Why we have updated this guidance
The ransomware threat to UK organisations continues to grow in both scale and severity. During 2025, SUVAT responded to a number of major ransomware incidents affecting the healthcare and education sectors, several of which caused prolonged disruption to essential services including patient care and examination administration.
These incidents revealed common weaknesses in preparedness, detection, and response that existing guidance did not adequately address. SUVAT has therefore undertaken a comprehensive revision of its ransomware guidance to ensure that organisations across all sectors have access to current, practical, and actionable advice.
The updated guidance — reference SUVAT/GD/2025/014 — replaces all previous versions and should be adopted as the primary reference for ransomware preparedness within your organisation.
Read the full guidance: Ransomware prevention and incident response — SUVAT/GD/2025/014
Summary of key changes
The revised guidance has been expanded and restructured. The principal changes are summarised below.
1. Immutable backup requirements
The guidance now strongly recommends that all organisations maintain immutable, offline backups of critical systems and data. The updated text provides detailed advice on backup architectures that are resilient to ransomware, including air-gapped storage, write-once media, and cloud-based immutable storage tiers. Organisations are advised to test backup restoration procedures at least quarterly.
2. Incident response playbook templates
A new annex provides sector-specific incident response playbook templates for healthcare, education, local government, and small-to-medium enterprises (SMEs). These templates set out clear roles and responsibilities, decision trees for containment and communication, and checklists for the first 72 hours following detection of a ransomware incident.
3. Expanded guidance on ransom payment decisions
The section on ransom payment has been substantially expanded. SUVAT continues to advise against making ransom payments. The updated guidance sets out the risks — including the possibility of sanctions implications, the absence of any guarantee that data will be recovered, and the role that payments play in funding further criminal activity. It also covers recommended notification steps when a payment is made.
4. Supply chain and third-party risk
A new chapter addresses the increasing use by ransomware actors of supply chain compromise as an initial access vector. The guidance provides practical advice on assessing the cyber security posture of third-party suppliers, including managed service providers (MSPs), and on incorporating ransomware-specific requirements into procurement contracts and service-level agreements.
5. Operational technology considerations
Recognising the growing risk of ransomware affecting operational technology (OT) environments — particularly in healthcare (medical devices) and education (building management systems) — the guidance now includes a dedicated section on protecting OT assets. This covers network segmentation, monitoring of IT/OT boundary traffic, and response procedures specific to OT environments.
Key new recommendations
In addition to the structural changes described above, the revised guidance introduces the following headline recommendations:
- Adopt a "presumption of compromise" mindset — organisations should plan on the assumption that a ransomware actor will eventually gain access to their network, and focus investments on detection, containment, and recovery capabilities.
- Implement endpoint detection and response (EDR) across all endpoints, including servers, and ensure that EDR telemetry is monitored around the clock, whether in-house or via a managed security service provider.
- Disable Remote Desktop Protocol (RDP) on all internet-facing systems unless there is a documented and risk-assessed business requirement. Where RDP must be used, it should be accessible only via a VPN with multi-factor authentication.
- Conduct regular ransomware simulation exercises — the guidance recommends that organisations run tabletop exercises at least annually, involving technical teams, senior leadership, communications, and legal counsel.
- Report ransomware incidents to SUVAT within 24 hours of detection, regardless of severity, to enable timely analysis and coordinated response.
Who this guidance is for
The guidance is intended for IT and security professionals, senior leaders, and board members across all sectors. It is structured to be accessible to both technical and non-technical audiences, with executive summaries and detailed technical annexes provided separately.
Organisations in the healthcare and education sectors are particularly encouraged to review the updated guidance and assess their current posture against the recommendations. SUVAT will be hosting a series of webinars in January 2026 to support adoption — details will be published on the news page in due course.
Feedback
SUVAT welcomes feedback on this guidance from practitioners and stakeholders. Comments may be submitted to guidance@suvat.uk and will be taken into account in future revisions.