Ransomware is the one cyber threat every business owner has heard of, and the one most consistently misunderstood. The picture in most heads (a hacker choosing a target) is backwards: modern ransomware is an industry that scans everything, breaks in wherever the door is loose, and only afterwards checks who it caught. Small businesses are not beneath its notice; they are its volume market, precisely because their doors are looser and their tolerance for downtime is lower, which makes them likelier to pay.
The encouraging truth hiding inside that grim picture: because the attacks are industrialised, they follow patterns, and a modest set of well-run defences breaks nearly all of them. This guide covers how the attack actually unfolds, the layers that stop it at each stage, and the preparation that turns the worst case from an existential threat into a bad week.
How a ransomware attack actually unfolds
Understanding the sequence is what makes the defences make sense:
- Entry. Overwhelmingly through one of three doors: a phishing email that harvests a password or lands malware, a stolen or reused credential on a service without MFA, or an unpatched vulnerability in something internet-facing.
- Dwell. The intruder does not encrypt on day one. They explore, escalate privileges, and, critically, hunt for your backups, because a business that can restore will not pay. Dwell time runs days to weeks: this is the window where monitoring wins.
- Detonation. Backups deleted or encrypted first, then the estate encrypted, often timed for a weekend or the small hours. Increasingly paired with data theft and a second threat: pay, or the data is published.
- The demand. Priced to what the attacker thinks you can pay, with a countdown for pressure.
Each stage has a defence, and the layers matter precisely because no single one is perfect.
The layers that stop it
Stopping entry
Three controls close the three doors: enforced MFA everywhere (turning stolen passwords into duds), patching within 14 days for high-severity fixes (the same discipline Cyber Essentials demands, because it works), and staff who recognise the approach: not a annual slideshow but ongoing phishing training with simulations, since the humans are door number one.
Catching the dwell
This is where EDR with monitoring earns its place: behavioural detection that flags the exploring intruder (odd logins, privilege changes, unusual tool use) during the days when they are present but not yet destructive. An alert acted on during dwell is an incident report; the same alert unread is a ransom note with a date on it.
Surviving detonation
One arrangement decides whether detonation is survivable: an immutable or offline backup copy that cannot be deleted or encrypted even by an attacker holding your administrator credentials, with restores tested recently enough that you know they work and how long they take. This is the 3-2-1-1-0 discipline, and it is the difference between “we restored over the weekend” and negotiating with criminals. Attackers target backups *because* this is true; protect them accordingly, as a managed Backup as a Service arrangement does by design.
Limiting the blast radius
Two quieter controls shrink what any single compromise can reach: admin accounts separated from daily-use accounts (so the phished user is not also the domain administrator), and sensible network segmentation so one infected laptop cannot see everything the business owns.
Preparing for the day it happens anyway
Honest security planning assumes eventual failure somewhere, and pre-decides the response:
- A written incident response plan: who does what in the first hour, isolate-don’t-power-off as standing instruction, and the notification list: insurer early (policies have requirements), the ICO within 72 hours where personal data is involved, and responders before anyone improvises.
- The ransom decision, considered in advance. Cold reality: payment guarantees nothing, marks you as a payer, and may raise legal complications depending on who is behind the demand. The National Cyber Security Centre’s position is not to pay. The businesses that face this dilemma are the ones without clean backups; the entire strategy above exists so the question never has leverage.
- Cyber insurance that will actually pay. Policies increasingly condition cover on MFA, EDR and tested backups: the controls above are also your claim’s survival kit. Our cyber insurance requirements guide covers what underwriters now check.
What this costs a small business
The complete stack (MFA enforcement, managed patching, monitored EDR at a few pounds per device, immutable backup, training, and the plan) lands within normal managed-support economics: for most SMEs, comfortably under £100 per month beyond basics they should have anyway, and much of it is included in a standard managed support plan rather than additional. Set against recoveries that routinely run into five figures, plus downtime, notification duties and reputational repair, prevention is the cheapest line item in the story.
Frequently asked questions
How do most small businesses get hit by ransomware?
Phishing, credentials without MFA, and unpatched internet-facing systems, in that rough order. Targeting is automated and indiscriminate; small size is exposure, not protection.
Does antivirus stop ransomware?
Traditional antivirus stops known strains and misses fresh ones, which is most of them. Behavioural EDR with someone monitoring it catches the attack pattern itself, including during the pre-encryption dwell period where it is cheapest to stop.
Should a business ever pay the ransom?
Take advice from responders, your insurer and where appropriate law enforcement before any decision; payment guarantees nothing and NCSC guidance is against it. The strategic answer is to make the question irrelevant with immutable, tested backups.
What makes backups ransomware-proof?
Immutability or genuine offline separation: a copy that cannot be altered or deleted from your network even with stolen admin rights, retained long enough to reach behind the attacker’s dwell period, and restore-tested so recovery time is a known number.
How fast can a business recover from ransomware?
With immutable backups, a tested plan and monitored detection: commonly days, sometimes less, depending on estate size and restore speeds you have measured in advance. Without them: weeks, and sometimes never fully.
Is Cyber Essentials enough to stop ransomware?
Its five controls block the standard entry routes, which is most of the battle, and certification forces the hygiene. Add monitored EDR and immutable backup on top and you have covered entry, dwell and detonation: the full chain.
Find your loose door before they do
Every business has a weakest point in this chain; the useful question is whether you know yours. Our free IT health check maps your defences against exactly the stages above (entry controls, detection, backup survivability, response readiness) and prices the gaps plainly. Get in touch; the scan that finds you first should be ours.