Ransomware afflicts 48% of UK enterprises
Large businesses at high risk of ransomware, but are under prepared to deal with it


Almost half of large UK businesses have suffered a ransomware attack in the past year, with nearly one third fearing that, although the situation has been resolved, the criminals may still be lurking in their systems.
Citrix surveyed 500 UK-based IT decision makers in companies with 250 or more employees, finding that 45% had fallen victim to a successful ransomware attack.
Despite this history of victimhood, the research also found that 11% of businesses this size don't have a formal ransomware policy in place and while 50% said plans are in place to have such a policy within the next 12 months, 38% said no such plans existed.
Knowing how to deal with a ransomware infection should one occur is increasingly important, though, as this strain of malware becomes ever more popular.
"A lot of this is about isolating a potentially infected machine, deciding whether you're going to pay the ransom or not there's a business choice to be made there - and then being able to build confidence that you have actually dealt with the ransomware attack and it isn't still lurking there," Chris Mayers, chief security architect at Citrix, told IT Pro.
This third element is also a current cause for concern, with 36% of those surveyed who had fallen victim to ransomware in the past 12 months telling Citrix they doubted all traces of that attack had been fully removed.
Ultimately, said Mayers, companies need to ensure they have a ransomware plan in place, including knowing who makes the decision as to whether or not to pay, as well as being sure they can isolate the infected machine(s) and having a solid backup-and-recovery plan in place.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives

Jane McCallion is Managing Editor of ITPro and ChannelPro, specializing in data centers, enterprise IT infrastructure, and cybersecurity. Before becoming Managing Editor, she held the role of Deputy Editor and, prior to that, Features Editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, and business strategy.
Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.
-
Prolific ransomware operator added to Europe’s Most Wanted list as US dangles $10 million reward
News The US Department of Justice is offering a reward of up to $10 million for information leading to the arrest of Volodymyr Viktorovych Tymoshchuk, an alleged ransomware criminal.
-
Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attack
News The attack on Jaguar Land Rover highlights the growing attractiveness of the automotive sector
-
Enterprises need to patch these Citrix flaws now
News Organizations should move quickly to install patches, according to Citrix
-
Ransomware attack on IT supplier disrupts hundreds of Swedish municipalities
News The attack on IT systems supplier Miljödata has impacted public sector services across the country
-
A notorious hacker group is ramping up cloud-based ransomware attacks
News The Storm-0501 threat group is refining its tactics, according to Microsoft, shifting away from traditional endpoint-based attacks and toward cloud-based ransomware.
-
Security researchers have just identified what could be the first ‘AI-powered’ ransomware strain – and it uses OpenAI’s gpt-oss-20b model
News Using OpenAI's gpt-oss:20b model, ‘PromptLock’ generates malicious Lua scripts via the Ollama API.
-
Data I/O shuts down systems in wake of ransomware attack
News Regulatory filings by Data I/O suggest the costs of dealing with the attack could be significant
-
Average ransom payment doubles in a single quarter
News Targeted social engineering and data exfiltration have become the biggest tactics as three major ransomware groups dominate