Jessica Entwistle
July 29 2026
The National Cyber Security Centre has published new guidance to help organisations respond to and recover from highly disruptive cyber incidents. The framework provides structured advice on managing the operational, technical and decision-making challenges that arise during a major security event, designed to support organisations that may feel overwhelmed when an incident occurs.
This guidance addresses a gap that many organisations only discover during an actual incident: knowing what to do next when systems are down, data may be compromised, and operational pressure is high. The framework recognises that recovery is not just a technical exercise but an organisational one, requiring clear communication, prioritisation of critical services, and coordination across multiple teams. It reflects the NCSC's understanding that incident response is now a routine part of business continuity planning, not an exceptional event. For UK businesses, the guidance provides a structured approach to decision-making under pressure, helping organisations avoid common pitfalls such as unclear ownership, poor communication with stakeholders, or attempting to restore everything at once without prioritising critical services.
Review whether your organisation has a documented and tested incident recovery plan that goes beyond technical restoration. Consider whether the plan includes clear decision-making frameworks, stakeholder communication protocols, and service prioritisation criteria. Check whether roles and responsibilities are clearly defined, whether the plan has been tested through tabletop exercises or simulations, and whether it is accessible to the people who will need it during an incident. Use the NCSC framework as a reference to identify any gaps in your current approach. Ensure that incident recovery planning is treated as an ongoing governance activity, not a one-time documentation exercise, and that it is reviewed and updated regularly to reflect changes in your organisation's systems, services and operating environment.
Source: NCSC UK