Skip to main content
Dig IT Solutions logo

Cyber Security

Ransomware: how it gets in and how a small business stops it

How ransomware enters a UK small business (phishing, exposed remote access, stolen logins), the layered defences that stop it and how to recover without paying.

By Dig IT SolutionsUpdated 8 September 20267 min read

Short answer

Ransomware gets into small businesses through three doors: phishing emails that deliver malware or steal logins, remote access services exposed to the internet, and reused passwords without MFA. Stopping it means closing those doors (MFA, patching, no exposed remote desktop), catching what gets through with EDR, and keeping an offline or immutable backup so you can recover without paying.

Ransomware is the incident that closes small businesses. Not because the malware is clever, but because it arrives after weeks of quiet preparation, hits every system at once including the backups, and leaves the directors choosing between paying criminals and rebuilding from nothing. The NCSC's ransomware guidance is the UK reference and the source for much of what follows. This article translates it for a business of up to 250 people: how the attack actually unfolds, the layers that stop it, and how to make sure you can recover without paying.

How a ransomware attack actually unfolds

The popular picture, a bad attachment that instantly encrypts a PC, is out of date. Modern ransomware against businesses is run by organised groups and unfolds in stages.

Initial access. One of three doors, almost always. A phishing email that either drops a loader or captures a Microsoft 365 or VPN login. A remote access service (remote desktop, a VPN, a remote support tool) exposed to the internet and protected by a password that was weak, reused or leaked. Or an unpatched flaw in something internet-facing, such as a firewall or a file transfer appliance. Increasingly, the group that runs the ransomware buys this access from a broker who specialises in getting in.

Quiet reconnaissance. Days to weeks inside your network, mapping systems, harvesting credentials, escalating to domain administrator, finding the backups and the most valuable data. This is the period in which monitoring catches attacks and unmonitored businesses notice nothing.

Data theft. Most groups now copy your data out before encrypting. The threat to publish client files, payroll and correspondence is the second lever if you have good backups, and it is what turns the incident into a reportable data breach under UK GDPR.

Backup destruction. Backup consoles are deleted, cloud backup accounts emptied, shadow copies removed. Any backup reachable with the credentials the attacker now holds is gone.

Encryption. Usually out of hours, often at a weekend, across every server and workstation at once. Then the ransom note.

Understanding this sequence is the key to defending against it: there are five separate stages at which the attack can be stopped, and a business needs controls at each.

Layer 1: close the doors

  • Enforce MFA everywhere, on email, VPN, remote access and admin consoles, with legacy authentication blocked. A leaked password without MFA is the commonest way in. See what MFA is and why your business needs it.
  • Nothing exposed that does not need to be. Remote desktop must never face the internet. Remote access goes through a VPN or gateway with MFA, and every firewall rule has an owner and a reason.
  • Patch within 14 days, including firewalls, VPN appliances and NAS devices, not just Windows. Retire unsupported systems, Windows 10 without extended support has been unsupported since October 2025.
  • Email filtering that sandboxes attachments and checks links at click time, with SPF, DKIM and DMARC on your own domain.
  • Staff who know the lures and never approve an MFA prompt they did not trigger. Our phishing guide covers the 2026 techniques.

Layer 2: limit what an intruder can do

  • No local administrator rights for everyday users. Most ransomware needs administrator rights to spread.
  • Separate admin accounts used only for admin tasks, protected with phishing-resistant MFA.
  • Least privilege on file shares. If the sales team cannot write to the finance share, ransomware running as a sales user cannot encrypt it.
  • Network segmentation. Servers, workstations, guest Wi-Fi, CCTV and phones on separate networks, so a compromised laptop cannot reach everything. Multi-site businesses should treat each site's link as a controlled boundary, as in our Mr Plant Hire case study.
  • Application control where practical, so only approved software runs.

Layer 3: detect and stop it in progress

This is where traditional antivirus fails and endpoint detection and response earns its keep. EDR watches behaviour on every device: credential dumping, unusual PowerShell, a process touching thousands of files in seconds, attempts to delete shadow copies. It isolates the device from the network automatically and alerts a response team. In practice this is the difference between one laptop reimaged and an entire estate encrypted. Insurers now ask for EDR by name. Our comparison of EDR and antivirus explains the difference.

Add identity monitoring in Microsoft 365 (impossible-travel sign-ins, new admin roles, mass downloads) and somebody who looks at firewall and backup alerts. The reconnaissance phase is noisy to anyone watching, and silent to anyone who is not. This is the case for continuous monitoring over periodic checks.

Layer 4: backups the attacker cannot reach

Every serious ransomware group targets backups first, so the design question is: if an attacker holds your domain administrator password and your backup console login, what survives?

  • Follow 3-2-1: three copies, on two different media, one off-site. Then add the modern requirement: at least one copy that is offline or immutable.
  • Immutable means the backup cannot be altered or deleted for a set retention period, even by an administrator. Most business backup platforms and cloud storage tiers now offer it. Offline means physically disconnected, such as rotated drives or a tape, which is old-fashioned and still effective.
  • Separate credentials. The backup system and its cloud storage must not accept your domain admin login. Its own accounts, its own MFA.
  • Back up Microsoft 365 separately. Microsoft's own retention and recycle bins are not a backup against a hostile administrator.
  • Test restores on a schedule, and time them. A backup that has never been restored is a hope, not a plan. Know how long a full server rebuild takes, because that number is your real downtime.

A typical arrangement for a business our size is local backup to a NAS for fast restores, replicated to immutable cloud storage with independent credentials, plus a Microsoft 365 backup, with restore tests documented. Our backup and disaster recovery service is built on that model, and the ransomware protection page describes how the layers fit together.

Layer 5: a plan for the day it happens

Even well-defended businesses can be hit. What separates a bad week from a closure is a written plan that answers, in advance:

  1. Who declares an incident and who leads it. Name the person and their deputy.
  2. First actions. Disconnect affected devices from the network but leave them powered on. Isolate backups. Preserve the ransom note and any logs. Do not contact the attackers.
  3. Who to call. Your IT provider, your cyber insurer (most policies require early notification and provide response specialists), and the police via Action Fraud. The NCSC also asks that ransomware incidents are reported to it.
  4. The 72-hour clock. If personal data was accessed or taken, the ICO must be notified within 72 hours of becoming aware, and affected individuals told if the risk to them is high. Decide in advance who makes that call.
  5. Communications. What to tell staff, customers and suppliers, and who says it.
  6. Recovery order. Which systems come back first, from which backup, and how you verify the restored environment is clean before reconnecting it.
  7. The ransom question. The NCSC and law enforcement advise against paying: there is no guarantee of a working key or of deleted data, it funds further attacks, and sanctions may apply. A business with tested, isolated backups does not need to consider it. Decide your position before the pressure is on.

Cyber insurance deserves a line of its own. A good policy pays for incident response specialists, legal advice, forensic investigation and business interruption, and most insurers will only pay if you notified them promptly and if the controls you declared on the application (MFA, EDR, isolated backups) were actually in place. Read the policy before the incident, keep the claims number in the plan, and answer the application honestly, because an inaccurate declaration is the commonest reason claims are refused.

Rehearse the plan once a year with a tabletop exercise. It takes two hours and it exposes the assumptions ("the backups are fine", "we'd call Dave") that fail on the day. Business continuity planning is where this sits.

What it costs versus what it saves

MFA is included with Microsoft 365. EDR and managed patching are priced per device. Immutable backup storage costs a little more than plain cloud storage. A firewall under support is a few hundred pounds a year. The Cyber Security Breaches Survey finds that the businesses which suffer the most disruptive incidents are those without these basics, and a single week of downtime for a 30-person firm, plus recovery, plus the ICO and customer conversations, costs more than several years of the controls above.

What to do next

If you cannot say with confidence that remote desktop is closed, EDR is on every device, and a backup exists that your own admin account could not delete, find out before an attacker does. An IT health check tests exactly those points and gives you a prioritised, costed list to close the gaps.

Frequently asked questions

How does ransomware usually get into a small business?
Through a phishing email that delivers malware or captures a login, through a remote access service such as RDP or a VPN exposed to the internet with a weak or leaked password, or through an unpatched flaw in an internet-facing system. Increasingly, attackers buy access from a broker who has already done one of those. Sophisticated zero-day exploits are rare against SMEs.
Should we pay the ransom?
The NCSC and UK law enforcement advise against it. Payment does not guarantee a working decryption key or the deletion of stolen data, it funds further crime, it marks you as a payer, and it may raise sanctions issues. Businesses that have tested, isolated backups do not face the choice. Report to Action Fraud and the NCSC and take advice before any decision.
Will antivirus stop ransomware?
Traditional antivirus stops known ransomware files and misses new variants and attacks that use legitimate tools. Endpoint detection and response (EDR) watches behaviour, such as rapid file encryption or credential theft, and isolates the device automatically. Cyber insurers now ask for EDR by name. It should be on every device, including servers.
Are cloud backups safe from ransomware?
Only if the attacker cannot reach them. Ransomware operators look for backup consoles and cloud storage that a compromised admin account can delete, and they delete them before encrypting. A safe backup is offline, or immutable (cannot be altered for a set period), in a separately authenticated account, and tested by actually restoring from it.
Does Microsoft 365 protect us from ransomware?
Partly. OneDrive and SharePoint keep file versions and a recycle bin, which helps with a small incident, but a determined attacker with an admin account can empty those, retention is limited, and Microsoft does not provide a full backup of your tenant. A separate Microsoft 365 backup, plus MFA and conditional access on the tenant, closes the gap.
What should we do in the first hour of a ransomware attack?
Disconnect affected devices from the network (unplug, disable Wi-Fi) but do not switch them off, because memory may hold evidence and keys. Call your IT provider. Do not contact the attackers. Preserve the ransom note. Check backups are intact and disconnect them if they are reachable. Start a log of what happened and when, for insurers and the ICO.

Next step

Not sure how exposed you are?

An IT health check reviews your security, backups, Microsoft 365 and network and gives you a prioritised list, whether or not you work with us afterwards.

WhatsApp us