Disruptive cyber attacks – reducing their impact, reducing the risk
How to recover your organisation, be better prepared for future incidents and make them less likely.
Pages
Page 9 of 16
3. Prepare your technical recovery capability
Response and recovery will need a skilled team with a strong understanding of the organisation’s systems as well as the relevant data and accesses. The NCSC recommends undertaking the following activities to be prepared to recover and restore your systems.
3.1 Securely store network and asset information
Store your network and asset information in a secure location, separate from primary systems, to ensure it remains accessible if production systems are unavailable or offline, and to protect it from unauthorised access to prevent it being used by attackers.
3.2 Maintain tested backups
Ensure you have up‑to‑date, secure backups as these are essential to an organisation’s recovery process. Backups should support the restoration of:
- data
- applications
- identity systems
- trust infrastructure
- configuration
- have them tested regularly by third-party auditors
- protect them from unauthorised modification or deletion
- make them immutable where possible, as they are often a target of attackers who want to prevent a speedy recovery
- store them separately from primary systems
3.3 Plan and test restoration processes
When planning restoration, you should consider how systems will be brought back online and how data will be reconciled. Regularly test restoration processes to ensure they function as expected.
organisations may well use manual processes or temporary workarounds that generate new data. Recovery plans should include how this newly-generated data will be validated and integrated with data restored from backups so that a single correct dataset is established.
When testing restoration processes, prioritise business‑critical services, as restoring systems can take significant time.
3.4 Document infrastructure dependencies
Most business services rely on shared infrastructure such as identity services, networking, storage and cloud connectivity. Rebuilding complex infrastructure requires a good deal of planning and rehearsal.
- maintain accurate network diagrams and asset inventories
- document system dependencies
- understand restart sequencing requirements
- store recovery documentation securely and separately from production systems
3.5 Enable logging and support observability
You should configure logging in systems in advance to help support investigation and recovery. Organisations should ensure they have observability across critical systems to detect malicious activity, understand the impact of an incident and support recovery decisions. The NCSC's blog on observability and threat hunting, and digital forensics guidance provide further information
- understand how the incident occurred
- identify affected systems
- detect persistence mechanisms
- reduce the risk of repeat compromise
Organisations should ensure their logs are centrally collected, retained appropriately and accessible during recovery.
3.6 Secure cloud and operational technology environments
If you use cloud services, ensure they are securely configured, monitored and resilient so they can be accessed, controlled and safely restored during a disruptive incident. For further information, see the NCSC’s guidance on using software as a service securely and using a cloud platform securely.
- access administrative functions even if corporate networks are offline
- enforce strong authentication for cloud administration
- validate security posture before reconnecting systems
- plan the level of assurance required – as external connections may require certain levels of assurance before allowing the organisation to reconnect
Organisations with Operational Technology (OT) should ensure systems can be safely managed, recovered and restored during an incident, with full understanding of operational and regulatory impacts. This includes identifying where manual intervention may be required and testing restoration of OT systems to a known good state.
If your organisation has interconnections between IT and OT systems, you will need to ensure the recovery plans for both are aligned.
3.7 Arrange specialist incident response support
Most organisations do not retain in-house specialists who can respond to a disruptive cyber incident.
The NCSC recommends that all UK organisations, regardless of size, engage an NCSC‑assured Cyber Incident Response (CIR) provider when responding to significant incidents. It’s worth noting that your cyber insurance package may include CIR provision.
For more information on the importance of good technical preparation in advance of a cyber incident, see the NCSC Incident Management guidance on effectively detecting, responding to and resolving cyber incidents.
- identify and retain a CIR company in advance of an incident – conducting exercises with the team who would be on the ground during an incident helps preparation and can support faster mobilisation
- clarify suppliers' skills and experience as well as roles and responsibilities for each area of activity – for example, the CIR provider won’t necessarily also rebuild IT systems
Ensure you store your cyber insurance details securely offline.