The National Cyber Security Council (NCSC) has released guidance for CEOs to navigate cyber incidents in an effort to ensure organisations are better managing breaches and cyber-attacks as the number of cybersecurity threats rise.
The immediate aftermath of a cyber-attack can be challenging for organisations, large and small.
Businesses will have to be strategic to minimise the impact cyber-attacks have on their organisations, but information on specific processes to take can be confusing and complex.
Organisational StepsÂ
First steps organisations can take to improve their cybersecurity posture is appointing a separate Senior Responsible Office (SRO) or to use a broader governance command structure to assign overall responsibility for the cyber-incident.
Organisations should ensure structures are in place to take into account the incident’s full impact across the whole organisation, and make it easy for those managing the response to regularly meet.
Further, senior-decisions makers should be informed and empowered in this process, by explaining how technical issues impact them.
This all boils down to allowing a robust response to the varied demands of the incident, including internal and external communications, collaborating with regulators and insurers, and providing updates to the board.
External SupportÂ
In addition to these organisational steps, the NCSC recommends companies bring in trusted and accredited external support. Using a cyber incident response (CIR) company can help recovery, and the NCSC has a number of assured CIR companies.
Insurers should also be informed of any incidents, as they may have in-house CIRs.
Data Breach Impact and Public Messaging
Key to responsible response and recovery is the consideration of a cyber incident’s impact on users.
It is critical that any risks to data is communicated to the data owners, and that regulatory requirements are considered.
The Information Commissioner’s Office offers specific guidance on responding to personal data breaches, and states that notifiable breaches must be reported “without undue delay.”
Companies should also have effective and transparent communication to reassure employees and protect their public reputation.
Recommended reading
- What is the Current Data Telling Us About Cyberattacks?
- Strong Cybersecurity Key to AI Superpower Ambitions, Microsoft Says
- The Unique Cybersecurity Threats Facing Education Institutions
While information should be honest and not downplay an incident, varying degrees of detail is to be expected for different stakeholders.
Ransomware
The continued rise of ransomware threats requires specific advice and guidance. The NCSC made clear that they and UK law enforcement “don’t encourage, endorse, or condone the payment of ransom demands.”
They warn that making a payment is no guarantee that an organisation will get their data back. Further, it may make them more susceptible to targeting in the future.
Team Resilience and Welfare
The NCSC advises that organisations put their staff’s welfare and moral at the top of their response plan, as cyber crises will raise stress and uncertainty across the company.
“Incidents often start with an intense period of activity, but many also have a ‘long tail’ with the impact lasting for months,” the NCSC said.
“The team will need to make important decisions throughout, but particularly when you are working out how to rebuild and prevent future incidents. It’s important to make sure that staff aren’t exhausted.”
Key to mitigating future stress is learning from the cyber incidents so that better structures can be put in place to de-risk an organisation.





