
February 28, 2024
Cyber-attacks are becoming an everyday risk to businesses of all sizes in every industry.
So, at Robert Gerrard, we’ve made it our mission this year to ensure our clients fully understand the threats posed by online crime, and that they’re fully covered against them.
We’re therefore launching a blog series which we hope will help you better understand the complex landscape of cybercrime.
In the first of the series, we are looking specifically at ransomware.
In this post (click to jump straight to each section):
- Overview – the growing risks of cyberattacks
- What is ransomware?
- How does a ransomware attack work?
- How to prevent ransomware attacks?
- What to do if you’ve experienced a ransomware attack?
- How to protect your business with cyber insurance
The growing risks of cyber attacks
Research released by Aviva in December 2023 reveals that:
- One in five UK businesses have experienced a cyber-attack or incident
- Almost one in ten businesses have experienced an attack in the past year
- Businesses are 67% more likely to have experienced a cyber incident than a physical theft
- Businesses are almost five times more likely to have experienced a cyber-attack than a fire
Operational disruption, data loss, system lockdowns… according to Aviva, interruptions like these led to businesses claiming an average of £21,000 per incident.
But costs can run into tens or even hundreds of thousands when regulatory fines, long term loss of goodwill and reputational damage are factored in.
What is ransomware?
Ransomware is one of the UK’s biggest cyber threats. So it’s vital that businesses and individuals protect themselves.
Ransomware involves stealing and encrypting data to make it inaccessible. Data extortion attacks, where data is stolen but not encrypted, are common too.
Between September 2022 and August 2023,
the National Cyber Security Centre received 297 reports of ransomware activity
across a range of industry sectors in the UK.

Ransomware is a type of malware. Malware is software that’s intentionally designed to:
- Cause disruption to a computer device, network, server or client
- Leak private information
- Gain unauthorised access to information or systems
- Deprive access to information
Ransomware specifically prevents users from accessing their devices and data, usually by encrypting files. A criminal will then make a demand for ransom in exchange for decrypting the data.
Following a ransomware attack, you may find that your device becomes locked, or the data on it might be encrypted, deleted or stolen. The criminals may also threaten to leak the data.
How does a ransomware attack work?
Attackers gain access to a network via a security vulnerability. They establish control, and plant malicious encryption software known as malware.
When the malware is activated, it locks devices, causing the data across the network to be encrypted, making it inaccessible to users.
An on-screen notification appears from the cybercriminal setting out details of the ransom, and how to make the payment they want to unlock devices or unencrypt data.
Payment demands are usually made via an anonymous web page in a form of cryptocurrency.
The payment of ransom demands is NOT encouraged,
endorsed or condoned by law enforcement agencies.
If the ransom is paid, there is no guarantee that access to data or devices will be reinstated. Your system will remain infected, and you will be more likely to be targeted in the future.
For this reason, it is vital to keep a recent offline backup of your most important files and data.
How to prevent and protect against ransomware attacks?
You should work on the assumption that malware will get into your organisation at some point, take steps to limit the impact this would cause, and plan a response.
We’ve put together a short guide with actions you can take to help protect against and recover quickly from potential malware and ransomware attacks.
Read the guide: How to protect against and recover from ransomware attacks
What to do in the event of a ransomware attack?
Here’s what to do in the immediate aftermath of a ransomware attack:
- Immediately disconnect infected devices from all network connections
- In a serious case, turning off your internet connection
- Reset all login credentials, but be sure to make sure you are not locking yourself out of any access you’ll need to recover your data
- Safely wipe infected devices and reinstall the operating system and other software from a clean network – you may need help from your IT provider for this
- Before restoring backups, check them for malware – again you will likely benefit from professional help with this
- Run antivirus software before reconnecting to your network
- Monitor network traffic and run regular scans in case any infection remains
Ransomware attacks are considered criminal activity and should be reported. You can do so using this government website link.
Useful resources
A useful free resource is the National Cyber Security Centre’s Exercise in a Box tool. This provides exercises for companies to test and practice their response to a range of cyber-attacks.
