How does ransomware work, and what can I do if I’m attacked?

Skip to main content

Last updated: 3 October 2026

Short answer: ransomware locks your files and demands payment to unlock them, and most attacks start with a phishing email, a stolen password or an unpatched system. If you are hit, isolate the affected devices, call your IT provider and insurer, and restore from clean backups. Law enforcement and the NCSC advise against paying.

Want this sorted for you?Talk to our Burgess Hill team about cyber security services. Free, friendly and no obligation.
1%of UK businesses reported ransomware in the Cyber Security Breaches Survey 2025
Phishingis the most common way in, cited by 85% of attacked businesses
Backupsare the difference between a bad day and a business-threatening one

How does ransomware work?

  1. Getting inA phishing email, a stolen or reused password, or an unpatched system gives the attacker a foothold.
  2. SpreadingThey move across your network, gain admin access and look for your most valuable data and your backups.
  3. Stealing dataMany attackers copy your files first, so they can threaten to publish them as well.
  4. EncryptingFiles, servers and sometimes backups are locked, and a ransom note appears.
  5. Demanding paymentYou are told to pay, usually in cryptocurrency, with a deadline to add pressure.

What should we do if we are hit by ransomware?

Act quickly and calmly. Disconnect affected devices from the network but leave them switched on, call your IT provider and your cyber insurer, and do not delete anything or pay without taking advice. Our guide to the first hour after a cyber attack walks through the steps in order. If personal data may be affected, you may need to tell the ICO within 72 hours.

How do we protect our business from ransomware?

Protection Why it helps Cyber Essentials control
Multi-factor authentication Stops stolen passwords being enough to get in. User access control
Fast patching Closes the holes attackers scan for. Security update management
Endpoint protection Blocks and flags malicious software. Malware protection
Tested, separate backups Lets you restore without paying. Good practice
Firewalls and secure settings Reduces what is exposed to the internet. Firewalls, secure configuration
Staff awareness Helps people spot phishing emails. Good practice
Test your backups. A backup you have never restored is a hope, not a plan. Keep at least one copy offline or separate from your network, and practise recovering a few files every quarter.

Can ABCOM help protect us from ransomware?

Yes. ABCOM provides layered protection for Sussex businesses: MFA, patching, endpoint protection, monitored backups and staff awareness, built around the Cyber Essentials controls. Book a free IT review and we will check how exposed you are.

Want this looked after for you?

ABCOM has supported Sussex businesses and charities since 1996 and is an NCSC Assured Service Provider – Cyber Advisor (Cyber Essentials). Talk to a real person about your IT.

Also read

How ABCOM can help

Talk to a real person at our Burgess Hill office. We are an NCSC Assured Service Provider and have supported Sussex businesses since 1996.

Scroll to Top
Free 3-minute quiz · No sign-up for your score

Is your team using AI you don’t know about?

Score your Shadow AI risk across policy, data, tools, people and detection, then get the three controls to fix first.

Take the Shadow AI Check10 questions · about 3 minutes