Skip to main content
Guidance

Disruptive cyber attacks – reducing their impact, reducing the risk

How to recover your organisation, be better prepared for future incidents and make them less likely.

Page 14 of 16

3. Limiting the impact of a successful compromise

Even well-protected organisations may experience a cyber attack. When this happens, the organisation’s ability to limit attacker movement becomes critical. As highlighted in the NCSC’s guidance on preventing lateral movement, organisations should assume an attacker may already have a foothold. They should focus on detecting attacker activity and limiting the damage it can cause.

After gaining access to a network, attackers typically try to:

  • increase their level of access (privilege escalation)
  • move between systems (lateral movement)
  • locate critical systems and valuable data

Slowing this activity using multiple layers of protection and mitigation – often referred to as defence-in-depth – gives organisations more time to detect and respond, and reduces the overall impact of the attack. The remainder of this section outlines defence-in-depth techniques. These controls should be used across your networks to limit an attacker’s opportunities. You should pay particular attention to your critical assets and other attractive targets.





Published

Reviewed