Skip to main content
Guidance

How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI

Act now to be ready to withstand and recover from severe cyber attacks.

Page 19 of 26

4.1 Prepare your organisation for adaptability

Taking the extraordinary hardening measures against severe cyber threat as set out earlier is likely to significantly affect your normal operations, so careful preparations are essential. Senior leadership must understand the trade-offs between security protection and operational disruption. You must document all agreed approaches in your existing business continuity or severe cyber threat plan.

Preparation activityHow to do it
Agree all extraordinary defensive procedures.
  • Agree step-by-step instructions for implementing each defensive action in 3.3 for severe cyber threat. 
  •  
    • Include technical details, required approvals, and rollback procedures if needed. 
Establish decision-making authority.
  • Define who can authorise each measure and under what circumstances. 
Assess operational impact of disruptions.
  • Evaluate how long your organisation can sustain operations under each defensive scenario. 
  • Understand the dependencies between systems and the cascading effects of isolation or shutdown.
Test and exercise regularly.
  • Conduct exercises and simulations to ensure teams understand procedures.
  • Test whether systems can be recovered as quickly as planned.
  • Identify gaps in your preparation. 
Consider additional implications for OT.

For organisations with ICS:

  • Assess how the defensive measures affect physical operations. 
  • Plan for safe system degradation.
  • Ensure critical processes can continue during IT disruption. 
Agree communications.
  • Draft briefing materials for senior leadership explaining:
  •  
    • why extraordinary measures are needed
    • what they will achieve
    • what disruption to expect
  • Ensure redundancy for internal communications are planned for in case existing channels are rendered unavailable.

Published

Reviewed

Version

1.0