For many organisations, cyber incident planning focuses on the first few hours: identifying the attack, containing the threat and establishing what has happened.
But what happens when those first few hours become days, or even weeks?
Recent guidance from the National Cyber Security Centre (NCSC) highlights the reality of highly disruptive cyber attacks. Recovery can take weeks or months, with consequences extending beyond technology to customers, services, supply chains, finances and reputation.
For leadership teams, the question is no longer simply “How do we recover our systems?” but “How do we continue operating while recovery takes place?”
The First 24 Hours Are Only the Beginning
As an incident continues, the challenge changes.
Employees may be unable to access normal systems. Communications may be restricted. Suppliers may be affected. Temporary manual processes may need to operate for far longer than anticipated, while customers and stakeholders still expect critical services to continue.
An organisation prepared to manage the first 24 hours is not necessarily prepared to operate effectively through the following three weeks.
What Absolutely Has to Keep Running?
One of the most important decisions during prolonged disruption is determining which operations must continue and which should be restored first.
Leadership teams need to understand their critical services and the technology, information, people and suppliers required to deliver them.
This means asking:
- Which services absolutely must continue?
- How long can they operate without normal technology?
- Are there practical alternative ways of delivering them?
- Which suppliers and third parties are critical?
- Who decides what gets prioritised?
- What happens if normal communications are unavailable?
The answers help establish Minimum Viable Operations: the level at which an organisation can continue its most important activities safely while wider recovery takes place. Clearly, thinking about these issues before an incident will allow you to be far better prepared.
Cyber Recovery Is a Leadership Challenge
As disruption continues, a cyber incident increasingly becomes an organisational crisis.
Mark Raeburn, Director of Cyber Security and Resilience at GSA Global, adds: “When a major cyber incident occurs, the challenge quickly moves beyond technology. Leaders need to understand what absolutely has to keep running, where the critical dependencies lie and how decisions will be made when normal systems are unavailable. Those are questions that are far easier to answer before an attack than during one.”
Technical teams may be focused on containment and rebuilding systems, while leaders must decide which services to prioritise, what customers should be told, how employees should operate and when it is safe to restore services.
These decisions may need to be made quickly and with incomplete information.
Clear leadership, established decision-making structures, and an understanding of operational priorities can therefore be just as important as the technical response.
Test Day Five, Not Just Day One
Cyber crisis exercises often concentrate on the dramatic opening stages of an attack. There is considerable value in going further.
What happens when systems are still unavailable five days later? What if a temporary workaround fails? What if a critical supplier cannot support recovery?
Testing prolonged disruption can expose dependencies and assumptions that traditional incident exercises may miss.
At GSA Global, our Cyber Resilience Readiness Assessments, Cyber Lifeboat and Minimum Viable Operations Planning and Cyber Crisis Exercising help organisations understand critical operations, establish practical alternatives and test leadership decision-making before a real incident occurs.
Could Your Organisation Operate for Three Weeks Without Its Normal Technology?
It is an uncomfortable question, but an increasingly important one when considering organisational security, resilience and trust.
Most organisations have considered what they would do during the first hours of a cyber incident. Far fewer have genuinely tested what happens if recovery takes weeks.
The middle of a major cyber incident is the worst possible time to discover that your recovery plan only really covered day one.



