Cyber Security Guide · 10 May 2026
Ransomware defence playbook for UK SMEs
A practical 10-control playbook to reduce ransomware risk and recover quickly if you're hit.

Ransomware is the single biggest existential risk to UK SMEs. The good news: the controls that work are well understood, and none of them are exotic.
Ten controls that actually reduce risk
- Phishing-resistant MFA on every account
- EDR on every endpoint and server, monitored 24/7
- Aggressive patching for internet-facing systems
- Least-privilege access and no permanent local admins
- Segmented network with restricted east-west traffic
- Email filtering with attachment sandboxing
- DNS-layer filtering to block command-and-control
- Immutable, offline backups tested monthly
- A written incident response plan people have rehearsed
- Cyber insurance that reflects the controls you actually have
If you're hit
- Isolate affected systems immediately - don't power them off
- Engage your incident response retainer and insurer within the hour
- Preserve logs and images for forensics
- Communicate with staff, customers and the ICO on a clear timeline
Recovery
The organisations that recover cleanly are the ones with tested backups and a rehearsed plan. Assume you will be tested at some point - and make sure the first time you run the plan isn't in a real incident.
