In short: Ransomware is malicious software that can lock devices or deny access to data, and businesses need to understand how attacks develop to reduce disruption and recover essential services. Attackers may also steal information, compromise accounts and threaten publication to increase pressure for payment. Layered measures such as secure configuration, access controls, timely updates, protected backups, monitoring, incident preparation and role-relevant employee awareness can reduce the likelihood and impact of an attack.
Ransomware: What It Is and How Businesses Can Reduce the Risk and Impact

Why Does Ransomware Require a Business-Wide Response?
Ransomware is one of several types of cyber attack, but reducing its likelihood and limiting its impact require coordinated action across technology, supplier management, data protection, incident response and workforce practices. Understanding the routes into a business, the stages of an attack and the demands of recovery helps leaders select proportionate controls and prepare people to act.
The National Cyber Security Centre provides guidance for organisations on ransomware prevention, monitoring, response and recovery (NCSC, 2026a).
An effective response must reflect the organisation’s systems, third-party services, data-sharing arrangements and working practices. Technical safeguards, recovery planning and informed employee action must work together.
How Does a Ransomware Attack Work?
There is no fixed sequence that every ransomware incident follows. One attack may move quickly from initial compromise to encryption. Another may involve a longer period of unauthorised access, account compromise and data theft before the organisation sees any obvious disruption.
- Initial Access: An attacker gains a foothold through a compromised account, vulnerable service, malicious message, exposed remote-access route or another weakness.
- Access Expands: The attacker may seek additional privileges, use trusted accounts or move to connected systems. Expanded access can increase the number of services and data sets within reach.
- Systems and Data Are Accessed: Information may be located, copied or removed. Attackers can steal data before the organisation knows that ransomware is involved.
- Disruption Follows: Systems or data may be encrypted, deleted or otherwise made unavailable. Some attacks also damage infrastructure or recovery mechanisms.
- Extortion Adds Pressure: The organisation may receive a payment demand, a threat to publish stolen information or both, while teams are trying to understand the incident and restore essential services.
A five-stage ransomware progression is only one possible attack pattern. The NCSC advises organisations to use layered defences because malicious software can reach a device despite preventive controls. Layered defences create more opportunities to detect activity, restrict its spread and reduce harm (NCSC, 2021).
How Does Ransomware Get Into a Business?
Ransomware does not have one entry point. Phishing and other malicious messages are possible routes, but treating every ransomware attack as an email failure leaves other exposures unaddressed. Attackers can use stolen or reused credentials, particularly where accounts lack appropriate multi-factor authentication. Weakly protected remote-access services, internet-facing devices and known vulnerabilities that have not been patched can also provide access.
A legitimate account or device may be compromised first. Supplier access and trusted connections can provide a route into another organisation, so ransomware risk should also be considered in procurement, supplier assurance and access reviews. UK government guidance on supply-chain resilience identifies service interruption, data loss, interconnected systems and privileged supplier access as material concerns (Home Office, 2025).
Prevention cannot sit with one team. IT may manage vulnerabilities, remote access and system configuration. Managers define approved processes and escalation routes. Procurement, service owners and IT or security teams should coordinate supplier access and remove it when it is no longer required. Employees need clear expectations for credentials, software, devices and reporting. Detailed password security guidance is useful, but stronger passwords alone do not protect an exposed service, an over-privileged account or an unpatched device.
What Happens During a Ransomware Attack?
The immediate effect may be loss of access to systems, records and operational data. Staff may be unable to serve customers, schedule work, process orders or use normal communications. Temporary processes may keep some activity moving, but they can be slower and may create additional operational, safety or data-quality risks.
Recovery may require more than restoring files from backup. Teams may have to rebuild devices and servers, confirm that attackers no longer have access, validate the integrity of data and restore services in a safe order. Dependencies matter. A sound backup is of limited use if the organisation has no clean infrastructure on which to restore it or if a critical application is no longer supported.
