Guidance
Small Business Guide: Response & Recovery
Guidance that helps small to medium sized organisations prepare their response to and plan their recovery from a cyber incident.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Guidance that helps small to medium sized organisations prepare their response to and plan their recovery from a cyber incident.
Page 3 of 7
How organisations can detect if they're being attacked.
The first step in dealing effectively with an incident involves identifying it. That is, how can you detect that an incident has occurred (or is still happening)?
Things that might indicate a cyber incident include:
The following 10 questions can help you identify what has occurred. It's a starting point that you can use to gather vital information as soon as you suspect something has gone wrong. The answers will:
Take a look at your security software (such as antivirus alerts and server/audit logs) to see if you are able to identify the specifics of the attack, and subsequently the cause of the incident. If you are unable to do this (but you know which device has been affected) run your antivirus programme to complete a full scan, and take notes of the results it gives you. If nothing is found, consider using an alternative antivirus programme.
Use the information you have gathered to look for advice online from trusted sources such as police or security websites. You may be able to find instructions there on how to fix the problem.


