Security

Ransomware protection for small businesses: a practical UK checklist

A small office of Windows PCs under a protective glowing dome, with corrupted red blocks bouncing off the outside.
In this article (7 sections)
  1. How a ransomware attack usually unfolds
  2. The small business ransomware checklist
  3. How immutable and versioned backups help
  4. What to do if you're hit by ransomware
  5. Where to find official UK guidance
  6. How EverSafe helps protect small businesses from ransomware
  7. Frequently asked questions

Good ransomware protection for small businesses doesn't need a security team or a big budget. It comes down to a handful of habits that make an attack less likely to succeed, and one thing that makes sure you can recover if it does: backups that ransomware can't reach. This checklist is written for UK businesses with anything from a few PCs to a few dozen, and follows the same principles as the National Cyber Security Centre's (NCSC) guidance, in plain English.

Ransomware is malicious software that encrypts your files and demands payment for the key. Many attacks now also copy data first and threaten to publish it. Small firms are attractive targets because they often have fewer defences, and because losing access to invoices, client files or email for even a few days hurts.

How a ransomware attack usually unfolds

  1. Getting in. Commonly through a phishing email, a password reused from another breached site, remote access left open to the internet, or software that hasn't been updated.
  2. Spreading. Once inside, attackers look for other PCs, servers, shared drives and administrator accounts. This can take hours or weeks.
  3. Going after the backups. Backups are targeted deliberately, because a business that can restore doesn't need to pay. Connected drives, network shares and any backup that an infected PC can change are all at risk.
  4. Stealing and encrypting. Data may be copied out, then files are encrypted and a ransom note appears.

Each stage is a chance to stop the attack or limit the damage, and the checklist below follows the same order.

The small business ransomware checklist

1. Keep Windows and software up to date

Turn on automatic updates for Windows, browsers, Microsoft 365 and anything else that offers them, and restart PCs when asked. Replace software that no longer receives security updates. Windows 10 reached the end of support in October 2025, so PCs still running it should move to Windows 11 or be enrolled in Microsoft's Extended Security Updates.

2. Use strong, unique passwords and multi-factor authentication

Turn on multi-factor authentication (MFA, sometimes called two-step verification) for email, remote access, banking, cloud services and admin accounts. Give everyone a password manager so nobody reuses passwords. Stolen and reused passwords are one of the most common ways in.

3. Lock down remote access

Don't leave Remote Desktop or other remote access tools open directly to the internet. Put them behind a VPN or a remote access service that requires MFA, and switch off access that nobody uses any more.

4. Limit administrator rights

Everyday accounts shouldn't be administrators. If someone clicks something they shouldn't, a standard account limits how far malware can get. Keep admin accounts for admin tasks only.

5. Train staff, and make it easy to report mistakes

Show people what phishing looks like and what to do if they've clicked a link or opened an attachment they're unsure about. The NCSC offers free online cyber security training for staff. Most importantly, make it safe to own up straight away: an early report can be the difference between one infected PC and all of them.

6. Turn on the protection already built into Windows

Make sure Microsoft Defender Antivirus, or another reputable antivirus, is running and up to date on every PC. Windows Security also has a ransomware protection feature called Controlled folder access, which stops unknown programs from changing files in protected folders. It can block legitimate programs too, so try it on one PC before rolling it out.

7. Back up in a way ransomware can't reach

This is the item that decides whether an attack is a bad day or a disaster. The NCSC advises keeping offline backups that are separate from your network and systems, or using a cloud service designed for the purpose, because ransomware actively targets backups. In practice, your backups should be:

  • Versioned: they keep earlier versions, so you can restore files as they were before the attack.
  • Off-site or offline: at least one copy isn't reachable from your network, following the 3-2-1 backup rule.
  • Immutable: stored copies can't be changed or deleted for a set period, even by someone who has your passwords.
  • Kept for long enough: attackers can be inside for days or weeks before they strike, so keep history that reaches well before any likely infection. Our guide to backup frequency and retention helps you choose.
  • Separately secured: the backup account has its own strong password and, where available, MFA, and isn't casually signed in everywhere as an administrator.

8. Test restores and write a recovery plan

Restore some files every few months, and time how long it takes to get a whole PC back. Then write down, on paper as well as on a computer, what happens if you're hit: who to call, which systems to restore first, where backup details and passwords are kept, and how you'll reach staff and customers if email is down. The NCSC's free Exercise in a Box tool lets small teams rehearse this.

