NCSC issues new guidance on long-term cyber resilience

News article

The guidance urges businesses to prepare for the potentially protracted period of heightened cyber threat from Russia

The National Cyber Security Centre (NCSC) has published new guidance in which it urges UK organisations to prepare for an extended period of heightened cyber security threat.

The guidance is designed to be applicable to any period of sustained heightened cyber threat, including the one arising from Russia in light of events in and around Ukraine.

While the NCSC is not aware of any current specific threats to UK organisations, it says that the cyber threat to the UK remains heightened, and they expect it to stay that way for some time.

The new guidance aims to help organisations avoid complacency and staff burnout. It advises that increased workloads for cyber security staff over an extended period can harm wellbeing and lead to lower productivity, with a potential rise in unsafe behaviours or errors.

The recommended actions in the guidance include:

  • following the NCSC's actions to take when the cyber threat is heightened guidance
  • revisiting risk-based decisions taken during the initial phase of heightened threat
  • empowering cyber staff to make day-to-day decisions about the threat response without requiring additional oversight
  • ensuring workloads are spread evenly across individuals and teams
  • ensuring frontline cyber staff can take breaks to recharge
  • accelerating planned action to harden networks and boost defence capabilities

Read the full guide on maintaining a sustainable strengthened cyber security posture.

Other resources remain available to help organisations improve their longer-term resilience, including 10 Steps to Cyber Security collection and Cyber Security Toolkit for Boards.

First published 5 July 2022