UK businesses underreport ransomware attacks due to stigma

Ransomware is a bigger problem than the numbers suggest. The issue is that many organisations choose not to report them. That creates a gap between what decision-makers think is happening and what is actually happening.

Many businesses worry that admitting a ransomware attack will damage their reputation, raise questions from customers and regulators, or expose the fact that they paid a ransom. Some also fear that disclosing an incident could be interpreted as supporting criminal activity or failing to meet compliance expectations. These concerns are understandable, but they come with a cost. Every unreported attack reduces the industry’s ability to understand how attackers operate and where they are evolving.

For executives, this is more than a communications issue. It is a business intelligence issue. Cybersecurity depends on accurate information. If organisations stay silent, governments, law enforcement, and security teams lose valuable insight into emerging attack methods. That makes it harder to identify trends, allocate resources, and improve defenses across the wider economy.

A stronger reporting culture also benefits individual organisations. Reporting incidents helps authorities build a clearer picture of ransomware campaigns, which can lead to faster threat intelligence, improved guidance, and better coordination during future attacks. Transparency should be viewed as part of modern risk management rather than a sign of weakness.

According to the national Report Fraud service, operated by the City of London Police, 323 UK organisations reported ransomware attacks between April 2025 and March 2026. Those incidents resulted in reported financial losses of £270,000. This figure almost certainly reflects substantial underreporting rather than the true financial impact of ransomware across UK businesses.

SMEs represent a significant proportion of ransomware incidents

Ransomware is not just a problem for large enterprises. The latest figures show that small and medium-sized enterprises are frequent targets. Attackers increasingly focus on organisations of every size because many smaller businesses hold valuable data while often operating with fewer cybersecurity resources.

According to Report Fraud, 175 of the 323 reported ransomware incidents between April 2025 and March 2026 involved SMEs. That represents more than half of all reported cases. The data reinforces an important point for business leaders: company size does not determine whether an organisation will be targeted.

For executives leading SMEs, cybersecurity should be treated as a core business function rather than an IT expense. An attack can interrupt operations, affect customer confidence, delay revenue, and create legal and regulatory challenges. Even if a business recovers its systems, the disruption can have lasting commercial consequences.

The good news is that many successful ransomware attacks exploit weaknesses that can be reduced with consistent security practices. Regular software updates, strong identity and access controls, reliable backups, employee awareness, and tested incident response plans significantly improve resilience. These measures are often less expensive than the financial and operational costs of recovering from an attack.

Amanda Wolf, Chief Superintendent and Head of Operations at Report Fraud, part of the City of London Police, emphasized that ransomware remains “a serious and evolving threat to organisations of all sizes across the UK.” Her message reflects a broader shift in cybersecurity thinking: resilience is no longer optional. It is a business capability that every organisation, regardless of size, needs to develop continuously.

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.

Proactive preparation and rapid reporting are critical

Ransomware cannot be eliminated completely, but its impact can be reduced significantly through preparation. Organisations that invest in prevention and response before an incident occurs are in a much stronger position when they face an attack. This is not simply about deploying security technology. It requires clear processes, executive oversight, and regular testing.

The National Cyber Security Centre (NCSC) recommends practical measures that consistently reduce risk. These include maintaining regular offline or otherwise protected data backups, enforcing strong access controls, keeping systems and software up to date, and following established cybersecurity guidance. Each measure addresses a common weakness that ransomware groups often exploit.

For executive teams, preparation should be integrated into business continuity planning. A ransomware attack can disrupt operations, interrupt supply chains, affect customer services, and expose sensitive information. An effective incident response plan should define decision-making responsibilities, communication procedures, recovery priorities, and reporting requirements before an incident occurs. When these plans have been tested, organisations can respond more quickly and reduce unnecessary disruption.

Speed also matters once an attack is detected. Prompt reporting allows specialist teams to provide guidance while the incident is still developing. Early engagement with authorities can improve coordination, preserve valuable evidence, and contribute to a broader understanding of current ransomware campaigns that may be affecting other organisations.

Amanda Wolf, Chief Superintendent and Head of Operations at Report Fraud, part of the City of London Police, stressed that “the most effective defence is preparation.” She encouraged organisations to adopt regular data backups, strong access controls, timely system updates, and NCSC guidance to reduce both the likelihood and impact of ransomware attacks. She also advised businesses experiencing an attack to report it immediately through Report Fraud, where a dedicated team is available to provide support during an incident.

Transparency and sharing attack details strengthen collective cybersecurity

Many organisations still believe the safest response to a ransomware attack is to keep it private. That approach protects short-term reputation, but it also limits the information available to other businesses, security professionals, and law enforcement. Over time, this makes it more difficult to identify emerging attack techniques and respond effectively.

