Open 9am–9pm, 7 days a week 0115 990 4332 support@hucknallit.co.uk
← All Articles Security Business

Ransomware and UK small businesses: what the NCSC warning actually means

The NCSC recorded 204 nationally significant incidents in a year, up 130%. Attackers are automating with AI, and small firms are targeted precisely because they are somebody's supplier.

7 min read By the Hucknall IT team

01

The numbers, without the drama

The NCSC handled 204 nationally significant cyber incidents in 2024/25, a 130% increase on the year before. The Cyber Security Breaches Survey found 43% of UK businesses identified a breach or attack in the previous twelve months. Ransomware remains the threat the NCSC calls most dangerous to UK organisations.

Those figures get quoted to frighten people, which is a shame, because the useful part is not the size of the number. It is what changed underneath it.

02

Why small businesses are targeted

The persistent myth is "we are too small to be worth attacking". It was never true, and automation has made it actively dangerous.

Most attacks are not aimed at you. They are aimed at a vulnerability, and they find every unpatched instance of it on the internet without a human choosing targets. Attackers now use automation and AI to run campaigns across thousands of victims at once. Being small does not hide you from a scanner.

There is a second reason, and it is the one that has changed the picture most: you are somebody's supplier. Supply chains are now a primary route in. The way into a large organisation is often a small professional services firm, a logistics company, a clinic — anyone with a trusted connection and a smaller security budget. That is why your customers keep sending you security questionnaires.

03

AI has improved the attacker's writing

The single most useful thing to tell staff is that the old advice has expired. Spelling mistakes, clumsy grammar and odd phrasing are no longer reliable signs of a phishing email, because attackers use language models to write them.

What has not changed is the structure of the con. It will create urgency. It will invoke authority. It will push you towards an action that is hard to reverse — a payment, a credential, an approval. Teach the shape rather than the spelling, because the shape is what stays constant.

04

The controls that actually earn their keep

Ranked honestly by how much risk they remove for the money:

  • Multi-factor authentication everywhere, especially email — it defeats the overwhelming majority of account takeovers on its own
  • Patching within days, not months — the automated attacks above are looking for exactly this
  • Offline or immutable backups, tested by actually restoring something — ransomware deliberately encrypts backups it can reach
  • Least privilege — most people do not need to be a local administrator, and the ones who are are how it spreads
  • A written incident plan naming a person, not a department, with phone numbers that work when email is down

None of that is exotic and none of it is expensive. It is unglamorous work done consistently, which is why it gets deferred, and why the businesses that do it are dramatically harder to hurt.

05

The question that matters most

Not "could we be attacked" — assume yes. The question is: if every file was encrypted this afternoon, how long until you could take orders again, and how do you know?

If the answer is a guess, that is the gap. A backup nobody has ever restored from is a hope, not a backup. The half hour it takes to test a restore is the cheapest insurance in IT, and it is the thing almost nobody does until after the first bad week.

Sources

Where the facts in this article came from. If any of it goes out of date, tell us and we will correct it.

Found this useful? Pass it on. LinkedIn Facebook X Email
Keep Reading

Related articles

AI voice scams, and the code word that beats them

A few seconds of audio is now enough to clone a voice convincingly. The defence is not clever technology — it is one agreed word and a habit of hanging up.

Passkeys have gone mainstream — should you switch?

Microsoft has been switching passkeys on by default, Google reports over 800 million accounts using them, and most large firms have deployed them. Here is the honest state of play.

Is a Copilot+ PC actually worth it in 2026?

Copilot+ machines need a 40+ TOPS neural processor, 16GB RAM and 256GB storage. The AI features are real, but the reason to buy one is probably the battery.

Want a straight answer about your setup?

Tell us what you are running and we will tell you honestly whether this affects you, what it would cost to put right, and how quickly we can do it. No hard sell.

Open 9am–9pm, 7 days a week
Call Now