In the wake of this year's cyber attack spree, the government has issued a stark warning to UK businesses...
With increased attacks leaving significant marks on key UK businesses, the NCSC is now urging CEOs to 'have plans on paper in case of attacks' - So what exactly does this mean, and what should you put on paper?
“For too long, cyber security has been regarded as an issue predominantly for technical staff. This must change. All business leaders need to take responsibility for their organisation’s cyber resilience.” - Richard Horne CEO, NCSC
The BBC and Telegraph have both recently echoed the NCSC's message of pen and paper as a crucial play as attacks surge. It's all part of a strategy referred to as 'resilience engineering', the idea of looking at systems and processes that can anticipate, absorb, recover, and adapt, in the event of an attack.
Every business will have its own unique take on what the pen and paper aspect of disaster planning should look like, and it really should be bespoke to your organisation. But if you are yet to start a physical copy of your disaster plans, here's a helpful starting checklist:
A well-prepared physical disaster pack keeps your team moving when systems stall. Start simple with an A4 folder or plastic wallet and make sure it’s stored securely but easy to grab in a crisis. It should hold the essentials: key contacts and roles, critical systems and suppliers, and a clear one-page activation checklist for the first hour of response.
On top of this, you should include the following: Recovery steps, communication templates & runbooks, holding statements, insurance and regulatory details, and a record of where your backups live. Add practical touches like site maps, access information, and a basic change log so it stays up to date. The goal is to ensure the right people have the right information, at the right time, when every minute counts.
The only way is to find out if it works is to test it. Ensure your team knows where to find the information, how to follow the steps, and which processes need the most attention. Testing uncovers gaps and reinforces what works.
These steps are a living process, a blueprint for resilience that can keep your business running smoothly when unexpected issues arise.
Does your business have these steps in place? If not, now’s the time to review and we can help ensure everything is structured and secure.
A physical copy of your business operations is only ever a contingency. What you really need is to stop breaches before they happen a proactive defence rather than a reactive response. That requires:
A good Security Operations Centre (SOC) can provide all of this, 24/7 protection, all year round. It's not just the big businesses that need one, and that's why we've made it more accessible, with a MISA (Microsoft Intelligent Security Association) backed service that gives your business the confidence to operate without compromise.
Contingency plans are essential whether that’s a physical backup, pen and paper, or another method. But the real win is not needing them at all, because your business is already protected against threats before they can cause disruption.
Discover the key takeaways from the NCSC’s 2025 Annual Threat Review here