Data theft may need to be managed separately from operational recovery. A ransomware incident may amount to a personal data breach, but not every incident is automatically reportable to the Information Commissioner’s Office. The organisation must assess the risk to people’s rights and freedoms. A notifiable breach must be reported within 72 hours of becoming aware of it, where feasible, and affected individuals must be told without undue delay where the risk is high (ICO, 2025). Data-protection procedures should be linked to the incident plan so that breach assessment and notification begin promptly when personal data may be affected.
Effects can also spread to customers and suppliers. Where one organisation delivers a critical service to others, its outage can become their operational problem. Financial and reputational consequences vary with the systems affected, the information exposed, the duration of disruption and the organisation’s ability to recover and communicate.
What Are Some UK Ransomware Examples?
The British Library
The British Library identified a major ransomware attack on 28 October 2023. Its incident review reported that attackers copied about 600 GB of files, encrypted data and systems and destroyed some servers. Secure copies of its digital collections and metadata existed, but recovery was held back by the loss of viable infrastructure and a complex legacy environment. Research services were severely restricted during the first two months, while some systems could not be restored in their previous form (British Library, 2024).
The Library had usable backup copies, yet restoration still depended on rebuilding suitable infrastructure. Recoverability also depends on supported applications, system dependencies and the order in which services can be brought back.
Synnovis and Connected Health Services
A ransomware attack on pathology supplier Synnovis in June 2024 disrupted services across several hospitals. Government supply-chain guidance records that 10,152 acute outpatient appointments and 1,710 elective procedures were disrupted at the two NHS trusts most affected by the incident during the following four months (Home Office, 2025). The figures show how disruption at one supplier can continue across connected organisations long after the initial incident.
How Can Businesses Reduce Ransomware Risk and Impact?
Ransomware resilience combines controls that reduce opportunities for compromise, restrict what an attacker can reach, preserve the ability to recover and prepare the organisation to respond. The mix should reflect the size of the business, its services, systems, threat exposure, legal duties and available expertise.
Reduce Opportunities for Initial Compromise
A business needs a current view of the devices, software, services and accounts it depends on. That makes it possible to identify unsupported products, apply security updates and respond quickly when a serious vulnerability becomes known. Internet-facing and remote-access services need particular attention because they can be reached without an attacker first entering the workplace.
Multi-factor authentication should protect appropriate accounts and remote-access points. Secure configuration, email and web filtering, and device protection add further barriers. Supplier connections should be limited to what the service requires and reviewed when roles or contracts change. Managed providers may handle some of this work for smaller organisations, but the organisation still needs to know what the provider covers and how incidents will be escalated.
Limit What Compromised Access Can Reach
An attacker who reaches one account or device should not automatically gain access to everything else. Give people and services only the permissions they need. Separate routine accounts from administrative accounts, and do not use privileged accounts for normal email or web browsing. Review access regularly and remove rights that are no longer required.
Appropriate separation between systems can make it more difficult for an attacker to move between them and can reduce the scale of disruption. Connections between systems should be necessary, restricted and monitored, and they should be removed when they are no longer required.
Keep Important Data and Services Recoverable
Backups support recovery. They do not prevent initial access, data theft or service interruption. Keep multiple suitable copies of important files and data, using different storage locations or solutions. At least some copies should be separated from the live environment or stored in a service that protects earlier versions. Backup administration needs strong access controls because attackers may target recovery systems before causing visible disruption.
Test restoration rather than assuming it will work. A useful test confirms that data can be restored, systems can be rebuilt and critical services can return in a safe order. It should identify dependencies on identity services, networks, cloud platforms, suppliers and unsupported applications. The British Library case demonstrates why the existence of data copies and the ability to restore an operational service are different questions.
Strengthen Detection and Incident Preparation
Logging, monitoring and endpoint protections should be proportionate to the organisation’s exposure and operating model. They can provide warning of unusual activity and information needed to understand what happened. Technical safeguards should be backed by clear incident roles, defined decision-making responsibilities and access to qualified external support.
