Cyber Security The UK SME ransomware playbook 2026
If a UK SME gets hit by ransomware tomorrow, the difference between a 2-day disruption and going out of business is a written playbook, run before the incident, by people who know what to do. Most SMEs don't have one. This post is the implementer's view: what to do in the first 60 minutes (detect, contain, preserve evidence), the first 24 hours (notify, scope, communicate, recovery start), and the first 30 days (full recovery, post-incident review, insurance and regulatory steps). Plus the honest position on the question every owner will ask within an hour of the first encrypted file: do you pay?
Iain Godding
16 Jun 2026