There is a cyber security training course that you can share with your workforce. This is provided by the National Cyber Security Centre and is free of charge.
You may also wish to download and display the National Cyber Security Centre poster to help with your efforts.
Cyber insurance: protecting your business against ransomware and other cyber threats
Aviva says that one in three organisations consider cyber threats the biggest risk to their business. Despite this, many still do not have cyber cover in place, leaving them exposed to significant unforeseen costs and considerable business disruption.
Many businesses will purchase cyber cover following an attack once they realise the devastating effects that are possible.
With the economy as it is, there is a tendency to side-line additional costs. But without financial protection, a cyber-attack will almost certainly cost an organisation far more than an insurance policy.
There are more affordable cyber insurance products coming onto the market which could prove an essential lifeline should the worst happen.
What is cyber insurance?
Cyber insurance is designed to protect against all types of cyber-related attacks.
There are products suited to smaller businesses too, including micro businesses and sole traders/self-employed individuals.
Some cover will provide access to a team of dedicated cyber experts who will help to deal with the impact of an incident, including in the first 60 minutes following an attack when fast action can significantly reduce the impact of the event.
As well as cover for financial losses, depending on the policy, some insurers also offer:
- A 24/7 helpline for round-the-clock assistance
- Specialist IT forensic experts to resolve the event and get the business back on track
- Cyber extortion cover
- Identity fraud and credit monitoring services
- Reputation management guidance
Remember that in the event of a ransomware attack, the first course of action should NOT be paying the ransom in exchange for the attacker unlocking your systems. You are best advised to report the matter to the police in the first instance.
Then, if you have cyber cover, speak with your insurer to establish your next steps.
The right advice during incidents like these is invaluable, which is why we are strongly recommending cyber insurance to all our business clients.
For bespoke advice on protecting against cybercrime with insurance cover tailored to your specific needs and operation, we welcome you to get in touch with our dedicated cyber protection team.
Share This Story, Choose Your Platform!
Cyber-attacks are becoming an everyday risk to businesses of all sizes in every industry.
So, at Robert Gerrard, we’ve made it our mission this year to ensure our clients fully understand the threats posed by online crime, and that they’re fully covered against them.
We’re therefore launching a blog series which we hope will help you better understand the complex landscape of cybercrime.
In the first of the series, we are looking specifically at ransomware.
In this post (click to jump straight to each section):
- Overview – the growing risks of cyberattacks
- What is ransomware?
- How does a ransomware attack work?
- How to prevent ransomware attacks?
- What to do if you’ve experienced a ransomware attack?
- How to protect your business with cyber insurance
The growing risks of cyber attacks
Research released by Aviva in December 2023 reveals that:
- One in five UK businesses have experienced a cyber-attack or incident
- Almost one in ten businesses have experienced an attack in the past year
- Businesses are 67% more likely to have experienced a cyber incident than a physical theft
- Businesses are almost five times more likely to have experienced a cyber-attack than a fire
Operational disruption, data loss, system lockdowns… according to Aviva, interruptions like these led to businesses claiming an average of £21,000 per incident.
But costs can run into tens or even hundreds of thousands when regulatory fines, long term loss of goodwill and reputational damage are factored in.
What is ransomware?
Ransomware is one of the UK’s biggest cyber threats. So it’s vital that businesses and individuals protect themselves.
Ransomware involves stealing and encrypting data to make it inaccessible. Data extortion attacks, where data is stolen but not encrypted, are common too.
Between September 2022 and August 2023,
the National Cyber Security Centre received 297 reports of ransomware activity
across a range of industry sectors in the UK.

Ransomware is a type of malware. Malware is software that’s intentionally designed to:
- Cause disruption to a computer device, network, server or client
- Leak private information
- Gain unauthorised access to information or systems
- Deprive access to information
Ransomware specifically prevents users from accessing their devices and data, usually by encrypting files. A criminal will then make a demand for ransom in exchange for decrypting the data.
