International Cyber Expo International Cyber Expo
  • About Us
Wednesday, 22 July, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Surviving Ransomware: Best practices to safeguard your business

by Lara Joseph
March 3, 2026
in Featured, Opinion
Surviving Ransomware: Best practices to safeguard your business
Share on FacebookShare on Twitter

By Robbie Ross, cyber security lead, Converged Communication Solutions

It’s not if but when.

This is a phrase that has been echoed across the cyber security industry for several years, but when it comes to ransomware the message is still not penetrating widely enough.

The 2025 UK Government Cyber Breaches Survey highlighted that just 32% of organisations have adopted the technical controls required in all five key Cyber Essentials areas, and that only 27% of UK businesses have a board member explicitly responsible for cyber security. The same survey highlighted that as few as 19% of businesses overall reported conducting formal staff cyber training activities while a mere 23% of businesses have a documented incident response plan in place.

These statistics show that despite the inevitability of a cyber attack organisations are predicted to face, many are not prioritising their defences effectively.

However, if the warning statements aren’t enough to drive action, perhaps looking back at the largest attack of 2025 will be more impactful.

It’s hard to believe that an organisation as large as Jaguar Land Rover (JLR) is still suffering the consequences of the incident it faced last year, which is already estimated to have cost the company over £3 billion. While this attack has been well publicised, it remains one of the clearest illustrations of the scale of operational and financial damage ransomware can cause.

The incident brought JLR to an operational standstill, threatening the solvency of thousands of businesses across the automaker’s supply chain, while also leaving employees locked out of systems and unable to perform their jobs.

While most businesses don’t operate on the same scale as JLR, this does not mean the threat should be underestimated as loss is relative.

Instead, business leaders must be asking: if my business were unable to operate due to ransomware for an hour, how much would it cost? What about a day, a week, a month, or six?

When business leaders carry out this calculation, they often find that the cost of not preparing for an attack is much greater than the cost of preparing for one.

So, what steps should organisations adopt to ensure they can not only defend against ransomware but also survive it?

  1. Train staff to be the greatest line of defence

Ransomware exploits people, so organisations must treat staff as their most important line of defence.

Most attacks begin with phishing emails, social engineering or deceptive prompts designed to exploit human behaviour rather than technical vulnerabilities.

Despite this, many organisations still frame staff as the weakest link, while failing to invest properly in their education and training.

Training should not be a tick-box exercise designed to satisfy compliance requirements. Effective security awareness training should focus on behavioural change, not just knowledge transfer. Staff should understand:

  • What phishing really looks like in the real world
  • How attackers use urgency, authority and familiarity
  • Why unexpected MFA prompts can be a warning sign
  • What the early stages of a ransomware attack might look like
  1. Make reporting easy, safe and clear

Spotting suspicious activity is only half of the battle. Staff must feel confident and supported when reporting potential incidents.

If employees worry about blame, embarrassment or getting into trouble, they are less likely to speak up and silence gives attackers more time to cause harm.

A strong security culture encourages reporting at the earliest possible moment, even if someone has already clicked a link or made a mistake. Clear reporting routes, simple guidance and visible support from leadership all reinforce the message that raising concerns is the right thing to do. 

  1. Ensure security is adopted from the top down

Security awareness training cannot be delegated to only certain job levels, it must be adopted company-wide, from the top down.

Senior leaders should never be missed out of training, they should be required to participate in it, just like all employees within the organisations.

Furthermore, senior leaders are often the priority target for threat actors, so they are at a higher risk than many other employees, while they also often have the power to action large monetary transfers which attackers will try to hijack.

This means when it comes to security, all senior leaders must be trained and it’s best to implement policies preventing any single employee, regardless of their position, from carrying out a large monetary transfer. All such transactions should be doubly verified before being authorised. 

  1. Prepare for ransomware attacks before they happen

One of the most common mistakes organisations make is assuming that ransomware is something they will “deal with if it happens”.

By the time an attack is underway, decision-making becomes harder, stress levels rise and mistakes are more likely.

Preparation significantly improves an organisation’s ability to respond calmly and effectively. Having nn incident response plan in place is only useful if it can be accessed when systems are down.

If the plan lives solely on SharePoint or internal systems, it may be unavailable during a ransomware incident. For this reason, it must be accessible and physically available, and all employees included in the plan must be aware of the role they need to play.

The plan must also be updated regularly, especially to account for staff moves plus new technology deployments, and it must lay out all the actions an organisation will take in the event of an incident, with the ultimate goal being to minimise losses and disruption.

  1. Rehearse incident response

The time to discover that a plan does not work is not during a live ransomware attack.

Organisations must ensure plans don’t simply sit on shelves gathering dust, they must be rehearsed regularly so gaps can be identified and remediated before plans are put into action during genuine incidents.

No organisation can guarantee immunity from ransomware.

Those that invest in people, culture and planning are far more likely to contain incidents, recover quickly and protect their reputation.

ShareTweet
Previous Post

5 Security Risks Hidden In Mobile App Permissions

Next Post

Talion Expands Governance-Aligned Agentic SOC as Board Cyber Scrutiny Intensifies

Recent News

privileged access management

KeeperPAM strengthens privileged access management for global construction SaaS provider Asite

July 21, 2026
Forescout 2026 H1 Threat Review

Forescout Report Reveals Surge in AI-Driven Cyber Threats

July 21, 2026
secure-software-supply-chain-feature

1 in 4 businesses hit by cyber attacks through their supply chain in the last year

July 21, 2026
partnership

DigiCert expands its EMEA channel strategy with Ignition Technology

July 21, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol