The Anatomy of a Ransomware Attack
Boardroom Exchange Blog
Halex Consulting Virtual Roundtable – 11 September 2025
Ransomware has rapidly evolved from an obscure cyber nuisance into one of the most significant threats to business continuity and even national security. At our latest Boardroom Exchange roundtable, Halex Consulting convened non-executive directors, governance professionals, and cyber experts to explore the “anatomy” of a ransomware attack – what happens before, during, and after an incident, and how boards can prepare for the decisions they may one day face.
Our discussion, led by subject-matter expert Vish Nayi, Chief Solutions Architect at CyberQ Group, was a candid and practical exploration of an increasingly common crisis scenario. Below we summarise the key themes and learning points that emerged.
Setting the Scene: The Escalating Threat
Ransomware is not just a technical issue – it is a critical business risk. Recent figures suggest UK organisations face a cyberattack every 44 seconds, with around 19,000 businesses hit by ransomware last year – roughly 52 incidents every single day. In reality, the numbers are likely higher, as many attacks go unreported to avoid reputational damage or regulatory scrutiny.
Vish reminded participants that today’s cybercriminals operate with the professionalism of legitimate enterprises. Ransomware gangs have HR departments, KPIs, and even franchise models offering “ransomware-as-a-service” to affiliates. The illicit economy they represent is vast, lucrative, and constantly innovating.
A striking theme was the supply chain dimension. Even organisations with robust controls can be compromised if a supplier or managed service provider is breached – as seen in several recent UK retail sector incidents. This underlines the importance of rigorous supplier assurance as part of overall resilience.
Before the Attack: Are We Ready?
Boards must first ask themselves: how confident are we that ransomware risk is being effectively managed?
Key questions discussed included:
- Do we know our “crown jewels”? Boards must have clarity on which systems, data, and processes are mission-critical and what downtime would cost.
- Have we defined our risk appetite? There is no “zero risk” option. Directors must balance the cost of controls against the risk tolerance of the organisation.
- Is our incident response plan real or theoretical? Too many organisations either lack a plan entirely or have one that sits unread on a shelf. The most effective boards run realistic ransomware simulations involving the executive team – rehearsing the legal, operational, and reputational aspects of a live crisis.
As one participant observed, “Documentation alone is meaningless unless senior leadership understands it and has tested it.”
During the Attack: Critical Decisions Under Pressure
Once an attack unfolds, the pressure on leadership is intense. Vish described the typical pattern: an initial phishing compromise, lateral movement within systems, and eventual encryption of key files with a ransom demand. At this stage, minutes matter.
Our discussion focused on three immediate dilemmas:
- Who decides whether to pay? The authority to make this call must be pre-agreed and documented. Uncertainty in the heat of the moment can waste vital time.
- Have we tested our communications plan? Regulators, insurers, customers, employees, and the media will all demand answers in the first 24 hours. Consistency and transparency are critical, but so too is caution: premature statements may worsen reputational damage or liability.
- What is our position on ransom payments? Here the conversation intersected with the UK Government’s July 2025 consultation response on ransomware. Proposals include a targeted ban on payments by public bodies and critical national infrastructure, alongside an economy-wide mandatory reporting regime. Many directors noted the practical challenges – especially for smaller businesses that may feel compelled to pay simply to survive – but acknowledged that legislative change is coming.
The debate was frank. One participant cited a case where a medium-sized firm, unable to afford a lump-sum ransom, negotiated monthly instalments via a “dark web broker”. Others pointed to long-established firms that chose to shut down entirely rather than pay criminals. These stories underscore the brutal realities boards may face.
After the Attack: Recovery and Resilience
The discussion turned to recovery. Even if a ransom is paid, there is no guarantee of regaining data – or of avoiding repeat attacks. True resilience lies in preparation:
- Backups must be robust, secure, and regularly tested. Too many organisations discover too late that backups are corrupted, incomplete, or inaccessible.
- Legal and regulatory reporting obligations must be clearly understood, particularly as mandatory reporting regimes become more likely.
- Lessons learned must be embedded. Boards have a duty not only to oversee recovery but also to ensure cultural and strategic changes reduce future risk.
As Vish put it: “Every attack should be a turning point – not just an operational reset.”
Broader Policy Context
Christopher Burt, Chair of the session, highlighted the Cyber Security and Resilience Bill, announced in the King’s Speech and currently in development. This Bill aims to modernise the UK’s cyber regulations, expand the scope of regulated entities (including managed service providers and data centres), and strengthen incident reporting requirements. Together with the ransomware consultation proposals, it signals a clear shift: government expects boards to treat cyber risk with the same seriousness as financial or operational risk.
Key Takeaways for Boards
Several practical messages emerged from the roundtable:
- Preparedness and validation – Boards must demand evidence that incident response and backup plans are realistic, tested, and understood by leadership.
- Decision-making clarity – Establish in advance who has authority to approve ransom payments (if permitted) and how communications will be handled.
- Financial resilience – Consider the financial exposure of a ransomware event, from ransom demands to operational downtime, regulatory fines, and reputational harm.
- Supply chain assurance – Assess the cyber resilience of key suppliers and managed service providers, recognising that an attack on them is effectively an attack on you.
- Continuous learning – Treat cyber incidents as opportunities to strengthen culture, governance, and oversight.
Conclusion
The anatomy of a ransomware attack reveals a sobering truth: while technology plays a role, the most critical decisions rest with boards. Directors must ensure their organisations know what matters most, are prepared to respond under pressure, and can recover without succumbing to criminal extortion.
As the policy landscape shifts – with new legislation, reporting requirements, and potential payment bans – governance professionals must help boards navigate not only the technical but also the strategic, legal, and ethical dimensions of cyber resilience.
The challenge is daunting, but the message from our roundtable was clear: ransomware is a business risk, not just an IT problem. Boards that prepare today will be far better placed to protect their organisations, customers, and stakeholders tomorrow.
Download a copy of the slides used during this roundtable discussion here
📅 The next Boardroom Exchange session will be held on Thursday 11 December 2025. We encourage all non-executives and governance colleagues to join the conversation.




