Skip to main content

How to Beat Ransomware in 2026: Prevent, Detect and Recover Without Paying

Media What Is SaaS Ransomware & How Can You Defend Against It?

 

Ransomware is no longer simply a piece of malware that encrypts a few files and displays a demand for Bitcoin.

A modern ransomware incident can involve stolen credentials, compromised administrator accounts, disabled security software, deleted backups, data theft, business disruption and extortion.

The attackers may have been inside the network for days or weeks before anybody sees a ransom note.

That changes how businesses need to defend themselves.

You cannot beat ransomware with one antivirus product.

You beat it by making the organisation difficult to compromise, quick to detect suspicious activity and capable of recovering even when some security controls fail.

That defence-in-depth approach is exactly what the NCSC recommends: assume no single control will be perfect and create several opportunities to prevent, detect and contain malicious activity.

What Does “Beating Ransomware” Actually Mean?

It does not mean guaranteeing ransomware will never reach one of your computers.

Nobody can credibly promise that.

Instead, imagine an employee opens something malicious.

A well-designed environment should give you several chances to stop what happens next.

Perhaps the web filter blocks the download.

If not, endpoint protection detects it.

If the attacker steals a password, phishing-resistant authentication prevents them using it.

If they compromise one laptop, limited privileges and network segmentation restrict where they can go.

If they eventually encrypt something, protected backups allow the business to recover.

That is how ransomware defence should work in 2026:

Layers.

Here are the most important ones.

1. Build Backups the Attacker Cannot Easily Destroy

Backups remain one of your most important ransomware protections.

But simply seeing:

Backup completed successfully

every morning is not enough.

Criminals know that organisations with good backups are less likely to pay, so backup infrastructure is itself a target.

The NCSC's ransomware-resistant backup principles recommend separating backup administration credentials from normal network administration, using MFA for actions that alter or destroy backup data, retaining recoverable historical versions and generating alerts for significant changes.

A good backup strategy should therefore answer:

Can someone who compromises our domain administrator account also delete our backups?

Can recovery points be immediately destroyed?

Are backup credentials different from everyday IT administrator credentials?

Is MFA protecting destructive actions?

Do we retain enough history to recover from before the attacker arrived?

Most importantly:

When did we last perform a real restore?

A backup you have never successfully restored is still partly an assumption.

Think Beyond 3-2-1

The traditional 3-2-1 concept remains useful, but ransomware resistance matters just as much as the number of copies.

Consider isolated, immutable or otherwise deletion-resistant recovery copies, depending on your backup platform.

The objective is simple:

Compromising production systems should not automatically compromise every route back to safety.

2. Make Stolen Passwords Less Valuable

A significant ransomware attack may begin without traditional malware.

The attacker obtains credentials instead.

That could happen through phishing, password reuse, malware, credential theft or a compromised supplier.

MFA makes stolen passwords less useful, but authentication has evolved further.

In April 2026, the NCSC began recommending passkeys wherever services support them, with 2-step verification where passkeys are not available. Passkeys are phishing-resistant because they cannot simply be captured by a fake login page and reused like a password.

Prioritise strong authentication around:

Microsoft 365

Administrator accounts

VPN and remote access

Backup systems

Firewall management

Cloud platforms

Financial applications


Administrator accounts deserve particular protection.

Your everyday account used for Outlook and browsing should not also be the account capable of controlling every server in the company.

3. Patch What Attackers Can Reach

Not every ransomware incident starts with somebody clicking an email.

Attackers also exploit vulnerabilities in:

Firewalls.

VPN appliances.

Servers.

Remote-access platforms.

Applications.

Web systems.

Operating systems.

The NCSC's 2026 vulnerability-management guidance recommends an “update by default” policy, applying security updates as quickly as practical and paying particular attention when vulnerabilities are being actively exploited.

The first requirement is knowing what you actually have.

Maintain an inventory covering:

Devices.

Servers.

Software.