9. Consider Cyber Essentials

Cyber Essentials is a government-backed scheme that certifies a set of basic security controls, several of which are on this list. Some public sector bodies and larger customers require it from suppliers, and working through it gives you a useful structure even if you don't certify.

How immutable and versioned backups help

Picture the morning after an attack. Every file on the office PCs and the shared drive has been encrypted, and so has the external backup drive that was plugged into the server. What decides the outcome is whether you have a copy the attackers couldn't touch.

Versioning means your backup holds files as they were yesterday, last week and last month, not only as they are now. When ransomware encrypts a file and the backup picks up the change, the encrypted file simply becomes the newest version. The clean versions are still there.

Immutability goes a step further. Stored backup data is locked so that nobody can alter or delete it for a set period: not the backup software, not an administrator, and not an attacker who has stolen the backup password. Even if someone gets into the backup account, they can't erase your history.

Some backup services add a third layer: noticing when a large number of files change at once, which is typical of ransomware, and automatically protecting the last clean backup so it isn't tidied away while you deal with the incident.

What to do if you're hit by ransomware

  1. Isolate affected devices. Disconnect them from the network by unplugging the cable and turning off Wi-Fi. Don't wipe anything yet.
  2. Get help. Call your IT provider, and your cyber insurer if you have one; many insurers run an incident helpline.
  3. Report it. In England, Wales and Northern Ireland, report to Action Fraud. In Scotland, contact Police Scotland on 101. The NCSC also takes reports of significant incidents.
  4. Consider your data protection duties. If personal data may have been affected, you may need to report a breach to the Information Commissioner's Office (ICO). Under UK GDPR, notifiable breaches must generally be reported within 72 hours of becoming aware of them.
  5. Change passwords from a clean device, starting with email, admin and backup accounts.
  6. Restore from clean backups onto cleaned or rebuilt machines, choosing a restore point from before the infection.

On paying: UK law enforcement doesn't encourage, endorse or condone paying ransoms. Paying doesn't guarantee you'll get your data back, it doesn't remove the malware, and it may mark you out as a business worth attacking again.

Where to find official UK guidance

If you're choosing a backup service as part of this work, our cloud backup buying checklist includes the UK GDPR questions to ask.

How EverSafe helps protect small businesses from ransomware

EverSafe gives each Windows PC an off-site backup designed with ransomware in mind. It keeps version history (hourly versions for the last day, then daily, plus weekly and monthly versions on plans with unlimited versions), and stored copies are immutable for 14 days, so they can't be altered or deleted during that time. If EverSafe sees suspicious mass changes that look like ransomware, it automatically protects the last clean backup for 30 days.

Files are encrypted on each PC with AES-256-GCM before upload, using a key derived from a password your business controls, and you can restore any version, deleted files, or a whole PC's backup onto a replacement machine. See the features or compare plans for multiple devices.

Frequently asked questions

Should a small business pay a ransomware demand?

UK law enforcement doesn't encourage, endorse or condone paying. Paying doesn't guarantee you'll get your files back or that stolen data won't be published, it doesn't remove the attackers from your systems, and it may make you a target again. Reliable, tested backups are what give you the choice not to pay.

Do I have to report a ransomware attack to the ICO?

If personal data may have been affected, you may need to. Under UK GDPR, a personal data breach that's likely to result in a risk to people's rights and freedoms must generally be reported to the ICO within 72 hours of becoming aware of it. The ICO's website has guidance and a self-assessment to help you decide. This is general information, not legal advice.

Can ransomware encrypt my cloud backups?

It can reach any backup that an infected PC can write to or delete, including drives, network shares and some cloud folders. Backups that keep earlier versions, and that store data immutably so it can't be changed or deleted for a set period, stay recoverable even if the PC or the backup password is compromised.

Is antivirus enough to stop ransomware?

Antivirus is an important layer, but it can't catch everything, especially new malware or attacks that use stolen passwords. Combine it with updates, multi-factor authentication, limited admin rights, staff awareness and backups that ransomware can't reach.

How far back should our backups go to recover from ransomware?

Further than you might think. Attackers can be inside a network for days or weeks before encrypting anything, and some files are damaged long before anyone notices. Keep frequent recent versions plus daily versions for at least a few weeks, and longer-term weekly or monthly copies if you can.

Written by the EverSafe Team. First published ; last updated . This guide is general information, not legal or professional advice.