The National Cyber Security Centre (NCSC) has published new guidance setting out a three-stage framework to help organisations respond to and recover from highly disruptive cyber attacks, warning that recovery from the most serious incidents can take weeks or months and that victims must plan for consequences extending well beyond their technology estate.
Introducing the guidance in a blog post, Ralph B, the NCSC's Chief Technology Officer for Economy and Society, said that as technology evolves and cyber threats grow in scale and sophistication, more organisations are having to prepare for the possibility of serious disruption, and that victim organisations should recognise from day one the emotional toll an incident takes on the people dealing with it.
The guidance, What to do when cyber attacks disrupt your organisation*, is structured around three phases of response and recovery:
1. Immediate activities: the first hours and days, covering containing and assessing damage, implementing governance and establishing lines of communication, with early actions designed to speed up recovery later.
2. Recovery and ongoing investigations: setting up and running a recovery programme over the first days and potentially weeks, focused on rebuilding the organisation to minimum viable operations (MVO) and supporting staff, with the programme developing dynamically as the investigation produces new information.
3. Rebuild: the longer-term phase once the organisation is out of crisis response mode, addressing the issues that contributed to the incident and rebuilding systems so that fundamentals such as patching, configuration and access control are easier to achieve.
The NCSC defines a highly disruptive attack as one that disrupts, disables or damages critical systems or services and prevents the organisation from operating normally, with consequences that can affect customers, services, supply chains, finances and reputation.
The guidance is aimed at executive leaders and boards, CISOs and cyber security teams, technology leaders, service owners, and business continuity, resilience and risk professionals, and the NCSC notes it is a framework rather than an exhaustive checklist, with the required activities varying according to the incident and the legal and regulatory jurisdictions that apply.
Those parallel obligations will typically include assessing whether the incident amounts to a personal data breach notifiable to the Information Commissioner's Office within 72 hours under Article 33 of the UK GDPR, alongside any sector-specific reporting duties.
The NCSC recommends that organisations secure the services of an NCSC-assured Cyber Incident Response (CIR) firm, and places particular weight on preparation. In his blog, Ralph B said organisations should not simply document a plan but practise it - testing failover systems, rehearsing shutdown and restart procedures, and rebuilding systems from backups. Realistic response exercises can reveal issues that plans alone cannot and build the "muscle memory" needed to respond effectively under pressure, he said.
The guidance is the first instalment in a collection that will bring together material on preparing for, responding to and recovering from highly disruptive cyber attacks, and sits alongside the NCSC's existing guidance for critical national infrastructure organisations on preparing for periods of heightened cyber risk.

