Security Concepts9 min read3 October 2026

What Is Ransomware? A Practical Guide for UK Businesses

Ransomware is the most financially damaging cyber threat facing UK businesses. This guide explains how it works, how it gets in, and what UK organisations can do to reduce their exposure.

By Yrzo AI — UK cybersecurity specialists

The Attack That Stops Everything

Ransomware is malicious software that encrypts the files on infected systems — documents, databases, emails, backups — and demands payment (typically in cryptocurrency) for the decryption key. When a ransomware attack succeeds against a business, the result is usually total operational paralysis: staff cannot access files, systems cannot run, customers cannot be served.

The UK's National Cyber Security Centre (NCSC) describes ransomware as the most significant cyber threat facing UK organisations. It is not hyperbole. In 2023 and 2024, ransomware attacks disrupted NHS trust operations, shut down UK law firms, paralysed logistics companies, and forced manufacturing plants offline. The ransom demand is often the smallest part of the cost — recovery, downtime, reputational damage, and regulatory investigation compound the financial impact significantly.

Understanding how ransomware works, how it gets into organisations, and what makes recovery hard is the starting point for understanding how to defend against it.

How Ransomware Gets In

**Phishing emails** remain the most common initial access vector. An employee receives an email with a malicious attachment (a Word document with macros, a PDF with embedded JavaScript, a ZIP file containing an executable) or a link to a fake login page that harvests credentials. One click on one email is enough.

Modern ransomware attacks rarely encrypt immediately on delivery. The initial access is the start of a multi-stage intrusion. After establishing a foothold, attackers spend days or weeks moving laterally through the network, elevating privileges, identifying backup systems, and maximising the damage they can cause before triggering the encryption.

**Exploiting public-facing vulnerabilities** — internet-facing systems with known vulnerabilities (unpatched VPN gateways, exposed Remote Desktop Protocol, vulnerable web applications) are scanned continuously by automated tools. The Cl0p ransomware group's exploitation of MOVEit Transfer vulnerabilities in 2023 compromised hundreds of UK organisations through a single software vulnerability in a file transfer tool.

**Compromised credentials** — stolen or guessed credentials for remote access systems (VPNs, Citrix, Microsoft Remote Desktop) are sold on dark web markets and used to gain initial access. Organisations without MFA on remote access systems are significantly more exposed.

**Supply chain compromise** — attackers compromise a software vendor or managed service provider and use their legitimate access to customer systems as an entry point. The 2020 SolarWinds attack was the most visible example of this pattern; smaller-scale supply chain attacks occur regularly.

What Happens During an Attack

The timeline of a modern ransomware attack typically looks like this:

**Day 0 — Initial access**: A phishing email is clicked, a credential is used, or a vulnerability is exploited. The attacker has a foothold on one machine.

**Days 1–14 — Reconnaissance and lateral movement**: The attacker explores the network, identifies domain controllers, file servers, and backup systems. They elevate privileges (often to domain administrator level) and deploy remote access tools (RATs, C2 beacons) to maintain persistent access. They identify and either exfiltrate or destroy backup copies.

**Days 14–21 — Data exfiltration**: Before triggering encryption, many ransomware groups exfiltrate sensitive data. This enables double extortion: "pay the ransom to decrypt your files, and pay again or we publish the stolen data on our leak site."

**Trigger day — Encryption**: The ransomware payload is deployed across the network simultaneously. Files are encrypted, ransom notes are left in every directory, and potentially the Master Boot Record of servers is overwritten to prevent startup.

The dwell time — the gap between initial access and encryption — averaged 10 days in 2024 according to incident response data. That window is the detection opportunity most organisations miss.

Why Recovery Is Hard

**Backups are targeted first.** Ransomware operators know that backups are the primary recovery mechanism. Before triggering encryption, they locate and destroy or encrypt online backup copies, shadow volume copies, and any backup agent they can access with the credentials they have compromised. Organisations that discover their backups are also encrypted are in the worst position.

**The decryptor may not work properly.** Even when a ransom is paid and a decryptor is provided, decryption is often slow, incomplete, or causes data corruption. Paying the ransom does not guarantee clean recovery.

**Rebuilding from scratch takes weeks.** For a mid-sized business, rebuilding a domain from clean images, restoring data, and verifying system integrity typically takes two to four weeks of concentrated effort from IT specialists.

**The regulatory clock is running.** If the attack resulted in personal data being accessed or exfiltrated, UK GDPR requires ICO notification within 72 hours of becoming aware of the breach. The ICO has issued fines to organisations that failed to report ransomware incidents involving personal data.

What the NCSC Recommends for UK Businesses

The NCSC's ransomware guidance (available at ncsc.gov.uk) is the authoritative UK source. The key recommendations:

**Offline or immutable backups.** The 3-2-1 rule: three copies of data, on two different media types, with one copy offline (not accessible from the network). An offline backup cannot be encrypted by ransomware. Cloud backup services that maintain immutable versions (versions that cannot be overwritten or deleted for a defined retention period) serve a similar function.

**MFA on all remote access.** VPN, RDP, Citrix, SSH — any remote access to your network should require MFA. This is the single most effective control against the credential-based initial access that enables a majority of ransomware attacks.

**Patching internet-facing systems promptly.** Vulnerabilities in internet-facing systems (VPN appliances, web applications, email gateways) are exploited within days of public disclosure. A patching cadence that applies critical patches within 48–72 hours of release dramatically reduces exposure.

**Network segmentation.** Flat networks where every machine can reach every other machine allow ransomware to spread without restriction. Segmenting the network (separating operational technology from corporate IT, separating high-value systems from general user workstations) limits blast radius.

**Endpoint detection and response (EDR).** Traditional antivirus is ineffective against modern ransomware, which uses legitimate system tools (PowerShell, WMI, PsExec) rather than malware signatures. EDR solutions detect behavioural patterns — lateral movement, credential dumping, bulk file encryption — rather than file signatures.

The Website Security Connection

Ransomware attacks against UK businesses often begin with a compromised web application. A vulnerable web application gives an attacker initial access to a server; from there, lateral movement into the broader network begins. SQL injection, remote code execution via file upload, and credential theft through XSS are all routes from a vulnerable website into the internal network.

Securing your web application reduces one of the most common initial access vectors. Yrzo AI's automated scan tests for the vulnerability classes most commonly exploited for initial access — injection flaws, authentication weaknesses, file upload vulnerabilities, and exposed admin interfaces. It takes under 20 minutes and starts at £99 at yrzoai.dev.

Find out if your website has these vulnerabilities

Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.

Scan your website →