Guidance
How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI
Act now to be ready to withstand and recover from severe cyber attacks.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 17 of 26
It’s vital to document and rehearse all the defensive measures you can implement quickly – without risk of inadvertently blocking access to critical functions – in the event of an escalation in cyber threat.
| Defensive action | How to implement |
|---|---|
| Invalidate existing credentials. | To prevent attackers using previously compromised credentials:
|
| Restore systems from trusted backups. |
|
| Establish a network isolation plan. | Plan how to segment or island critical systems to contain threats.
|
| Establish alternative processes for critical business functions. |
|
| Factory reset devices. |
|
| Plan for the ability to rebuild network from scratch. | In some circumstances the only option may be to build entire sections or whole networks from scratch.
|
| Evict adversaries from your network. | The Cybersecurity and Infrastructure Agency (CISA) Eviction Strategies Tool provides actionable, risk-aware playbooks to rapidly contain and remove advanced threats from the network while preserving resilience. |


