Skip to main content
Guidance

Disruptive cyber attacks – reducing their impact, reducing the risk

How to recover your organisation, be better prepared for future incidents and make them less likely.

Page 11 of 16

Reducing the risk of highly disruptive cyber attacks

Industrial style office interior with pipework, exposed brick walls and ergonomic furniture

10'000 Hours via Getty Images

Practical steps to make it harder for attackers to gain access, spread through your systems and cause disruption.

Highly disruptive cyber attacks, such as ransomware, can prevent organisations from operating normally by denying access to systems, disrupting essential services, and causing significant financial and operational damage. In ransomware attacks, attackers seek to maximise disruption in order to increase pressure on victims to pay a ransom.

While this guidance focuses on reducing the risk of such attacks, some cyber risk will always remain. To minimise the impact of attacks that are successful, organisations must also prepare for disruptive cyber incidents.


Understanding the path to disruption

It’s useful to note here that there are typically 2 distinct stages of attacker behaviour in highly disruptive cyber attacks:

  1. Initial access where attackers gain a foothold in the organisation's environment.
  2. Expansion and disruption where attackers move through the environment, targeting critical systems and data to maximise operational impact.

Understanding these stages helps organisations focus their defences where they are most effective. 


Published

Reviewed