Guidance
How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI
Act now to be ready to withstand and recover from severe cyber attacks.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 15 of 26
In preparation for increased cyber threat, it’s important to plan architectural changes now, and in advance of your next infrastructure update. Changes made in a hurry, when crisis hits, may be poorly implemented and create unforeseen risks.
Flexibility, defensibility and resilience are key watchwords for architecture design. To help in your design, you may wish to consult the following sources of guidance:
| Guidance | How it helps |
|---|---|
| Identifying and mitigating living off the land techniques | Identifying and mitigating attacker techniques that exploit built-in system tools enables stronger controls and reduces opportunities for stealthy compromise. |
| Secure design principles | Embedding security into system design from the start, applying principles like least privilege, defence in depth, secure defaults, and resilience. |
| Engineering resilience against critical loss | Embedding the resilience principles – anticipate, absorb, recover, and adapt – into systems and processes ensures they can withstand and rapidly recover from severe cyber disruptions. |
| Privileged access management | Ensuring administrative privileges are tightly controlled and monitored reduces the risk of compromise through misuse or escalation of high-level access. Organisations can further limit security risks to OT through strict access controls and the use of Privileged Access Workstations (PAWs). |
| Zero trust architecture design principles | Following a threat-led zero trust approach – which uses multiple contextual signals to continuously authenticate and authorise access – builds resilience against sophisticated cyber threats by reducing attack surfaces and preventing lateral movement in your network. |
| Modern defensible architecture | This Australian Cyber Security Centre (ACSC) guidance can help organisations plan, invest in and implement Modern Defensible Architecture (MDA). |
| ICS Community of interest Research Institute in trustworthy interconnected cyber-physical systems guidance | Provides community authored guidance covering a range of OT security topics for OT practitioners. |


