Ransomware Protection and Recovery for UK SMEs
Ransomware is a business continuity problem before it is a technical one. We close the three routes it actually uses, make sure your backups survive the attack, and rehearse the recovery.
How does ransomware get into a small business?
Almost always through one of three routes: a phished credential used to log into email or remote access, an internet-facing service left unpatched, or a compromised supplier connection. Attacks rarely start with a clever exploit — they start with a login that should not have worked.
The three doors, and how to shut them
Ransomware groups are businesses with cost pressures. They use the cheapest route that works, and for UK SMEs that is nearly always stolen credentials, an exposed remote service, or a trusted supplier connection. Shutting those three doors removes most of your realistic exposure.
The single highest-value control is multi-factor authentication on everything reachable from the internet, without exception and without legacy protocol bypasses. The second is removing internet exposure of remote desktop and unpatched VPN appliances. The third is knowing which suppliers have standing access into your systems, and constraining it.
- Enforce MFA on email, VPN, remote desktop and every administrative account
- Remove direct internet exposure of RDP; patch VPN appliances urgently
- Inventory supplier access and remove standing privileges nobody uses
- Patch internet-facing systems within days, not quarters
- Restrict local administrator rights on staff workstations
Backups that survive the attack
Modern ransomware deliberately seeks out and destroys backups before encrypting anything, because that is what forces payment. A backup on a network share, or in a cloud account reachable with the same administrator credentials as everything else, is not a backup — it is another target.
The rule that works is 3-2-1-1: three copies, on two different media, one off-site, and one that is offline or immutable. Then the part almost everyone skips: actually restore from it, on a schedule, and record how long a full restore takes. A backup you have never restored from is a hypothesis.
- Three copies of data on two media types, one off-site, one offline or immutable
- Backup credentials separated from normal domain administrator accounts
- Immutability or object-lock enabled so backups cannot be deleted or encrypted
- Documented recovery time and recovery point objectives agreed with the business
- Scheduled restore tests with the results recorded
Limiting the blast radius
Most small business networks are flat: any device can reach any other. That design turns a single infected laptop into a company-wide outage. Segmentation puts boundaries between staff devices, servers, guest Wi-Fi and any operational or card-handling equipment, so an infection is contained where it starts.
Alongside it, removing local administrator rights from everyday accounts and restricting which machines can hold administrative sessions dramatically reduces how far an attacker can move after the first foothold.
- Separate VLANs for staff, servers, guests and operational technology
- No local administrator rights for standard user accounts
- Dedicated administrative accounts, never used for email or browsing
- Application allow-listing on critical servers where practical
Included in every engagement
Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.
Ransomware Protection — your questions answered
Will antivirus stop ransomware?
What is an immutable backup?
How much does a ransomware attack cost a small business?
Does cyber insurance cover ransomware?
How do we test whether we would survive a ransomware attack?
Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.
You might also need
Ready to talk about ransomware protection?
Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.