TL;DR:

  • The first 30 minutes matter: isolate affected systems, don’t turn them off, and don’t pay anything yet
  • Report to Action Fraud and the ICO (if personal data was affected) — this is legally required for UK businesses in certain cases
  • Most UK small businesses that recover well do so because of backups, not because they paid the ransom

Ransomware feels catastrophic when it hits. Files encrypted, systems locked, a countdown clock on screen demanding payment. But most UK small businesses that face ransomware do recover — if they act systematically in the first hours and have even basic backup practices in place.

This guide covers what to do, in order, if ransomware hits your business.

In the first 30 minutes

1. Isolate, don’t shut down. The instinct is to switch everything off. Resist it. Powering down can destroy forensic evidence in RAM that might help identify what happened and whether data was exfiltrated. Instead, isolate: disconnect affected machines from the network by unplugging ethernet cables and disabling Wi-Fi. Leave the machines running but disconnected.

2. Identify the scope. Quickly check which machines are affected. Look for the ransom note (usually a text file on the desktop or in encrypted directories) — it often identifies the ransomware variant, which matters for recovery options. Check whether servers, network drives, and cloud-synced folders show encrypted files.

3. Stop the spread. If some machines appear unaffected, keep them that way. Disconnect them from the network too if you’re unsure. Ransomware moves laterally through Windows shares, mapped drives, and Active Directory credentials. Better to isolate clean machines than to discover they’ve also been encrypted.

4. Alert your key people. Call your IT support if you have one, your business owner/director, and anyone who will need to make decisions. Don’t use potentially compromised machines for internal communications — use your mobile.

Who to contact in the UK

Action Fraud: Report at actionfraud.police.uk or by calling 0300 123 2040. UK businesses are expected to report ransomware attacks. Action Fraud connects to the National Cyber Crime Unit (NCCU) and may alert you if your attack variant has a known decryption tool.

The NCSC: The National Cyber Security Centre (ncsc.gov.uk) has a 24/7 incident reporting line for significant incidents. Small business attacks may not meet the threshold for active NCSC response, but reporting adds to threat intelligence and the NCSC website has current guidance on active ransomware campaigns.

The ICO: If your business holds personal data and that data was potentially accessed or exfiltrated, you have 72 hours from discovering the breach to notify the Information Commissioner’s Office under UK GDPR. Ransomware with data exfiltration is a reportable breach. Failure to notify in time can result in fines separate from the ransomware itself. Report at ico.org.uk/make-a-complaint/data-protection-complaints/report-a-personal-data-breach.

Your cyber insurance provider: If you have cyber insurance (and most UK SMBs should), call your insurer early. Many policies have incident response services that include forensics, legal advice, and recovery support. Your policy may also cover ransom payments or recovery costs, but only if you involve the insurer promptly.

Your bank: If the attack may have compromised banking credentials or payment systems, alert your business bank immediately. They can monitor for fraudulent transactions and may be able to reverse recent payments.

Should you pay the ransom?

The NCSC’s official guidance is not to pay, for several reasons:

  • Payment does not guarantee decryption. Many ransomware groups provide decryptors that partially work or don’t work at all.
  • Paying marks you as a paying target. Groups share victim lists, and paying once significantly increases the probability of being targeted again.
  • You may be unknowingly paying sanctioned entities. Several ransomware groups are subject to UK/US financial sanctions — making a payment could expose you to regulatory penalties.
  • Payment funds further criminal activity.

That said, the NCSC acknowledges this is a business decision. If you have no backups, no cyber insurance, and your entire business depends on encrypted data, the calculus changes. Before paying anything, consult your lawyer and your insurer.

If you’re considering payment, the NCSC recommends contacting them first. They may have intelligence on whether the group actually delivers working decryptors.

Recovery from backups

If you have recent, clean backups, recovery is painful but achievable.

Verify the backups are clean first. Check when the ransomware actually began encrypting — the visible attack may have been preceded by weeks of dwell time where attackers had access but hadn’t yet deployed encryption. If your backups were made during that dwell period, they may contain the initial malware or compromised credentials. Use your most recent backup that predates any suspicious activity.

Rebuild, don’t restore in place. Where possible, wipe affected machines and restore to clean hardware or freshly imaged systems rather than trying to clean the encrypted machines. Ransomware can leave persistence mechanisms that survive a file-level restore.

Restore in stages. Bring up critical business systems first — accounting, email, customer-facing services. Don’t restore everything at once.

Change all credentials before reconnecting. Any accounts that existed on affected systems should be considered compromised. Reset passwords for all business accounts, particularly admin accounts, email, and any systems with stored credentials. Enable multi-factor authentication on everything if you haven’t already.

Check for free decryptors

Before paying or declaring total loss, check nomoreransom.org — a joint initiative by EUROPOL, the Dutch Police, and security vendors. It hosts decryption tools for ransomware variants where law enforcement or researchers have recovered the encryption keys. The site currently has tools for over 150 ransomware families.

Upload your encrypted file and ransom note to the ID Ransomware tool (id-ransomware.malwarehunterteam.com) to identify the specific variant, then check whether a decryptor exists.

After recovery: closing the door

Ransomware typically enters through one of three routes: phishing emails, exposed RDP (remote desktop) on the internet, or exploitation of an unpatched vulnerability. Finding and closing the entry point is essential before reconnecting to the internet.

Check your internet-facing attack surface. Use Shodan or ask your IT support to review what’s exposed on your external IP addresses. RDP (port 3389) should never be directly accessible from the internet.

Review email security. If a phishing email was the entry point, review what got through your spam filters and why. Consider adding a DMARC policy to your domain to reduce impersonation of your business in phishing attacks.

Patch immediately. Run Windows Update and update all software, particularly VPN clients, remote access tools, and any internet-facing applications.

Improve your backups. If this attack has demonstrated that your backup situation was insufficient, fix it before the next incident. The 3-2-1 rule: three copies, on two different media, with one copy offsite or offline. Offline or air-gapped backups can’t be encrypted by ransomware.

Getting professional help

For attacks beyond what your internal team can handle, consider engaging a specialist incident response firm. Many cyber insurance policies include access to IR firms — check your policy. The NCSC maintains a list of certified cyber incident response companies at ncsc.gov.uk/section/products-services/incident-response.

Ransomware is serious, but it’s recoverable. The businesses that recover fastest are the ones that have tested their backups, know who to call, and don’t panic into paying a ransom they didn’t need to pay.