CORE GUIDES READYUK EDITIONOFFICIAL DATA // SOURCE STATUS
GET PREPPED NOWUK PREPAREDNESS // OFFICIAL SOURCES // PRACTICAL GUIDANCE
OFFICIAL SOURCESCHECK STATUSSTATUS & FRESHNESSGB GRID FREQUENCYCHECK SOURCEELEXON BMRSUK WEATHER WARNINGSCHECK SOURCEMET OFFICEENGLAND FLOOD STATUSCHECK SOURCEENVIRONMENT AGENCYUK OFFICIAL UPDATESLATEST UPDATESSOURCE ATTRIBUTEDMY AREALOCAL INFORMATIONPOSTCODE CHECK
BUSINESS PLAYBOOK 03 // CYBER INCIDENT

SYSTEMS ARE COMPROMISED.
CONTAIN. THEN RECOVER.

Do not rush blindly back to business as usual. Establish what is affected, get the right technical help, protect critical services and restore in a controlled order.

ACTION ORDER // REDUCE CONFUSION

CONTROL THE FIRST HOUR.

The exact technical response varies by business and incident. This sequence keeps the first decisions focused on people, the critical service and a deliberate fallback.

FIRST 15 MINUTES

Recognise and contain

Record what was observed and when. Isolate affected devices or services where appropriate without deleting evidence, and activate the incident lead / IT support route.

NEXT 60 MINUTES

Understand the operational impact

Identify which critical services, accounts, data and suppliers are affected. Move the business to agreed manual or alternate processes where they are safe.

STABILISE

Recover in priority order

Use trusted backups and technical recovery procedures. Restore the systems supporting critical services first, validate them, then work back toward normal operation.

DECISION POINTS // WRITE THEM DOWN

DON'T WAIT FOR THE CRISIS.

Pre-agreed thresholds reduce hesitation and stop a degraded situation from drifting without ownership.

SCOPEWhich services and accounts are affected?

Do not assume the incident is limited to the first machine or user that reported it.

AUTHORITYWho can shut down or isolate systems?

Use documented incident roles and escalation points.

BACKUPSCan data be restored from a known-good copy?

Test restoration and avoid overwriting the only viable recovery copy.

COMMUNICATIONCan normal email or chat be trusted?

Use an alternate route if the normal communications system may be compromised.

REPORTINGWho must be told?

Use current NCSC / law-enforcement / regulatory guidance relevant to the incident and organisation.