NCC Group’s latest quarterly threat intelligence report, published this week, confirms what most cybersecurity teams already suspected: ransomware isn’t slowing down. Global attacks climbed 3% in Q2 2026, up from 2,165 incidents in Q1 to 2,229, with 665 recorded in June alone. What’s more useful for a UK SME than the headline number, though, is where the report says attackers are actually getting in — and it’s not through anything glamorous. Corporate VPNs and internet-facing edge devices remain the ransomware ecosystem’s single most exploited entry point, with active groups including Akira, Qilin, and The Gentlemen specifically targeting known vulnerabilities in products from vendors like Fortinet, SonicWall, Citrix, and Check Point.

Why “boring” infrastructure is the real risk

It’s tempting to assume ransomware groups are running sophisticated, custom-built attacks against each target. Mostly they’re not. They’re scanning the internet for organisations still running unpatched or misconfigured versions of exactly the kind of remote-access appliances that let your team work from home or connect to the office network securely. If your VPN gateway or firewall hasn’t been updated in a while, or if it’s still using default or reused admin credentials, you are — statistically — a more attractive target than a business running the same setup patched last week. The report also flags that supply chain attacks are growing fast, with threat groups increasingly targeting software development ecosystems rather than individual companies, so that one compromised vendor spreads to every downstream customer at once.

What to actually do this week

Start with an inventory, not a panic. List every internet-facing device your business relies on — VPN concentrators, firewalls, remote access gateways, any hardware with a login page reachable from outside your network — and check two things for each: is it running the latest firmware, and does it still use factory-default or years-old credentials? This is genuinely a 30-minute job for most small businesses, and it closes off the single most common way ransomware groups get their first foothold. Pair that with basic network segmentation, so that a compromised device doesn’t hand an attacker a clear run at everything else, and make sure whoever manages your IT has patching for edge devices on a recurring calendar reminder rather than an “as and when” basis.

It’s also worth checking who in your business actually has admin access to these devices, and whether that list still matches who needs it. Former employees, old contractors, or a supplier relationship that ended months ago are common sources of stale credentials that nobody remembers to revoke — and a forgotten login is just as useful to an attacker as an unpatched vulnerability.

Don’t treat this as an IT-only problem

The industrials sector was the most heavily targeted this quarter, accounting for 30% of all attacks, but ransomware groups don’t discriminate by size — SMEs are targeted precisely because they’re less likely to have dedicated monitoring watching for these exact vulnerabilities. If you don’t currently have visibility into whether your business’s internet-facing systems have known, unpatched vulnerabilities, that’s a genuine blind spot rather than a hypothetical risk. KeepSafe is built for exactly this — ongoing monitoring for the kind of exposure that turns a routine unpatched device into a six-figure incident — so you find out about a vulnerable VPN gateway before an extortion group does.

The takeaway

You don’t need a bigger security budget to close off the most common entry point ransomware groups use right now — you need to know which of your internet-facing devices are running out-of-date firmware or default credentials, and fix that this week. It’s unglamorous work, but it’s exactly the work that keeps you off the list.