(TLP:CLEAR) UK NCSC Guidance Helps Organizations Prepare to Operate through Highly Disruptive Cyber Attacks
Created: Thursday, October 1, 2026 - 14:57
Categories: Cybersecurity, Emergency Response & Recovery, Security Preparedness
Summary: The UK National Cyber Security Centre (NCSC) has expanded its guidance on highly disruptive cyber attacks into a full collection, Disruptive Cyber Attacks: Reducing Their Impact, Reducing the Risk. The collection pairs NCSC’s earlier recovery guidance with two new publications on preparing for these incidents and reducing their likelihood. NCSC defines a highly disruptive cyber attack as one that disrupts, disables, or damages critical systems or services so that an organization can no longer operate normally. Recovery from such an attack can take weeks or even months.
The collection has three parts, and each one is available as a downloadable PDF:
- Recovering covers the immediate response, a return to minimum viable operations (MVO), and the longer-term rebuild.
- Preparing addresses business continuity, people, technical recovery capability, and critical decision-making.
- Reducing the risk sets out five priorities: identifying critical systems, services, and data; reducing exposure to attack; limiting the impact of a successful compromise; building resilience into systems; and detecting and responding to attacks quickly.
Analyst Note: This guidance applies directly to water and wastewater utilities. Utilities often plan for losing power or a chemical supplier, but these types of disruptive cyber attacks are different because they can remove the tools a utility relies on to coordinate its response (such as email, VoIP phones, network file shares, or emergency response plan stored only on the network). These types of incidents show both the operational and the customer-facing sides of disruption.
Many water processes can run manually, which gives the water sector an advantage that other industries lack. That advantage only holds if staff are trained, procedures are current, and staffing can sustain manual operations. NCSC’s point that recovery may take weeks matters. Running manually for a day is a very different problem from running manually for three weeks, once staff fatigue, sampling, compliance reporting, and billing come into play.
Additionally, this guidance compliments the emergency response plans that America’s Water Infrastructure Act requires of community water systems serving more than 3,300 people. It also supports WaterISAC’s Cybersecurity Fundamentals.
Original Source: https://www.ncsc.gov.uk/collection/disruptive-cyber-attacks
Additional Reading:
- NCSC Guidance on Effective Communications in a Cyber Incident
- CISA, FBI, and EPA Release Incident Response Guide for Water and Wastewater Systems Sector
- U.S. EPA Incident Action Checklist: Cybersecurity
- WaterISAC 12 Cybersecurity Fundamentals for Water and Wastewater Utilities
Related WaterISAC PIRs: 6, 8, 11, 12
