Disruptive cyber attacks – reducing their impact, reducing the risk
How to recover your organisation, be better prepared for future incidents and make them less likely.
Pages
Page 14 of 16
3. Limiting the impact of a successful compromise
Even well-protected organisations may experience a cyber attack. When this happens, the organisation’s ability to limit attacker movement becomes critical. As highlighted in the NCSC’s guidance on preventing lateral movement, organisations should assume an attacker may already have a foothold. They should focus on detecting attacker activity and limiting the damage it can cause.
After gaining access to a network, attackers typically try to:
- increase their level of access (privilege escalation)
- move between systems (lateral movement)
- locate critical systems and valuable data
Slowing this activity using multiple layers of protection and mitigation – often referred to as defence-in-depth – gives organisations more time to detect and respond, and reduces the overall impact of the attack. The remainder of this section outlines defence-in-depth techniques. These controls should be used across your networks to limit an attacker’s opportunities. You should pay particular attention to your critical assets and other attractive targets.
3.1 Restrict access
Controlling access is one of the most effective ways to limit what attackers can do. Applying the principle of least privilege ensures that users and systems only have access to what they need at the time they need it. This reduces opportunities for attackers to escalate privileges or move more widely. In practice this means you should:
- grant access based on role and necessity
- review and remove unnecessary permissions
- enforce access policies before allowing access, for example through Zero Trust Network Access (ZTNA)
3.2 Segment your network
Network segmentation limits how far an attacker can move within an organisation’s environment. Without segmentation, a compromise in one area can quickly spread to others. By dividing your network into controlled segments, you’re able to:
- restrict access to sensitive systems and data
- contain incidents more effectively
Network segmentation is most effective when it is built into system design, as outlined in section 4.
3.3 Improve visibility and detection
The earlier an attack is identified, the more effectively an organisation can respond and limit disruption. Organisations should develop strong observability across their systems, services and networks, giving them the information needed to detect unusual activity, investigate incidents and understand their cyber risk.
To support this, organisations should:
- establish appropriate monitoring across critical systems and services
- develop the capability to identify and investigate anomalies and potential threats
- ensure security teams can respond quickly to signs of compromise
- continuously improve detection capabilities as technologies and threats evolve
3.4 Protect backups and administrative controls
Backups and administrative access accounts are frequent targets in disruptive attacks. If attackers can compromise them, they can significantly increase the scale of damage – such as deletion or destruction of data – or gain broader access to more data.
To reduce this risk, you should: