Ransomware attacks: a postmortem from a real incident response

What actually happens when ransomware hits a UK business, from the first suspicious email to the painful recovery. Insights from our Security Operations Centre.

By Jack Walters | February 17, 2026

Ransomware attack represented as a locked digital lock over a network
4.7 days

Average time to discover an active breach

60 %

Of SMEs close within 6 months of an attack

0 ransoms

Ransoms we recommend paying

Last month we helped a Bristol manufacturer recover from a ransomware attack. Their story is a textbook case — and that’s the worrying part. Nothing about it was exotic.

How it started

It began, as it usually does, with email. An invoice that looked like it came from a supplier. One member of staff clicked the link and entered their credentials. That was enough.

From there, the attackers moved laterally across the network over several days, quietly exploring file shares, disabling backups and mapping the estate before anyone noticed.

The discovery

The first sign was a slow morning — applications grinding to a halt, files refusing to open. By lunchtime, every file server showed the same message: your files are encrypted, contact us for the key.

The recovery took nine days. That’s better than most, and it was possible only because backups existed, were off-site, and had been tested. Our team rebuilt systems, restored data from clean copies and hardened the network before bringing anything back online.

What we learned

A few lessons worth sharing:

  • Email is the front door. User training and strong filtering are your first line of defence, not optional extras.
  • Backups are the difference between an incident and a disaster. Tested, off-site, offline copies are non-negotiable.
  • Ransomware is a business problem, not just an IT one. The cost is downtime, lost orders and reputational damage, not the ransom itself.
  • Speed matters. The longer an attacker has access, the more damage they can do — and the harder recovery becomes.

What you should do today

If you haven’t thought about ransomware in the last six months, you’re already behind. A free IT audit takes an hour and will tell you exactly where the gaps are — often including a few you didn’t know existed.

Ransomware doesn’t discriminate between a dental practice and a manufacturer. But preparation does. Make sure you’re on the right side of it.

Don’t learn this the hard way. Book a free IT audit and we’ll show you how your defences hold up.

Jack Walters

Jack Walters

Head of Client Success