Imagine arriving at work tomorrow morning and discovering that nobody can open the company files.
Your accounts team cannot access their documents.
Sales cannot get to customer information.
Projects in progress are unavailable.
Employees start calling the person responsible for IT.
And instead of the usual Windows desktop, some computers are displaying a ransom demand.
For a 30-person business, this is not really an IT problem anymore.
It is a business continuity problem.
The question is not simply whether you have antivirus.
It is:
Could your business continue operating if a ransomware attack succeeded?
What actually happens when ransomware hits a business?
Ransomware is malicious software designed to make systems or data unavailable, commonly by encrypting them.
Some modern ransomware attacks can go further. Attackers may steal company information before encrypting systems and threaten to release it unless money is paid.
The impact therefore is not necessarily confined to a few unusable computers.
Depending on what has been compromised, a business could lose access to:
- Company files
- Shared folders
- Business applications
- Servers
- Customer information
- Finance systems
- Individual computers
- Cloud services
- Backups
For the person responsible for the smooth running of the company, the immediate problem becomes:
How do we keep the business running?
Thirty employees unable to work gets expensive very quickly
Cybersecurity is often discussed in terms of the cost of a ransom or the value of stolen information.
But there is a much simpler cost to consider.
Downtime.
Imagine a company with 30 employees.
If the average employment cost across those employees were £25 per hour, one hour of lost productivity across the workforce would represent:
30 employees x £25 = £750
Four hours becomes £3,000.
A full eight-hour working day becomes £6,000.
And that is before considering lost sales, delayed projects, customer disruption, overtime, external specialists, recovery work or reputational damage.
The precise numbers will obviously differ between businesses.
The point is that when technology is fundamental to how your employees work, an IT outage has a very real business cost. You can read more about how managed IT reduces downtime and unexpected costs.
“We are backed up”
That is reassuring.
But it should not be the end of the conversation.
A backup is only useful if you can recover from it.
Ask:
- What exactly are we backing up?
- How frequently?
- How long are backups retained?
- Could an attacker delete or encrypt the backups as well?
- When was a restore last tested?
- How long would restoring everything actually take?
There is an important difference between:
“We have backups.”
and:
“We know how we would recover the business.”
Ransomware attackers may target the backups too
If an attacker wants to maximise the pressure on a company to pay a ransom, destroying its recovery options is extremely useful.
That is why a well-designed backup strategy should not assume that the live environment is the only thing under attack.
Important backups should be appropriately separated and protected so that compromising the main business systems does not automatically give an attacker the ability to destroy every usable recovery copy as well.
Retention matters too.
Imagine an attacker has been present for some time before being discovered.
Restoring yesterday’s copy of something is not particularly useful if yesterday’s copy is already compromised.
Having appropriate historical versions gives the recovery team choices.
OneDrive synchronisation is not necessarily your recovery plan
This is another area worth understanding.
Synchronisation and backup solve different problems.
If a file changes on one device and OneDrive synchronises that change, having the change appear everywhere is normally exactly what you want.
But during a destructive incident, automatically propagating unwanted changes is not necessarily helpful.
Cloud platforms may provide versioning and recovery capabilities, but the person responsible for IT should understand exactly what protection exists rather than simply assuming:
“It is in the cloud, so we are covered.”
A managed backup strategy should define what needs protecting, where recovery copies exist, how long they are retained and how they would be restored.
Prevention still comes first
Having excellent backups does not mean you should be relaxed about ransomware.
Recovering an entire business is considerably more disruptive than preventing the incident in the first place.
Good protection therefore uses multiple layers.
Depending on the organisation, these can include:
- Keeping computers and applications patched
- Endpoint security
- Threat monitoring
- Restricting unnecessary administrative privileges
- Multi-factor authentication
- Identity and Microsoft 365 protection
- Email security
- Web protection
- Employee cybersecurity awareness
- Controlled access to company information
- Secure backup systems
The idea is that an attacker should not have only one obstacle to overcome.
If one layer fails, another may still prevent a serious incident.
Detection matters too
Imagine malicious activity begins on one computer.
Would anybody know?
Modern endpoint security is not simply about scanning files against a list of known viruses.
Security systems can also look for suspicious behaviour.
That might allow unusual activity to be detected and investigated before a problem spreads further.
This is why Bitwise-IT uses layers of protection including Microsoft Defender and Huntress within our managed IT environments.
But there is another important element:
Somebody needs to respond to the alert.
