Skip to main content
Guidance

What to do when cyber attacks disrupt your organisation

How to recover from disruption, get ready for future incidents and make them less likely.

Page 1 of 5

decorative image

Thomas Barwick via Getty Images

This collection will bring together guidance on preparing for, responding to and recovering from highly disruptive cyber attacks. The first guidance currently available focuses on responding to and recovering from a disruptive cyber incident.


What is a highly disruptive cyber attack?

A highly disruptive cyber attack is one that disrupts, disables or damages an organisation's critical systems or services, preventing it from operating normally. Recovery can take weeks or even months. The consequences can extend well beyond technology, affecting customers, services, supply chains, finances and organisational reputation. To recover, organisations may need to rebuild systems, redesign business processes and introduce temporary workarounds while full service is restored.


Who this guidance is for

This collection is intended for organisations where the loss of critical digital systems would have significant operational consequences.

It will be particularly useful for:

  • executive leaders, boards and senior decision-makers
  • CISOs and cyber security teams
  • CIOs, CTOs and technology leaders
  • service owners
  • business continuity, resilience and risk professionals

Responding to an incident?

If you are responding to a highly disruptive cyber incident, read Recovering from a highly disruptive cyber attack. This guidance provides practical advice covering the immediate response, recovery to minimum viable operations (MVO), and the longer-term rebuild of your organisation.


Related guidance

The NCSC also provides guidance to help CNI organisations prepare for periods of heightened cyber risk. It covers the planning, resilience and defensive measures needed to withstand and recover from severe cyber attacks. 


Published