26 ransomware attacks a month, and more than half hit smaller businesses
At the end of June, City of London Police published a sobering set of numbers: 323 UK businesses reported ransomware attacks in the year to March 2026 (more than 26 a month), with average losses of around £270,000, up 50% on the year before. And because those are only the incidents that were reported, the real picture is almost certainly worse.
The detail that should reset assumptions: over half of those victims were small and medium-sized businesses. Ransomware is not a big-company problem that occasionally strays down-market. Smaller firms are the market.
Why smaller businesses are the target
Attackers are rational. Large enterprises have security teams, monitoring and rehearsed incident response; smaller businesses often have none of those, but still have data worth encrypting, customers who expect them to keep trading, and, the attackers hope, a willingness to pay to make the problem go away. Manufacturing topped the victim list, followed by professional services and education.
There's also a supply-chain lesson from the past year. When Jaguar Land Rover was forced to halt production for weeks after its 2025 cyber attack, the damage, estimated by analysts at around £1.9 billion to the UK economy, landed heavily on the small suppliers downstream. You can inherit a cyber incident without being breached yourself.
The police advice: don't pay
The headline of the police warning was blunt: don't pay the ransom. Payment funds the next wave of attacks and buys no guarantee of decryption, or of stolen data staying private. The organisations that decline to pay are, almost without exception, the ones with working backups.
The defences are boring, and that's the good news
None of the recommended protections are exotic, and that's precisely the point:
- Backups you've actually restored from. A backup that's never been tested is a hope, not a plan.
- Multi-factor authentication everywhere, enforced from day one. Not "rolled out to most people", but enforced at account creation, with no legacy exceptions quietly excluded.
- Systems that are current and patched. Old, unsupported software is the soft entry point in most incidents we hear about. If a critical system can't be updated because "nothing else works with it", that's not an IT quirk; it's the vulnerability.
- Access that matches reality. Leavers removed promptly, admin rights rationed, licences tidied up.
That third point is where we spend much of our time: modernising the legacy systems businesses are afraid to touch, precisely so they stop being the thing that can't be patched. If part of your business runs on software nobody dares update, that's a conversation worth having before someone else finds it.