The Security Briefing

The NCSC's guide to surviving a cyber attack starts with a question about your building

Written by Karyee Lee | Oct 2 2026

The National Cyber Security Centre has completed a three-part guide to the cyber attack that stops an organisation operating normally. It was written for boards and CISOs. Its first questions are just as pointed for the people who run the building. 

The NCSC opens its guidance for the worst day by addressing the person reading it. If your organisation has just been hit by a highly disruptive cyber attack, it says, you are probably feeling heightened emotions and a great deal of uncertainty.

It is an unusual start for technical guidance, and it sets the tone for Disruptive cyber attacks: reducing their impact, reducing the risk, which the NCSC published in full on 1 October. The recovery section came out in July. The October release adds two more: how to prepare, and how to reduce the risk in the first place.

The NCSC defines a highly disruptive attack as one that disrupts, disables or damages critical systems or services so that an organisation cannot operate normally. Recovery can take weeks or even months, and the damage spreads to customers, supply chains, finances and reputation. Its latest annual review, covering September 2024 to August 2025, shows how often it deals with serious cases. Nearly half the incidents it handled were nationally significant, 4% of those were highly significant, and highly significant incidents rose 50% for the third year running.

Three questions before anything else

Preparation begins with business continuity, and with questions any security manager will recognise. Which technology and business services matter most? How long can the organisation operate without them? Which systems support them?

From there the NCSC asks for workarounds, identified in advance and risk assessed, for the day technology is unavailable. It wants the resources for those workarounds ready, the most important systems prioritised for protection, and an agreed order for restoring them. The people who run a service day to day usually understand it best, the NCSC says, so they belong in the planning, along with customers, delivery partners and suppliers.

Suppliers get particular attention. The guidance asks organisations to plan for losing one abruptly, and warns that attackers may go after a supplier as a way in, or use a supplier's disruption to widen the damage.

Then comes the line that gives the guidance its edge. Plans should be tested, with a full exercise where possible, because many plans fail in practice. Tabletop exercises can check governance, roles and decisions. Technical recovery testing shows how complicated restoration really is. The NCSC points to its Exercise in a Box tool and its Cyber Incident Exercising scheme.

The first hours, and what comes after

The recovery guidance has three stages. In the first hours, the aim is to stabilise the situation, build a shared understanding of what has happened and enable informed decisions. The NCSC's list starts with securing an NCSC-assured cyber incident response provider and putting governance in place, because decisions made through that structure guide much of what follows. It also points to its guidance on communicating during an incident. It asks organisations to report the incident to the NCSC if it affects data on employees, customers or clients, the organisation's firmware, software or hardware, or personal data. The NCSC says it is not a regulator and will not pass information to regulators without first seeking consent.

The second stage covers the first days and possibly weeks. It means running a recovery programme built around rebuilding to what the NCSC calls minimum viable operations, supporting staff, and adjusting as the investigation turns up new information. The third, rebuild, is the longer work once the organisation is out of crisis mode. The NCSC calls all of this a framework and says it is not an exhaustive checklist, because the right actions depend on the incident and the legal and regulatory rules involved.

Who decides, and who gets looked after

People get as much space as technology. Staff will have to adapt, decide under uncertainty and find new ways to keep essential work going, the NCSC says, so exercises should involve technical responders and wider roles. Critical response roles should never depend on one person. Employees outside the response team need to know what is expected if systems are down, such as how to report a problem or whether to power devices off. Long hours can quickly lead to fatigue and burnout, so support for staff needs planning too.

Four decisions are best settled before the day: who has authority to make strategic decisions, the organisation's risk appetite, escalation thresholds, and the legal and regulatory considerations. On ransomware, the NCSC and UK law enforcement do not encourage, endorse or condone paying. Systems may stay compromised, the organisation may be targeted again, and decrypting every machine can take weeks even with a key. The NCSC adds that well-prepared organisations are more likely to have other ways to recover.

On the technical side, it says organisations need visibility across critical systems, and that most do not employ specialists who can handle a disruptive incident. It recommends that every UK organisation, whatever its size, engage an NCSC-assured incident response provider for significant incidents, and keep cyber insurance details stored securely offline.

Making the day less likely

The third part covers reducing the risk, in five steps.

It starts with visibility. You cannot defend systems effectively without knowing what you have, the NCSC says, and gaps in visibility can become entry points or let attackers operate unnoticed. Attackers go for high-privilege accounts, identity systems such as Active Directory, backups and whatever underpins essential functions.

Next is reducing exposure. That means baseline practices such as keeping systems up to date, using frameworks like Cyber Essentials or the Cyber Assessment Framework, and then closing the common ways in. For stolen credentials, the NCSC points to resilience against phishing. It recommends a vulnerability management process, securely configured internet-facing systems and unnecessary services switched off. For forgotten or unknown systems it recommends attack surface management tools.

The third step assumes some attacks will get through. Grant access by role and necessity, segment networks so a problem in one area does not spread quickly, and isolate backups and administrative controls, which the NCSC calls frequent targets in disruptive attacks.

The fourth is design. Security and resilience work best when built in from the start, because retrofitting controls is often more complex and less effective, though the same principles can guide upgrades to legacy systems. The NCSC lists verifying access continuously instead of trusting network location, using dedicated hardened environments for administrative tasks, cutting unnecessary complexity and limiting dependencies between critical systems. Organisations with operational technology are told to manage IT and OT connections carefully.

The fifth is detection. The NCSC points to services including Protective DNS, which stops systems connecting to known malicious domains, and its free Early Warning service.

Read it with a control room in mind

The collection is written for executive leaders, boards, CISOs, CIOs and CTOs, service owners, and business continuity, resilience and risk professionals. Physical security is not named among the readers. The services it protects are all in there anyway.

Door release, video recording, alarm signalling to a monitoring centre and visitor management run on networks, cloud platforms and supplier contracts that an attack can take down. Put the NCSC's three questions to them and the answers get specific. Which of those functions can a site not do without? How long can it run without them? What does each depend on: the network, a cloud service, an identity system, an integrator's remote access?

The workarounds have a security version too. Manual door procedures, extra officers and paper logs each carry their own risks, which is why they are worth assessing before an incident. Control room staff and officers are also exactly the employees outside the response team who need to know what is expected if systems go down.

Two points from the reducing section land on security estates. The NCSC warns that attackers can get in through systems an organisation is not monitoring or even aware of. Cameras and door controllers added by an installer years ago are the sort of device that can be missing from an asset list. Its advice to limit dependencies between critical systems reads as the design answer to the three questions: the fewer things a door depends on, the shorter the list of things that can take it down.

If an integrator or monitoring company supports your systems, losing it suddenly is one of the scenarios the NCSC asks organisations to plan for. And the advice to settle authority and escalation thresholds in advance suggests a simple test. If IT would isolate a network during an attack, does the person who answers for the building know, and have they been in the same exercise?

The NCSC's 27 August advisory on internet-exposed operational technology ends by pointing readers to this guidance for response and recovery planning.

Register your interest for The Security Event 2027  

Subscribe to The Security Briefing for monthly updates!