The National Cyber Security Centre published new guidance in late July on recovering from a disruptive cyber attack. It’s genuinely good advice, but it’s written for organisations with a CISO, a Board and a dedicated IT team. If you run a smaller business, some of it won’t map onto your world at all. Here’s what it actually means for you, and where the guidance falls short if you don’t have fifty people to call on.

Your cyber attack response plan: the first few hours
The first thing to sort out is who’s actually making decisions. It sounds obvious, but in the panic of an incident, decisions get made by whoever’s shouting loudest, or don’t get made at all. Pick one person, even if that’s just you, and make sure everyone knows to check with them before switching anything off or telling a customer anything.
Get help fast. The guidance talks about engaging an assured incident response provider, which for a large organisation means a specialist firm on retainer. For most small businesses, that starts with a call to your existing IT support and asking them directly: is this beyond what you can handle, and who do you know who specialises in this? Don’t be embarrassed to ask. Attacks like this are exactly what specialist help exists for.
Work out what’s actually broken, as opposed to what’s merely inconvenient. Which systems do you need to serve customers today? Which can wait? And check your legal position early: if personal data is involved, you may have 72 hours to notify the ICO under UK GDPR. It’s also worth reporting the incident to the NCSC directly, which is free and doesn’t replace any other legal reporting you’re required to do, but can get you expert guidance quickly.
The days and weeks that follow
Here’s the most reassuring part of the whole document, once you strip out the jargon: you don’t need everything back at once. The guidance calls this recovering to ‘minimum viable operations’, which really just means getting the essentials running safely rather than restoring everything perfectly in one go. If you can take orders, pay your staff, and keep your core promise to customers, you’re in a workable position even if half your systems are still down.
The guidance describes separate workstreams for communications, legal, HR, customer relations and finance, each with its own lead. In a small business, that’s realistically one or two people juggling all of it at once. If that’s you, be honest about the limits of what you can do in a day, and lean on outside help where you can: your accountant for the financial side, your insurer if you have cyber cover, a trusted contact for anything legal.
Keep customers and staff briefed, even when there’s not much to say yet. Silence gets filled with speculation. And build in some slack for the timeline: recovery from a disruptive attack almost always takes longer than expected, often weeks rather than days, so set expectations accordingly with anyone waiting on you.
The months ahead
Once the immediate pressure is off, resist the urge to just patch things up and move on. Take the time to understand what actually let the attack happen, and fix that properly rather than the symptom in front of you. This is also the point to look after the people who carried you through the incident, not just the systems. Recovery takes a toll, and burnout among the people who stepped up is a real risk if it goes unacknowledged.
Write down what you learned while it’s fresh, even briefly. What would have helped you respond faster? What did you wish you’d had in place beforehand? That record is worth more to your future self than any amount of good intentions after the event.
None of this needs a security team or a six-figure budget. It starts with knowing which of your systems truly matter and what you’d do without them, which is exactly what a business impact analysis sets out to answer, and it’s a lot easier to think through calmly before an incident than during one.





