It starts on a Saturday. Phones stop working. Nobody can get into the case management system. Someone asks who is supposed to make the call on whether staff should keep working, and nobody quite knows. By Monday, people are back to pen and paper for things a computer has handled for a decade.
That was the experience inside Redcar and Cleveland Borough Council in February 2020, when a ransomware attack took hold of a network that had, until that point, been treated as fully joined up and reasonably well protected. It wasn’t a small business with no IT budget. It was a functioning local authority with industry standard tools in place. That is part of why the story has stayed relevant for six years.
Bondgate IT worked with the BBC on the original investigation into the attack, which became the documentary Cyber Siege: From Russia to Redcar. The BBC has now returned to the story with a six part podcast series, Cyber Hack – The Conti Files, going deeper into how the attack unfolded and what it exposed about local government resilience.
Off the back of the new series, our Managing Director Garry Brown recently joined Gary Philipson on BBC Radio Tees. The question put to him was simple: have we learned the lessons?
The numbers that never made it onto a slide
The council’s own reporting puts the recovery cost at somewhere between £8.7 million and £11.3 million, depending on which stage of the financial review you look at. Central government eventually reimbursed a fraction of that, under £3.7 million, leaving the shortfall to come from council reserves. Around 135,000 residents lost access to online services including housing, planning and social care support. Disruption to normal operations ran for months, not days.
Redcar and Cleveland, February 2020
None of that is a criticism aimed at the council. Their leader has been open, in parliamentary evidence, about the fact that they didn’t believe they were at risk and that hindsight has changed how they think about preparation. That honesty is part of why the story has held public attention. Most organisations that get hit don’t talk about it at all.
What Garry said on air
Garry’s view was that awareness has genuinely shifted since 2020. Cyber security conversations that used to sit entirely with an IT department are now regularly happening at board level, across the businesses Bondgate IT speaks to in the region. That’s a real change, not a talking point.
His advice to listeners, whether they were a business owner or simply someone in their living room, was deliberately unglamorous. Keep your systems updated. Use a password manager. And treat urgency as a warning sign rather than a reason to act quickly. Most scams and attacks rely on rushing someone into a decision before they’ve had time to check it. Pausing for five minutes, the classic Take 5 approach, is still one of the more effective defences available to anyone.
He also made a point that matters more than it might first appear: there is no shame in being targeted. The organisations that recover well are the ones who talk about what happened and plan on the basis that it will happen again, rather than treating it as a one-off event to move past quietly.
Why this isn’t only a council story
It’s easy to file Redcar under “public sector problem” and move on. That would miss the point. The pattern that caused the damage, a fully integrated network with no segmentation, unclear ownership of the decision to act, and no rehearsed plan for what happens in the first 48 hours, exists in plenty of commercial organisations too. The difference is usually scale, not exposure.
Where we see this repeat with our own clients, it tends to follow one of two operating models.
Reactive model
- IT support called after something breaks
- Backups exist but haven’t been tested
- No single owner for a security decision
- Response plan lives in someone’s head
Governed model
- Monitoring flags issues before they escalate
- Backups tested on a set schedule
- Named owner for incident decisions
- Response plan documented and rehearsed
Neither model is about how much a business spends on tools. It’s about whether the business has decided, in advance, who does what when things go wrong. That decision is cheap to make on a quiet Tuesday and expensive to make for the first time during an actual incident.
Where to start, practically
If you’re reading this as a managing director or operations lead, the useful question isn’t “are we secure.” It’s narrower and easier to answer: if our systems went down tomorrow, who picks up the phone, what gets prioritised first, and how old are our last tested backups. If those three answers come quickly, you’re in reasonable shape. If they take longer than a minute, that’s worth fixing before it’s tested for real.