October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk6 min

What Should a Business Continuity Plan Include for a Cyberattack?

A cyberattack continuity plan explains which services must keep running, who makes decisions, how staff work safely during disruption, and how systems are restored and validated.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A business continuity plan for a cyberattack should spell out how the organization will keep its most important services operating safely while responders contain the incident and restore trustworthy systems. It needs service priorities and dependencies, decision-makers and alternates, workable fallback procedures, communications routes, a tested recovery sequence, and a schedule for exercises and updates. It should work alongside—not replace—the cyber incident response and disaster recovery plans.

Define the plan’s scope and activation authority

State which business services the plan protects and who can activate it. Triggers might include suspected compromise of a critical service, ransomware encryption, data theft, loss of trusted identity or communications systems, or an outage at a provider the organization depends on. Set out how staff report suspicious activity and who can declare that continuity arrangements are in effect or stand them down.

Keep activation instructions and escalation contacts available when corporate email, directories, collaboration tools, or identity systems cannot be trusted. CISA recommends that business leaders identify the systems supporting critical functions and ensure continuity tests are conducted. Its guidance is written for corporate leadership, but the planning principle applies broadly. CISA guidance for corporate leaders and CEOs.

Prioritize services and document what each depends on

For every important service, identify its owner, minimum acceptable operating level, and the dependencies needed to deliver it. This makes it possible to decide what must continue, what can pause, and what should be restored first. CISA recommends identifying assets that support health and safety, revenue, or other critical services and documenting interdependencies to inform restoration priorities. CISA’s #StopRansomware Guide and Infrastructure Dependency Primer discuss these planning principles.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • People: service owner, required skills, staffing coverage, and decision-makers.
  • Technology and data: applications, endpoints, servers, networks, identity systems, data stores, configurations, and recovery dependencies.
  • Facilities and infrastructure: locations, utilities, telecommunications, and any operational technology or equipment.
  • External dependencies: cloud and software vendors, payment or identity providers, suppliers, and upstream or downstream services.
  • Operating threshold: what “minimum service” means in practice, which functions may stop, and the conditions under which operations should pause for safety, security, quality, privacy, or fraud prevention.

For each service, also record whether a manual or alternate process is feasible and what checks must remain in place. CISA’s infrastructure dependency guidance describes continuity planning that considers supplemental providers of critical services and commodities.

Assign roles, alternates, and decision rights

Name a continuity lead, deputies, executive decision-maker, service owners, IT and security responders, communications contact, legal contact, and key provider contacts. Make sure each role has an alternate and a way to reach the person outside normal corporate systems.

Specify who may isolate an affected system or network, suspend transactions, invoke manual operations, direct staff, approve customer or public messaging, request outside assistance, and authorize restoration. The continuity lead coordinates business-service decisions; security responders assess the incident and determine containment actions. Set escalation routes for disagreements or decisions that cannot wait for the usual approval chain.

Coordinate continuity actions with incident response

The continuity plan should explain how business operations will adapt without interfering with investigation and containment. Include the reporting route for suspected compromise, how responders can be contacted if corporate systems are unavailable, and how relevant logs and other evidence will be preserved. Record who can authorize temporary disconnection of an affected service or network.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not reconnect affected systems or move data into a recovery environment simply to resume service. CISA advises isolating affected systems, preserving relevant evidence when appropriate, and taking care not to reinfect clean systems during recovery. The precise technical actions depend on the incident and should be directed by qualified responders. CISA’s ransomware guidance.

Prepare safe ways to operate during an outage

For every priority service, define the fallback that staff can actually use: manual processing, alternate equipment or location, another provider, delayed processing followed by reconciliation, or a controlled shutdown. Document the procedure, who can invoke it, required forms or equipment, how work will be tracked, and how records will be reconciled when normal systems return.

Set limits on fallback operations. For example, specify the approvals or verification checks required before staff accept a transaction, handle sensitive information, or resume a safety-critical task. For operational technology or other safety-critical operations, work with responsible engineering and safety teams to define safe states and manual controls, then test those procedures. CISA’s critical-infrastructure advisory specifically calls for exercised incident response, resilience, and continuity plans so critical functions can continue when technology is disrupted or taken offline. CISA’s January 11, 2022 critical-infrastructure advisory.

Plan communications and applicable notifications

Maintain current contact lists and alternate channels for employees, customers, suppliers, insurers, regulators, law enforcement, and service providers as applicable. Identify who approves internal instructions, customer notices, supplier directions, and public statements. Prepare short holding statements, but require facts to be checked before release. Specify how staff will receive instructions if email, collaboration tools, or identity services are unavailable.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not treat a generic plan as a source of legal deadlines. Notification duties and timelines depend on jurisdiction, sector, contracts, and the circumstances of the incident. Have qualified counsel identify the applicable triggers and coordinate with relevant sector or jurisdictional authorities. CISA recommends including response and notification procedures, organizational communications procedures, and holding statements in incident planning. CISA’s #StopRansomware Guide.

Set recovery priorities and validate clean restoration

List critical data and systems, their backup owners, backup frequency, retention, encryption and access controls, and the dependencies needed to restore them. Maintain offline, encrypted copies of critical data and test that they are available and intact in a recovery scenario. Keep relevant recovery instructions, configuration information, software or licensing details, and system images where applicable.

Write down the intended restoration order—for example, the foundational identity and network services that other systems rely on, followed by endpoints, applications, and data stores as appropriate to the organization. Specify the validation checks and approver required before each service returns to normal operation. CISA recommends restoring from offline, encrypted backups according to critical-service priorities and cautions against reinfecting clean systems. It also recommends maintaining and testing golden images and recovery materials. CISA’s #StopRansomware Guide.

When evaluating a backup or recovery approach, check whether it is separated from production credentials and networks, how encryption keys are controlled, whether data is resistant to unauthorized deletion, and whether the organization has demonstrated restoration in a clean environment. Consider coverage of cloud services, endpoints, servers, and critical configurations, plus portability, provider dependencies, access controls, and retention. Do not promise a recovery time or acceptable data-loss tolerance unless the organization has analyzed and tested those objectives. A single consumer external drive is not, by itself, a complete organizational recovery strategy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Exercise the plan and keep it current

Run continuity and cyber incident response exercises together. A tabletop exercise should require participants to make decisions, not merely read the plan. Include leadership, IT and security, business service owners, communications, and relevant suppliers where practical.

  • Decide whether the incident meets activation criteria and who has authority to act.
  • Choose which services continue, pause, or move to a fallback, and explain the dependencies behind those choices.
  • Work through isolation, alternate communications, stakeholder updates, and the limits of manual operations.
  • Describe how responders will preserve evidence and how the organization will establish that a restoration environment is safe.
  • Record gaps, assign each a responsible owner and due date, and revise procedures after the exercise.

Repeat exercises after major changes to services, suppliers, technology, staffing, or facilities. CISA recommends continuity tests for critical functions and tabletop exercises; its ransomware guide also calls for recording lessons and using them to refine plans and procedures. CISA’s leadership guidance and #StopRansomware Guide.

Tailor objectives and obligations to the organization

A usable plan is specific about the organization’s services, suppliers, systems, safety needs, contracts, and location. It should identify recovery-time and data-loss objectives where the organization has set and tested them, but there is no universal target that fits every service. Legal reporting duties, insurance conditions, engineering controls, and acceptable fallback risks likewise require organization-specific review. CISA’s cited guidance is U.S. government guidance, with some recommendations focused on ransomware or critical infrastructure; it supplies planning principles, not a determination of another organization’s legal duties or technical requirements.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.