If you run a local business, ransomware probably isn’t at the top of your worry list. It should be. Attacks on small businesses are rising fast, and the fallout can shut down operations for days or longer. Let’s take a closer look at how these attacks work and what you can do to stop them.
What Ransomware Actually Is
Ransomware is a type of malicious software that locks you out of your own files. Criminals get into your network, encrypt your data so you can’t open it, then demand a payment (usually in cryptocurrency) for the key to unlock it. Until you pay or restore from a backup, your systems are frozen, so no invoicing, no customer records, no access to the files you run the business on.
Many groups now go a step further. They steal a copy of your data before they encrypt it and threaten to publish it if you don’t pay, which is known as double extortion. That means even a business with solid backups can be held to ransom, because the threat isn’t just losing your files, it’s having client data leaked.
Why Small Businesses Are Prime Targets
There’s a common assumption that cybercriminals only go after large corporations with deep pockets. In reality, small businesses are easier to hit. They tend to have fewer security measures, smaller IT budgets and staff who haven’t been trained to spot threats. That combination makes them attractive targets.
The UK’s Cyber Security Breaches Survey 2025 found that the number of businesses hit by ransomware doubled in a year to around 19,000, and smaller firms remain the softer target thanks to lighter defences and less staff training.
Healthcare practices, solicitors’ offices, accountancy firms and local retailers are all in the firing line. For a business with 10 employees, losing access to customer records, invoices and financial data for even a few days can mean missed deadlines, lost revenue and damaged client trust.
How Ransomware Actually Gets In
Most ransomware doesn’t arrive through some sophisticated hack. It comes through an email. A staff member clicks a link in what looks like a legitimate message, downloads an attachment or enters their login details on a fake website. That’s all it takes.
Phishing emails have become harder to spot. They’ll mimic suppliers, banks or even government agencies. Once the malware is on your network, it encrypts your files and demands a payment to unlock them. Some variants will also steal data before encrypting it, giving attackers extra leverage.
Other common entry points include outdated software with known vulnerabilities and weak or reused passwords. If your business still runs old versions of Windows or hasn’t updated its accounting software in months, you’re leaving the door open.
Step-by-Step Guide to Protect Your Business
You don’t need a massive IT budget to reduce your risk significantly. A few sensible measures will go a long way.
- Keep software updated. Every update you skip is a potential gap in your defences. Set operating systems, browsers and business applications to update automatically where possible. This applies to routers and firewalls too.
- Train your staff. Your team spots most attacks before your software does, but only if they know what to look for. Run short, regular sessions on how to recognise phishing emails. Teach them to check sender addresses carefully, avoid clicking unexpected links and report anything suspicious.
- Use strong passwords and two-factor authentication. Weak passwords are one of the easiest ways in for attackers. Use a password manager to generate and store unique passwords for every account, and turn on two-factor authentication wherever it’s available.
- Back up your critical files. Regular backups are your safety net if the worst happens. The NCSC’s advice is clear: keep at least one recent backup offline, so ransomware on your network can’t reach it. Encrypted cloud storage services are now becoming essential as a second layer. Aim to back up at least daily and test your restores now and then to make sure they actually work.
What to Do If You’re Hit
If ransomware does get through, don’t panic. Disconnect the affected machines from your network immediately to stop the malware spreading further. Don’t try to fix it yourself unless you have genuine expertise.
Report the attack straight away. In the UK, call Report Fraud on 0300 123 2040 and press 9, which runs a 24/7 line for businesses under active cyber attack, and notify the NCSC. If personal data has been exposed, you’re also legally required to consider reporting to the Information Commissioner’s Office within 72 hours. Contact your insurance provider too if you have cyber liability cover.
The NCSC, National Crime Agency and ICO all advise against paying the ransom. There’s no guarantee you’ll get your files back, paying funds further criminal activity, and the ICO has made clear that payment won’t reduce any enforcement action against you. Businesses that pay are also more likely to be targeted again.
Your Best Defence Starts Before the Attack
Ransomware thrives on unpreparedness. The businesses that recover quickly are the ones that had backups in place, staff who knew the warning signs and systems that were kept up to date. None of these steps require specialist knowledge or a big budget. They just need to be done consistently. If you haven’t reviewed your business’s security recently, this week is a good time to start.