Why annual cyber security training isn't enough
Annual cyber training provides an important baseline, but lasting security behaviours need reinforcement. See how smaller organisations can make training more effective.
4 minute readGuides
Cyber security often focuses on stopping an attack. That matters. But no organisation can remove cyber risk completely. A compromised account, malicious email, lost device or unavailable system can quickly become a business problem. When that happens, the quality of your response can matter just as much as the controls you had in place beforehand. For a smaller organisation, incident planning doesn't need to mean a complicated crisis management framework. It means knowing who needs to do what, who can help and which decisions cannot wait until something has already gone wrong.
An incident response plan shouldn't exist simply so you can say you have one.
Its value is in helping people make good decisions when information may be incomplete and the organisation is under pressure.
Imagine you discover that a colleague's email account has been compromised.
Who makes the initial decision about what to do?
Who contacts your IT provider?
How would you establish whether other accounts or information had been affected?
Who decides whether customers need to know?
Would you know whether the incident needed to be reported externally?
Those questions are much easier to answer on a normal working day than during an incident.
The National Cyber Security Centre recommends planning incident response processes in advance because doing so helps organisations identify gaps and make better decisions when a real incident occurs.
Many smaller organisations outsource some or all of their IT.
That doesn't outsource the business impact of an incident.
Make sure you know what support your provider will actually give you. Understand how to contact them urgently, including outside normal working arrangements where appropriate.
There may be other contacts you need too. These could include your insurer, legal support, communications support or specialist cyber incident response services.
The National Cyber Security Centre maintains an assured Cyber Incident Response scheme and recommends assured providers for organisations that need specialist support following an attack.
The important point is to work this out before you need them.
Searching for emergency support while systems are unavailable and customers are waiting for answers isn't a good incident response strategy.
A cyber incident can become an operational problem very quickly.
If email stopped working, could you still contact your team?
If an important system became unavailable, what work could continue?
If information was stolen, who would establish what had been affected?
Who would deal with customer questions?
Who has authority to make decisions about spending, shutting down services or bringing in external support?
Incident response therefore shouldn't sit entirely with whoever looks after your technology.
For a small business, the people involved might include whoever manages IT, a business owner or senior decision-maker and the people responsible for customers, staff or communications.
The names and roles will differ between organisations. The principle doesn't.
One simple question can expose a surprising weakness in an incident plan:
Where is the plan stored?
If the answer is on the same system that has just become unavailable, it may not be much help.
Think about what information you would need during an incident and whether you could still reach it.
That might include contact details, insurance information, key suppliers, system information, recovery arrangements and a simple record of who has authority to make important decisions.
You should also understand your backups: what is protected, how frequently it is backed up and how it would actually be restored.
The objective isn't to plan for every possible attack.
It is to make sure the organisation can still coordinate a response when normal ways of working are disrupted.
Writing a plan is useful. Testing it tells you whether it works.
This doesn't have to involve an expensive simulation.
Take a realistic scenario and talk it through with the people who would actually be involved.
What would you do first?
What information would you need?
Who would make each decision?
Where would you get help?
What would prevent you from responding effectively?
The National Cyber Security Centre provides Exercise in a Box, a free service designed to help organisations rehearse their response to scenarios including ransomware, phishing, supply-chain attacks and vulnerabilities.
A short exercise can reveal missing contact details, unclear responsibilities and assumptions that would otherwise only become apparent during a real incident.
If you haven't tested how your organisation would respond to a cyber incident, start with five questions.
1. Who takes control? Be clear about who coordinates the response and who can make important business decisions.
2. Who would you call? Record the details of your IT provider and any other external support you may need.
3. What needs protecting or restoring first? Understand which systems, information and services matter most to the business.
4. Can you operate without your normal systems? Make sure essential contacts and response information remain accessible during an outage.
5. Have you tested the plan? Run through a realistic scenario and use what you learn to improve your arrangements.
You don't need to predict exactly how a cyber incident will happen.
You need enough preparation to avoid making every important decision for the first time while it is happening.
Cyber Security Advice
H Change helps smaller organisations understand their cyber risks, strengthen their response arrangements and turn incident planning into something practical and proportionate.