What to do when cyber attacks disrupt your organisation
How to recover from disruption, get ready for future incidents and make them less likely.
Page 2 of 5
Recovering from a highly disruptive cyber attack

Lemon_tm via Getty Images
Practical guidance to help organisations manage disruption, prioritise recovery and restore critical services.
Your organisation has just suffered a highly disruptive cyber attack and you’re likely to be experiencing heightened emotions and a great deal of uncertainty. This guidance will help CEOs, CISOs, Boards and cyber professionals in large organisations take the steps needed to respond to the attack. It is divided into 3 sections which mirror the typical response and recovery phases:
- Section 1 sets out the immediate activities to undertake in the first few hours to contain and assess damage, implement governance, and establish lines of communication. The information gathered from the assessment activities will inform the next steps in section 2.
- Section 2 guides you in setting up and running your recovery programme and supporting activities during the first few days, and potentially weeks. The recovery programme will develop dynamically as new information from the investigation emerges. It will focus on measures which support rebuilding your organisation to minimum viable operations (MVO), and helping your people.
- Section 3 focuses on the organisational rebuild phase which is when your organisation begins to recover its processes and is operating its business as usual. At this point, the organisation is no longer in crisis response mode and instead can focus on a more positive future.
This guidance provides a framework for handling highly disruptive cyber incidents, but it does not provide an exhaustive checklist of all activities required which will vary depending on the details of the incident and the legal and regulatory jurisdictions that apply.
