Digital Gnome
TECHNOLOGY ASSURANCE

Tell us who you are and we’ll cut the rest

One tool for the whole job, from a locked laptop to a signed policy. Answer two questions and we’ll show you only what fits, priced for your size.

1 · HOW MANY OF YOU?
2 · WHAT DO YOU DO? OPTIONAL
✓ NO CARD NEEDED ✓ FREE FOREVER FOR SMALL TEAMS ✓ BUILT IN WALES
Your business
LIVE PREVIEW
YOUR PLAN
WHAT YOU’D GET
← Back to news
RESEARCH 26 APR 2026 · 3 MIN

Ransomware in a 20-person firm: an honest account

A real recovery, told plainly. The ransom was never the biggest number, and the worst week was the one after everyone thought it was over.

SARA MITCHELL · RESEARCH
SHARE LinkedIn X Email
RESEARCH cover image

The firm was a professional services practice with twenty staff and a single server room in a converted back office. The infection came in through a remote-access tool that had been left open for an out-of-hours contractor, and by the Monday morning every shared drive was encrypted and the accounting system would not open. Nobody had touched a dodgy link; the door had simply been left ajar for months.

The ransom demand was the part everyone fixates on, and it was the least of it. They did not pay, because a backup from the Friday night had survived on a drive that happened to be unplugged. What actually cost money was the standing still: three days with no billing, no client files and no email while the systems were rebuilt from scratch, and a specialist bill for the forensic work needed to be sure the intruder was really gone.

The fortnight nobody talks about came next. Restoring the data was quick; trusting it was not. Every password had to be changed, every device rechecked, and every member of staff walked through what had happened so they would not quietly reuse an old login. Two clients heard about it secondhand and had to be reassured in person. The work of proving you are clean takes far longer than the work of getting back online.

What saved them was ordinary and unglamorous. One backup that was genuinely offline, so it could not be encrypted with everything else. One person who knew where it was. And a willingness to shut everything down on the Monday rather than press on and hope. The mistake that let it in was equally ordinary - a convenient shortcut that nobody revisited once the contractor had finished.

We tell this story because the honest version is more useful than the frightening one. It was not a sophisticated attack and it did not need to be. It needed one forgotten door and one working backup to decide the outcome, and the difference between those two things was a couple of hours of dull maintenance that never got booked in.

WHAT TO DO
  • ✓Keep one backup genuinely offline, so it cannot be encrypted alongside everything else.
  • ✓Close remote-access tools the moment the contractor or job that needed them is finished.
  • ✓Write down who knows where the backups are, and test that person can actually restore.
  • ✓Report ransomware to Action Fraud and the NCSC before you pay anyone anything.