Disruptive cyber attacks – reducing their impact, reducing the risk
How to recover your organisation, be better prepared for future incidents and make them less likely.
Pages
Page 7 of 16
1. Prepare your business continuity
You should understand which technology and business services are most important to your organisation, how long you can operate without them, and which systems support them. The following information should be captured in your business continuity plan (BCP).
1.1 Identify and prioritise critical services
During a disruptive cyber incident, full business as usual may not be possible. However, early preparation can help you maintain critical services at an acceptable level and restore them in a controlled way.
A clear understanding of business-critical services and their dependencies enables you to:
- identify feasible workarounds if technology is unavailable, and risk assess them
- prepare resources required to implement any workarounds
- prioritise systems for additional protection
- sequence system restoration effectively
Recovery should follow a prioritised approach, based on agreed business-critical services and the systems that support them.
1.2 Involve the wider community
Business continuity planning should involve:
- stakeholders from across the organisation – local teams often have the best understanding of how services operate in practice and what adjustments may be possible during disruption
- customers/delivery partners where critical services are delivered jointly or depend on shared processes – so that roles, priorities and workarounds can be agreed in advance
- suppliers, where critical services rely on them, including:
- planning for abrupt loss of supplier services
- understanding the resilience arrangements of key suppliers
- considering the impact of supplier disruption on your operations
- recognising that attackers may target suppliers as a route into your organisation, or use supplier disruption to amplify operational impact
1.3 Consider how to rebuild your systems securely
Your BCP should address how technology services will be restored if systems are compromised. Manual workarounds may provide short-term mitigation, but sustained recovery often requires organisations to establish trusted environments from which services can be securely restored. Planning and rehearsing this process in advance can help speed recovery and provide greater confidence that restored systems are secure and fit for purpose.
1.4 Test and exercise plans
Business continuity and recovery plans should be tested regularly and with a full exercise where possible, as many plans fail in practice. Testing and exercising can uncover issues that would have gone unnoticed until a real incident, at which point it is too late for changes and improvements.
Testing before a real incident occurs helps:
- identify gaps
- validate assumptions
- improve coordination
Exercising your plans in advance helps to expose weaknesses which may otherwise only become apparent during live response, when there is limited opportunity to adapt.
- Tabletop exercises can help validate governance, roles and decision‑making.
- Testing technical recovery procedures, where possible, helps with understanding the practical complexities of restoration.
The NCSC provides a range of exercising support, including Exercise in a Box for practical, scenario-based exercises, and the Cyber Incident Exercising (CIE) scheme for more structured and advanced exercising.
1.5 Cyber Incident Response (CIR)
The NCSC recommends using NCSC‑assured Cyber Incident Response (CIR) providers to support exercising and preparation activities, where appropriate.