Copy article

AI Ransomware Detection: Progress or Just Another False Sense of Security?

ended 01. October 2025

Google's announced its new AI product can stop ransomware before it spreads through Google Drive data which is both welcome and impressive. Until you remember attackers adapt faster than detection models, and the cleverest threats still slip through when fallible humans are the weakest link.

The new system for Drive for desktop uses AI trained on millions of ransomware samples to detect suspicious file modifications and pause file syncing automatically. 

But here's what Google isn't shouting about: this only protects files stored in Drive for desktop on Windows or Mac—it's irrelevant if ransomware is attacking files elsewhere on a company's network: workstations, servers and other cloud-based services.

UK businesses desperately need protection. The UK Government published 2025 figures from the Department for Science, Innovation, and Technology showing ransomware attacks against UK businesses doubled from less than 0.5% to 1% in 2024—a small percentage point increase, but that's approximately 19,000 businesses hit.Meanwhile, 43% of UK businesses experienced some form of cyber breach, with phishing enabling 85% of those breaches.

Ransomware is a human problem as much as a technical one. The NHS third-party supplier Synnovis ransomware attack in June 2024 forced the cancellation of over 1,700 procedures and 10,000 appointments, with 400GB of sensitive patient data published online.

As an SME business owner trying to protect your systems, if your strategy is "let Google's AI handle it," you're already compromised. If your staff are clicking dodgy links or your backups are a mess, no AI will save you.

Discussion points:

  • If 85% of breaches start with phishing that bypasses technical controls by exploiting human behaviour, what does effective staff training actually look like rather than writing internal governance policies that are ignored?
  • What practical steps can less tech-savvy SMEs undertake to test their disaster recovery plans are robust without disrupting normal operations?
  • With 17,000 UK cybersecurity roles unfilled, and the rate of attack rising significantly, should SMEs be pooling resources for shared security expertise rather than trying to manage on their own?

The cybersecurity skills crisis is creating a perfect storm for SMEs. With approximately 17,000 unfilled roles in the UK, particularly in penetration testing, ethical hacking, and AI threat analysis, individual businesses are competing for talent they can't afford or attract. Meanwhile, attackers face no such constraints. This widening expertise gap makes the case for collaborative security models: shared threat intelligence, pooled incident response capabilities, and fractional security expertise that gives smaller organisations access to skills typically reserved for enterprises. The solo cybersecurity defender is dead. Small businesses just don't know it yet.

3 responses from the Newspage community

Copy all

Star Quote
Copy

Effective security training isn't about compliance PDFs gathering dust, it's practical capability building. Staff need mental shortcuts they can rely on. Focus on pattern recognition: training your team to spot the red flags that signal phishing before they click. Create a no-judgement reporting culture. If an email looks suspicious, pause the task until someone technical can verify it's safe to continue. Empower and praise human judgement for monitoring phishing risks. If you're relying on fractional help, make sure a swift response in a crisis is feasible.

Set up daily backups and check they run as scheduled. Practice recovering a single large folder of dummy data stored outside your live environment on a monthly basis. This verifies your backup integrity, measures actual recovery time, and ensures your team can follow the process before pressure hits. Your disaster recovery plan must work on its worst day, because that's the day it matters.
Copy

Google’s new AI ransomware defence is progress, but misses the real crisis: the UK’s widening cyber skills gap. Many job postings demand mid-level experience, creating a "catch-22" where new talent cannot get started. I've seen this compounded by AI. As soon as AI pilots deliver efficiencies, the immediate "benefit" to business owners is hiring feeezes at the entry level, something I rail against by educaing businessowners on the need for succession planning and the long term ROI of keeping humans "in the loop." Short-term thinking destroys skills pipeline and leaves SMEs defenceless when today’s juniors should be tomorrow’s experts. The solution? The government must expand the availability of cyber apprenticeships. Then they must incentivise SMEs to hire apprentices. This helps them build their own cyber resilience from the ground up while addressing the nation's cyber skills shortage. Without apprenticeships and incentives for SMEs, the UK is sitting on a cyber time bomb.
Copy

I think the danger here is that it could give business a false sense of security. Yes, of course, anything that helps to detect spyware/malware is welcome but the danger is that organisations take this option, look at the cost of cyber-security training and consider it to be an either/or argument.

This is shortsighted and dangerous, and puts me in mind of the phrase, if you think training is expensive, consider the cost of ignorance. Tools like this new Google tool undoubtedly have their place, but as part of your arsenal against cyber-criminals, not as your sole solution. Far more important is training your workforce on the signs to look for, why cybersecurity matters and the impact it can have if your defences are overwhelmed.

If someone is determined to steal your data can you 100% stop them? Probably not, but with the right mindset you can make yours far more difficult to steal. Adding gamification to training makes it more memorable.