Guidance
Disruptive cyber attacks – reducing their impact, reducing the risk
How to recover your organisation, be better prepared for future incidents and make them less likely.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
How to recover your organisation, be better prepared for future incidents and make them less likely.
Page 11 of 16

10'000 Hours via Getty Images
Practical steps to make it harder for attackers to gain access, spread through your systems and cause disruption.
Highly disruptive cyber attacks, such as ransomware, can prevent organisations from operating normally by denying access to systems, disrupting essential services, and causing significant financial and operational damage. In ransomware attacks, attackers seek to maximise disruption in order to increase pressure on victims to pay a ransom.
While this guidance focuses on reducing the risk of such attacks, some cyber risk will always remain. To minimise the impact of attacks that are successful, organisations must also prepare for disruptive cyber incidents.
This guidance is intended for senior decision makers and those responsible for organisational resilience. It provides a framework for identifying and prioritising investment in cyber security fundamentals, and taking action early, to reduce the likelihood and impact of highly disruptive cyber attacks.
The guidance is especially useful for organisations seeking assurance that appropriate measures are in place to protect critical services and operational delivery. Organisations already following Cyber Essentials or another recognised cyber security framework, are likely to find that many of the measures described here are already reflected in their existing security activities.
It’s useful to note here that there are typically 2 distinct stages of attacker behaviour in highly disruptive cyber attacks:
Understanding these stages helps organisations focus their defences where they are most effective.
This guidance is organised into 5 sections that help organisations strengthen their resilience. These are not sequential steps, but complementary capabilities that work together to reduce the risk and impact of highly disruptive cyber attacks:
Sections 2 and 3 focus on preventing initial access and restricting attacker movement, while sections 1, 4 and 5 support these activities by helping organisations identify critical assets, design resilient systems and improve detection.


