Cyber Resilience Readiness Guide
Cyber security aims to reduce the likelihood of an attack. Cyber resilience is your organisation’s ability to respond, continue operating and recover when disruption still occurs. Use this guide to review the technology, suppliers and recovery arrangements your business depends upon.
This guide does not determine whether your organisation falls within the legal scope of the Cyber Security and Resilience Bill. It is a practical resilience review that remains useful whatever the final legislation says.
Step 1: Identify critical services
Start by listing the services your business cannot operate without:
- Microsoft 365 or Google Workspace
- Line-of-business applications
- Accounting and payroll
- Customer records
- Telephone systems
- Internet connectivity
- Remote access
- Websites and online sales
- File storage
- Backup systems
- Security platforms
- Building or access-control systems
For each critical service, record the business owner, the technology owner, the supplier, where the data is located, the acceptable downtime, the recovery priority and the alternative process if the service is unavailable.
Step 2: Map your technology suppliers
- Managed IT provider
- Internet provider
- Cloud provider
- Data-centre or hosting provider
- Software suppliers
- Backup provider
- Cyber-security provider
- Website provider
- Telephone provider
- Payment provider
- Specialist consultants
For each supplier, record the service supplied, any administrative access held, the support contact, the emergency contact, the contract renewal date, the incident-notification requirement, the data-export process and the exit arrangement.
Step 3: Review provider access
- We know which provider staff can access our systems.
- Named accounts are used instead of shared accounts where practical.
- Multi-factor authentication protects administrative access.
- Privileged access is limited.
- Access activity is logged.
- Old supplier accounts have been removed.
- Temporary access is removed after use.
- Remote-management tools are documented.
- Access is reviewed periodically.
Step 4: Review incident notification
- Our contract defines a cyber-security incident.
- It specifies how quickly we must be told.
- It identifies an emergency contact.
- It explains what information we will receive.
- It requires ongoing updates.
- It covers incidents affecting subcontractors.
- We know who internally receives the notification.
- We know what actions follow the notification.
A provider saying it will inform customers “where appropriate” is not the same as a clear, tested incident-notification process.
Step 5: Check backups and recovery
- Critical systems are included.
- Cloud data is considered separately.
- Backup frequency matches business needs.
- Retention is documented.
- Backups are encrypted.
- Backup access is protected by MFA.
- Backups are isolated from production systems.
- Failed jobs are investigated.
- Restores are tested.
- Recovery time has been measured.
- Recovery responsibilities are clear.
- The business can access backup information during a provider outage.
Step 6: Prepare an incident plan
An incident plan should name who does what: the incident lead, the IT provider, senior management, the data-protection lead, the insurer, the legal adviser, whoever handles communications, and who speaks to customers and suppliers.
- Emergency contacts are stored offline.
- Decision-makers are identified.
- Cyber-insurance details are accessible.
- Alternative communication is available.
- Critical systems have recovery priorities.
- Regulatory reporting responsibility is understood.
- Staff know how to report suspicious activity.
- A basic incident exercise has been completed.
Step 7: Plan business continuity
- Can staff work without email?
- Can customers still contact us?
- Can orders be processed manually?
- Can payroll continue?
- Can critical documents be accessed?
- Can phones be diverted?
- Can staff work from another location?
- Can the website display an emergency message?
- How long can the business operate without each service?
For each critical service, record it in a simple continuity table:
| Service | Maximum Acceptable Downtime | Alternative Process | Recovery Owner |
|---|---|---|---|
Step 8: Review and test
- Monthly backup monitoring
- Quarterly access review
- Quarterly supplier review
- Annual restore test
- Annual incident exercise
- Annual continuity review
- Immediate review after a major system or supplier change
- Immediate review after a cyber incident
This is the Operational Heartbeat in practice: controls are checked on a schedule, failures are acted upon, and recovery is tested before an emergency rather than during one.
Questions for your IT provider
- 1Who can access our systems, and how is that access protected and logged?
- 2How quickly would you tell us about an incident affecting our business, and is that in our contract?
- 3Are our backups isolated from production systems and when was recovery last tested?
- 4What happens if your own systems become unavailable?
- 5Which security responsibilities belong to you and which remain with us?
- 6Can we retrieve our data, configurations and credentials if we change provider?
Want the full business explanation?
Read our Technology Intelligence article on the proposed legislation behind rising supply-chain expectations:
The UK Cyber Security and Resilience Bill: Could It Affect Your Business? →
Plain-English Takeaway
Cyber resilience means knowing which systems and suppliers your business depends upon, how you will learn about an incident and how operations will continue and recover. Document these arrangements and test them before disruption occurs.
Downloadable guide
Download the Business Cyber Resilience Checklist
A printable checklist covering critical systems, IT suppliers, incident notification, backups and business continuity.
Download PDFFree download. No email address required.
Want the full business explanation?
The Technology Intelligence article covers why this matters, where it helps and what to watch out for.
Read the full Technology Intelligence articleRelated Knowledge Centre resources
Cyber Essentials Readiness Checklist
Work through the key controls to review before applying for Cyber Essentials.
View guideSupplier Access Review
Check which suppliers can access your systems and whether they still need to.
View guideBusiness Backup Checklist
Confirm what is backed up, where it goes and who checks that it works.
Coming SoonMicrosoft Passkey Readiness Guide
Check which users, devices, authentication policies and recovery procedures your business should review before Microsoft retires its own SMS and voice authentication.
View guideRemote Working Security Checklist
The security basics to check for staff working from home or on the move.
View guide