Disruptive cyber attacks – reducing their impact, reducing the risk
How to recover your organisation, be better prepared for future incidents and make them less likely.
Pages
Page 6 of 16
Preparing for highly disruptive cyber incidents

metamorworks via Getty Images
How to prepare people, plans and processes so your organisation can respond and recover effectively.
Although organisations should take steps to prevent cyber attacks, there is no guarantee of avoiding a highly disruptive incident. Organisations that recover most effectively are those that prepare in advance – establishing the plans, people, technical capabilities and decision-making processes needed to operate through disruption and recover safely.
While much cyber security guidance focuses on preventing attacks, organisations must also be prepared for the possibility that an attacker succeeds despite those defences. Highly disruptive cyber incidents do not always result from a direct attack on your organisation. Disruption can also arise from cyber attacks affecting suppliers, managed service providers, technology providers or other organisations that your critical services depend upon. Preparation for recovery is a core resilience capability, not an afterthought.
As the NCSC CEO said in the 2026 RUSI Annual Security Lecture:
The ability to absorb cyber attacks, contain their impact, sustain critical operations and recover quickly is no longer optional. It is a core competence for any digital organisation.
Richard Horne, NCSC CEO
About this guidance
This guidance is for CEOs, CISOs, Boards and cyber professionals in large organisations. (Leaders of CNI organisations should also refer to our guidance on planning for severe cyber threat which sets out the additional, time-critical precautionary measures required in response to a significant step-change in the threat environment).
This guidance provides advice on how to prepare your organisation now – in advance of an attack – to:
- reduce its impact
- support informed decision-making under pressure
- enable faster recovery
Organisations should expect recovery to be delivered as a coordinated programme involving multiple workstreams across technical, operational and business functions. This is covered in depth in the NCSC’s companion guidance on recovering from a highly disruptive cyber attack.
What this guidance covers
There are 4 distinct areas of preparation:
- Business continuity: prepare how your organisation will maintain and prioritise critical services during disruption, and plan for their structured recovery.
- People: ensure your staff are ready to respond effectively, with clear roles, communication methods and the skills needed to operate under disruption.
- Technical recovery: establish the systems, data, and processes required to securely restore technology and rebuild operations.
- Making critical decisions: equip leaders with the authority, context, and principles they need to make timely, high-impact decisions.
Each of these areas is expanded in more detail in the sections below.
Why prepare?
During a disruptive cyber incident, you need to be able to make decisions quickly, communicate them effectively and coordinate a wide range of stakeholders and activities. When an incident is underway, you don't have time to think about what your response plan entails; you simply want to be confident it is ready to be used. Early planning also allows you to test and refine your response plans which helps ensure they are effective when they are deployed in earnest.
Many organisations document their response plan in a cyber incident ‘playbook’ or similar, setting out roles, responsibilities, escalation routes and recovery priorities.
