Ransomware attacks don’t always arrive through your own front door. Increasingly, criminals get in through a supplier’s system, a software vendor’s compromised update, or an IT partner’s misconfigured access. And UK businesses of all sizes are now squarely in the crosshairs.
This week the UK government published new guidance on supply chain resilience against ransomware, produced in collaboration with international partners through the Counter Ransomware Initiative — a 67-nation coalition co-chaired by the UK. The guidance is practical, direct, and aimed at helping organisations identify and fix the supplier-side gaps that attackers exploit most. For UK SMEs, it’s a message worth taking seriously.
Why Supply Chains Are the New Attack Route
The ransomware attacks on Marks & Spencer and the Co-op Group in spring 2025 demonstrated the scale of disruption a single campaign can cause. The combined estimated cost ran to over £440 million. Both incidents highlighted a pattern that security researchers have flagged for years: attackers don’t always breach through brute force. They find a way in through a trusted connection, a third-party system with weaker controls, or a supplier with access to credentials they shouldn’t still hold.
SMEs are particularly exposed in this model. Many have relationships with larger organisations — as suppliers, contractors, or service providers — without the security standards those larger organisations maintain. Criminals treat smaller businesses as a stepping stone into bigger targets. But SMEs suffer direct damage too: when their own suppliers are compromised, systems go down, data is exposed, and operations halt.
Research from the Federation of Small Businesses found that 43% of UK SMEs experienced a cyber attack in the past year. Many of those incidents were enabled not by failures in the business’s own defences, but by weaknesses in connected third-party systems.
What the New Guidance Recommends
The UK government guidance sets out five practical areas for supply chain ransomware resilience:
Understand your supplier relationships. Map who has access to your systems, data, and email environment. Many businesses genuinely don’t know which suppliers can log into their platforms until something goes wrong.
Assess supplier security posture. Don’t assume that because a supplier is established or large, their security is sound. Ask directly: what controls do they have? Do they use multi-factor authentication? When were they last assessed?
Set minimum security expectations. Make cyber security requirements part of your supplier contracts. Basic expectations — MFA, patching cadence, incident notification — can be written into agreements without legal complexity.
Monitor for early warning signs. Unusual access patterns or failed authentication attempts from supplier IP addresses can signal that something is wrong before a full breach occurs.
Plan for supplier-linked incidents. Know what you will do if a critical supplier’s systems go down or are compromised. Have a continuity plan for your key dependencies.
For most UK SMEs, working through steps one and two alone would represent a meaningful improvement.
What You Can Do Now
Start with a simple audit: list every supplier, contractor, or software platform that has access to your systems or data. Then ask whether you know what security controls each one has in place. If the honest answer is no, that’s your starting point.
If you use a managed IT provider, they should be able to explain exactly what access they hold and how it’s protected. If they can’t answer that clearly and quickly, that’s a flag worth acting on.
For businesses that want ongoing visibility of their threat exposure — including signals that something in their supplier network may be compromised — KeepSafe (keepsafe.report) monitors for cyber incidents, dark web mentions, and early-warning indicators so you know before an issue becomes a crisis.
The Takeaway
The UK government doesn’t coordinate a 67-nation ransomware initiative and publish supply chain guidance for businesses to file and forget. Supply chain compromise is the dominant ransomware entry point of 2026.
A ransomware attack doesn’t have to start with you — but it can very easily end with you. Knowing your suppliers’ security posture is no longer optional.