In October 2023 the Rhysida group attacked the British Library, exfiltrating data and destroying servers. The Library's own published review is unusually honest and worth reading. Recovery ran for many months and the estimated cost ran into millions.
The findings that apply to a 20-person business
The review pointed at things that are very familiar from small-business networks:
- Legacy systems that couldn't be patched and were kept running because something depended on them
- A flat network, so once attackers were in one place they could reach everywhere
- Incomplete multi-factor authentication, particularly on remote access
- Reliance on institutional knowledge rather than documentation
None of those are exotic. They are the normal result of a business growing faster than its IT.
Where to start
- Turn MFA on everywhere, especially remote access and email. This is the single highest-value change.
- Find the old box in the corner that everyone is scared to touch, and make a plan for it.
- Keep at least one backup copy offline or immutable — ransomware goes looking for backups first.
- Write down how you'd rebuild. Not a 40-page plan; two sides of A4 with accounts, contacts and priorities.
We do this as a piece of work rather than a sales pitch: audit, fix the cheap things first, plan the rest.