Guidance
How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI
Act now to be ready to withstand and recover from severe cyber attacks.
Pages
Page 6 of 26
1.4 Identify potential future threats
Consider where future potential threats to your organisation may come from, for example:
- a destructive or disruptive attack within your wider sector
- the compromise of a major supplier
- a complete loss of your enterprise IT
- loss of key services upon which you depend, for example, a communications provider outage
Consider how your risk posture will adapt to those elevated threat levels. Focus primarily on your business critical functions and systems which, if compromised, may impact the continuity of your organisation's operations.
The following threat identification techniques can help:
| Threat identification technique | Supporting information |
|---|---|
| Threat modelling | Threat modelling can be used at any time to help better understand how a system or service might be attacked or otherwise go wrong. |
| 2x2 scenario planning | 2x2 scenario planning is a futures tool to help decision making about changes to cyber security where there is a high degree of uncertainty in the future. |
| Counterfactuals | Counterfactuals provide a way to explore complex scenarios that haven’t happened, by building on information from previous events. This provides the opportunity to analyse options and consequences, to improve decision making. |