems
- Limit admin access to the people and devices that genuinely need it
- Patch laptops, servers, firewalls, remote access tools and cloud applications
- Train staff to spot phishing and report suspicious activity quickly
- Write down who does what during an incident
- Review cyber insurance and reporting requirements before anything happens
At BM Technologies, we help businesses put those practical layers in place: secure backups, managed devices, Microsoft 365 security, endpoint protection, monitoring and recovery planning. The goal is simple: keep your business running, protect your data, and make sure a ransomware demand is not your only option.
If you are not sure how exposed your business is, start with a quick cyber risk check. A few minutes now is better than a crisis call later.
