
Ransomware advice is easy to agree with in theory: keep good backups, patch systems, use strong access controls and do not pay criminals. The difficult bit is proving those controls will still work on a bad day.
That is why the latest UK ransomware campaign is worth taking seriously. Report Fraud data shared in July 2026 said 323 UK organisations reported ransomware attacks between April 2025 and March 2026, with more than half of those reports coming from SMEs. Reported SME losses were around £270,000, and the campaign warned that real losses are likely to be higher because incidents are often under-reported.
For BM Technologies clients, the practical lesson is simple: a backup is not the same thing as a recovery plan. A business only has a ransomware plan when someone has tested how quickly critical systems can be restored, who makes the decisions, and what happens if normal admin accounts, file shares or cloud apps are unavailable.
Why this matters now
The UK Government’s Cyber Security Breaches Survey 2025/2026 found that 43% of businesses identified a cyber breach or attack in the previous 12 months. Phishing remained the most common route in, affecting 38% of businesses, while the survey also highlighted gaps in two-factor authentication, user monitoring, risk assessments and incident response planning.
Those numbers line up with what we see in real environments. Most businesses have some security tools in place. Fewer have a joined-up process that answers the uncomfortable questions: which systems come back first, whether backups are clean, who can approve emergency spend, and how customers are updated if services are disrupted.
What a tested backup plan should cover
- Recovery order: list the systems the business needs first, such as Microsoft 365, line-of-business apps, finance, shared files, phones and website access.
- Offline or isolated copies: make sure ransomware cannot encrypt every backup using the same compromised credentials.
- Restore testing: schedule real test restores, not just green ticks in a backup dashboard.
- Access control: protect admin accounts with multi-factor authentication, separate admin logins and least-privilege permissions.
- Monitoring: watch for suspicious sign-ins, mass file changes, disabled backups and unusual endpoint behaviour.
- Incident roles: decide who contacts IT, insurers, legal advisers, customers, suppliers and law enforcement.
The NCSC’s small organisation guidance keeps the same message deliberately practical: secure email, protect important accounts, protect devices, back up data and help staff spot attacks. None of this needs to start with a giant security programme. It does need ownership, repetition and evidence.
The common mistake: assuming cloud means covered
Cloud services are resilient, but they do not remove every recovery risk. If an attacker gets into a Microsoft 365 account, deletes files, changes mailbox rules or compromises an admin login, the business still needs a clear restore route and a way to prove what changed.
The same applies to hosted desktops, SaaS applications and website platforms. Provider resilience helps with infrastructure failure. It does not automatically solve accidental deletion, account takeover, malicious encryption, data export or recovery priorities for your specific business.
A sensible first step for August
Pick one critical system and run a controlled restore test this month. Time it. Record who was involved. Confirm whether the restored data is complete enough to work from. Note anything that slowed the process down, then fix the weak points before moving to the next system.
For smaller organisations, that single exercise often reveals more useful information than a long theoretical policy. It shows whether the backup is readable, whether the right people know the process, whether permissions are sensible, and whether the business can operate while recovery is in progress.
Ransomware preparation is not about panic. It is about removing guesswork before the pressure arrives.
