Organisations need to have plans in place for cyber attack response, which should only be used infrequently but must be able to limit damage and speed recovery. The plan needs to be thoroughly analysed and rehearsed, involve stakeholders of increasing seniority, and should be built into existing structures. It should be regularly exercised to ensure it will function correctly in a crisis situation, and a senior manager should be accountable in its development and maintenance.

The NCSC wants developers to get serious on software security
The NCSC’s new Software Security Code of Practice has been praised by cyber professionals as a significant advancement in enhancing software supply chain security.