What to do when cyber attacks disrupt your organisation
How to recover from disruption, get ready for future incidents and make them less likely.
Page 4 of 5
2. Recovery and ongoing investigations (what to do in the first days and weeks)
Once you have established and recorded your initial assessment of the impacts of the incident, you can set up a structured recovery programme. Note, however, that if you are not sure whether the attacker has been evicted from your network, proceeding with recovery carries a risk of the incident restarting.
The recovery programme brings together the leadership, coordination and activities required to reduce the impact of the incident and support the organisation’s recovery in a controlled way, including the involvement of any relevant third parties.
Recovery from a disruptive cyber incident often takes longer than leaders initially expect. It's common for organisations to operate with limited or no IT services for weeks, and for full recovery to take many months. Building a recovery programme will help you, but you should be prepared for setbacks.
Leaders should set realistic expectations, protect teams from excessive pressure, and recognise that recovery is a sustained effort rather than a rapid technical fix.
2.1 Setting up your recovery programme
The purpose of the recovery programme is to reduce harm from the incident and to recover your organisation to minimum viable operations (MVO) as quickly and safely as possible. MVO is the lowest level of operational capability at which the organisation can continue to operate safely, meet its legal and regulatory obligations, and maintain trust with customers, partners and staff.
2.1.1 How recovery should be organised
Recovery should be run as a formal programme, with clear structure, ownership and decision‑making authority. The programme will consist of:
- A set of clearly defined recovery workstreams (core and context-specific), each with a named lead, designed to restore the organisation to MVO. (See Sections 2.2 and 2.3, below).
- A small number of cross‑cutting supporting functions that apply throughout the programme and underpin effective delivery. (See Section 2.4, below).
Together, these provide both the mechanism for recovery and the conditions for it to succeed.
2.2 Core recovery workstreams
Section 2.2 outlines examples of the main lines of effort needed to restore your organisation to MVO, but note there may be others not included here.
Recovery requires strong central coordination, but not all activity need be controlled from the incident command structure. Over-centralisation creates a bottleneck which can actually slow progress.
The incident command structure provides the overall direction and should:
- ensure a formal handover from the initial response activities to the structured recovery workstreams
- prioritise all activities in line with the prioritised business functions from phase 1
- delegate ownership of workstreams to specific business units or functions
- coordinate dependencies and rapid information-sharing between workstreams
- provide governance and assurance
To understand the incident and inform other workstreams, to enable safe recovery.
Activities
- Establish how the attacker gained access and moved through systems.
- Identify what actions were taken and whether access persists.
- Establish whether the attacker has been evicted and inform Incident Command to help them decide when the risk is low enough for recovery to proceed.
- Share findings rapidly with other recovery workstreams (especially system recovery).
- Use assured incident response providers unless you have an experienced in-house incident response team. Note that some insurance providers require you to use an independent response team.
To restore priority business functions and the systems that support them to MVO, safely and confidently.
Activities
Note that trusted identity is a critical dependency for recovery. Attackers may have compromised existing accounts or created new ones, and confidence in identity systems is often required before other recovery activities can proceed.
- Re‑establish a trusted source of identity to support recovery activities, recognising that some accounts may be compromised.
- In the absence of a trusted source of identity, agree how staff will be identified, for example, using cameras and personal endorsement in incident meetings.
- Be prepared to rebuild identity systems, recognising organisation‑wide impacts.
- Recover systems identified as priorities during triage, including dependencies.
- Reset credentials where required, including privileged accounts.
- Assess the availability, completeness and reliability of backups needed to support system recovery.
- Prioritise the use of backups to support restoration of business-critical services.
- Recognise that backups may not cover the full environment, including applications, identity systems and sources of trust.
- Plan recovery timelines recognising that restoring systems and data from backups can take considerable time.
- Bring core business functions back online in a controlled manner, with security considerations in mind. Assign a security lead to oversee where necessary.
- Inform customers when services will be restored and how to reconnect.
To enable safe and orderly restoration of systems by managing shared infrastructure dependencies and assurance requirements.
