All systems operational London · UK
Mon–Sat 10:00–18:00 ☎ 0207 096 0936
← Guides
Cyber Security

How to Protect Your Small Business from Ransomware

Ransomware doesn't only hit big corporations — small UK firms are now the easiest targets. Here's a plain-English guide to the defences that actually stop it.

Ransomware is the type of cyber-attack that keeps business owners up at night, and rightly so. It encrypts every file it can reach — your accounts, your client records, your emails — then demands a payment to unlock them. For a small firm, a bad attack isn’t an inconvenience; it can be the difference between trading and not.

The dangerous myth is that this is a big-company problem. It’s the opposite. Attackers know that large corporations have security teams, and that small businesses often don’t. Most ransomware today isn’t a targeted hit by a criminal mastermind — it’s automated, scanning the internet for any business with a weak password or an unpatched system. A ten-person accountancy practice in Croydon is a far easier target than a bank, and just as likely to pay.

The good news: the defences that stop the overwhelming majority of attacks are neither exotic nor expensive. They’re mostly about doing a handful of unglamorous things properly.

How ransomware actually gets in

Understanding the front door helps you lock it. Attacks almost always start in one of three ways:

  • A stolen or guessed password — often reused from a personal account that was leaked in a breach elsewhere. The attacker simply logs in as a member of your staff.
  • A convincing email — a fake invoice, a “your account is suspended” warning, a shared document that isn’t what it claims. One click, one downloaded file, and the attacker has a foothold.
  • An unpatched system — a server, firewall or PC running software with a known flaw the vendor has already fixed, but which nobody has updated.

Notice what’s not on that list: some brilliant, unstoppable hacking technique. Nearly every real-world attack on a small business exploits an ordinary, preventable weakness.

The defences that genuinely work

1. Multi-factor authentication (MFA), everywhere

If you do only one thing this week, do this. MFA means a password alone isn’t enough to log in — a code from a phone app is also required. It single-handedly blocks the most common attack of all: someone logging in with a stolen password. Turn it on for email, for Microsoft 365, for remote access, for everything that faces the internet.

2. Tested, offline backups

Backups are what turn a catastrophe into an afternoon of annoyance. If your data is safely copied somewhere the ransomware can’t reach, you can wipe the infected machines and restore — no ransom, no negotiation. But two things matter enormously:

  • The backup must be offline or otherwise isolated, so the attack can’t encrypt your backups too. A backup sitting on the same network, permanently connected, is often encrypted right alongside everything else.
  • The backup must be tested. An untested backup is a hope, not a plan. We regularly meet businesses whose “backups” hadn’t actually worked for months. Proper backup and continuity means someone verifies a real restore on a schedule.

3. Keep everything patched

Every update you keep clicking “remind me later” on is potentially the exact hole an attacker walks through. Operating systems, applications, firewalls, and especially anything that allows remote access — all need updating promptly. This is dull, which is precisely why it gets neglected, and precisely why attackers rely on it.

4. Filter email and train your team

Since so many attacks begin with an email, good filtering removes a large chunk of the risk before it reaches an inbox. The rest comes down to people. Your staff don’t need to become security experts — they need to know the handful of warning signs, and to feel able to ask “does this look right?” without fear of looking silly. A five-minute conversation has stopped more attacks than most software.

5. Limit who can access what

Not everyone needs administrator rights or access to every folder. The more limited each account is, the less damage any single compromised login can do. If reception’s PC is infected, it shouldn’t be able to reach your entire finance archive.

What to do if you’re hit

Even with good defences, it pays to know the drill:

  1. Disconnect immediately — unplug the affected machine from the network (and Wi-Fi) to stop it spreading. Don’t turn it off if you can avoid it; it may hold useful evidence.
  2. Don’t pay yet, and don’t panic — call your IT support. If your backups are sound, you have options.
  3. Report it — ransomware should be reported to Action Fraud, and if personal data is involved you may have obligations to the ICO within 72 hours.
  4. Restore from clean backups once the infection is contained and the entry point is closed — otherwise you’ll simply be reinfected.

The honest summary

You don’t need a fortune or a full-time security team to be genuinely hard to attack. You need multi-factor authentication turned on, backups that are isolated and tested, systems that are kept up to date, sensible email filtering, and a team that knows what a dodgy email looks like. That combination stops the vast majority of attacks that ever reach a small business.

The catch is that “set up properly and kept up to date” is doing a lot of work in that sentence — it’s the part that quietly slips when everyone’s busy running the actual business. That’s exactly the sort of thing a good managed IT support arrangement exists to own, so it’s handled quietly in the background rather than remembered in a crisis.

If you’re not sure where your business stands, we’re happy to take a look and tell you straight — no scare tactics, just a clear picture of your real risks and what’s worth fixing first.

Frequently asked questions

Will antivirus alone protect us from ransomware?

No. Antivirus catches known threats, but modern ransomware often arrives through a stolen password or a convincing email that no antivirus will flag. It's one layer of several — you also need multi-factor authentication, tested backups, patching and staff awareness.

Should we ever pay the ransom?

Paying is a last resort with no guarantees — many businesses pay and still don't get usable data back, and it marks you as a firm that pays. UK guidance is not to pay. With tested, offline backups you almost never need to consider it, which is exactly why backups are the single most important defence.

How much does ransomware protection cost for a small business?

Most of the core defences — multi-factor authentication, patching, sensible email filtering — are configuration rather than expensive products, so the cost is mostly getting them set up correctly. A managed IT provider will typically fold all of this into a monthly per-user support plan.

Related services

Free · no obligation

Want a hand with any of this?

Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.