A security notification sitting unnoticed in an inbox at 2am is not the same as having a security monitoring process.
Technology, monitoring and human response need to work together.

If one computer is compromised, can you contain it?
This is where management of the company’s computers becomes important.
Your IT provider should know which devices it is responsible for.
Those devices should be visible within its management and security systems.
If something suspicious happens, the provider needs the tools and information required to investigate.
Compare that with discovering during an incident that nobody is quite sure:
- How many laptops exist
- Which employees have them
- Whether all of them have security software
- Which devices are still in use
- Whether they are patched
- How to remotely access them
An incident is a terrible time to start building your IT inventory.
Recovery is not just “restore the files”
Suppose ransomware does succeed.
You have good backups.
Problem solved?
Not quite.
Before restoring data, you need confidence that you are restoring it into a clean environment.
Potentially compromised machines may need cleaning or rebuilding.
Accounts and credentials may need investigating.
The original route into the business needs identifying.
Systems may need to be restored in a particular order.
And someone needs to decide which services matter most.
For example, would you restore:
- Email first?
- Your accounting system?
- Shared company files?
- Production systems?
- Customer-facing services?
The answer depends entirely on your business.
That is why recovery planning needs business input as well as technical input.

What does your business need to operate tomorrow?
Here is a useful exercise.
Imagine every company computer and system becomes unavailable tonight.
Tomorrow morning, what are the first five things your employees need in order to operate?
Perhaps:
- Microsoft 365 and email
- Access to customer records
- Company files
- Accounting or ERP software
- A specialist line-of-business application
Those are your critical systems.
Now ask:
- Where is each one hosted?
- Who is responsible for it?
- Is it backed up?
- How would we recover it?
- How long would that take?
- What would employees do while it was unavailable?
If nobody knows the answers, that is worth addressing before an emergency provides the opportunity to find out.
Who makes the decisions during an attack?
Technology is not the only thing that can cause confusion during a cyber incident.
People can too.
- Who has authority to shut down systems?
- Who contacts your IT provider?
- Who talks to employees?
- Who deals with customers?
- Who contacts your insurer?
- Who handles regulatory or legal requirements?
- Who speaks publicly if necessary?
- What happens if the Managing Director is on holiday when the incident occurs?
A basic incident response plan does not need to be a 100-page manual gathering dust on a shelf.
It needs to give the right people enough information to make good decisions under pressure.
Test the plan before you need it
There is a very simple way to discover whether a recovery plan works.
Test it.
Backups should be monitored and recovery should be tested appropriately.
Businesses can also run tabletop exercises.
Put the relevant people in a room and give them a scenario:
“It is 8:15 on Monday morning. We believe ransomware has affected our network and employees cannot access company files. What do we do?”
You will quickly discover questions nobody had considered.
That is useful.
Finding gaps during an exercise is considerably cheaper than finding them during a real attack.
Five questions to ask your IT company
You do not need to become a ransomware expert.
Instead, ask your IT provider:
- How would you know if ransomware started running on one of our computers?
- What could you do to contain the affected device or account?
- Which of our systems and data are independently backed up?
- When was our ability to restore from those backups last tested?
- If our main systems became unavailable tomorrow, what would our recovery process actually look like?
These are business questions, not technical ones.
A good IT provider should be able to answer them clearly.
The goal is not perfect cybersecurity
No responsible IT company can guarantee that a client will never experience a cyber incident.
The goal is to make a successful attack considerably harder and its consequences considerably more manageable.
That means thinking about:
Prevention.
Stopping as many threats as possible.
Detection.
Recognising suspicious activity when something gets through.
Response.
Having somebody capable of investigating and containing it.
Recovery.
Having protected data and a practical way of getting the business working again.
For a company employing 25, 30, 40 or 50 people, those are not simply cybersecurity considerations.
They are part of running a resilient business.
Could your business keep operating?
If you are responsible for IT within your organisation, try asking one question:
“If ransomware stopped our systems working tomorrow morning, what would we actually do?”
If you receive a confident answer, that is reassuring.
If the answer is:
“I am sure our IT company has it covered…”
it might be worth finding out.
Bitwise-IT provides managed IT and cybersecurity services to businesses across Essex and beyond. We help organisations manage their technology, protect their users and devices, monitor for threats and prepare for the occasions when something does go wrong.
If you would like an independent conversation about your current protection and recovery arrangements, we are happy to help.
No scare tactics. Just sensible preparation for a risk every modern business should understand.