Activities
- Align with your Disaster Recovery or IT Service Continuity plans, as appropriate.
- Identify common infrastructure services and systems that underpin multiple business and recovery workstreams.
- Understand dependencies between infrastructure, shared services and business systems – and plan restart sequencing accordingly.
- Prioritise restoration of infrastructure required to support recovery of MVO.
- Treat backups as a critical dependency. Assess whether they can be accessed, trusted and used to support restoration.
- Assume backups may have been targeted by attackers and seek appropriate assurance that they are immutable and uncompromised.
- Balance the pace of restoration with the level of assurance required to reduce the risk of compromise.
- Consider regulatory, contractual and business continuity requirements when determining assurance thresholds.
- Factor in the availability and assurance requirements of external and cloud services, including connectivity constraints and third‑party access controls. Other organisations may require independent assurance or evidence of compromise remediation before restoring connectivity or access, which may further delay recovery timelines.
To keep your organisation operating while systems are unavailable.
Activities
- Base workarounds on an agreed prioritisation of business-critical services and the systems that support them, led by senior leaders.
- Ensure workarounds are security reviewed before being implemented (to ensure they don’t inadvertently increase risk).
- Implement alternative ways of working to support those functions identified from triage activities as business critical.
- Recognise that what is considered business critical may vary depending on timing and context (for example, cashflow, payroll, regulatory reporting, or peak operational periods).
- If backups are unavailable or can’t be trusted, identify alternative sources of information that can be used to reconstruct critical business data and maintain clarity on data ownership.
- Accept that early recovery may operate without corporate systems.
- Plan early for how data created through workarounds will later be reconciled with restored systems and backups.
- When reconciling systems, you may need to include requirements from external parties (such as financial auditors) for assurance around particular datasets.
- Agree a review date for each workaround to ensure that it doesn't become permanent.
To manage communications with the public, media, regulators and stakeholders.
Activities
- Provide clear, consistent guidance to staff and partners who interface directly with the public, ensuring they understand what can and cannot be said outside of the organisation, and how to handle queries or escalation.
- Communicate clearly and consistently with regulators, partners and the public.
- Share threat intelligence about the attack with industry, law enforcement and government partners, if relevant. Your incident may be part of a coordinated campaign and sharing what you know can help protect against wider impacts.
- The NCSC will help to coordinate and manage communications and engagement within government for reported incidents assessed as nationally significant.
- Reduce confusion and speculation by providing timely updates.
- Align messaging with legal, customer and operational realities.
- Follow the NCSC guidance on effective communications during a cyber incident.
To enable coordinated action and reduce uncertainty.
Activities
- Keep all staff informed of agreed external-facing lines to take.
- Provide timely updates, even where information is scant or incomplete.
- Assume internal systems may be unavailable or untrustworthy.
- Reinforce priorities, expectations and support arrangements.
To manage the impact on customers and partners, and preserve trust.
Activities
Customer relations activities will vary by sector and regulatory context, but typically include the following:
- Identify and respond to customer and partner concerns and service impacts early.
- Manage assurance requests from third parties, for example that your compromise won't infect their environment.
- Communicate clearly about service disruption and recovery timelines.
- Provide up to date, relevant information to staff members who are handling worried and irate customers.
- Provide practical guidance to customers if there are any actions they need to take.
- Coordinate closely with external communications and legal teams.
To manage legal risks and obligations.
Activities
Legal and regulatory requirements will vary by sector and organisation and should be addressed with appropriate professional advice.
- Identify legal and regulatory requirements arising from the incident.
- Manage ongoing business as usual obligations that fall due during recovery and rebuild.
To sustain workforce capability throughout recovery.
Activities
- Recognise recovery will require skills beyond IT and security.
- Be aware of the risks of fatigue and burnout and put staff welfare at the forefront of the incident response process.
- Implement shift systems and surge capacity where required.
- Redeploy and retrain staff to support critical activities.
- Draw on external support where internal capacity is insufficient.
To mobilise external support quickly.
Activities
- Coordinate suppliers, insurers and specialist providers.