Sharing information about ransomware incidents creates practical benefits. Attack methods, exploited vulnerabilities, and indicators of compromise help security teams improve their own defenses before they become targets. This knowledge also enables law enforcement and government agencies to build a clearer picture of how ransomware groups operate and how their tactics are changing.

Executives should consider transparency as part of long-term resilience rather than a reputational risk alone. Customers, investors, and regulators increasingly expect organisations to respond responsibly to cyber incidents. Clear communication, combined with appropriate reporting and evidence-based lessons learned, demonstrates that the organisation is focused on managing risk rather than concealing it.

A culture of responsible disclosure also accelerates learning across industries. As more organisations contribute information about attacks, security guidance becomes more accurate, defensive technologies improve, and businesses gain a better understanding of where to invest their cybersecurity resources.

Jake Moore, Global Cyber Security Advisor at ESET, said that “one of the biggest barriers to tackling ransomware is that so many organisations still feel they have to deal with it in silence.” He argued that every unreported incident makes it harder for law enforcement and other organisations to understand how ransomware groups operate. Moore also noted that organisations willing to publish details of their attacks have likely prevented many future incidents by helping others recognize and defend against the same techniques.

Authorities encourage both reporting and refusing ransom payments

Governments and cybersecurity agencies are becoming increasingly aligned on one message: report ransomware incidents quickly and avoid paying ransoms whenever possible. This approach is intended to improve national cyber resilience while reducing the financial incentives that allow ransomware groups to continue operating.

The UK’s Report Fraud service has launched a ransomware awareness campaign to encourage organisations to report cyberattacks rather than handling them privately. Better reporting provides government agencies, including the National Cyber Security Centre (NCSC), with a more accurate understanding of the threat landscape. That information supports stronger threat intelligence, better policy decisions, and more coordinated responses across both the public and private sectors.

The campaign also reinforces long-standing guidance against paying a ransom. Although organisations under operational pressure may view payment as the fastest path to recovery, there is no guarantee that attackers will restore encrypted systems, return stolen data, or refrain from making additional demands. In many cases, organisations face continued disruption even after making a payment. Paying also provides criminal groups with additional funding, allowing them to expand their operations and target more victims.

For executive teams, this highlights the importance of making critical decisions before an incident occurs. A well-defined ransomware response policy should establish the organisation’s position on ransom payments, define escalation procedures, identify external partners, and ensure legal, regulatory, and communications teams are prepared to respond together. Making these decisions during a crisis significantly increases operational and legal risk.

Business leaders should also ensure that cybersecurity strategy extends beyond prevention. Recovery planning, executive-level incident exercises, employee awareness, and alignment with government guidance all contribute to a more resilient organisation. The objective is to withstand an attack and to recover quickly while maintaining stakeholder confidence.

Amanda Wolf, Chief Superintendent and Head of Operations at Report Fraud, part of the City of London Police, encouraged organisations experiencing ransomware to report incidents immediately so dedicated specialists can provide support. Neither the NCSC nor UK law enforcement agencies endorse or condone paying ransoms because doing so funds criminal activity and offers no assurance that encrypted or stolen data will be recovered. Organisations seeking practical guidance are directed to the NCSC’s Cyber Action Toolkit and its ransomware response resources.

Key executive takeaways

  • Treat underreporting as a business risk: Ransomware is likely far more widespread than official figures indicate because many organisations avoid reporting incidents. Leaders should encourage transparent reporting to improve threat intelligence, strengthen industry resilience, and support informed risk management.
  • SMEs are a prime target: More than half of reported UK ransomware cases involved small and medium-sized enterprises, showing that attackers do not focus only on large organisations. Executives should ensure cybersecurity investment matches business risk, regardless of company size.
  • Build resilience before an attack: Regular backups, strong access controls, timely system updates, and a tested incident response plan significantly reduce the impact of ransomware. Fast reporting also gives organisations access to specialist support and improves coordination with authorities.
  • Share lessons to strengthen collective defence: Responsible disclosure of ransomware incidents helps businesses, security teams, and law enforcement identify attacker tactics more quickly. Leaders should view transparency as a long-term investment in organisational and industry-wide resilience.
  • Align incident response with government guidance: Report attacks promptly and avoid paying ransoms, as payment funds criminal activity without guaranteeing data recovery. Establish clear executive policies and recovery plans before an incident occurs to improve decision-making under pressure.

Alexander Procter

July 29, 2026

8 Min

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.