Ransomware attacks on UK small businesses have increased significantly in recent years. They're no longer the preserve of large enterprises - attackers increasingly target smaller organisations precisely because their defences tend to be weaker and their need to recover quickly is acute.
What does it actually look like when it happens? Here's a realistic account of how a ransomware incident unfolds - and how a well-prepared business, with the right IT partner and backup strategy, recovers from it.
The First Call
It usually starts with a panicked call or ticket early in the morning - often from someone who has arrived at the office and found files they can't open, a desktop background replaced with a ransom note, or multiple machines showing errors simultaneously.
The first questions we ask are always the same:
- How many machines appear to be affected?
- Are any servers involved, or is it isolated to workstations?
- Is the network still active - are devices still able to communicate?
- Has anyone clicked on an unusual link or opened a suspicious email in the last 24–48 hours?
The priority in the first five minutes is containment. Every second the ransomware continues running, it encrypts more files. Isolating affected machines - disconnecting them from the network, either physically or via a managed switch - stops the spread.
Critical: Do not turn off affected machines immediately. In some ransomware variants, a hard shutdown can make recovery harder or impossible. Contact your IT provider first before taking any action.
Hours 1–4: Assessment and Isolation
Once the immediate spread is contained, the assessment phase begins:
Identifying the variant
Understanding which ransomware family is involved matters. Different variants have different characteristics - some have known decryption keys published by security researchers; others do not. Sites like No More Ransom (a joint initiative by Europol and security vendors) maintain a database of decryptors.
Identifying the entry point
How did the attacker get in? Common entry points include:
- Phishing email with a malicious attachment or link
- Compromised credentials used to access Remote Desktop Protocol (RDP)
- Unpatched vulnerability in a public-facing application or VPN
- Malicious software downloaded from an unofficial source
Identifying the entry point isn't just forensic curiosity - you need to close it before you restore anything, or the attacker will simply re-enter.
Assessing the backup situation
This is the pivotal moment. Everything from here depends on the answer to one question: do you have clean, recoverable backups that weren't also encrypted?
Why Backups Are the Only Real Answer
There are only three ways to recover from ransomware if no decryptor is available:
- Restore from backup
- Pay the ransom (not recommended - no guarantee of recovery, funds criminal activity)
- Accept the data loss and rebuild
Option 1 is the only acceptable business outcome. But here's the crucial detail: not all backups survive a ransomware attack.
Standard backup solutions that store copies on the same network, or that are continuously connected to the network, can be encrypted by ransomware just like any other file. Attackers often wait days or weeks after initial infection before triggering the encryption - specifically to ensure backup versions are also compromised.
What you need is:
- Immutable backups - copies that cannot be modified or deleted, even by an admin account. Cloud providers like Veeam, Datto and Acronis offer this.
- Air-gapped copies - backup copies that are physically or logically isolated from the live network
- Multiple retention points - the ability to restore to a point in time before the infection, not just the most recent backup
- Separate Microsoft 365 backup - Microsoft's own recycle bin and version history are not a backup solution. You need a dedicated third-party M365 backup tool.
Hours 4–24: Recovery Planning
Once the environment is isolated and backup viability is confirmed, recovery planning begins. This involves decisions about:
- Whether to restore to existing hardware or build a clean environment and migrate data across
- Prioritisation - which systems does the business need first to resume operations?
- Communication - who needs to be told, including customers, suppliers, insurers, and potentially the ICO
Reporting obligations
Under UK GDPR, if the attack has resulted in a personal data breach, you must report it to the Information Commissioner's Office (ICO) within 72 hours of becoming aware. This is a legal obligation, not optional - and the consequences of failing to report can be worse than the incident itself.
Recovery: Real Timelines
Recovery timelines vary enormously depending on the scale of the attack and quality of backups. As a rough guide:
| Scenario | Approximate recovery time |
|---|---|
| Single workstation, good backups | 4–8 hours |
| Multiple workstations, no servers affected | 1–2 days |
| Server affected, good immutable backup | 1–3 days |
| Server affected, backup also compromised | 1–2 weeks (rebuild) |
| Full network encryption, no usable backup | Weeks to months |
The difference between the first row and the last is almost entirely down to backup quality.
What Happens After Recovery
Recovery isn't the end. After restoring systems, any responsible IT response includes:
- Full security audit of the environment - patching, configuration hardening, access review
- Password reset for all accounts (attackers often harvest credentials during dwell time)
- MFA enforcement across all systems
- Staff awareness training - particularly if phishing was the entry point
- Review and update of backup strategy based on lessons learned
The Uncomfortable Truth About Prevention
Most ransomware attacks are preventable. The NCSC's own data consistently shows that the majority of successful attacks exploit known vulnerabilities that had available patches, or use credentials obtained through phishing - both of which are addressable with relatively modest investment in security hygiene.
Cyber Essentials certification, implemented properly, addresses the vast majority of common attack vectors. Read our guide to Cyber Essentials for more detail.
If you're not sure whether your current backup solution would actually protect you in a ransomware scenario, contact CloudHost. We'll review your setup honestly and tell you where the gaps are - before they become a crisis.