- Clarify roles between incident responders and rebuild teams.
- Enable rapid procurement of new contracts for expertise or resources, often when corporate systems are unavailable.
- Expect heavy reliance on suppliers for investigation and system recovery (for example, a supplier may need to advise how a system works to enable forensic investigation or inform the rebuild).
To support informed recovery decisions.
Activities
For effective recovery, leaders need to understand the financial implications of different recovery options and the trade-offs involved.
- Track costs and financial exposure arising from the incident.
- Model recovery options and trade‑offs.
- Support decisions on investment, prioritisation and risk acceptance.
- Model cash‑flow impacts over time and develop financial scenarios as recovery plans evolve, recognising that costs, revenues and timing assumptions may change as assurance and restoration progress.
Workstream | Activities |
|---|---|
2.2.1 Cyber incident investigation To understand the incident and inform other workstreams, to enable safe recovery. |
|
2.2.2 Recover business functions To restore priority business functions and the systems that support them to MVO, safely and confidently. | Note that trusted identity is a critical dependency for recovery. Attackers may have compromised existing accounts or created new ones, and confidence in identity systems is often required before other recovery activities can proceed.
|
2.2.3 Common infrastructure and assurance To enable safe and orderly restoration of systems by managing shared infrastructure dependencies and assurance requirements. |
|
2.2.4 Develop workarounds to achieve MVO To keep your organisation operating while systems are unavailable. |
|
2.2.5 External communications To manage communications with the public, media, regulators and stakeholders. |
|
2.2.6 Internal communications To enable coordinated action and reduce uncertainty. |
|
2.2.7 Customer and partner relations To manage the impact on customers and partners, and preserve trust. | Customer relations activities will vary by sector and regulatory context, but typically include the following:
|
2.2.8 Legal and regulatory management To manage legal risks and obligations. | Legal and regulatory requirements will vary by sector and organisation and should be addressed with appropriate professional advice.
|
2.2.9 HR enabling To sustain workforce capability throughout recovery. |
|
2.2.10 External enablers To mobilise external support quickly. |
|
2.2.11 Financial modelling To support informed recovery decisions. | For effective recovery, leaders need to understand the financial implications of different recovery options and the trade-offs involved.
|
2.3 Additional activities (context-dependent)
Beyond the core recovery activities needed to restore your organisation to MVO, organisations may need to undertake additional activities depending on the characteristics of the incident.
To reduce harm from data compromise.
What to do
- Assume attackers may have accessed all data until evidence suggests otherwise.
- Treat data loss management as a parallel activity to system recovery.
- Prepare for contact from attackers, and extortion attempts.
- Consider all regulatory notification requirements under all applicable laws.
To ensure decisions are lawful, ethical and informed.
What to do
- Consider ransom demands carefully; the NCSC and UK law enforcement do not encourage, endorse or condone ransom payment.
- Your CIR firm may provide advice on whether and how to engage with the attacker.
- Understand that if you pay the ransom and receive the encryption key, the decryption process can take weeks to complete, and does not address the underlying vulnerabilities.
- Base decisions on legal, operational, ethical and reputational factors.
- Follow the guidance for organisations considering payment in ransomware incidents, as applicable.
To enable safe and realistic recovery of operational technology (OT).
What to do
- Recognise that OT recovery is often slower and more complex than IT recovery.
- Expect reliance on vendors, system integrators or specialist suppliers to support investigation and recovery.
- Consider whether OT recovery requires manual intervention, including on-site activity, where remote access or centralised visibility is unavailable.
- Understand how safety cases, regulatory requirements or operational constraints may limit recovery options or sequencing.
- Assess whether your organisation has access to the trusted tools, devices, spare hardware, and licensed software required to restore OT systems to a known-good state.
- Plan recovery carefully to maintain safe operation where central monitoring, telemetry or control systems are unavailable.
