Ransomware in 2026: Fewer Attacks, Bigger Demands
UK ransomware reports fell to 1% of businesses while ransom demands and recovery costs rose. What the 2026 data shows, and what to do about it.
Nerdster Team
The research published this year says two things about ransomware that look like opposites. Reported incidence among UK businesses has fallen to a third of what it was in each of the previous two years. Ransom demands, recovery costs and the share of attacks that succeed in encrypting data have all risen.
Both are right, and the space between them is the most useful thing on this page. Here is what the 2026 data actually shows, and what it changes about how you defend a mid-sized firm.
The two findings, held at once
Reported incidence is down. The government’s Cyber Security Breaches Survey 2025/26, published on 30 April 2026 from fieldwork carried out between August and December 2025, found ransomware affected 1% of UK businesses, down from 3% in each of the two previous years.
Severity is up. Sophos’s State of Ransomware 2026 reports an average recovery cost of $1.7 million, up 11% year on year, and found that 56% of attacks succeeded in encrypting data, up from 50%. The UK recorded the highest median ransom demand of any country surveyed, at $2.5 million.
The serious end is busier. The NCSC Annual Review 2025, published on 14 October 2025 and covering 1 September 2024 to 31 August 2025, records 1,727 incident tips triaged into 429 incidents. Of those, 204 were nationally significant, up from 89 the previous year, and 18 were categorised as highly significant — an almost 50% increase, and the third annual increase in a row.
Why those numbers disagree
The disagreement is not a contradiction. It is three different measurements of three different populations.
The Breaches Survey is a random probability sample of 2,112 UK businesses, dominated by very small organisations, asking whether they identified ransomware in the past year. It measures how common ransomware is across the UK economy as a whole — and it measures identification, so an organisation with no monitoring cannot report what it never noticed.
Sophos surveyed 2,158 IT and cyber security leaders across 17 countries whose organisations had a ransomware incident, and asked what happened. It measures severity among the affected, and says nothing about how many organisations were affected.
The NCSC counts what reaches a national authority, which skews heavily towards incidents with national consequences.
Put together, they describe a shift rather than a puzzle: fewer, larger, more deliberately chosen targets. The most plausible explanation is unglamorous economics. Wider adoption of multi-factor authentication and endpoint detection makes low-effort, high-volume campaigns less productive, while data theft makes a smaller number of well-chosen victims considerably more valuable. Criminal groups appear to have responded the way any business would.
One consequence matters more than the rest. A 1% chance of being hit sounds reassuring right up until you read the severity figures next to it. Low frequency and high severity is the risk profile you insure and rehearse for, not the one you can afford to ignore because the headline percentage looks small.
How ransomware actually gets in
Two findings from different vantage points, both worth acting on.
For ransomware specifically, Sophos found 79% of attacks used identity-based methods — credentials that were stolen, phished, guessed or reused, and sessions taken from a legitimate user. Not malware arriving in an attachment. Someone logging in.
Across intrusions generally, M-Trends 2026, published by Mandiant and Google Cloud on 23 March 2026 covering 2025 investigations, found exploitation of a vulnerability was the leading initial infection vector for the sixth consecutive year, at 32%, with highly interactive voice phishing second at 11%.
Set those against the Breaches Survey finding that only 47% of UK businesses have any two-factor authentication, and the priority order writes itself: authentication first, then internet-facing systems, then the phone call your finance team is going to receive.
Voice phishing at 11% is worth taking seriously in a professional firm. It targets the help desk and the finance function rather than the network, and it defeats technical controls by asking a person to bypass them. A verification procedure for password resets and payment changes — a callback on a known number, never a number supplied in the request — costs nothing and closes most of it.
Assume they are inside for longer than you would like
M-Trends puts the global median dwell time at 14 days, up from 11 days in 2024. Encryption is the last act, not the first. Before it, an intruder maps the network, escalates privileges, locates and damages the backups, copies data out and turns off what is watching.
There is genuine good news in the same report: 52% of intrusions were detected internally, up from 43% the year before. Organisations are finding intruders themselves more often than they are being told by someone else.
The UK case that shows what the window costs is Capita. The ICO’s decision, published on 15 October 2025, records that a malicious file was downloaded onto an employee device on 22 March 2023 and a high-priority security alert was raised within ten minutes — but the device was not quarantined for 58 hours. Between 29 and 30 March, nearly a terabyte of data was exfiltrated. On 31 March, ransomware was deployed and every user password was reset. The personal information of 6.6 million people was stolen, and Capita was fined £14 million.
