Cyber Security
Ransomware: how it gets in and how a small business stops it
How ransomware enters a UK small business (phishing, exposed remote access, stolen logins), the layered defences that stop it and how to recover without paying.
By Dig IT SolutionsUpdated 8 September 20267 min read
Short answer
Ransomware gets into small businesses through three doors: phishing emails that deliver malware or steal logins, remote access services exposed to the internet, and reused passwords without MFA. Stopping it means closing those doors (MFA, patching, no exposed remote desktop), catching what gets through with EDR, and keeping an offline or immutable backup so you can recover without paying.
Ransomware is the incident that closes small businesses. Not because the malware is clever, but because it arrives after weeks of quiet preparation, hits every system at once including the backups, and leaves the directors choosing between paying criminals and rebuilding from nothing. The NCSC's ransomware guidance is the UK reference and the source for much of what follows. This article translates it for a business of up to 250 people: how the attack actually unfolds, the layers that stop it, and how to make sure you can recover without paying.
How a ransomware attack actually unfolds
The popular picture, a bad attachment that instantly encrypts a PC, is out of date. Modern ransomware against businesses is run by organised groups and unfolds in stages.
Initial access. One of three doors, almost always. A phishing email that either drops a loader or captures a Microsoft 365 or VPN login. A remote access service (remote desktop, a VPN, a remote support tool) exposed to the internet and protected by a password that was weak, reused or leaked. Or an unpatched flaw in something internet-facing, such as a firewall or a file transfer appliance. Increasingly, the group that runs the ransomware buys this access from a broker who specialises in getting in.
Quiet reconnaissance. Days to weeks inside your network, mapping systems, harvesting credentials, escalating to domain administrator, finding the backups and the most valuable data. This is the period in which monitoring catches attacks and unmonitored businesses notice nothing.
Data theft. Most groups now copy your data out before encrypting. The threat to publish client files, payroll and correspondence is the second lever if you have good backups, and it is what turns the incident into a reportable data breach under UK GDPR.
Backup destruction. Backup consoles are deleted, cloud backup accounts emptied, shadow copies removed. Any backup reachable with the credentials the attacker now holds is gone.
Encryption. Usually out of hours, often at a weekend, across every server and workstation at once. Then the ransom note.
Understanding this sequence is the key to defending against it: there are five separate stages at which the attack can be stopped, and a business needs controls at each.
Layer 1: close the doors
- Enforce MFA everywhere, on email, VPN, remote access and admin consoles, with legacy authentication blocked. A leaked password without MFA is the commonest way in. See what MFA is and why your business needs it.
- Nothing exposed that does not need to be. Remote desktop must never face the internet. Remote access goes through a VPN or gateway with MFA, and every firewall rule has an owner and a reason.
- Patch within 14 days, including firewalls, VPN appliances and NAS devices, not just Windows. Retire unsupported systems, Windows 10 without extended support has been unsupported since October 2025.
- Email filtering that sandboxes attachments and checks links at click time, with SPF, DKIM and DMARC on your own domain.
- Staff who know the lures and never approve an MFA prompt they did not trigger. Our phishing guide covers the 2026 techniques.
Layer 2: limit what an intruder can do
- No local administrator rights for everyday users. Most ransomware needs administrator rights to spread.
- Separate admin accounts used only for admin tasks, protected with phishing-resistant MFA.
- Least privilege on file shares. If the sales team cannot write to the finance share, ransomware running as a sales user cannot encrypt it.
- Network segmentation. Servers, workstations, guest Wi-Fi, CCTV and phones on separate networks, so a compromised laptop cannot reach everything. Multi-site businesses should treat each site's link as a controlled boundary, as in our Mr Plant Hire case study.
- Application control where practical, so only approved software runs.
Layer 3: detect and stop it in progress
This is where traditional antivirus fails and endpoint detection and response earns its keep. EDR watches behaviour on every device: credential dumping, unusual PowerShell, a process touching thousands of files in seconds, attempts to delete shadow copies. It isolates the device from the network automatically and alerts a response team. In practice this is the difference between one laptop reimaged and an entire estate encrypted. Insurers now ask for EDR by name. Our comparison of EDR and antivirus explains the difference.
