Skip to main content
Guidance

Disruptive cyber attacks – reducing their impact, reducing the risk

How to recover your organisation, be better prepared for future incidents and make them less likely.

Page 15 of 16

4. Building resilience into systems

Security and resilience are most effective when they are built into systems from the outset. Retrofitting controls later is often more complex and less effective. Where organisations rely on legacy systems, these principles can be used to guide upgrades, integrations and other changes, helping improve security and resilience over time.

When designing or updating existing systems, organisations should consider how they will:

  • prevent unauthorised access
  • limit attacker movement
  • support detection and response

Zero trust principles can help reduce opportunities for unauthorised access and limit attacker movement. As explained in the NCSC’s Zero Trust Network Access guidance, this means verifying access continuously, rather than assuming trust based on network location.

You can also improve security by:

  • using dedicated and hardened environments for administrative tasks, for example following NCSC guidance on privileged access workstations
  • reducing unnecessary system complexity
  • limiting dependencies between critical systems

For organisations using Operational Technology (OT), it's important to carefully manage connectivity between IT and OT environments, ensuring that interactions are tightly controlled and aligned to the NCSC’s cross‑domain principles for securely managing data flows between systems of differing trust.

To this end, you should:

  • secure and monitor connections between networks
  • restrict access to essential interactions only
  • design systems to limit the impact of compromise

Published

Reviewed