The UK official National Cyber Security Centre (NCSC) has brought out a guidance document for preparing in case of ‘a highly disruptive cyber attack’ – setting out the ‘immediate activities’ to undertake in the first few hours to contain and assess damage; how then to go about recovering; and thirdly, beyond ‘crisis response mode’, the ‘organisational rebuild phase’ when you begin to recover processes and operate ‘business as usual’.
In the first hours, the NCSC acknowledges emotions – stress, and guilt and blame. It advises: “It’s important for leaders to set a calm, professional tone from the outset, to avoid rushing to judgement, and to support their people through the uncertainty ahead.” As for recovery in the next days and weeks, that ‘brings together the leadership, coordination and activities required to reduce the impact of the incident and support the organisationโs recovery in a controlled way’. And as for a rebuild, the guidance notes that a cyber incident can place exceptional demands on people as well as systems. “By the time an organisation reaches the rebuild phase, those involved in the response may have experienced sustained psychological, emotional and physical strain.”
Where to read
The guidance is aimed at CEOs, Chief Information Security Officers (CISOs) and others of the c-suite. You can read the 31-page document at the NCSC website.
Comment




