Skip to main content
Guidance

Disruptive cyber attacks – reducing their impact, reducing the risk

How to recover your organisation, be better prepared for future incidents and make them less likely.

Page 1 of 16

decorative image

Thomas Barwick via Getty Images

If you are currently responding to a highly disruptive cyber attack, read Recovering from a highly disruptive cyber attack.


About this collection

This collection brings together 3 pieces of guidance to help organisations recover from, prepare for and reduce the risk of highly disruptive cyber attacks and is structured as follows:

  • Recovering from a highly disruptive attack provides practical advice covering the immediate response, recovery to minimum viable operations (MVO), and the longer-term rebuild of your organisation.
  • Preparing for a highly disruptive cyber incident provides guidance on preparing the plans, people, technical capabilities and decision-making processes in advance, to enable your organisation to operate through disruption and recover safely.
  • Reducing the risk of highly disruptive cyber attacks provides a framework to help organisations prioritise investment in cyber security fundamentals and take action early to reduce the likelihood and impact of an attack.

This collection is intended for organisations that would face significant operational disruption if critical digital systems became unavailable, and will be particularly useful for:

  • executive leaders, boards and senior decision-makers
  • CISOs and cyber security teams
  • CIOs, CTOs and technology leaders
  • service owners
  • business continuity, resilience and risk professionals

What is a highly disruptive cyber attack?

A highly disruptive cyber attack is one that disrupts, disables or damages an organisation's critical systems or services, preventing it from operating normally. Recovery can take weeks or even months. The consequences can extend well beyond technology, affecting customers, services, supply chains, finances and organisational reputation. To recover, organisations may need to rebuild systems, redesign business processes and introduce temporary workarounds while full service is restored.


Related guidance

Large organisations - including operators of critical national infrastructure (CNI) - that face threats from highly capable cyber actors may also find useful our guidance on preparing for periods of severe cyber threat. It covers the planning, resilience and defensive measures needed to withstand and recover from severe cyber attacks. 


Published

Reviewed