Skip to main content
Guidance

How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI

Act now to be ready to withstand and recover from severe cyber attacks.

Page 5 of 26

1.3 Review your risk management activities

Risk management is fundamentally about planning for uncertainty and change, so risk assessments should always be informed by threat and factor in both current and potential future threats (see 1.4). Standard methods for managing risk aren’t enough to prepare an organisation for the sudden change in risk posture that severe cyber threats will likely bring.

Your severe threat response plan needs to strike a balance between current and potential future threats, the cost and impact of defences, and the overall risk to the organisation.  

It's worth bearing in mind that there may be professionals within your organisation who have similar scenario planning roles which aren’t focused on cyber security. We recommend you engage Business Continuity and Emergency Planning Resilience and Response (EPRR) professionals to better understand and align approaches. 

Risk management activitySupporting information
Review current risk management activities and capture where any increase in threat will alter how you manage risks.

The NCSC's CAF tool for assessing cyber resilience outlines several risk management activities.  

The CAF specifies several outcomes which, when met, serve to demonstrate an organisation’s cyber resilience. The CAF also links to a number of other useful guidance documents. 

Reassess any previously accepted risks in light of potential severe threats against your sector.Ask yourself if any previously accepted risks would directly impact your ability to withstand, respond to, or recover from a severe cyber attack. 
Consider and capture what additional risk management activities you might need to undertake.

For example, record and understand contractual aspects to your network and devices.

Refer to the NCSC’s guidance explaining component-driven and system-driven approaches to identifying cyber risk to help surface additional activities.

Published

Reviewed

Version

1.0