How the channel weakened ransomware’s grip
What tools and techniques are empowering businesses to say no to ransomware demands?
More businesses than ever are now reporting that they’re choosing to recover from backups, rather than cede to ransomware demands. In fact, recent Databarracks research found that just 17% of UK businesses paid the ransom in the past year.
The changes in response and recovery are in part down to better backup practices. Managed Service Providers (MSPs), IT partners, and resellers have all played a crucial role in supporting businesses beyond the common compliance checkboxes and anti-virus software solutions of the past.
Businesses are now utilizing channel partners’ expertise to implement resilience strategies that include air-gapped and immutable backups and conducting regular testing, planning, and rehearsal. All of this is giving businesses the confidence to say no to ransom demands.
Air-gapped, immutable backups
The best exit route for organizations facing ransomware is to be in a position where they can choose not to make the payment. In order to do that, they first need to have an air-gapped, immutable backup that can’t be compromised.
There are several different methods to create air gaps now. There are also several ways to introduce ‘immutability’ that balance access with storage and cost. The channel can play a crucial part in supporting businesses with this step, advising on the best method, solution, and supporting technology per a business’s unique needs, then handling the implementation too.
One of the added benefits of outsourcing backups to a managed service provider is that you introduce another level of separation between production data and backups. Our recommendation from a continuity perspective would be to adopt a multi-vendor approach wherever possible. For example, having one supplier delivering production IT and another looking after IT resilience.
Implementing immutable storage is often touted as a silver bullet, but channel partners need to explain to their customers that they are committing to an increase in storage, too. There’s no blanket policy or simple answer for every organization; any decisions need to balance cost and risk.
Stay up to date with the latest Channel industry news and analysis with our twice-weekly newsletter
Having all of this in place isn’t enough on its own, either; businesses also have to want to refuse the ransom. In rare cases, the ransom will even cost less than carrying out your own recovery.
Prepared, rehearsed, and resilient
The right channel partner can support more than just implementing new techniques and technologies. They also play a role in keeping cybersecurity policies and incident response plans up to date and can ensure that businesses are aware of any new requirements.
Crucially, they ensure teams are trained to recognize and report incidents promptly. While most organizations are already delivering cybersecurity awareness training — a necessary baseline — not all are pairing it, as they should, with incident response exercises.
Channel partner support with recovery planning and rehearsal is integral in instilling confidence for when disaster strikes. It’s always advisable to conduct regular cyber crisis management exercises to test plans and ensure preparedness.
Regulation plays its part
The shift in ransomware response is also in part due to new regulations. The UK Government confirmed its new ransomware policy in July, which includes a ban on ransom payments by public sector bodies and critical national infrastructure operators, plus mandatory reporting and pre-payment notification for the private sector.
While this is bold, the data shows the direction of travel was already clear. In one sense, the policy is a formalization of where UK businesses were already headed. Paying the ransom used to feel like the only option. Now, the best-prepared organizations are recovering faster, more reliably, and without funding criminals.
Overall, the balance is shifting. Despite these changes, the best antidote to ransomware – beyond any regulatory directives – remains preparedness.
The road ahead
The channel is empowering more organizations to make that choice and take a meaningful step towards strengthening the UK’s cyber resilience and breaking the cycle of ransomware attacks.
Recovery isn’t a last resort; it’s a strategy. The organizations that plan and rehearse their recoveries are the ones that come through an attack strongest. That’s how you beat ransomware: not by paying, but by preparing to recover.
James has been with Databarracks for almost 20 years. During that time he has helped shape the company's growth from one of the UK’s first online backup providers into a global leader in business and technology resilience and public cloud continuity.
He became managing director in 2023 after holding senior roles in sales and marketing.
-
Asus Zenbook 14 (Snapdragon X UX3480Q) reviewReviews Poor battery performance and an older Snapdragon chip, but still a good choice for the office
-
Softcat to acquire North American technology solutions provider GDTNews The deal will create a transatlantic IT solutions platform to increase support for businesses with international requirements
-
The hidden cost of tool sprawl on the channelIndustry Insights Tool sprawl represents major challenges for MSPs, so how can the issue be tackled?
-
Why the MSSP model is broken, and how to fix itIndustry Insights CISOs are struggling to differentiate between MSSPs due to confusing metrics and SLAs
-
How MSSPs can deliver continuous pentesting without hiring more security expertsIndustry Insights MSSPs can scale and strengthen their security posture using AI instead of expanding security teams...
-
The CISO now owns physical security. Here’s what that means for the channelIndustry Insights Physical security budgets have moved to CISOs, and partners must adapt to this important shift
-
Why software supply chain security is the next accountability challenge for channel partnersIndustry Insights Partners need to be able to confidently answer key client questions relating to supply chain security going forward...
-
Sovereignty is the channel’s next trust testIndustry Insights Data sovereignty has become a key channel priority
-
Why MSPs should rethink the browser as the new security control pointIndustry Insights Enterprise browsers simplify security by consolidating multiple security controls
-
Why quantum-ready data protection belongs in the channel portfolioIndustry Insights Quantum-ready, data-centric protection is the channel’s next major differentiator