Knowledge Centre
Cyber Security GuidesChecklist and Guide

Cyber Resilience Readiness Guide

7 minutes to completeEvergreen guide — kept up to date

Cyber security aims to reduce the likelihood of an attack. Cyber resilience is your organisation’s ability to respond, continue operating and recover when disruption still occurs. Use this guide to review the technology, suppliers and recovery arrangements your business depends upon.

This guide does not determine whether your organisation falls within the legal scope of the Cyber Security and Resilience Bill. It is a practical resilience review that remains useful whatever the final legislation says.

Step 1: Identify critical services

Start by listing the services your business cannot operate without:

  • Email
  • Microsoft 365 or Google Workspace
  • Line-of-business applications
  • Accounting and payroll
  • Customer records
  • Telephone systems
  • Internet connectivity
  • Remote access
  • Websites and online sales
  • File storage
  • Backup systems
  • Security platforms
  • Building or access-control systems

For each critical service, record the business owner, the technology owner, the supplier, where the data is located, the acceptable downtime, the recovery priority and the alternative process if the service is unavailable.

Step 2: Map your technology suppliers

  • Managed IT provider
  • Internet provider
  • Cloud provider
  • Data-centre or hosting provider
  • Software suppliers
  • Backup provider
  • Cyber-security provider
  • Website provider
  • Telephone provider
  • Payment provider
  • Specialist consultants

For each supplier, record the service supplied, any administrative access held, the support contact, the emergency contact, the contract renewal date, the incident-notification requirement, the data-export process and the exit arrangement.

Step 3: Review provider access

  • We know which provider staff can access our systems.
  • Named accounts are used instead of shared accounts where practical.
  • Multi-factor authentication protects administrative access.
  • Privileged access is limited.
  • Access activity is logged.
  • Old supplier accounts have been removed.
  • Temporary access is removed after use.
  • Remote-management tools are documented.
  • Access is reviewed periodically.

Step 4: Review incident notification

  • Our contract defines a cyber-security incident.
  • It specifies how quickly we must be told.
  • It identifies an emergency contact.
  • It explains what information we will receive.
  • It requires ongoing updates.
  • It covers incidents affecting subcontractors.
  • We know who internally receives the notification.
  • We know what actions follow the notification.

A provider saying it will inform customers “where appropriate” is not the same as a clear, tested incident-notification process.

Step 5: Check backups and recovery

  • Critical systems are included.
  • Cloud data is considered separately.
  • Backup frequency matches business needs.
  • Retention is documented.
  • Backups are encrypted.
  • Backup access is protected by MFA.
  • Backups are isolated from production systems.
  • Failed jobs are investigated.
  • Restores are tested.
  • Recovery time has been measured.
  • Recovery responsibilities are clear.
  • The business can access backup information during a provider outage.

Step 6: Prepare an incident plan

An incident plan should name who does what: the incident lead, the IT provider, senior management, the data-protection lead, the insurer, the legal adviser, whoever handles communications, and who speaks to customers and suppliers.

  • Emergency contacts are stored offline.
  • Decision-makers are identified.
  • Cyber-insurance details are accessible.
  • Alternative communication is available.
  • Critical systems have recovery priorities.
  • Regulatory reporting responsibility is understood.
  • Staff know how to report suspicious activity.
  • A basic incident exercise has been completed.

Step 7: Plan business continuity

  • Can staff work without email?
  • Can customers still contact us?
  • Can orders be processed manually?
  • Can payroll continue?
  • Can critical documents be accessed?
  • Can phones be diverted?
  • Can staff work from another location?
  • Can the website display an emergency message?
  • How long can the business operate without each service?

For each critical service, record it in a simple continuity table:

ServiceMaximum Acceptable DowntimeAlternative ProcessRecovery Owner

Step 8: Review and test

  • Monthly backup monitoring
  • Quarterly access review
  • Quarterly supplier review
  • Annual restore test
  • Annual incident exercise
  • Annual continuity review
  • Immediate review after a major system or supplier change
  • Immediate review after a cyber incident

This is the Operational Heartbeat in practice: controls are checked on a schedule, failures are acted upon, and recovery is tested before an emergency rather than during one.

Questions for your IT provider

  1. 1Who can access our systems, and how is that access protected and logged?
  2. 2How quickly would you tell us about an incident affecting our business, and is that in our contract?
  3. 3Are our backups isolated from production systems and when was recovery last tested?
  4. 4What happens if your own systems become unavailable?
  5. 5Which security responsibilities belong to you and which remain with us?
  6. 6Can we retrieve our data, configurations and credentials if we change provider?

Want the full business explanation?

Read our Technology Intelligence article on the proposed legislation behind rising supply-chain expectations:

The UK Cyber Security and Resilience Bill: Could It Affect Your Business?

Plain-English Takeaway

Cyber resilience means knowing which systems and suppliers your business depends upon, how you will learn about an incident and how operations will continue and recover. Document these arrangements and test them before disruption occurs.

Downloadable guide

Download the Business Cyber Resilience Checklist

A printable checklist covering critical systems, IT suppliers, incident notification, backups and business continuity.

Download PDF

Free download. No email address required.

Still unsure what applies to your business?

Ask the IT Club Advisor about Microsoft 365, browsers, cyber security, productivity or any everyday technology problem.

Ask Your IT Question

Free to ask. No credit card. No sales pressure. Fair usage applies.