Following a ransomware attack, you may find that your device becomes locked, or the data on it might be encrypted, deleted or stolen. The criminals may also threaten to leak the data.
How does a ransomware attack work?
Attackers gain access to a network via a security vulnerability. They establish control, and plant malicious encryption software known as malware.
When the malware is activated, it locks devices, causing the data across the network to be encrypted, making it inaccessible to users.
An on-screen notification appears from the cybercriminal setting out details of the ransom, and how to make the payment they want to unlock devices or unencrypt data.
Payment demands are usually made via an anonymous web page in a form of cryptocurrency.
The payment of ransom demands is NOT encouraged,
endorsed or condoned by law enforcement agencies.
If the ransom is paid, there is no guarantee that access to data or devices will be reinstated. Your system will remain infected, and you will be more likely to be targeted in the future.
For this reason, it is vital to keep a recent offline backup of your most important files and data.
How to prevent and protect against ransomware attacks?
You should work on the assumption that malware will get into your organisation at some point, take steps to limit the impact this would cause, and plan a response.
We’ve put together a short guide with actions you can take to help protect against and recover quickly from potential malware and ransomware attacks.
Read the guide: How to protect against and recover from ransomware attacks
What to do in the event of a ransomware attack?
Here’s what to do in the immediate aftermath of a ransomware attack:
- Immediately disconnect infected devices from all network connections
- In a serious case, turning off your internet connection
- Reset all login credentials, but be sure to make sure you are not locking yourself out of any access you’ll need to recover your data
- Safely wipe infected devices and reinstall the operating system and other software from a clean network – you may need help from your IT provider for this
- Before restoring backups, check them for malware – again you will likely benefit from professional help with this
- Run antivirus software before reconnecting to your network
- Monitor network traffic and run regular scans in case any infection remains
Ransomware attacks are considered criminal activity and should be reported. You can do so using this government website link.
Useful resources
A useful free resource is the National Cyber Security Centre’s Exercise in a Box tool. This provides exercises for companies to test and practice their response to a range of cyber-attacks.
There is a cyber security training course that you can share with your workforce. This is provided by the National Cyber Security Centre and is free of charge.
You may also wish to download and display the National Cyber Security Centre poster to help with your efforts.
Cyber insurance: protecting your business against ransomware and other cyber threats
Aviva says that one in three organisations consider cyber threats the biggest risk to their business. Despite this, many still do not have cyber cover in place, leaving them exposed to significant unforeseen costs and considerable business disruption.
Many businesses will purchase cyber cover following an attack once they realise the devastating effects that are possible.
With the economy as it is, there is a tendency to side-line additional costs. But without financial protection, a cyber-attack will almost certainly cost an organisation far more than an insurance policy.
There are more affordable cyber insurance products coming onto the market which could prove an essential lifeline should the worst happen.
What is cyber insurance?
Cyber insurance is designed to protect against all types of cyber-related attacks.
There are products suited to smaller businesses too, including micro businesses and sole traders/self-employed individuals.
Some cover will provide access to a team of dedicated cyber experts who will help to deal with the impact of an incident, including in the first 60 minutes following an attack when fast action can significantly reduce the impact of the event.
As well as cover for financial losses, depending on the policy, some insurers also offer:
- A 24/7 helpline for round-the-clock assistance
- Specialist IT forensic experts to resolve the event and get the business back on track
- Cyber extortion cover
- Identity fraud and credit monitoring services
- Reputation management guidance
Remember that in the event of a ransomware attack, the first course of action should NOT be paying the ransom in exchange for the attacker unlocking your systems. You are best advised to report the matter to the police in the first instance.
Then, if you have cyber cover, speak with your insurer to establish your next steps.
The right advice during incidents like these is invaluable, which is why we are strongly recommending cyber insurance to all our business clients.
For bespoke advice on protecting against cybercrime with insurance cover tailored to your specific needs and operation, we welcome you to get in touch with our dedicated cyber protection team.



