How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI
Pages
Page 2 of 26
Activity 1. Factor severe cyber threat response into your plans

As outlined in the NCSC's Cyber Assessment Framework (CAF) Response and recovery planning principle, organisations should already have in place:
- well-defined and tested incident management processes to ensure continuity of essential functions in the event of system or service failure
- mitigation activities designed to contain or limit the impact of compromise
You must build on your existing crisis response plans or incident playbooks to include the activities and processes that will be triggered in the event of a severe cyber threat. These activities are a mix of immediately deployable and longer term strategic actions which are all covered in detail in this guidance.
Strategic requirements may need to be adopted into technology roadmaps. Building in new functionality to meet the defensive measures needed for severe cyber threat can be difficult, costly and take time, particularly for OT systems.
The activities and recommended measures in this guidance will inform the contents of your response plan.