Technology · September 20, 2025 · Amelia Hart · 4 min
The UK government's Cyber Security Breaches Survey has found around half of UK businesses reporting a cyber attack or breach in the past 12 months in recent years. Here is what the NCSC's own guidance says actually reduces ransomware risk.
Ransomware advice dates quickly, because attacker tactics evolve continuously and because the UK government's own data on how many businesses are actually affected is updated annually, not fixed. What has not changed is the core set of defensive measures that consistently show up as effective across successive years of NCSC guidance and government survey data — the challenge for most businesses is less "what should we do" and more "why haven't we actually done it yet."
DSIT's Cyber Security Breaches Survey, the UK government's official annual tracking study, has repeatedly found that roughly half of UK businesses report identifying a cyber breach or attack in the preceding 12 months. That headline figure masks significant variation by business size: medium and large businesses report breaches at notably higher rates than micro-businesses and sole traders, a gap the survey's own methodology attributes partly to larger organisations simply having better detection and monitoring capability to notice an attack in the first place, rather than necessarily facing proportionally more attempted attacks — smaller businesses may be under-reporting because they are under-detecting, not because they are under-targeted.
Ransomware specifically remains one of the costliest categories of incident, both in direct ransom demands and in business disruption during recovery, which for organisations without tested backups can extend to weeks rather than days.
"The organisations that recover fastest from a ransomware incident are almost never the ones with the most sophisticated prevention. They are the ones that can restore from a clean backup within hours instead of negotiating with criminals for days." — a conclusion the NCSC's own incident response guidance has repeatedly emphasised across successive versions of its ransomware advice.
Rather than expanding, NCSC guidance across successive years has increasingly concentrated on a small number of controls shown to have outsized impact relative to cost:
If your business has no dedicated IT security function — the position most micro-businesses and sole traders are in — the practical priority order based on cost-to-impact ratio is MFA first (largely free to enable on most modern business email and cloud platforms), followed by verifying your backup strategy genuinely includes an offline or otherwise network-isolated copy, since this is the single control most likely to determine whether a successful attack is a costly inconvenience or an existential threat to the business. For businesses handling customer payment data or operating in regulated sectors, the NCSC's Cyber Essentials certification scheme provides a structured, relatively low-cost route to formalising these controls, and is increasingly required by larger clients and insurers as a condition of doing business.
Cyber insurance has also become a more demanding, rather than simply available, layer of protection over the past several years. Insurers increasingly require evidence of specific controls — MFA, tested offline backups, endpoint detection tooling — before offering cover at all, and several have introduced coinsurance clauses or reduced payouts where a policyholder is found not to have implemented controls they attested to having in place. This shift means cyber insurance is now better understood as a complement to genuine technical controls rather than a substitute for them, since insurers themselves are increasingly unwilling to underwrite risk for businesses that have not done the basic groundwork described above. Some insurers now conduct their own pre-policy technical audits, effectively outsourcing a meaningful share of small business cybersecurity assessment work that many companies would otherwise never commission independently.
Watch DSIT's next annual Cyber Security Breaches Survey release for whether the roughly 50% breach-identification rate among UK businesses continues, falls as defensive measures scale, or rises further as detection capability improves industry-wide — a rising figure would not necessarily mean attacks are increasing, given the survey's own acknowledgement that improved detection can itself drive reported numbers up. Also watch whether ransomware-as-a-service — the criminal ecosystem that lets relatively unsophisticated attackers rent ransomware tools and infrastructure from more capable developers — continues lowering the technical barrier to launching attacks, a trend the NCSC has flagged as a key driver of ransomware's persistence despite improving defensive awareness. For the specific entry-point risk that precedes most ransomware incidents, see our guide on how to spot phishing emails.