ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

When ransomware strikes

According to the latest Cyber Security Breaches Survey, only 30% of UK businesses conducted a risk assessment covering cyber-security in the past year, yet 43% experienced a breach or attack in the same period. This means that 70% of businesses are navigating the most volatile threat landscape without a plan.

 

Many of us in the industry appreciate that a ransomware attack is a question of when, not if. Especially now, as AI has democratised and industrialised attacks in a way that allows even low-skilled threat actors to execute sophisticated attacks. Attackers often spend months inside a network before they act, mapping recovery capabilities and identifying backup systems. By the time most organisations know something is wrong, prevention is no longer an option. As a result, recovery is determined by the quality of the structures built before the attack took place.

 

The scale of the problem in the UK is no longer deniable. Nationally significant incidents reported by the NCSC more than doubled in a single year, rising from 89 to 204. In April alone, we saw headlines about attacks on prominent organisations and large financial institutions. Recovery timelines looked different across organisations, and the difference was not based on who was stronger going in; it was in who had invested in recovery after the attack.

 

Against that backdrop, the UK government’s Cyber Security and Resilience Bill has begun its journey through Parliament and is due to enter into force by the end of 2026. Organisations will soon have legal obligations that make ransomware readiness not just operational, but regulatory. 

 

So, what does true ransomware resilience look like in practice?

 

Ransomware resilience

Isolate your recovery environment

If your recovery data lives within the same environment as your production systems, it is exposed to the same exact risks. In an attack, the first target is always backup infrastructure, with experienced threat actors expecting it to be the weakest point.

 

Organisations must maintain copies of critical data, stored separately from the primary network and protected against modification or deletion. This framework treats recovery as a core function, and in the same level as protection or detection stages, reflecting a clear path to restoring operations that does not depend on engaging with attackers.

 

Know your data before you need to recover it

Many organisations have an incomplete understanding of their own data landscape, and many only become aware of this during a breach. Systems, like HR, which may have been assumed to be low priority turn out to underpin critical operations such as workforce scheduling and sensitive staff information.

 

Organisations must understand what data they hold, where it lives, and what its recovery priority should be, before an attack ever takes place. 

 

Define the command structure in advance

A common failure in ransomware response is the lack of clear decision-making hierarchy. Technical teams wait for board authorisation, the board defers to the legal team and legal waits for the insurers, while the attack continues to spread. All of this costs precious seconds in the form of downtime or more data for attacks to download. 

 

To avoid this, incident response plans must define who can isolate systems, who leads external communications and who notifies regulators within the required timeframe. There should be well-documented and rehearsed protocols for backup decision makers if primary responders are unavailable.

 

Limit the impact through access controls

Ransomware often begins with human error like a phishing email or credentials exposed in a third-party breach. Zero trust principles address this at its core. It limits damage through least-privilege access and multi-admin approval for sensitive data, reducing the single points of failure attackers commonly exploit. These controls reduce the risk of breach regardless of individual behaviour.

 

Recovery is not an afterthought; it is the strategy

Organisations that survive ransomware attacks treat recovery infrastructure as seriously as preventative measures. This means backups are tested and not just created, recovery processes are practised, and clear command structures that remove ambiguity during an attack are planned and in place.

 

With the Cyber Security and Resilience Bill advancing through Parliament and mandatory incident reporting obligations on the horizon, resilience is no longer an operational issue. Organisations without structured, tested recovery capabilities risk both operational disruption and the regulatory scrutiny that follows.

 


 

Chris McKean is Technical Solutions Specialist at NetApp

 

Main image courtesy of iStockPhoto.com and Just Super


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543