Key Takeaways

  • Cleveland Police recorded 323 ransomware reports in FY 2025/26, with more than half coming from SMEs.
  • Global ransomware activity continues to outpace official reporting channels, creating a widening visibility gap for business leaders.
  • UK and international research points to sustained operational and financial pressure on organisations in 2025 and 2026.

Ransomware has been climbing the agenda for UK organisations for years, but the latest figure confirmed by Cleveland Police brings a sharper focus to the scale of the problem. The force recorded 323 organisations reporting ransomware attacks in FY 2025/26, and more than half were small or medium-sized enterprises. SMEs often run lean IT functions and have limited capacity to manage extended periods of disruption, prompting new questions among leadership teams regarding how to maintain resilience when global activity is accelerating faster than the capacity to detect and report it.

Comparitech tracked 7,419 ransomware attacks worldwide in 2025, a 32% rise on 2024, with 6,292 of those incidents targeting businesses. The gap between these global tallies and police reporting suggests ongoing underreporting and reflects inconsistent victim disclosure practices. Some organisations inform law enforcement quickly, while others prioritise internal triage or external consultants. A similar visibility gap was noted in the UK Government's Cyber Security Breaches Survey 2025, which found that 43% of UK businesses experienced a cyber breach or attack in the previous year.

Another data point shaping the conversation comes from the FBI's Internet Crime Complaint Center. The IC3 logged 3,156 ransomware complaints in 2024 with adjusted losses exceeding $12.4 million. That figure only reflects losses reported directly to the FBI, as many businesses work through private incident response firms without submitting a formal complaint, or fold ransomware incidents into broader cyber insurance claims.

The United States Department of Homeland Security provided further context in its Homeland Threat Assessment, stating that more than 5,600 publicly disclosed ransomware attacks occurred globally in 2024, with over 2,600 victims in the United States. Those numbers show that the threat continues to cut across geographies and sectors. Healthcare providers, local authorities, manufacturing plants, logistics operations, and educational institutions all feature in incident lists, and each sector carries its own operational constraints.

Organisations commonly turn to specialist vendors to help manage the threat. CrowdStrike, SentinelOne, and Sophos remain widely adopted in the B2B market for endpoint protection, incident response, and managed detection. Their tooling often forms part of a broader operational picture involving in-house security teams, cloud service providers, and external forensics partners. Analysts at Gartner have noted that businesses with clear governance and early response playbooks tend to recover more effectively, while organisations relying on ad-hoc practices face longer operational impact.

Timely reporting can support law enforcement investigative work, help other organisations through shared threat intelligence, and assist with regulatory expectations. The National Institute of Standards and Technology provides the NIST Cybersecurity Framework, which is widely used to structure detection and response processes. Similarly, ISO/IEC 27001 gives organisations a recognised structure for information security management. Research from the NIST program has suggested that alignment with these practices often helps teams triage faster and reestablish core systems in a more predictable way.

Looking at the UK specifically, a practical issue is the operational impact on SMEs, which often face limited capacity to absorb downtime and may lack the layered controls that larger enterprises build over time. A report by Deloitte highlighted that small organisations tend to face longer disruptions because they operate with constrained headcount and fragmented legacy technology. This dynamic creates a ripple effect: an SME that cannot process orders for several days may face cancelled contracts or supply chain penalties, and this economic stress can persist well beyond the initial recovery window.

To address these risks, organisations are adopting more rigorous backup processes and offsite data retention. Others are segmenting networks or deploying managed detection services to handle alert fatigue. More advanced firms are running table-top exercises to test decision-making under pressure. These steps help reduce the operational impact of an attack, even if they do not prevent it outright.

Ransomware has become a familiar headline, which sometimes creates the impression that it is an unavoidable cost of doing business. However, the patterns in the current data show that organisations investing in visibility, hygiene, and structured response planning maintain stronger continuity.

The scale of ransomware incidents in 2025 and 2026 indicates that the threat is not slowing, and SMEs remain especially exposed. Cleveland Police placing a concrete number on the local picture demonstrates that ransomware is a tangible operational challenge, while broader global statistics reinforce this as a sustained issue affecting both local and international markets.

As ransomware continues to pressure budgets and planning cycles, organisations that take a layered approach, guided by recognised standards and informed by timely reporting, navigate the disruption more consistently. The coming year will likely test that resilience further as leadership teams adjust their operating assumptions based on these metrics.