Cyber Incident Response

Information for Cyber Incident Response buyers
About the scheme
All Cyber Incident Response (CIR) Scheme Assured Service Providers have been assured against NCSC standards and are considered capable of providing high quality cyber incident response.
The activities that you can expect your chosen CIR Assured Service Provider to undertake will include:
- determining the extent and severity of the incident
- managing its immediate impact
- providing advice and assistance to fix the compromise of that system
- working to increase security across the network
- delivering a report that describes:
• the extent and severity of the cyber attack
• its impact on your organisation and (where relevant) its partners
• the remedial actions implemented and
• any recommendations for future activities
When to use a Cyber Incident Response Assured Service Provider
Below is the Cyber Buyer's Guide with further guidance and clarity around the Cyber Incident Response scheme.
If your organisation has been the victim of a cyber attack, the NCSC recommends that you start by visiting gov.uk/report-cyber to identify where you should report your incident.
We recommend that all UK organisations use a CIR Assured Service Provider when dealing with cyber incidents.
If you wish to plan and practise your organisation’s response to a cyber incident in a safe environment, we have plenty of advice in the Board Toolkit. In addition, you can take advantage of our free Exercise in a Box package. We have also launched an Assured Cyber Incident Exercising scheme which gives you access to NCSC assured exercising providers to help you rehearse, evaluate and improve your cyber incident response plans.
How to select a Cyber Incident Response Assured Service Provider
The NCSC recommends that all UK organisations should use an NCSC-assured Cyber Incident Response provider when dealing with cyber incidents. This includes, but is not limited to, businesses from small, local companies to large, multinational organisations, central and local government, and charities.
The NCSC assures Cyber Incident Response companies at two levels. Assured Service Providers from either CIR Enhanced Level or Standard Level will be able to assist with most cyber incidents. The key differences between Enhanced Level providers and Standard Level providers are outlined in the table below.
The CIR Standards confirm that the Assured Service Providers have experience of the following situations:
| Enhanced Level | Standard Level | |
|---|---|---|
| Experience dealing with cyber criminal attacks | ✓ | ✓ |
| Experience dealing with APT attacks | ✓ | |
| Experience of incidents involving organisations in regulated sectors | ✓ | |
| Experience of incidents affecting multinational companies | ✓ | |
| Experience with incidents involving external legal counsel | ✓ | |
| Cyber threat intelligence production and its use in responding to incidents | ✓ | |
| Basic malware analysis | ✓ | ✓ |
| Advanced malware analysis | ✓ | |
| End point detection | ✓ | |
| Log analysis on smaller estates | ✓ | ✓ |
| Log analysis on larger estates | ✓ | |
| Network traffic inspection | ✓ | ✓ |
| Digital forensics | ✓ | ✓ |
| Experience of dealing with incidents where Law Enforcement are involved | ✓ |
NCSC strongly recommend that you should choose a CIR Enhanced Level Assured Service Provider if your organisation is;
- operating in a regulated sector
- operating in more than one country
- likely to be specifically targeted by nation state backed attackers
- part of the Critical National Infrastructure (CNI)
- part of UK Central Government
You should select an Assured Service Provider appropriate to your needs and contact them directly - the NCSC is not party to these contracts. Please note that the companies listed on the NCSC CIR scheme (Enhanced and Standard Levels) have been assessed against the CIR standard which relates to the level of the scheme they are on (as indicated in the table above) so you can be confident that these skills and experience are in place. We do however recommend that you stipulate that all work is carried out under the Terms and Conditions of the NCSC assured CIR Scheme. You may also wish to make sure that the company you contact has had experience in the sector relevant to your organisation.
Considerations for Government buyers
Government and public sector buyers can use the Crown Commercial Service’s Dynamic Purchasing System to invite suppliers to bid for work. Full guidance is available on the Crown Commercial Services website.