How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI
Pages
Page 1 of 26

Cyber incidents targeting organisations – particularly those against critical national infrastructure (CNI) – are becoming more frequent, sophisticated and potentially destructive. This is happening against a backdrop of greater geopolitical instability, rapid technological advances, and increasingly capable adversaries. In an environment where cyber threat escalates to ‘severe’, it is feasible that highly capable threat actors would target the UK’s CNI to cause major disruption.
What do we mean by 'severe cyber threat'?
Severe cyber threat means there is a much greater likelihood of a deliberate and highly disruptive or destructive cyber attack against UK CNI. Such an attack intends to cause severe harm to systems, data or infrastructure, often with widespread consequences.
Severe cyber attacks go far beyond simple data breaches or minor service interruptions. For example, they aim to:
- Shut down critical services or operations for extended periods.
- Erase or corrupt data – making recovery difficult or impossible - to affect critical services or operations.
- Damage physical systems, such as Industrial Control Systems (ICS).
Severe cyber attacks like this can trigger cascading effects across industries, governments and society. The impact often includes substantial financial loss, prolonged operational downtime and increased risks to public safety and national security.
When faced with an increased threat of severe cyber attack, organisations need to be able to act quickly to both mitigate or limit the effectiveness of the attack, and continue to operate and recover.
Adaptability to risk builds greater resilience
Cyber resilience is not about eliminating all risk – which is impossible – but about managing risk to acceptable levels while ensuring business continuity.
The reality is that cyber threats won't always be preventable, so in the event of severe cyber attacks – which for example shut down services or operations – organisations must be ready to continue operating through disruption and to undertake recovery activities, all whilst under immense pressure. This is what the NCSC means by resilience. It isn't simply the ability to resist failure. It is the ability for a system – including people, processes, and technology – to keep functioning despite setbacks.
The time to act is now
To be prepared to respond to a step-change in threat, you must identify, design, implement and rehearse the defensive actions your organisation will need to take. And you must do it now.
You should already have incident response plans or playbooks in place to respond to particular cyber incidents, such as detecting phishing emails or a network compromise.
Now CNI operators must evolve those plans to include activities which enable rapid deployment of a more defensive posture in the event of severe cyber threat.
About this guidance
This guidance aims to help people in CNI organisations involved in all aspects of risk and resilience planning and oversight, such as:
- leaders
- business continuity/emergency planners
- systems architects
- risk managers
- cyber security specialists
It will also help regulators – and overseers of sector resilience in government – to understand best practice.
CNI organisations should already have a good understanding of the threats they face, and know how their systems and supply chains interconnect. You will already follow NCSC and other cyber security guidance and implement best practice to secure your cyber defences. To note: it is particularly important that you understand which of your systems are critical to the operation of service for your customers. If you don't know this, ensure you define these first.
This guidance goes beyond the defensive measures an organisation needs in the current threat environment. As geopolitical uncertainty is growing, and adversary intent can change quickly, this guidance will prepare you for escalated cyber threat. It recommends additional measures and considerations which will help shape how you prepare your organisation for crisis posture in advance, allowing you to develop and test your plans before they are needed in earnest.
How to use this guidance
This guidance is organised into 4 complementary activity areas that collectively strengthen resilience against severe cyber threats. They help organisations prepare by putting in place the capabilities, resources, and defensive measures needed to respond effectively, and plan by defining how those measures will be deployed under severe threat conditions.
The activities cover:
- Developing organisation-wide response strategies and plans.
- Enhancing situational awareness through monitoring and intelligence sharing.
- Hardening systems and networks to reduce vulnerabilities and enable rapid escalation.
- Ensuring the ability to maintain operations and recover during disruption.
All 4 areas should be integrated into routine processes and applied collectively to ensure your organisation can anticipate, withstand, and adapt to extreme cyber risk. This guidance documents a typical workflow - the exact order of activities may vary according to your organisation.
Note, there is no one-size-fits-all approach to getting ready for severe cyber threat. You will need to determine an acceptable level of risk for your organisation when deciding which actions to take and when, based on your specific business context.