The ICO also found that Capita had not implemented a tiering model for administrative accounts, which allowed the attacker to escalate privileges and move laterally across multiple domains.
Read that timeline carefully and the lesson is not that detection failed. Detection worked, in ten minutes. What failed was the response: nobody was in a position to act on the alert quickly enough. That is a very common shape of failure, and it is an operational problem rather than a tooling one.
Backups designed for an attacker who already holds admin
Attackers go for the backups first, because restoration is the thing that makes the ransom unnecessary. In practice that means locating and deleting shadow copies and local backup files, using stolen credentials to reach the backup repositories, and sitting long enough that recent backup sets are already compromised.
Design accordingly:
- Immutable copies. Storage that locks data for a set retention period, where nothing can alter or delete it inside that window — including an administrator.
- At least one copy your production network cannot reach. Offsite media works. So does a cloud repository whose credentials exist nowhere in your production identity system.
- Backup credentials kept entirely separate from domain administration. Losing Active Directory should not hand anyone your backups.
- Full restore tests, not file spot-checks. Rebuild a system, record the time it took, and compare that to the recovery time you have promised the business. Our backup and disaster recovery checklist sets out what a test should actually prove, and our backup service page covers how we run it.
The layers that break the sequence
No single control stops ransomware. Each layer removes a stage the attack depends on.
Close the ways in. Multi-factor authentication on every account, preferably phishing-resistant methods such as FIDO2 security keys for administrators. Prompt patching of anything internet-facing — VPNs, firewalls, remote access gateways — given that exploitation remains the leading initial vector. Email filtering that detonates links and attachments before delivery, with DMARC, DKIM and SPF configured so your domain cannot be spoofed. Remote desktop off the public internet entirely.
Limit how far they travel. Separate administrative tiers, so a compromised workstation does not lead to a domain. Admin rights granted for a task rather than held permanently. Unique local administrator passwords per device. Network segmentation between user devices, servers and critical systems.
Watch, and be able to act. Endpoint detection and response is necessary but not sufficient — the Capita timeline shows an alert without a responder is just a log entry. What closes that gap is somebody on duty with the authority to isolate a machine at three in the morning without waiting for a decision.
Rehearse the recovery. Agreed recovery time and recovery point objectives, signed off by the people who run the business rather than only by IT. Written rebuild procedures for each critical system. Communication drafts for clients, staff, regulators and insurers, written now rather than during the incident. And cyber insurance whose scope you have actually read.
Decide about paying before you have to
The NCSC’s position is unambiguous. Its guidance on mitigating malware and ransomware attacks states that “law enforcement do not encourage, endorse, nor condone the payment of ransom demands”, and sets out that if you pay:
- “there is no guarantee that you will get access to your data or computer”
- “your computer will still be infected”
- “you will be paying criminal groups”
- “you’re more likely to be targeted in the future”
It also notes that attackers will threaten to publish data whether or not payment is made, so paying does not reliably resolve the exfiltration half of the problem either. Depending on who is behind an attack there may be sanctions implications, which is a question for your legal advisers rather than your IT provider.
None of that is a decision anyone should be making for the first time at two in the morning. Make it in the calm, write it down, and make sure the people who would have to act know what has been decided.
Scoring your own readiness
Five questions, answered honestly:
- Would your backups survive an attacker holding domain administrator credentials?
- When did you last restore a full system, rather than spot-check a file — and how long did it take?
- If an alert fired at 2am on a Saturday, who would see it, and what are they authorised to do without waking anyone?
- Does your incident response plan exist, and has it been exercised in the last twelve months?
- Is multi-factor authentication genuinely on every account, including service accounts and the secondary cloud platforms?
Any “no” or “not sure” is a gap worth closing this quarter. Question three is the one that catches most firms, and it is the one the Capita timeline is about.
Find out how your firm would fare
We build ransomware resilience into every managed IT environment we run: identity hardened first, immutable backups with restore tests on a schedule, round-the-clock monitoring with someone able to act on what it finds, and an incident response plan that gets rehearsed rather than filed.
If you would like to know how your current arrangements would hold up, book a conversation. We will walk through the five questions above with you, show you where the gaps are, and give you a prioritised plan with costs attached.