Skip to main content

There’s Only One Thing You Can Rely on Cyber Criminals For: Themselves

Media

Cyber criminals turning on each other might sound like good news.

One ransomware group threatens another. Identities are exposed. Stolen data is leaked. Rivals claim they can provide decryption keys or even “help” businesses caught in the middle.

For anyone watching from the outside, there can be a certain satisfaction in seeing criminals fighting amongst themselves.

But if your business is the victim of an attack, there is a much more important lesson:

You cannot build your recovery plan around anything a cyber criminal tells you.

Not their promises.
Not their deadlines.
Not their claims that your data will be deleted.
And certainly not another criminal group suddenly offering to help.

The only thing you can reliably expect is that cyber criminals will act in their own interests.

And that is exactly why your business needs a recovery strategy that doesn't depend on them.

Cyber Criminals Don't Suddenly Become the Good Guys

Ransomware groups operate for money, influence and leverage.

If two criminal groups fall out, one group leaking information about another doesn't suddenly make either organisation trustworthy.

The same applies when an attacker claims that paying a ransom will restore your data.

The UK's National Cyber Security Centre makes the problem very clear: paying a ransom provides no guarantee that you will regain access to your data, the affected computers may still be compromised, and paying criminals can increase the likelihood of being targeted again. The NCSC and UK law enforcement therefore do not encourage or endorse ransom payments.

That matters because ransomware is deliberately designed to create urgency.

The attacker wants the situation to feel impossible.

Your systems aren't working. Staff can't access files. Customers may be calling. Senior management wants answers. A countdown clock may be ticking away on the ransom note.

Then somebody offers a seemingly simple solution:

Pay us and we'll make the problem disappear.

Or perhaps another criminal group appears and claims it can recover your information instead.

That's exactly when good preparation matters.

The Real Cyber Threat to UK Businesses in 2026

It is easy to dismiss ransomware and cyber attacks as problems that mainly affect enormous organisations.

The latest UK Government Cyber Security Breaches Survey shows otherwise.

In the 2025/26 survey, 43% of UK businesses said they had identified some form of cyber-security breach or attack during the previous 12 months. That rose to 46% of small businesses, 65% of medium-sized businesses and 69% of large businesses.

Phishing remained by far the most common form of attack identified by businesses.

Ransomware itself was reported by a much smaller proportion of organisations than phishing, but that shouldn't make businesses complacent. Ransomware is only one possible outcome after an attacker gains access. Stolen credentials can also lead to email compromise, financial fraud, data theft, impersonation and unauthorised access to cloud services.

The more worrying statistic may be preparedness.

Only 25% of businesses in the latest government survey reported having a formal incident-response plan.

In other words, when many organisations discover an attack, they're making some of the most important decisions they'll ever make about their IT for the first time and under enormous pressure.

That's not where you want to be.

Your Recovery Plan Should Exist Before the Attack

Good cyber security isn't about pretending you can prevent every incident.

You can't.

The NCSC specifically recommends a defence-in-depth approach because no organisation can completely eliminate the possibility of malware reaching its systems. Multiple layers of protection give you more opportunities to prevent, detect and contain an attack before it causes serious damage.

That means combining preventative controls with the ability to recover.

For most SMEs, that should include things such as strong identity protection, multi-factor authentication, endpoint protection and EDR, secure configuration, patching, appropriate access controls, monitoring and reliable backups.

But one of the most important controls is often far less exciting:

Know what you're going to do when something goes wrong.

Who makes the decisions?

Who contacts your IT provider?

Who determines whether systems need disconnecting?

Where are your backups?

Can you access them if your Microsoft 365 tenant or administrator accounts are compromised?

Who communicates with staff?

Who contacts customers, insurers, regulators or law enforcement where required?

Which systems must be restored first?

Those are much easier questions to answer on an ordinary Tuesday afternoon than at 2am during a ransomware incident.

Having a Backup Isn't Enough

Businesses often tell us:

“We're fine. Everything is backed up.”

That's a good start.

But the important question is:

Could you actually restore it after a serious cyber attack?

Modern ransomware operators understand that a company with reliable backups has much less reason to pay them.

So attackers may deliberately target the backup environment itself.

The NCSC warns that ransomware actors can attempt to delete or destroy backups and supporting infrastructure to make recovery harder and increase pressure on the victim to pay. It recommends designing backups specifically to withstand destructive ransomware attacks.

A proper backup strategy therefore needs more than simply copying files somewhere every evening.

Your organisation should know that critical information is being backed up, that backup data cannot easily be deleted by a compromised administrator account, that suitable retention and version history exist, and — crucially — that restoration is regularly tested.

