The attacks were not a surprise to anyone in cybersecurity. Ransomware had been escalating through early 2026, warnings had been issued, and the targets — well-known UK brands with consumer-facing operations — were exactly the kind of organisations threat actors prioritise. Still, when the Easter 2026 incidents at M&S, Co-op and Harrods became public, the scale of the damage landed differently.

Combined financial impact: £440 million. Systems down for weeks. Customer data exposed. Operations disrupted during one of retail’s busiest trading periods. Three household names, three separate incidents within weeks of each other, all hitting in the same sector.

The question for every UK SME watching the coverage is not “why did it happen to them?” The question is: “what stops it happening to us?”

Why these attacks matter to businesses a tenth of the size

A common assumption is that ransomware groups target the biggest organisations because the biggest payouts come from there. That is partly true — the M&S and Co-op incidents demonstrated exactly that logic. But it is only part of the picture.

The same criminal groups that compromise large enterprises also run automated campaigns sweeping thousands of smaller targets simultaneously. SMEs are attractive precisely because they hold real commercial data, often process payments, and typically have weaker incident response capabilities. Attackers know smaller businesses are more likely to pay quickly, because the alternative — extended downtime without an IT team capable of restoring from backups — is existential.

The Easter attacks showed that no sector, no company size, and no brand reputation provides meaningful protection against a determined attacker. What does provide protection is operational resilience: the ability to absorb an incident without the whole business stopping.

The three things that determined how badly it went

Post-incident analysis of similar ransomware cases consistently identifies the same failure points.

Backups that were not tested. Most businesses have backups. Most businesses have never actually tried to restore from them under pressure. A backup that has never been validated is not a backup — it is a false sense of security. The businesses that recover fastest from ransomware are the ones whose recovery process is practiced, not theoretical.

No incident response plan. When systems go down at 2am on a bank holiday weekend, who gets called? Who has authority to take systems offline? Who talks to the press? Who contacts customers? Without a documented plan, every decision under pressure becomes a negotiation, and attackers count on that confusion to extend their leverage.

Delayed detection. Ransomware groups typically spend weeks inside a network before deploying the final payload — mapping systems, escalating privileges, and disabling backup solutions. By the time the ransom demand appears, the attacker has often been inside for 20 to 60 days. Early detection during that reconnaissance phase is where the game is actually won or lost.

What smaller businesses should do differently

The M&S and Co-op incidents are uncomfortable benchmarks, but they point to a practical checklist that SMEs can work through without enterprise-level budgets.

Start with backups. Test them. Restore a small selection of files from your most recent backup this week — not because you expect a problem, but because you need to know the process works before you need it under pressure.

Build a one-page incident plan. It does not need to be sophisticated. It needs to answer: who calls who, who shuts what down, and who communicates with customers. A document that exists is more useful than a perfect plan that does not.

For monitoring, KeepSafe provides continuous cyber incident monitoring that looks for the early indicators of compromise — the kind of activity that precedes a ransomware payload deployment. Catching an intrusion at the reconnaissance stage is significantly cheaper than responding to one that has already detonated.

The bottom line

£440 million is not a realistic consequence for most UK SMEs — but weeks of downtime, lost customer data, and a reputational hit absolutely are. The Easter 2026 incidents were a reminder that the threat is real, the timing is unpredictable, and preparation is the only variable you can control in advance.