How does ransomware work? It breaks in, spreads across the network, and steals a copy of your files. Then it encrypts them and demands payment for the key. That’s the mechanic. What matters more for most UK businesses is why this keeps happening at a growing scale despite years of warnings. The answer is mostly economic, not technical.

Table of Contents
How does ransomware work, step by step?
Every attack follows a similar shape. An attacker gets in, usually through a phishing email, an exposed remote login, or an unpatched device. They explore the network and look for backups. They copy out anything valuable. Only then do they encrypt your files and send a ransom note.
None of that requires much skill on its own. It’s a process built from ordinary, well-worn steps, which is exactly why it scales so easily.
The criminal supply chain behind a single attack
Very few ransomware attacks are carried out start to finish by one person. The National Cyber Security Centre (NCSC) has mapped an ecosystem where different criminals specialise in different stages. Initial access brokers break into networks and confirm the victim is a genuine company. They then sell that access on. Ransomware-as-a-service (RaaS) groups build and maintain the malware. They license it to affiliates, who carry out the actual attacks.
This division of labour is why ransomware has scaled the way it has. An attacker no longer needs to be good at everything. They only need to be good at one narrow part of the chain. A marketplace is ready to supply the rest. The NCSC found RaaS operators traditionally kept around 45% of each ransom payment. That share has fallen only because competition between rival groups has increased, not because the model is shrinking.
Why encryption is often the least of your worries
Backups have improved. Most organisations with any security maturity can, in principle, restore encrypted files without paying a ransom. Criminal groups know this too. That’s why the NCSC’s research describes gangs choosing whichever tactic is most likely to get them paid. Sometimes that’s encryption plus data theft. Sometimes it’s extortion without encryption at all.
That shift matters. Because of it, a business can do everything right on backups and still face a serious extortion threat over stolen data. Good backup discipline solves half the problem. It was never designed to solve the other half.
The entry points haven’t changed, and that’s the real problem
What’s striking about how ransomware gets in is how unoriginal it usually is. The NCSC’s guidance names the same three routes again and again. Phishing harvests credentials. Exposed Remote Desktop Protocol is left open to the internet. Unpatched vulnerabilities sit on internet-facing devices such as VPNs and firewalls.
None of these are exotic. All three show up reliably in basic security assessments. The NCSC’s own assessment is direct about this: most ransomware incidents are not the product of a targeted, bespoke campaign. They result from ordinary gaps in cyber hygiene. Automated scanning tools find those gaps every day, for attackers and defenders alike.
That’s an uncomfortable framing for any business that assumes ransomware only happens to unlucky victims. More often, it happens to whichever network has a weak spot nobody checked.
Insurance won’t fix a gap it can’t see
Cyber insurance has become a common part of the conversation. It can genuinely help with recovery costs. But a policy pays out after the fact. It only pays if its conditions were met at the time of the attack, and even then it does nothing to close the entry points described above.
Treating insurance as a substitute for finding and fixing the gap gets the order backwards. The NCSC’s advice is about stopping the attack succeeding in the first place. That means patching, MFA and tested backups, not what happens once an attack has already succeeded.
The numbers say this isn’t slowing down
City of London Police recorded 323 corporate ransomware victims in the UK. That was over the year to March 2026, so more than 26 successful attacks a month. Manufacturing bore the brunt with 42 reports, ahead of scientific and technical firms (21) and education (19). More than half of all reported victims were small or medium-sized businesses, not large enterprises with dedicated security teams.
Reported losses across those cases totalled roughly £270,000, a 50% increase year on year. Police were explicit that the real figure is likely much higher, because businesses routinely under-report what an incident actually cost.
Compliance checklists were never designed to catch this
Many businesses treat an annual compliance review, such as Cyber Essentials, as evidence they’ve addressed ransomware risk. It’s a useful baseline. But it’s only a self-assessed or lightly audited snapshot. It’s not a test of whether a determined attacker could actually get past your defences on the day.
Ransomware affiliates don’t check whether you passed a compliance form last year. They check whether an RDP port is open today. They check whether last month’s VPN patch has actually been applied. Then they check whether an employee will click a convincing email this week. That’s a different, more current question, and it needs a different kind of answer.
What actually closes the gap
Given that most attacks exploit known, findable weaknesses rather than novel techniques, the fixes are not mysterious. The NCSC’s guidance on mitigating ransomware puts four things at the centre of its recommendations. Patch internet-facing systems. Enforce MFA on remote access. Disable unneeded RDP, and keep tested offline backups.
The gap for most businesses isn’t knowing that these things matter. It’s not knowing, with any confidence, whether their own environment has one of these weaknesses live right now. That’s the specific question a penetration test answers. It’s not a generic checklist. Instead, it actively looks for the exposed RDP port, the unpatched appliance or the overprivileged account. It tests the way an attacker would, before one finds it first.
Ransomware groups aren’t running sophisticated operations against most of their victims. They’re running an efficient, well-organised business that profits every time a basic gap goes unchecked. Closing that gap is a more realistic goal than trying to out-innovate a criminal supply chain built for scale.
So, would you rather know the answer for your own network than guess at it? A scoped penetration test is built to find exactly these weaknesses. It looks before an affiliate does. Aardwolf Security is happy to talk through what that would cover for your environment. Feel free to get in touch.
Frequently asked questions
Why is ransomware still increasing if defences have improved?
Because the criminal side has industrialised faster. Ransomware-as-a-service and initial access brokers let attackers specialise and scale. Overall improvements in defence haven’t kept pace with the growth in attackers able to launch attacks.
Do small businesses actually get targeted, or just large ones?
Small and medium-sized businesses made up over half of reported UK ransomware victims in the year to March 2026. Most attacks are opportunistic, rather than aimed at specific large organisations.
If we pay the ransom, do attackers keep their word?
Not reliably. The NCSC and UK police advise against paying, because it funds further crime. There’s also no guarantee data comes back intact, or that stolen copies aren’t kept or sold anyway.
Is a firewall enough to stop ransomware getting in?
No. Firewalls help, but most attacks succeed through stolen credentials, phishing or an unpatched service. A firewall alone won’t catch any of those, which is why patching and access control matter just as much.
How do we find out if we’re already exposed?
A penetration test is the most direct way to find out. It actively tests for the same exposed services, weak credentials and unpatched systems that ransomware affiliates look for.
Does having cyber insurance reduce the risk of an attack?
No. It reduces the financial impact if an attack succeeds, and only if the policy’s conditions were met at the time. It doesn’t close the technical gaps, like an open RDP port or an unpatched VPN, that let an attacker in.
Is ransomware mostly a large-enterprise problem, given the scale of the criminal operations behind it?
No, the opposite. An industrialised criminal supply chain makes it cheaper to target smaller organisations at volume. That’s a large part of why small and medium-sized businesses made up over half of reported UK victims. This held true in the year to March 2026.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.