This guide provides an overview of a cyber attack response plan. Organisations of all sizes and types should download this plan today in readiness for when a cyber incident takes place. This will help reduce your business risk and improve business resiliency.
These days most organisations rely heavily on information technology. This means a cyber attack can seriously harm a business. However, the disruption caused by a cyber attack can be minimised if an organisation creates guidance documents, as well as tests and reviews a business resiliency plan (BRP).
A cyber attack response plan must form part of a BRP for organisations of any size, including small/medium-sized businesses. A key step to help reduce the impact of a cyber attack is to have an incident response team and a response plan in place. This guide will help you prepare.
1. Action Plan
The key stages to responding to a cyber incident are:
We have devised an example response plan into the key components and stages of a response plan and colour coded the suggested actions to match these components.
2. Incident log
During a cyber attack event it is recommended that a log of all the major events and actions is maintained. This log helps to manage and coordinate the response to the incident. The log may also be used later as mitigating evidence if the incident were to be investigated by a regulator or supervisory body.
3. Reporting to the ICO
Not all cyber incidents need to be reported to the ICO but those that do will have to be reported within 72 hours of becoming aware of the breach.
For advice on how to report a data breach to the Information Commissioner’s Office (ICO), and examples of what constitutes a data breach, see ICAEW helpsheet: GDPR – Data Breaches. The ICO advice on how to report a data breach can be found here.
Finance in a Digital World
Make sure you're ready for the changes that digital technologies are bringing to finance functions and accountancy work. Complete eLearning, watch webinars and read bite-sized summaries on the opportunities and challenges brought by automation, artificial intelligence and big data.