Network appliances.

Cloud services.

Remote-access systems.

Unsupported systems deserve particular attention.

A forgotten VPN appliance sitting on the edge of the network does not become safe because nobody remembered it was there.

4. Use EDR and Reduce the Attack Surface

Traditional antivirus still matters.

But modern endpoint protection can look for behaviour, not merely known malicious files.

Endpoint Detection and Response can identify suspicious scripts, credential theft, unusual process behaviour and other activity that may indicate an attacker is operating inside the environment.

Microsoft's Attack Surface Reduction capabilities are specifically designed to restrict behaviours frequently abused by malware, including suspicious scripts, executable content delivered through email and applications spawning potentially dangerous child processes.

For Microsoft environments, appropriately configured ASR rules can add another valuable layer of ransomware resistance.

They should not simply be switched on blindly across every business, however.

Older applications may behave in ways that conflict with some rules.

A sensible rollout involves audit, testing, pilot deployment and then enforcement, with tightly controlled exceptions where genuinely necessary. Microsoft's current deployment guidance recommends exactly that staged approach.

5. Stop One Compromised Device Becoming the Entire Network

Imagine an employee laptop becomes compromised.

Does that laptop need unrestricted access to:

Your domain controllers?

Backup server?

Finance system?

Hypervisor?

Every other workstation?

Probably not.

Network segmentation and access controls can reduce an attacker's ability to move laterally.

Separate areas such as:

User devices

Servers

Backup infrastructure

Management systems

Guest Wi-Fi

Critical workloads

Administrative interfaces should also be protected from ordinary user networks where practical.

Remote Desktop and management services should not simply be exposed directly to the internet because it is convenient.

Use secure remote-access methods, MFA, individual accounts and monitoring.

The goal is that compromising one account or endpoint creates a contained incident rather than organisation-wide access.

6. Reduce the Chance of Phishing Succeeding

Phishing remains an important ransomware delivery route.

But phishing protection should not rely entirely on an employee spotting a dodgy logo or spelling mistake.

Modern attacks can be extremely convincing.

Use layers including:

Email filtering

Link protection

Attachment scanning

DNS and web filtering

Managed browsers and devices

Phishing-resistant authentication

Then train employees around behaviour.

An unexpected Microsoft login.

An invoice from a supplier with new bank details.

A request to enable content.

An MFA notification they did not initiate.

A password-protected attachment nobody expected.

Employees should know what to do when something feels wrong.

More importantly, they should know exactly how to report it.

Someone saying:

“I think I've clicked something dodgy.”

within five minutes gives your security team far more options than somebody quietly saying nothing for two days.

7. Make Sure Someone Is Actually Watching the Alerts

An EDR platform detecting ransomware activity at 2:13am is useful.

An alert sitting unnoticed until 9:00am is considerably less useful.

Monitoring is therefore part of ransomware defence.

Important alerts can include:

Unexpected administrator accounts.

Security software being disabled.

Credential theft.

Suspicious PowerShell activity.

Mass file modifications.

Backup deletion attempts.

Unexpected authentication.

Lateral movement.

Malicious network connections.

The aim is to detect the attack before the ransom note becomes your first security alert.

Appropriate organisations may therefore benefit from managed detection and response or other arrangements that ensure critical alerts can be investigated when they occur.

Technology does not respond to an incident merely by generating a red icon on a dashboard.

Somebody has to act on it.

8. Prepare to Recover Before You Need To

This is where many ransomware plans are weakest.

Businesses spend a great deal of time thinking:

How do we stop ransomware?

They should also ask:

What exactly happens at 7:30 tomorrow morning if ransomware succeeds?

The NCSC published updated disruptive cyber-attack recovery guidance in August 2026 that places particular emphasis on recovering first to Minimum Viable Operations before attempting a complete rebuild of every system.

That is extremely useful thinking.

If 30 systems are offline, you may not need all 30 restored immediately.

You may first need:

Email or alternative communications.

