Disruptive cyber attacks – reducing their impact, reducing the risk
How to recover your organisation, be better prepared for future incidents and make them less likely.
Pages
Page 10 of 16
4. Prepare to make critical decisions
Leaders must make high-impact decisions quickly in the event of disruptive cyber incidents. Organisations should identify in advance:
- who has the authority to make strategic decisions
- the organisation’s risk appetite
- escalation thresholds
- legal and regulatory considerations
It may be useful to document your pre-agreed decision principles in your ‘playbook’ as this will help guide leaders when under the pressure of an unfolding incident. As outlined in the companion guidance on responding to and recovering from a highly disruptive cyber incident, one of the first actions to take in the event of a disruptive cyber incident is to establish an incident command structure to enable rapid information exchange and decision making.
4.1 Consider taking pre-emptive containment action
If an organisation becomes aware of the attack early enough, it may be possible to take action to halt the spread of the disruption, up to and including disconnecting systems. However, it should be noted that taking such actions may also cause disruption.
Planning ahead enables leaders to evaluate the potential impact of pre-emptive actions and to decide whether to pursue controlled disruption, rather than risk the uncontrolled disruption caused by an attacker. This decision will depend on the organisation’s risk appetite.
Organisations responsible for essential services should consider additional advance preparations to enable rapid containment during periods of severe cyber threat. The NCSC’s guidance on responding to severe cyber attacks highlights rehearsing in advance those actions which will quickly limit the impact of compromise. These may include:
- the ability to isolate systems
- operating critical services in a degraded or manual mode
- continuing essential functions while recovery is underway
4.2 Consider the risks of paying the ransom
The NCSC and UK law enforcement do not encourage, endorse or condone the payment of ransom demands.
Many disruptive cyber attacks are designed to maximise damage and pressure organisations into paying a ransom, but there are several risks with doing so. The NCSC’s Guidance for organisations considering payment in ransomware incidents outlines these in detail. They include:
- there is no guarantee that you will get access to your data or computer, or that the stolen data will be deleted
- systems may remain compromised
- you may become a future target
- you may be funding criminal activity – some criminals are sanctioned entities and so you could even be breaking sanctions laws
In addition, even if an organisation is given the decryption key in exchange for the ransom, decryption of all machines can take weeks to complete. And there still remains the risk that the organisation hasn’t fixed the underlying problems that permitted the attack in the first place.
Well-prepared organisations are more likely to have alternative ways to recover that do not involve paying the ransom.
4.3 Develop a communications strategy
Large-scale attacks are likely to be noticed by individuals and organisations outside of your organisation. It would be useful to develop a communications plan to help you decide when and what information to share. This should include:
- defined roles and responsibilities
- pre-prepared messaging
- clear processes for notifying stakeholders
- alternative communication channels in case primary systems are unavailable
Keeping suppliers and customers appropriately informed can be important to maintain confidence and trust throughout the incident, as well as helping them manage the impact on their own businesses. This helps the resilience of your supply chain, and aids in returning to business as usual after the incident.
All communications should be:
- clear, accurate and timely
- tailored to different audiences
- maintaining consistent core messages, and avoiding speculation
This helps the resilience of your supply chain, and aids in returning to business as usual after the incident.