How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI
Pages
Page 5 of 26
1.3 Review your risk management activities
Risk management is fundamentally about planning for uncertainty and change, so risk assessments should always be informed by threat and factor in both current and potential future threats (see 1.4). Standard methods for managing risk aren’t enough to prepare an organisation for the sudden change in risk posture that severe cyber threats will likely bring.
Your severe threat response plan needs to strike a balance between current and potential future threats, the cost and impact of defences, and the overall risk to the organisation.
It's worth bearing in mind that there may be professionals within your organisation who have similar scenario planning roles which aren’t focused on cyber security. We recommend you engage Business Continuity and Emergency Planning Resilience and Response (EPRR) professionals to better understand and align approaches.
| Risk management activity | Supporting information |
|---|---|
| Review current risk management activities and capture where any increase in threat will alter how you manage risks. | The NCSC's CAF tool for assessing cyber resilience outlines several risk management activities. The CAF specifies several outcomes which, when met, serve to demonstrate an organisation’s cyber resilience. The CAF also links to a number of other useful guidance documents. |
| Reassess any previously accepted risks in light of potential severe threats against your sector. | Ask yourself if any previously accepted risks would directly impact your ability to withstand, respond to, or recover from a severe cyber attack. |
| Consider and capture what additional risk management activities you might need to undertake. | For example, record and understand contractual aspects to your network and devices. Refer to the NCSC’s guidance explaining component-driven and system-driven approaches to identifying cyber risk to help surface additional activities. |