Skip to main content
    NixInfinity-AI
    Ransomware

    Most Ransomware Attacks Start With Basic Cyber Gaps

    Published 2 July 2026

    The unglamorous truth about how attackers get in

    Industry threat reporting consistently shows the same short list of initial access routes behind ransomware incidents: known vulnerabilities in internet-facing systems, VPN and remote access gateways that are behind on patches, credentials bought or phished from staff, and admin accounts with no multi-factor authentication.

    None of that requires a zero-day. It requires an organisation that has not tightened the basics.

    Why SMEs get hit

    • They assume they are too small to be targeted. Ransomware affiliates scan the whole internet, not a shortlist.
    • They have public-facing services that nobody is clearly responsible for patching.
    • Admin accounts are shared, reused or lack MFA.
    • End-user devices are managed inconsistently.
    • Backups exist but have never been tested end-to-end.

    How the five Cyber Essentials controls map to real ransomware entry points

    1. Firewalls and internet gateways reduce exposed services.
    2. Secure configuration removes default accounts and unnecessary features attackers rely on.
    3. Security update management closes the known vulnerabilities affiliates scan for.
    4. User access control stops one compromised account from becoming domain-wide access.
    5. Malware protection catches commodity payloads before they detonate.

    See the full breakdown in the 5 Cyber Essentials controls and the specific MFA requirements for 2026.

    Practical hardening checklist

    • Enforce MFA on every cloud admin account and every remote access route.
    • Patch internet-facing systems within 14 days, ideally within 48 hours for critical CVEs.
    • Remove unsupported operating systems and end-of-life network appliances from the internet perimeter.
    • Review who holds administrator rights and revoke anything unused.
    • Maintain an asset inventory so nothing gets forgotten on the edge.
    • Test backups by restoring, not by looking at green ticks in a console.

    Cyber Essentials is not a ransomware guarantee. What it does is make sure the door is locked, the windows are shut and someone owns the keys.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions