Your severe cyber threat response plan sets out how to proceed in the event of crisis, for example:
which functions must continue
how you will deliver them in the absence of normal systems
alternative processes, such as manual procedures
Transitioning back to normal operations during an ongoing crisis is different from normal disaster recovery because you have to restore systems while threats persist and resources are stretched. You will have assessed how long your organisation can operate in degraded mode before business impact becomes unsustainable, and this will help inform and prioritise your recovery efforts.
You should:
map out what you need for recovery, such as backup systems and skilled staff