This collection will bring together guidance on preparing for, responding to and recovering from highly disruptive cyber attacks. The first guidance currently available focuses on responding to and recovering from a disruptive cyber incident.
A highly disruptive cyber attack is one that disrupts, disables or damages an organisation's critical systems or services, preventing it from operating normally. Recovery can take weeks or even months. The consequences can extend well beyond technology, affecting customers, services, supply chains, finances and organisational reputation. To recover, organisations may need to rebuild systems, redesign business processes and introduce temporary workarounds while full service is restored.
Who this guidance is for
This collection is intended for organisations where the loss of critical digital systems would have significant operational consequences.
It will be particularly useful for:
executive leaders, boards and senior decision-makers
CISOs and cyber security teams
CIOs, CTOs and technology leaders
service owners
business continuity, resilience and risk professionals
Responding to an incident?
If you are responding to a highly disruptive cyber incident, read Recovering from a highly disruptive cyber attack. This guidance provides practical advice covering the immediate response, recovery to minimum viable operations (MVO), and the longer-term rebuild of your organisation.