top of page

Why Ransomware attacks are growing among SME's and what to do about it

  • Aug 6
  • 4 min read

Updated: 3 days ago

Ransomware attacks are a growing threat to UK businesses, especially small and medium-sized enterprises (SMEs) in regulated sectors such as accountancy, law, and financial services. Recent data from Report Fraud shows that 323 organisations reported ransomware incidents between April 2025 and March 2026, with over half involving SMEs.


Delays in reporting or acting when ransomeware attacks occur can worsen the damage, increase costs, and complicate recovery. Many SMEs hesitate to disclose attacks due to concerns about stigma or losing client trust. This reluctance can lead to:


  • Missed opportunities for early containment

  • Delayed involvement of cyber experts and law enforcement

  • Inadequate communication with regulators and clients

  • Greater risk of data loss or prolonged downtime


For regulated firms, silence can also raise compliance risks. Regulators expect timely notification of cyber incidents, especially when client data or financial information is involved. Failure to report promptly may result in penalties or damage to professional reputation.


Removing this silence means building ransomware plans that make early reporting and decision-making straightforward. Firms should create a culture where incident disclosure is seen as a necessary step towards recovery, not a source of shame.





Practical steps for ransomware planning


1. Ensure reliable offline backups


Backups are the cornerstone of ransomware recovery. Firms must maintain regular, secure backups stored offline or in isolated environments. This protects data from being encrypted or deleted by attackers.


  • Schedule frequent backups of critical systems and client data

  • Test backup restoration regularly to confirm data integrity

  • Keep backups physically separate from the main network to prevent infection spread


Offline backups allow firms to restore operations without paying ransoms, reducing financial and reputational risks.



2. Strengthen access controls and patching


Ransomware often exploits vulnerabilities in software or weak access controls. Firms should:


  • Implement multi-factor authentication for all critical systems

  • Restrict user permissions to the minimum necessary for job roles

  • Apply security patches promptly to close known vulnerabilities

  • Monitor network activity for unusual behaviour that could indicate an attack


These measures reduce the chances of ransomware gaining a foothold and spreading.



3. Review cyber insurance conditions carefully


Many firms rely on cyber insurance to cover ransomware-related costs. However, policies often have specific conditions that must be met for claims to be valid.


  • Understand reporting deadlines and notification requirements

  • Confirm coverage includes ransom payments, forensic investigations, and business interruption

  • Keep documentation of all incident-related actions and communications


Failing to meet insurance conditions can lead to claim denials, leaving firms exposed to significant losses.



4. Define clear decision rights and incident roles


During a ransomware incident, confusion over who decides what can cause costly delays. Firms should establish:


  • A designated incident response team with clear responsibilities

  • Pre-agreed authority levels for decisions such as paying ransom or shutting down systems

  • Contact lists for internal and external stakeholders, including legal counsel and cyber experts


Having these roles defined in advance helps teams act quickly and confidently under pressure.



5. Plan regulator and client communications


Regulated firms must notify authorities and clients about ransomware incidents in a timely and transparent manner. Effective communication plans should:


  • Identify which regulators require notification and within what timeframe

  • Prepare template messages for clients explaining the situation and steps being taken

  • Assign spokespeople trained to handle sensitive communications

  • Keep records of all communications for compliance purposes


Clear communication builds trust and demonstrates professionalism even during crises.



6. Maintain detailed evidence logs


Collecting and preserving evidence during an incident is vital for investigations and potential legal actions. Firms should:


  • Log all system activity related to the attack

  • Record timelines of events and decisions made

  • Securely store copies of ransom notes, emails, and communications with attackers

  • Work with forensic experts to analyse the attack without contaminating evidence


Good evidence management supports regulatory reporting and helps prevent future attacks.



7. Rehearse recovery steps regularly


A ransomware plan is only effective if teams know how to execute it. Firms should conduct regular exercises that simulate ransomware scenarios, including:


  • Detecting and reporting the attack

  • Isolating affected systems

  • Restoring data from backups

  • Communicating with clients and regulators

  • Coordinating with cyber insurers and law enforcement


These rehearsals reveal gaps in the plan and build confidence in the response process.



What leaders should prioritise now


Leaders in regulated SMEs must take ransomware planning seriously. The threat is real and growing, and silence only makes recovery harder. Key priorities include:


  • Reviewing and updating ransomware plans annually

  • Ensuring all staff understand their roles in incident response

  • Investing in secure backup solutions and patch management

  • Engaging cyber insurance brokers to clarify policy details

  • Building relationships with regulators and cyber experts before incidents occur


By taking these steps, firms can reduce the impact of ransomware and meet their regulatory obligations with confidence.



The Main Takeaway


Ransomware incidents are underreported in the UK, especially among SMEs, due to fears of stigma and regulatory consequences. This silence can delay critical decisions and worsen the impact of attacks. Regulated firms must build ransomware plans that encourage early reporting, clear decision-making, and transparent communication with clients and regulators.


Practical steps include securing offline backups, strengthening access controls, understanding cyber insurance conditions, defining decision rights, planning communications, maintaining evidence logs, and rehearsing recovery actions. Leaders should prioritise reviewing these areas regularly to ensure readiness. The key question for every firm is: does your ransomware plan remove the silence and enable swift, confident action when it matters most?



 

Prime Signal helps accountancy, legal and finance firms review AI use, client data, cyber risk, recovery and IT support quality. Request a no-fee IT Risk Review



 
 
Prime-New-Logo-Light.png
ico.1b4b71e0ec72.webp
image.png
tps.57326048e40a.webp

Prime Signal Group Ltd provides B2B data, prospect research and lead generation services. Information submitted through this site is used to respond to enquiries, prepare quotes or samples, and deliver requested services.

©2026 Prime Signal Group Ltd  

Business registration: 17181178

ICO registration: ZC134554

General Enquiries

info@primesignal.co.uk

 

Data Enquiries

data@primesignal.co.uk​​​​​

MSP Enquiries

msp@primesignal.co.uk​​​​​

telephone.png

020 4600 7340

pin.png

167-169 Great Portland Street

London, W1W 5PF

linkedin.png
bottom of page