Context
New guidance provides a framework for response and recovery when cyber attacks happen. As technology evolves and cyber threats continue to grow in scale and sophistication, more organisations are having to prepare for the possibility of serious disruption.
Key points to note and next actions
- The NCSC’s new response and recovery guidance guides you through a highly disruptive cyber incident. It shows that organisations can and do recover from even the most severe attacks and provides a framework to understand what has happened, deal with the impacts, and move forward to full recovery. The guidance is split into 3 sections, to enable focus on the key aspects for the challenges faced as recovery proceeds:
- The first hours matter: as you’re working out what’s happened, what the impact is and trying to coordinate your actions. It emphasises the importance of swift defensive actions, establishing governance and getting control of communications.
- Building your recovery programme: The second stage is focused on building and implementing your recovery programme. This is key to getting your organisation back up and running, to minimum viable operations (MVO)
- Beyond recovery: Rebuilding stronger. This is a distinct shift from the recovery stage and focuses on getting the organisation back to business as usual or stronger than before. It includes ensuring the issues that contributed to the incident occurring in the first place are addressed and taking the opportunity to rebuild in a more secure and resilient way.
It is best to prepare and practice for these types of incident in advance. Organisations that act early are often better placed to respond effectively, maintain critical operations and recover more quickly. The guidance will help develop plans and test response arrangements before an incident occurs.
