Establish scope and preserve data
Identify affected devices, cloud/SaaS services, files and users. Record symptoms and timing, protect known-good copies and check whether cyber compromise is suspected.
Treat ordinary technical failure differently from a confirmed cyber incident. Protect data integrity, move the minimum operation to a safe workaround and restore services in critical order.
Use the documented minimum operation rather than improvising under pressure. Record decisions, ownership and the next review point as the incident develops.
Identify affected devices, cloud/SaaS services, files and users. Record symptoms and timing, protect known-good copies and check whether cyber compromise is suspected.
Use the documented manual, alternate-device, alternate-service or offline process. Contact the responsible IT/provider route and prioritise the minimum operation.
Recover from known-good sources, validate data and service behaviour, then reconnect dependent systems deliberately. Record what changed during the outage.
Pre-agreed thresholds reduce hesitation and stop a degraded situation from drifting without ownership.
If compromise is suspected, switch to the Cyber Incident playbook rather than overwriting evidence through routine troubleshooting.
Restore business services in dependency order, not simply whichever computer is easiest to fix.
A backup only counts if the required data can actually be restored within the business tolerance.
Define what can be recorded safely offline and how those records will be reconciled later.
Validate key records, permissions, transactions and synchronisation before declaring the system recovered.
If there are signs of compromise, ransomware, unauthorised access, suspicious account activity or deliberate interference, stop treating this as a routine IT outage and switch to the Cyber Incident playbook. Preserve evidence and use appropriate technical support.
Use current provider, regulator and official guidance during a real incident. GPN is the planning layer, not the authority controlling the incident.