Essential contacts, checklists and recovery priorities must remain available if normal systems are unavailable. The incident plan should cover internal and external communications, regulatory and contractual reporting and supplier coordination, and identify the minimum level of service needed to resume essential operations. Exercising the plan exposes unclear ownership and unrealistic assumptions while there is still time to correct them. The cyber security policy should assign incident response ownership, while the incident response plan or playbook should document contacts, recovery priorities and tested procedures.
Support Safer Decisions and Early Reporting
Employees need role-relevant guidance on suspicious activity, credentials, approved software, devices, data handling and remote access. The reporting process must be simple to use and trusted by employees. If people expect blame after clicking a link or making a mistake, they may delay the report that allows technical teams to act early.
Training is therefore one control within the system. It can improve understanding and reinforce expected behaviour, while filtering, access control, patching, endpoint protection, backups and response processes reduce the consequences if an attacker gains access through a malicious message or another route.
What Should Employees Know About Ransomware?
Employees without incident-response responsibilities do not need to investigate malware or understand how ransomware is engineered. They need to know what the organisation expects them to do and where to report suspicious activity or unusual system behaviour.
- Use approved account and authentication procedures, including multi-factor authentication where required.
- Treat unexpected login prompts, requests to download files and changes to normal processes as reasons to pause and verify.
- Follow approved rules for software, devices, data handling and remote access.
- Report suspicious messages, mistakes and unusual system behaviour promptly through the agreed route.
- Leave containment and technical investigation to the people responsible for incident response.
Not every malicious message is obvious, particularly when it uses familiar names or normal work pressures. NCSC guidance says training cannot teach users to spot every phishing attempt and warns against blame-led reporting cultures. A clear, quick reporting process gives the organisation information it can act on (NCSC, 2024).
What Should a Business Do If Ransomware Is Suspected?
Activate the incident response procedure and establish who is leading the technical, operational and management decisions. Escalate promptly to the appropriate internal teams and qualified external specialists. Where relevant, an NCSC-assured Cyber Incident Response provider can offer specialist support.
Containment should follow the plan and specialist advice. Disconnecting systems from networks can limit further spread and preserve evidence, while powering them down may remove valuable evidence and make the incident harder to understand. The decision has to balance containment, safety, operational impact and investigation needs (NCSC, 2026b).
Establish a central record of what has been discovered, what decisions have been made, what actions have been agreed and who is responsible for each action. Identify critical services, affected accounts or systems, dependencies and the condition of backups. Recovery should prioritise restoring the minimum level of service needed for safe operations rather than attempting to restore everything at once.
Assess each reporting obligation. The government’s cyber incident reporting service directs organisations to the appropriate UK route, but reporting to the NCSC does not fulfil separate legal or regulatory duties (NCSC, 2026b). Where personal data is involved, the business must separately assess whether ICO notification is required. Sector rules, contracts or insurance terms may create additional requirements.
The UK government does not encourage or condone ransom payments, and payment does not guarantee access to data or systems. Under UK financial sanctions, making funds or cryptoassets available directly or indirectly to a person subject to an asset freeze is prohibited. An organisation considering payment should report the incident promptly and seek independent legal advice (OFSI, 2026).
How Can a Business Build Ransomware Resilience?
Ransomware resilience depends on technical controls, data that can be restored, clear decision-making responsibilities and a rehearsed incident response plan. Access restrictions and monitoring help contain a compromise, while protected backups and restoration testing support the safe recovery of essential services. Employee awareness supports safer day-to-day decisions and early reporting alongside these technical and recovery controls.
How Can Human Focus Support Ransomware Awareness?
Human Focus Cyber Security Awareness Training covers common cyber threats, password and multi-factor authentication practices, suspicious messages, safer online behaviour and reporting responsibilities.
Technical protection, monitoring, backups and incident response remain separate organisational controls.




