Core identity services.

Customer systems.

A critical database.

Finance functionality.

Essential operational systems.

Determine those priorities before the attack.

Your response plan should also identify:

Who leads the incident.

Who has authority to disconnect systems.

Who contacts your cyber insurer.

Which incident-response specialists are called.

How employees communicate if Microsoft 365 is unavailable.

Where offline contact information is kept.

Which systems recover first.

How customers are updated.

Who considers regulatory obligations.

Then test the plan.

A tabletop exercise can expose missing telephone numbers, unrealistic recovery expectations and unclear responsibilities without anybody having to learn those lessons during an actual ransomware attack.

What Should You Do If Ransomware Is Already Happening?

If ransomware is actively suspected, your immediate priority is containment.

Affected devices should be isolated from wired, wireless and mobile network connections where possible. Avoid reconnecting systems simply to see whether they now work.

Contact your IT or cyber-security team quickly and preserve information that could help establish what happened.

Do not automatically wipe everything immediately.

Incident responders may need logs, memory or other evidence to determine:

How the attacker entered.

Which accounts were compromised.

Which systems were accessed.

Whether information was stolen.

Whether persistence remains.

Recovery should happen from a known-good state, not by restoring backups straight back into an environment that may still contain the attacker.

Current NCSC recovery guidance also recommends treating potential data loss as a parallel workstream to system restoration rather than assuming successful restoration ends the incident.

Should You Switch the Computer Off?

Not automatically.

Disconnecting a compromised device from the network can help stop communication and lateral movement while preserving volatile information useful to investigators.

Powering a machine off may stop active encryption in some circumstances, but it can also destroy useful evidence held in memory.

Follow your incident-response procedure and get specialist advice as quickly as possible.

If encryption is visibly spreading and expert help is not immediately available, isolating the affected device and network connectivity is urgent.

Should You Pay the Ransom?

The NCSC and UK law enforcement do not encourage, endorse or condone ransom payments. Paying does not guarantee that data will be recovered, that stolen information will be deleted, or that criminals will not target the organisation again.

Even receiving a working decryption key does not magically make the incident disappear.

You still need to understand:

How the attacker got in.

What they accessed.

What they stole.

Whether they created other accounts.

Whether malware remains.

Which security weaknesses need fixing.

The strongest position is therefore to prepare your organisation so that paying criminals is not your only apparent recovery option.

Don't Forget Data-Breach Responsibilities

Ransomware can also become a data-protection issue.

The ICO makes clear that a ransomware incident can constitute a personal data breach even when information has not been stolen, because losing availability of personal information through encryption can itself amount to a breach.

If a personal data breach is likely to create a risk to people's rights and freedoms, the organisation must notify the ICO as soon as possible and, where feasible, within 72 hours of becoming aware of it. If the risk is unlikely, notification may not be required, but the decision and risk assessment should still be documented.

This is another reason regulatory and legal considerations should already exist inside your ransomware response plan.

How Hamilton Group Helps Businesses Fight Ransomware

Ransomware cannot be beaten with one security product.

Hamilton Group can help businesses build the layers around their environment, including Microsoft Defender for Business, endpoint detection and response, Microsoft 365 security, Conditional Access, MFA and passkeys, attack surface reduction, vulnerability management, patching, network security, managed detection, ransomware-resistant backups, disaster recovery and cyber-security awareness training.

We can also help answer the uncomfortable questions before an attacker does:

Would anyone notice an attack starting tonight?

Could one administrator account delete every backup?

When did we last perform a full recovery test?

Could one compromised laptop reach our critical servers?

Do we know which systems need restoring first?

Who would take control during a ransomware incident?

Those are much more useful questions than:

“Do we have antivirus?”

And when your team needs IT support, our aim is to make first contact on support requests within 15 minutes.

Call Hamilton Group on 0330 043 0069 or visit hgmssp.com to discuss ransomware protection, managed cyber security and recovery planning.