Skip to main content
Guidance

What to do when cyber attacks disrupt your organisation

How to recover from disruption, get ready for future incidents and make them less likely.

Page 4 of 5

2. Recovery and ongoing investigations (what to do in the first days and weeks)

Once you have established and recorded your initial assessment of the impacts of the incident, you can set up a structured recovery programme. Note, however, that if you are not sure whether the attacker has been evicted from your network, proceeding with recovery carries a risk of the incident restarting.

The recovery programme brings together the leadership, coordination and activities required to reduce the impact of the incident and support the organisation’s recovery in a controlled way, including the involvement of any relevant third parties.

Recovery from a disruptive cyber incident often takes longer than leaders initially expect. It's common for organisations to operate with limited or no IT services for weeks, and for full recovery to take many months. Building a recovery programme will help you, but you should be prepared for setbacks.

Leaders should set realistic expectations, protect teams from excessive pressure, and recognise that recovery is a sustained effort rather than a rapid technical fix.


2.1 Setting up your recovery programme

The purpose of the recovery programme is to reduce harm from the incident and to recover your organisation to minimum viable operations (MVO) as quickly and safely as possible. MVO is the lowest level of operational capability at which the organisation can continue to operate safely, meet its legal and regulatory obligations, and maintain trust with customers, partners and staff.

2.1.1 How recovery should be organised

Recovery should be run as a formal programme, with clear structure, ownership and decision‑making authority. The programme will consist of:

  • A set of clearly defined recovery workstreams (core and context-specific), each with a named lead, designed to restore the organisation to MVO. (See Sections 2.2 and 2.3, below).
  • A small number of cross‑cutting supporting functions that apply throughout the programme and underpin effective delivery. (See Section 2.4, below).

Together, these provide both the mechanism for recovery and the conditions for it to succeed.


2.2 Core recovery workstreams

Section 2.2 outlines examples of the main lines of effort needed to restore your organisation to MVO, but note there may be others not included here.

Recovery requires strong central coordination, but not all activity need be controlled from the incident command structure. Over-centralisation creates a bottleneck which can actually slow progress.

The incident command structure provides the overall direction and should:

  • ensure a formal handover from the initial response activities to the structured recovery workstreams
  • prioritise all activities in line with the prioritised business functions from phase 1
  • delegate ownership of workstreams to specific business units or functions
  • coordinate dependencies and rapid information-sharing between workstreams
  • provide governance and assurance

2.3 Additional activities (context-dependent)

Beyond the core recovery activities needed to restore your organisation to MVO, organisations may need to undertake additional activities depending on the characteristics of the incident.


2.4 Cross-cutting supporting functions

Alongside the recovery workstreams, you should actively manage a set of cross‑cutting supporting functions that apply throughout the recovery programme and help ensure it is delivered effectively.

Published