Skip to main content
Guidance

What to do when cyber attacks disrupt your organisation

How to recover from disruption, get ready for future incidents and make them less likely.

Page 5 of 5

3. Rebuild (what to do over the course of the next few months)

In this phase, the organisation is moving beyond crisis response and restoring all business processes to business as usual. While recovery focuses on regaining MVO, the rebuild phase is about establishing a new steady state.

This phase provides an opportunity to step back from the intensity of the incident and take a more deliberate, forward‑looking approach – strengthening the organisation so it is better prepared for the future, not just returned to where it was before.

If your organisation has a mature business continuity plan this should inform your actions during this stage. However, many organisations find that their existing business continuity plans are only partially effective during a disruptive cyber incident. Plans may be outdated, insufficiently tested, or based on assumptions that no longer hold, so you should be prepared to adapt beyond documented plans, using them as a reference rather than a constraint.


3.1 Recover your people, not just the organisation

Highly disruptive cyber incidents place exceptional demands on people as well as systems. By the time an organisation reaches the rebuild phase, those involved in the response may have experienced sustained psychological, emotional and physical strain.

It's important to make time for the recovery of staff involved in the incident response and recovery effort. Supporting people’s longer‑term wellbeing is not only the right thing to do, but also essential for retaining skills, restoring morale, and enabling the organisation to move forward effectively.

Leaders should recognise the toll the incident may have taken and ensure appropriate support, reflection and recovery time for individuals and teams.


3.2 Deciding the long-term approach to rebuilding

The rebuild phase requires deliberate choices about what the organisation is rebuilding towards.

Leaders should consider how the new steady state should differ from the pre‑incident environment. Rebuilding systems provides an opportunity to address foundational issues that may previously have constrained security, resilience or change, and to align technology more closely with future business plans.

However, organisations should be cautious not to overload this phase. Attempting a full‑scale transformation programme before the organisation has fully stabilised can delay the return to business as usual and place additional strain on already stretched teams.

As a minimum, organisations should identify proportionate actions that deliver meaningful improvements to security and resilience without jeopardising recovery.


3.2.1 Building for resilience and sustainability

Rebuild decisions should prioritise sustainability over one‑off fixes. This may include:

  • designing systems to be easier to patch, maintain and recover
  • avoiding future obsolescence through planned lifecycle management
  • improving flexibility and resilience so services can degrade and recover safely
  • embedding recovery considerations into system design, not treating them as an afterthought

This is an opportunity to move towards proactive, sustainable resilience – enabling the organisation to respond more effectively to future incidents.

Investment decisions should reflect this longer‑term view. Rebuild activity is unlikely to be a single capital investment and may require ongoing operational funding to sustain improved security and resilience. Leaders should ensure funding models support long-term resilience and not just immediate remediation.


3.2.2 Rebuilding with confidence and assurance

Many organisations find that incident response and recovery were made harder by incomplete or outdated records of systems, dependencies and configurations.

The rebuild phase provides an opportunity to improve this position by ensuring systems are rebuilt with clear documentation and accurate records. You can use the opportunity to update your customer management database with business owners, or applications list with service owners . This supports future development, change, and incident response, and reduces reliance on institutional memory or undocumented knowledge.

Where specialist expertise is required, the NCSC advises organisations use companies assured under the NCSC Assured Cyber Security Consultancy Scheme (ACSC) for the delivery of security architecture and/or risk management advice.


3.3 Transitioning from workarounds to long-term solutions

As systems are rebuilt, organisations will need to transition away from temporary workarounds introduced during recovery.

This includes not only systems, but data. Leaders should ensure there is a clear plan for combining data from backups and workarounds into a single, trusted source of truth, recognising that data reconciliation can be complex and time‑consuming.

Decisions taken here will shape data integrity, reporting confidence and operational effectiveness well beyond the incident.


3.4 Learning and renewal

The rebuild phase is also the right time to conduct a structured lessons‑learned exercise.

This should consider:

  • what happened during the incident and response
  • which assumptions did not hold
  • where plans, processes or structures hindered effective action
  • which foundational issues increased impact or slowed recovery

Recording and acting on these lessons helps organisations be better prepared for the future, and demonstrates to regulators, partners and customers that the organisation has learned from the incident and is addressing root causes.

The NCSC encourages organisations to share lessons from the incident and the actions taken in response. Being open about what has happened, what was learned and what has changed can help other organisations improve their resilience. It can also demonstrate organisational maturity.

This learning should inform future plans, investment decisions and resilience improvements – helping to rebuild trust and confidence alongside systems and services. 

Published