Services

Ransomware Protection and Recovery for UK SMEs

Ransomware is a business continuity problem before it is a technical one. We close the three routes it actually uses, make sure your backups survive the attack, and rehearse the recovery.

ENTRY ROUTES
Phishing, Exposed Services, Suppliers
KEY CONTROL
Tested, Offline or Immutable Backups
REVIEW
Ransomware Readiness Assessment
GUIDANCE
Aligned to NCSC Recommendations
In short

How does ransomware get into a small business?

Almost always through one of three routes: a phished credential used to log into email or remote access, an internet-facing service left unpatched, or a compromised supplier connection. Attacks rarely start with a clever exploit — they start with a login that should not have worked.

The three doors, and how to shut them

Ransomware groups are businesses with cost pressures. They use the cheapest route that works, and for UK SMEs that is nearly always stolen credentials, an exposed remote service, or a trusted supplier connection. Shutting those three doors removes most of your realistic exposure.

The single highest-value control is multi-factor authentication on everything reachable from the internet, without exception and without legacy protocol bypasses. The second is removing internet exposure of remote desktop and unpatched VPN appliances. The third is knowing which suppliers have standing access into your systems, and constraining it.

  • Enforce MFA on email, VPN, remote desktop and every administrative account
  • Remove direct internet exposure of RDP; patch VPN appliances urgently
  • Inventory supplier access and remove standing privileges nobody uses
  • Patch internet-facing systems within days, not quarters
  • Restrict local administrator rights on staff workstations

Backups that survive the attack

Modern ransomware deliberately seeks out and destroys backups before encrypting anything, because that is what forces payment. A backup on a network share, or in a cloud account reachable with the same administrator credentials as everything else, is not a backup — it is another target.

The rule that works is 3-2-1-1: three copies, on two different media, one off-site, and one that is offline or immutable. Then the part almost everyone skips: actually restore from it, on a schedule, and record how long a full restore takes. A backup you have never restored from is a hypothesis.

  • Three copies of data on two media types, one off-site, one offline or immutable
  • Backup credentials separated from normal domain administrator accounts
  • Immutability or object-lock enabled so backups cannot be deleted or encrypted
  • Documented recovery time and recovery point objectives agreed with the business
  • Scheduled restore tests with the results recorded

Limiting the blast radius

Most small business networks are flat: any device can reach any other. That design turns a single infected laptop into a company-wide outage. Segmentation puts boundaries between staff devices, servers, guest Wi-Fi and any operational or card-handling equipment, so an infection is contained where it starts.

Alongside it, removing local administrator rights from everyday accounts and restricting which machines can hold administrative sessions dramatically reduces how far an attacker can move after the first foothold.

  • Separate VLANs for staff, servers, guests and operational technology
  • No local administrator rights for standard user accounts
  • Dedicated administrative accounts, never used for email or browsing
  • Application allow-listing on critical servers where practical
What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Frequently asked questions

Ransomware Protection — your questions answered

Will antivirus stop ransomware?
Not reliably on its own. Modern ransomware operators disable endpoint protection, use legitimate administrative tools, and often log in with valid stolen credentials that antivirus has no reason to flag. Endpoint protection is necessary but must sit alongside MFA, patching, segmentation and recoverable backups.
What is an immutable backup?
A backup that cannot be modified or deleted for a set retention period, even by someone holding administrator credentials. It is the single most effective control against ransomware, because it removes the attacker's ability to destroy your recovery option.
How much does a ransomware attack cost a small business?
The ransom is usually the smaller part. Downtime, rebuilding systems, forensic investigation, legal and ICO handling, staff overtime and lost customers typically dominate. Businesses without tested backups routinely lose one to three weeks of trading capability.
Does cyber insurance cover ransomware?
Many policies do, but cover increasingly depends on control questions you answered on the application — MFA coverage, backup regime, patching cadence. If those answers do not match reality, a claim can be challenged. We help clients evidence the answers they give.
How do we test whether we would survive a ransomware attack?
A readiness assessment plus a live restore test. We simulate the loss of your primary systems, restore from your existing backups, and measure how long it actually takes and what fails. It is the only honest answer to the question.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about ransomware protection?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.