NCSC issues a three-stage playbook for disrupted organisations
The UK’s National Cyber Security Centre (NCSC) has published What To Do When Cyber-Attacks Disrupt Your Organisation, a practical guidance document aimed at organisations whose critical systems have been “disrupt[ed], disabl[ed] or damage[d].” The guidance is organised into three clear chronological stages: the first few hours and days; building and implementing a recovery programme to reach minimum viable operations (MVO); and longer-term recovery to business as usual.
First few hours and days: defensive actions, governance and communications
For the immediate window after an incident the NCSC advises “swift defensive actions, establishing governance and getting control of communications.” Crucially, the guidance recommends organisations engage an incident response firm vetted by the NCSC at this stage. Those early steps are presented as a combination of technical containment and rapid decision-making structures to stabilise a crisis and reduce further harm.
Building a recovery programme and achieving minimum viable operations (MVO)
The second phase described in the guidance focuses on rebuilding to a minimum viable operations state. The NCSC frames this as a pragmatic, staged recovery that may employ temporary workarounds to restore core services while a fuller rebuild proceeds. The document positions MVO as an explicit target: getting the organisation functioning at the lowest acceptable level so critical services can continue while remediation continues.
Longer-term recovery: address root causes and rebuild more securely
The third phase covers returning to “business as usual,” which the NCSC defines as addressing the underlying issues that caused the incident and rebuilding systems “in a more secure and resilient way.” The guidance points organisations toward corrective measures that go beyond patch-and-pray fixes, urging structural changes to reduce the chance of repeat disruption.
Escalating threats, AI acceleration, and the case for realistic exercises
The guidance arrives as the NCSC warns the threat landscape is intensifying. ManageEngine data cited by the NCSC shows 77% of British organisations suffered a cyber incident over the past year — a figure the source notes is 11% above the European average. The NCSC has repeatedly urged investment in resilience, arguing that “rapid technological change, geopolitical uncertainty, and the evolution of the threat landscape” have made the environment more perilous for defenders.
The centre has also warned that AI is already helping adversaries “conduct offensive activity at much greater speed and scale than before, reducing the time available for defenders to respond, detect and contain threats.” Earlier in July the NCSC announced plans for a national cyber‑defence capability driven by agentic AI, warning that threat actors will soon be able to launch “fully autonomous attacks operating across the complete intrusion lifecycle.”
Against that backdrop, Ralph B reiterated the value of preparation and practice: beyond documenting plans, organisations should “practice and test their response to disruptive incidents.” He recommended testing failover systems, rehearsing shutdown and restart procedures, and rebuilding systems from backups. In particular, the NCSC argues realistic simulation exercises are more useful than tabletop approaches because they help build the “muscle memory” teams need to respond under pressure.
What this means for security teams, procurement leaders, and policymakers
- Security teams: The guidance places operational muscle — rehearsed, realistic exercises and repeated failover testing — at the centre of readiness. Teams are pointed toward concrete actions the NCSC has prioritised: rehearsing shutdown/restart, rebuilding from backups and engaging NCSC-vetted incident response firms in the immediate aftermath.
- Procurement leaders and affected enterprises: Organisations buying incident response or recovery services now have a clear NCSC recommendation to use firms vetted by the centre in the first hours and days. The MVO framing also gives procurement teams a clearer target for contractual response timeframes and contingency workarounds.
- Policymakers and regulators: The NCSC’s public emphasis on agentic AI and its plans for a national cyber‑defence capability — together with the warning about “fully autonomous attacks operating across the complete intrusion lifecycle” — is a direct signal that defenders and regulators will need to track AI-driven offensive capabilities and the national responses recommended by the centre.
The NCSC’s guidance is practical and staged: stabilise quickly, prioritise a return to minimum viable operations, then rebuild with more resilience. Its repeated call for realistic rehearsals and the recommendation to bring in NCSC-vetted responders underline a single theme in the document and accompanying blog: preparation and practice shorten the road from disruption to recovery. Read the original guidance and coverage here: https://www.infosecurity-magazine.com/news/ncsc-publishes-guidance-incident/




