Skip to main content
Guidance

Cyber Security Toolkit for Boards

Resources to help Boards implement the actions outlined in the Cyber Governance Code of Practice.

Page 16 of 27

Planning your response to cyber incidents

Good incident management can reduce their financial, reputational and operational impact.


Ransomware attack on a large industrial business from the eyes of its C level team

What preparation did the organisation have in place before the attack?

The board had agreed the organisation’s cyber strategy well in advance of the attack. Our cyber risks had been updated and we had carried out both technical and board-level exercises. Helpfully, we had anticipated ransomware as a potential risk and so it was one of the incidents we’d rehearsed. Underpinning this was business continuity plans across our businesses and a disaster recovery plan to support it. This level of planning undoubtedly helped us in the real event.

What were the first signs of the attack?

Our security operations team experienced an increase in alerts which were indicative of a serious threat to our systems. These were out of the ordinary and conducive to their being an active cyber criminal in the network.

What was the immediate response?

The immediate response was to contain the attack on our network and systems. This alone took more than a week and was like being in a fist fight with a determined cyber criminal. Every action we took to defend our systems was met with a counter-response from the criminals.

What third party organisations did you contact for help/advice?

We engaged with external third party subject matter experts and used relationships we had built within the industry to get externally skilled resources onsite. The NCSC incident team and local law enforcement were also informed. Relationships we had built with other third parties allowed us to spend time speaking with another CEO who had experienced a devastating ransomware attack. This not only provided us with an external perspective on how impactful these types of attacks can be, but their knowledge and experience also provided myself and the board with more insights  to help us lead the business out of the crisis.

Were they helpful?

Getting support from outside the organisation played a critical part in our defence and recovery.  We had highly skilled internal resources but realised quickly that we would need more support to ensure we could continue defending and recovering the business without burning out our teams. 

Did anything change?

We felt the tempo and intensity of the attack increase throughout the week. NCSC confirmed to us during the post-incident forensic analysis that the attack had indeed intensified and that sophisticated and determined cyber criminals were involved. 

How was the morale of the team?

The general morale of the team varied as the incident progressed and this is something we had to closely monitor throughout. The team were working hard to tackle what was a particularly complex attack, in a fast-paced and fluid environment. In addition to incident containment, the team also had to address business continuity. This resulted in a stressful time for us all, and many members of the team had to spend time away from home or numerous hours on Teams calls. Where possible we tried to put measures in place to reduce the amount of business continuity tasks teams had to be involved in so they could focus on incident response. The CEO and Chair also helped to boost morale by visiting the team on a number of occasions.

When were comms issued to shareholders and customers?

Our communications strategy was multi-faceted so that we could ensure the interests of a number of different stakeholders (employees, customers, shareholders, suppliers, relevant regulators) were met.

No customer data was compromised, however, we did notify customers where appropriate where it was determined that delivery times would be impacted.

Did you pay the ransomware money?

No. We did not engage with the ransomware attackers at all. We disrupted the attack, and felt that we could recover without having to engage with the cyber criminals. We had confidence in our team and our business that we could recover from the attack on our own terms.

What was the cost to the organisation?

The organisation was impacted through deferred revenue and loss of associated profit,  under-recoveries and direct costs associated with incident response, with total financial impact in the year estimated at around £25m.

Did you suffer any reputational damage?

We did not suffer any long-term reputational damage and were able to provide more clarity and information to our stakeholders as time went on. Further details on the status of the attack and updates on the financial impact were provided in our trading updates. 

Were there any lessons learned as a result of the attack and has it resulted in positive changes to the organisation?

The positive impact was that we were able to accelerate planned changes to enhance our security, and we benefitted from tailored input from external expertise.

Is there any advice you would give to other organisations regarding planning for or dealing with a ransomware attack?

Use exercises to ensure the basics are being done really well when it comes to key cyber hygiene across areas like patching and access control across your systems.  It is also helpful to understand your environment as much as possible (for example, what suppliers you have in your supply chain, how they are connected to your systems, what data they have).

Experiencing an incident?

If you are currently experiencing an incident, you can contact the NCSC. 


 If you're one of these organisations, then you should address this immediately.

* Cyber security breaches survey 2024:Formal incident response plans are not widespread only 55% of medium-sized businesses and 73% of large businesses have them.


Published

Reviewed

Version

3.0