Activity | What to do |
|---|---|
2.3.1 Manage data loss To reduce harm from data compromise. |
|
2.3.2 Ransom payment approach To ensure decisions are lawful, ethical and informed. |
|
2.3.3 Operational Technology considerations To enable safe and realistic recovery of operational technology (OT). |
|
2.4 Cross-cutting supporting functions
Alongside the recovery workstreams, you should actively manage a set of cross‑cutting supporting functions that apply throughout the recovery programme and help ensure it is delivered effectively.
To set the direction, pace and tone for recovery
What to do
To support your organisation through the uncertainty of the incident, and guide it towards a successful recovery, you should:
- communicate early and regularly with staff, sharing what is known and what is being done
- be honest and reassuring: acknowledge uncertainty and the pressure ahead
- set realistic expectations for recovery times to reduce stress and burnout
- avoid assigning blame; reserve judgement while the investigation develops to help people feel safe to share what they know and admit any actions that may have contributed to the incident
- stay calm and professional to improve decision‑making and reduce attacker leverage
- role model actively taking downtime to encourage and demonstrate support to staff to do the same
While much of the organisation will focus on urgent recovery, leaders should ensure that some capacity is reserved to:
- consider longer‑term scenarios
- identify emerging risks and opportunities
- prepare for the rebuild beyond MVO
This balance helps avoid short‑term decisions that create long‑term problems.
To enable coordinated decision-making and accountability
What to do
Good governance and record‑keeping are essential to support regulatory and insurance requirements, reduce confusion, and enable later learning and rebuild. As outlined in 1.1, you will have established an incident command to coordinate workstreams, for example using the Gold, Silver and Bronze governance hierarchy.
You should:
- run frequent coordination meetings structured around:
- what has changed
- what decisions are required
- what needs to be communicated
- maintain clear records of decisions, rationales and actions
- ensure decisions are communicated, implemented and followed up
- retain records to support regulators, insurers and later recovery and rebuild phases
To sustain performance and wellbeing during a prolonged recovery
What to do
Recovery from disruptive cyber incidents places exceptional demands on people, and is likely to take several weeks. You should take measures to protect staff (and frontline staff in particular) from excessive workloads and prolonged stress.
You should:
- put staff welfare at the heart of the response
- enforce staff downtime and ensure it is honoured, as part of active management of fatigue and burnout
- set up and encourage use of welfare support networks allowing staff to discuss experience and impacts
- use shift patterns and surge staffing where needed
To capture insights during recovery to improve rebuild and reduce future risk
What to do
There is a lot to be learned from incidents. You should aim to record lessons as the incident unfolds, to inform recovery and rebuild to MVO.
To understand the causes of the incident, you should:
- look beyond the immediate technical cause to understand systemic factors
- consider whether any human error was influenced by stress, workload or poor usability – and how these risks could be reduced
- examine whether organisational incentives, priorities or decision-making processes contributed to poor outcomes
- identify gaps in visibility, such as undocumented systems or shadow IT, and how these can be addressed
- use the learning to inform longer-term prevention and resilience activities
Function | What to do |
|---|---|
2.4.1 Good leadership To set the direction, pace and tone for recovery | To support your organisation through the uncertainty of the incident, and guide it towards a successful recovery, you should:
While much of the organisation will focus on urgent recovery, leaders should ensure that some capacity is reserved to:
This balance helps avoid short‑term decisions that create long‑term problems. |
2.4.2 Governance and record-keeping To enable coordinated decision-making and accountability | Good governance and record‑keeping are essential to support regulatory and insurance requirements, reduce confusion, and enable later learning and rebuild. As outlined in 1.1, you will have established an incident command to coordinate workstreams, for example using the Gold, Silver and Bronze governance hierarchy. You should:
|
2.4.3 Workforce wellbeing To sustain performance and wellbeing during a prolonged recovery | Recovery from disruptive cyber incidents places exceptional demands on people, and is likely to take several weeks. You should take measures to protect staff (and frontline staff in particular) from excessive workloads and prolonged stress. You should:
|
2.4.4 Log learning To capture insights during recovery to improve rebuild and reduce future risk | There is a lot to be learned from incidents. You should aim to record lessons as the incident unfolds, to inform recovery and rebuild to MVO. To understand the causes of the incident, you should:
|