The NCSC also recommends maintaining independent copies rather than relying entirely on a single cloud service or storage location.

A backup you've never successfully restored is still partly an assumption.

What Should You Do If Ransomware Hits?

The first few minutes matter.

If you believe a computer or server has been infected with ransomware, don't simply carry on working and hope the problem remains isolated.

NCSC ransomware guidance recommends disconnecting affected devices from network connections to help prevent the malware spreading. In a severe incident, temporarily isolating wider network connectivity may also be necessary.

Your incident-response team or IT provider can then determine the scope of the compromise.

That may involve identifying affected accounts and devices, protecting unaffected systems, reviewing logs, securing administrator accounts and changing credentials.

Recovery also needs to be controlled.

The NCSC specifically advises checking that a backup is free from malware before restoring it. Restoring compromised data straight back into an infected environment can simply restart the problem.

This is another reason why an incident-response plan matters.

During a serious attack, speed matters — but uncontrolled panic doesn't help.

Don't Assume Payment Is Your Only Option

Attackers naturally want victims to believe they have no alternative.

You may have more options than they want you to realise.

There could be unaffected backups.

Copies of critical information may exist elsewhere.

Parts of the environment may be recoverable.

Law enforcement or security researchers may already have obtained decryption keys for a particular ransomware family.

The NCSC advises organisations to properly assess those alternatives before considering any payment.

Even if a ransom is paid, the attacker doesn't suddenly become your trusted IT provider.

There is no service-level agreement.

No regulator overseeing the transaction.

No guarantee that every file will decrypt correctly.

No guarantee that stolen information hasn't already been copied elsewhere.

And no guarantee that another attacker won't return later.

Your goal should therefore be to build enough resilience that criminals have as little leverage over your organisation as reasonably possible.

Monitoring Can Change the Outcome

A ransomware demand is usually the visible end of the attack.

The compromise may have started considerably earlier.

An attacker could initially gain access through stolen credentials, phishing, an exposed service, an unpatched vulnerability or a compromised endpoint.

From there, they may attempt to increase privileges, access additional systems or steal data before launching the disruptive stage of the attack.

That's why proactive monitoring matters.

Good cyber-security monitoring isn't simply looking for a giant warning that says “Ransomware attack in progress.”

It's about identifying behaviour that doesn't look right early enough to investigate it.

Unexpected administrator activity.

Suspicious logins.

Endpoint detections.

Unusual changes to security controls.

Attempts to access or alter backup systems.

Unexpected network behaviour.

The earlier suspicious behaviour is identified and contained, the better the chance of limiting its impact.

Your Staff Are Part of the Defence

Technology alone can't solve everything.

Phishing remains the dominant attack type detected by UK organisations. Among businesses that identified a breach or attack in the latest government survey, 88% had experienced phishing.

Employees therefore need to know what suspicious behaviour looks like and, just as importantly, what to do when they see it.

A member of staff who immediately reports a suspicious Microsoft 365 login prompt could help prevent an account compromise.

Somebody who recognises a fraudulent invoice request might prevent financial loss.

An employee who reports an unexpected MFA approval request rather than simply tapping Approve could stop an attacker getting into the organisation.

Cyber-security awareness should therefore be a normal part of operating the business, not a once-a-year tick-box exercise everybody clicks through as quickly as possible.

The Best Time to Prepare Is Before You Need the Plan

Cyber criminals are unpredictable.

Your response shouldn't be.

You don't need to know which ransomware group might target you or what argument is currently taking place between competing criminal gangs.

You need to know that, if something happens, your organisation has:

layered security controls, proper endpoint protection, secure and tested backups, monitoring, trained employees, clear ownership of incident response, and trusted people to call when something goes wrong.

Because when systems stop working and pressure starts building, that's not the moment to discover that nobody knows where the backups are or who is supposed to make the next decision.

How Hamilton Group Can Help

Hamilton Group helps businesses strengthen their cyber security before an incident happens and gives them experienced support when something doesn't look right.

We can help with cyber-security assessments, our IT Security Baseline, Cyber Essentials and Cyber Essentials Plus, endpoint protection and EDR, Microsoft 365 security, backup and recovery, proactive monitoring, employee awareness and wider managed IT support.

More importantly, we can help you understand where your current weaknesses actually are rather than simply selling another security product.

If you're not confident what would happen if ransomware or another cyber attack hit your organisation tomorrow, that's something worth fixing today.

Book your free IT & Cyber Security Review with Hamilton Group.

We'll review your current IT, security and support setup and give you practical advice on where improvements could be made — with no obligation and no hard sell.

Call 0330 043 0069 or visit hgmssp.com.