Add identity monitoring in Microsoft 365 (impossible-travel sign-ins, new admin roles, mass downloads) and somebody who looks at firewall and backup alerts. The reconnaissance phase is noisy to anyone watching, and silent to anyone who is not. This is the case for continuous monitoring over periodic checks.
Layer 4: backups the attacker cannot reach
Every serious ransomware group targets backups first, so the design question is: if an attacker holds your domain administrator password and your backup console login, what survives?
- Follow 3-2-1: three copies, on two different media, one off-site. Then add the modern requirement: at least one copy that is offline or immutable.
- Immutable means the backup cannot be altered or deleted for a set retention period, even by an administrator. Most business backup platforms and cloud storage tiers now offer it. Offline means physically disconnected, such as rotated drives or a tape, which is old-fashioned and still effective.
- Separate credentials. The backup system and its cloud storage must not accept your domain admin login. Its own accounts, its own MFA.
- Back up Microsoft 365 separately. Microsoft's own retention and recycle bins are not a backup against a hostile administrator.
- Test restores on a schedule, and time them. A backup that has never been restored is a hope, not a plan. Know how long a full server rebuild takes, because that number is your real downtime.
A typical arrangement for a business our size is local backup to a NAS for fast restores, replicated to immutable cloud storage with independent credentials, plus a Microsoft 365 backup, with restore tests documented. Our backup and disaster recovery service is built on that model, and the ransomware protection page describes how the layers fit together.
Layer 5: a plan for the day it happens
Even well-defended businesses can be hit. What separates a bad week from a closure is a written plan that answers, in advance:
- Who declares an incident and who leads it. Name the person and their deputy.
- First actions. Disconnect affected devices from the network but leave them powered on. Isolate backups. Preserve the ransom note and any logs. Do not contact the attackers.
- Who to call. Your IT provider, your cyber insurer (most policies require early notification and provide response specialists), and the police via Action Fraud. The NCSC also asks that ransomware incidents are reported to it.
- The 72-hour clock. If personal data was accessed or taken, the ICO must be notified within 72 hours of becoming aware, and affected individuals told if the risk to them is high. Decide in advance who makes that call.
- Communications. What to tell staff, customers and suppliers, and who says it.
- Recovery order. Which systems come back first, from which backup, and how you verify the restored environment is clean before reconnecting it.
- The ransom question. The NCSC and law enforcement advise against paying: there is no guarantee of a working key or of deleted data, it funds further attacks, and sanctions may apply. A business with tested, isolated backups does not need to consider it. Decide your position before the pressure is on.
Cyber insurance deserves a line of its own. A good policy pays for incident response specialists, legal advice, forensic investigation and business interruption, and most insurers will only pay if you notified them promptly and if the controls you declared on the application (MFA, EDR, isolated backups) were actually in place. Read the policy before the incident, keep the claims number in the plan, and answer the application honestly, because an inaccurate declaration is the commonest reason claims are refused.
Rehearse the plan once a year with a tabletop exercise. It takes two hours and it exposes the assumptions ("the backups are fine", "we'd call Dave") that fail on the day. Business continuity planning is where this sits.
What it costs versus what it saves
MFA is included with Microsoft 365. EDR and managed patching are priced per device. Immutable backup storage costs a little more than plain cloud storage. A firewall under support is a few hundred pounds a year. The Cyber Security Breaches Survey finds that the businesses which suffer the most disruptive incidents are those without these basics, and a single week of downtime for a 30-person firm, plus recovery, plus the ICO and customer conversations, costs more than several years of the controls above.
What to do next
If you cannot say with confidence that remote desktop is closed, EDR is on every device, and a backup exists that your own admin account could not delete, find out before an attacker does. An IT health check tests exactly those points and gives you a prioritised, costed list to close the gaps.

