A new national policing campaign launched this week is putting fresh, uncomfortable numbers in front of UK business owners: 323 UK organisations reported a ransomware attack between April 2025 and March 2026 — more than 26 every month — and over half of those reports, 175, came from small and medium-sized enterprises. Financial losses reported by victims totalled around £270,000, a 50% increase on the year before. Regional police forces, including Northamptonshire’s Cyber Team, are now actively encouraging businesses to report incidents through the national Report Fraud campaign, partly because underreporting has made it hard to know the true scale of the problem.
Why the reporting gap matters as much as the attacks
Ransomware has been a known threat to SMEs for years, so the headline figures alone are not the news. What is new is the emphasis from police on getting businesses to actually report attacks rather than quietly paying a ransom and moving on. Every unreported incident is a gap in the intelligence picture that helps other businesses defend themselves, and it also means many affected companies never access the support and advice that comes with an official report.
The National Cyber Security Centre’s position remains unchanged and worth repeating plainly: do not pay ransom demands. Payment doesn’t guarantee data recovery, funds further attacks, and offers no assurance the same attacker — or another one — won’t return. Law enforcement’s consistent advice is to isolate affected systems, report the incident, and restore from clean backups.
What actually reduces your risk
A layered backup strategy is the single most effective defence. Police guidance this week specifically highlights maintaining offline copies wherever possible — backups that are disconnected from your network cannot be encrypted by an attacker who has already gained access to your systems. If your current backup is just another networked drive or synced cloud folder, it is vulnerable to the same attack as everything else.
Test your recovery process, not just your backup schedule. A backup nobody has ever restored from is a hope, not a plan. Set aside time to actually run a recovery test on a non-critical system and time how long it takes — that number tells you how long your business would actually be down in a real incident.
Know who you call and what you say before you need to. A short, rehearsed incident response plan — who isolates affected devices, who reports to police and the ICO if personal data is involved, who communicates with customers — turns a chaotic first hour into a manageable one.
Where ecosystem support fits
Monitoring for early warning signs of compromise, rather than discovering an attack only once files are encrypted, is where continuous oversight pays for itself. KeepSafe.Report is built for exactly this: ongoing incident monitoring that flags exposure before it becomes a full-blown ransomware event, giving SMEs without a dedicated security team a way to stay ahead of the threat rather than reacting to it.
Reporting is not just a formality
There’s a natural instinct to want an incident to simply go away — restore the backups, tell no one, get back to work. But an unreported attack means the specific tactics used against your business never reach the intelligence picture that helps law enforcement track ransomware groups and warn other potential targets. It also usually means missing out on guidance and support that comes with a formal report, including help understanding whether attacker claims about stolen data are credible or bluff. Reporting takes minutes; the alternative can cost far more in a repeat attack nobody saw coming.
The takeaway
A 50% year-on-year rise in reported SME ransomware losses is a real trend, not a one-off statistic, and police are actively asking businesses to report incidents rather than absorb them quietly. This week is a good prompt to check three things: are your backups genuinely offline, have you tested a restore recently, and does anyone on your team know exactly what to do in the first hour of an incident. If the honest answer to any of those is no, that is this week’s most useful fix.