Disruptive cyber attacks – reducing their impact, reducing the risk
How to recover your organisation, be better prepared for future incidents and make them less likely.
Pages
Page 8 of 16
2. Prepare your people
People are central to organisational resilience. During a disruptive cyber incident, technology and processes alone will not determine how well you respond. Your staff will need to adapt, make decisions in uncertain conditions, and find new ways to continue essential activities. Preparing them in advance helps ensure they can do this effectively.
2.1 Run regular practise exercises
It’s useful for organisations to conduct regular incident exercises and simulations to help staff practise responding to disruption. These activities allow teams to test how they would operate if normal systems or processes were unavailable, and to experiment with alternative ways of working.
These exercises should involve both technical responders and wider organisational roles so that dependencies and decision-making processes can be tested.
2.2 Define roles and responsibilities
It’s important to establish who is responsible for key activities during an incident, including:
- operational response
- technical recovery
- legal and regulatory
- decision-making
- communications
You should ensure that key decisions – for example, shutting down systems, invoking recovery plans, or communicating publicly – can still be made if senior leaders are unavailable. Organisations should clearly define delegated decision-making authority so that high-priority operational decisions can be taken rapidly, including during out-of-hours periods.
The roles and responsibilities information should be kept up to date as staff change roles or leave the organisation.
You should also ensure responsibility is assigned for maintaining a clear record of decisions, actions and their rationale throughout an incident. Accurate records can support coordination, recovery activities, regulatory reporting, legal obligations and post-incident review.
2.3 Plan alternative communication methods
Disruptive cyber incidents may interfere with normal communication platforms such as corporate email or messaging services.
You should aim to establish alternative and secure communication channels that can be used to coordinate response activities if primary systems are unavailable or untrusted. It is also useful to maintain an offline copy of contact lists for key staff, suppliers and partners in case corporate directories are unavailable.
2.4 Support staff welfare
Responding to a disruptive cyber incident can involve long hours and sustained pressure, which can quickly lead to fatigue and burnout.
You should plan how you will support staff during extended incidents, for example by:
- rotating responsibilities
- ensuring adequate rest periods
- providing additional support where needed
You should also make sure that employees outside the response team know what is expected of them if systems are unavailable – such as how to report issues, or whether to power down devices.
2.5 Ensure sufficient skills and capacity
A number of recovery activities can be highly resource intensive, for example:
- resetting large numbers of user credentials
- rebuilding systems
- reimaging devices
- issuing replacement laptops
You should assess whether you have the required skills and capacity to carry out these activities at scale and, if necessary, identify how you would secure additional resource during an incident. Critical response roles should never rely on a single individual.
2.6 Plan for external support
Many organisations will need assistance from external partners during a disruptive cyber incident.
You should identify the external organisations who may need to support recovery. These could include:
- IT providers
- cloud providers
- incident response partners
Establish relationships with them in advance where possible, and agree how you would communicate in the event of IT being unavailable during an incident.