Skip to main content
Guidance

How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI

Act now to be ready to withstand and recover from severe cyber attacks.

Page 2 of 26

Activity 1. Factor severe cyber threat response into your plans

Monty Rakusen via Getty Images

As outlined in the NCSC's Cyber Assessment Framework (CAF) Response and recovery planning principle, organisations should already have in place:

  • well-defined and tested incident management processes to ensure continuity of essential functions in the event of system or service failure
  • mitigation activities designed to contain or limit the impact of compromise

You must build on your existing crisis response plans or incident playbooks to include the activities and processes that will be triggered in the event of a severe cyber threat. These activities are a mix of immediately deployable and longer term strategic actions which are all covered in detail in this guidance. 

Strategic requirements may need to be adopted into technology roadmaps. Building in new functionality to meet the defensive measures needed for severe cyber threat can be difficult, costly and take time, particularly for OT systems.

The activities and recommended measures in this guidance will inform the contents of your response plan.

Reviewed

Version

1.0