Skip to main content

Cyber resilience matters as much as cyber defence

Why planning and rehearsing your recovery from an incident is as vital as building your defences
Richard Drury via Getty Images

In recent months, we’ve seen incidents against major UK retailers and manufacturers causing serious disruption to supply chains and services. These examples remind me why medium and large organisations must plan not only their defences, but also their recovery. In this blog, I set out NCSC recommendations for how organisations can do this. 

Start with the basics: Cyber Essentials

A key step for any organisation is implementing the five foundational security measures set out by the Cyber Essentials programme. This ensures the most important preventative controls – including patching, access management, and boundary defences –  are in place. These measures form a baseline that every organisation should meet to guard against the most common cyber threats. 

Using the Cyber Assessment Framework to focus on what matters

For larger, more complex organisations, the Cyber Assessment Framework (CAF) helps to improve their cyber security and resilience, managing cyber risks and protecting essential services from cyber threats, whether commodity-based or from more advanced cyber actors. 

While primarily designed for organisations playing a vital role in the UK’s daily life, I've seen how using the CAF helps organisations focus on what matters most to:

  • understand which services are critical to the business
  • manage cyber risks to them appropriately and 
  • ensure they can be maintained and recovered during disruption

Planning for recovery

From my perspective, the organisations that handle incidents best are the ones that have rehearsed them. They understand what they need to do to keep their operations going without some or all of their technology estate. In practice, this means:

  • knowing your IT estate so you can identify critical systems
  • conducting business impact assessments, to identify what must keep running and to minimise the impact on business operations
  • having clearly defined roles and communications plans in place so you can act decisively even when systems are down
  • running table-top exercises to enable help teams practise decision-making under pressure

These aren’t abstract steps. They are practical ways to prepare for the moment when something goes wrong, and to make sure that while you rebuild, your customers and partners still get the services they depend on. 

Working together to build resilience

No organisation faces these challenges alone. Sector-wide trust groups and information exchanges, supported by the NCSC, are a powerful way to build resilience by sharing real-world experiences. But resilience depends on openness: it is not just about learning from others, it is about being willing to share your own. By talking candidly about incidents and lessons learned, organisations help raise the bar for the whole community.

Next steps

As Richard Horne, our CEO, has recently underlined, the UK is facing increasingly hostile activity in cyberspace. We cannot afford complacency. Resilience is a continuous process, and it is every bit as important as prevention.

It is also vital that CEOs and Boards take an active role in overseeing cyber resilience – the NCSC’s Cyber Governance for Boards guidance explains how leaders can embed cyber risk into their decision-making and ensure their organisations are prepared to withstand disruption.

So, I encourage you to take the next step today.

By putting these tools into practice, you can build the confidence to withstand disruption, recover quickly, and remain operational.

Jonathon Ellison
NCSC Director of National Resilience

Written by

Jonathon Ellison Director of National Resilience, NCSC