Why small firms are a target, not an afterthought
There’s a persistent myth that ransomware only hits hospitals, councils and household-name companies. In reality, small businesses are attractive precisely because they tend to run without dedicated IT, patch slowly and back up inconsistently. Attackers don’t need to pick you personally — most ransomware arrives through automated, opportunistic campaigns that scan for any machine with a weak point. A five-person accountancy practice or a busy dental surgery is just as reachable as a large firm, and often far easier to compromise.
The damage isn’t only the ransom demand. It’s the days of downtime, the lost invoicing and client records, the awkward conversations with customers about their data, and the possible reporting obligation to the ICO. For a small business, that disruption alone can be more costly than the ransom itself.
How ransomware actually gets in
Understanding the entry routes is the whole game, because nearly all of them are things you can close off cheaply. In the machines we see in the workshop, the common ways in are:
- Phishing emails. By far the most frequent. A convincing message with a malicious attachment or link — a fake invoice, a “failed delivery”, a shared document that asks you to sign in.
- Weak or reused passwords on remote access. If you have Remote Desktop exposed to the internet, or staff reusing the same password everywhere, attackers can simply log in.
- Unpatched software. Old versions of Windows, browsers, VPN appliances and plugins carry known holes that automated tools exploit.
- Compromised credentials. Passwords leaked in unrelated breaches get tried against your email and cloud accounts.
Notice that none of these needs a sophisticated hacker. They rely on ordinary human habits and neglected maintenance — which is good news, because it means ordinary discipline defends against them.
The realistic defences that fit an SME budget
You don’t need an enterprise security budget. You need a handful of measures applied consistently. In rough order of impact for the money:
Turn on multi-factor authentication (MFA) everywhere. This is the single highest-value step. Even if a password leaks, MFA stops the login. Enable it on email, cloud storage and any remote access — it’s free on most platforms and takes minutes per account.
Keep everything updated. Enable automatic updates for Windows, browsers and business applications. Retire any machine still on an unsupported version of Windows, because it stops receiving the security fixes that block these attacks.
Close off remote access. Never expose Remote Desktop directly to the internet. If staff work remotely, put it behind a proper VPN or a managed access tool, and protect it with MFA.
Use reputable, centrally managed security software. The built-in Microsoft Defender is genuinely capable for many small firms; the priority is that it’s switched on, updating, and someone is actually watching the alerts.
Limit who has administrator rights. Day-to-day accounts should be standard users. Ransomware run by a limited account can do far less damage than one run as an administrator.
Train your team. Ten minutes explaining how to spot a suspicious email, and a clear “when in doubt, ask” culture, prevents more incidents than any product. Getting your email onto a properly configured platform — a clean Microsoft 365 setup with spam filtering and MFA enforced — removes a large slice of the risk before it reaches anyone’s inbox.
Pulling these together into a coherent plan is what our cybersecurity work for local firms is really about: not selling you a magic box, but closing the doors attackers actually use.
Why tested backups are your real last line of defence
Every defence above reduces the chance of infection. None of them makes it zero. That’s why your backup is the measure that decides whether a ransomware hit is an afternoon’s inconvenience or an existential crisis. If you can wipe the affected machines and restore clean data, the attacker has nothing to sell you.
But a backup only counts if it survives the attack and actually restores. Two failures we see repeatedly:
- The backup was connected and got encrypted too. Modern ransomware deliberately hunts for attached drives and synced cloud folders. Your backup needs at least one copy that’s offline or otherwise isolated — versioned cloud storage or a rotated drive that isn’t permanently plugged in.
- Nobody ever tested a restore. A backup you’ve never restored from is a hope, not a plan. At least once a quarter, actually recover a few files — and ideally a whole machine — to prove it works and to time how long it takes.
Proper, isolated, regularly tested backup solutions are the difference between shrugging off an attack and paying a criminal. If you set up nothing else this month, set up this.
Where to start
If you’re not sure how exposed you are, start with the basics: switch on MFA today, confirm your machines are fully updated, and check whether your backup includes a copy that ransomware can’t reach.
If you’d like a hand hardening your setup — or a straight review of your current defences without the jargon — call us on 020 7610 0500, drop into the Putney workshop, or use the contact form. We help small businesses across South West London and remotely UK-wide put sensible cybersecurity in place before anything goes wrong, not after.




