How Organizations Bounce Back from Cyber Incidents
“Everyone has a plan until they get punched in the face.” — Mike Tyson
The same is true for cyber incidents. Having a response plan is essential, but the real test comes when your organization is hit by a cyber-attack. Organizations that have invested in cyber resilience are the ones that stay standing when the punch lands.
In October the UK National Cyber Security Centre (NCSC) published its annual report. This makes for uncomfortable reading, reporting an increasing number of nationally significant cyber-attacks this year. These include attacks on the major retailers Marks & Spencer (M&S), and the Co-op Group, as well as the motor manufacturer Jaguar Land Rover (JLR) which have resulted in major disruptions and significant financial costs.

Most of the commentary around cyber incidents dwells on their impact, the cancelled orders, disrupted manufacturing, and even bankruptcy. But in this blog, I will describe how organizations bounced back when an incident occurred. It will focus on resilience, what real organizations have done right, and the lessons others can take away.
Cyber Resilience
Cyber resilience is about more than just stopping attacks — it is about bouncing back from them. It is the ability of an organization to keep operating, recover quickly, and adapt when faced with disruption. True resilience blends technology, people, and process: strong defenses, well-rehearsed recovery plans, clear communication, and a culture that learns from every incident to come back stronger.
While organizations often invest heavily in cyber protection processes and technologies official statistics show less investment in resilience.
- According to the UK government cyber security breaches survey 2024 only 22% of UK businesses have a formal incident response plan in place (rising to 73% for large firms). Even basic IR processes (clear roles, reporting guidance) sit at ~30–37% adoption.
- The European Court of Auditors found preparedness across EU institutions “not commensurate with the threats,” with key controls not implemented and “a number of EUIBAs clearly underspending on cybersecurity.”
According to the 2025 IBM Cost of a Data Breach report “Among the organizations that had fully recovered, 76% said the recovery took longer than 100 days”. This illustrates the need for improved cyber resilience.
Business Process Resilience
As business processes have become digitized the way they were done before is often forgotten. Having another way to perform the most important business processes in the event of a cyber incident is a key element of resilience.
- When the aluminum smelter Norsk Hydro was hit by a ransomware attack in 2019, they were able to keep the production processes operating using the knowledge of retirees and former employees using a paper-based system.
- During the 2025 cyber-attack on M&S, they were able to keep their stores open by moving some of their processes and systems offline.
Data Resilience
Data backup, often seen as the last line of defense against cyber-attacks, takes on a strategic role in this context. A well-planned backup strategy, whether to a cloud or physical location, provides your organization with resilience against not only cyber threats but also other risks to your business continuity.
- In October 2023, The British Library was hit by the Rhysida ransomware group, leading to extensive server encryption, data exfiltration, and a full lockout of many networked systems. While many systems were down, non-IT/onsite services (events, exhibitions) continued in degraded or offline mode, showing that they had fallback arrangements. According to the report into the incident, they were able to identify viable sources of backups from which data could be recovered.
- In another example, reported by Bandicoot, in August 2025, a medium-sized UK trading company suffered a ransomware attack. The attack encrypted multiple user computers and the main server, leaving critical files inaccessible. Immutable backups prevented major data loss, and business downtime was minimized.
Prepare and Practice Incident Response
Proper preparation and practice prevent problems from getting worse. Your organization needs a well-prepared incident response plan with clearly defined people, processes and responsibilities. You may also need to have set up arrangements with cyber-incident response specialists to help.
- Microsoft published an example case study of how their incident response teams helped a customer following a ransomware attack in November 2024.
- In the UK, Gloucester City Council published a report on their recovery from an incident that was due to a single spear phishing email that was inserted into an existing email chain with a supplier. More on this later.
Pen and Paper
The UK NCSC recommends that organizations have a cyber incident plan on paper because, when a cyber incident occurs, you cannot depend on access to your systems. This includes email, messaging, and internet-based phones. You must have access to your plan and have prepared how you will communicate in advance.
- In 2021 Health Services Executive (HSE) was hit by Conti Ransomware. The PwC / HSE Independent Review reports that “Normal communication channels, both at HSE’s national center and within operational services were also immediately lost… Staff switched to communicating using mobile and analogue phones; fax; and face to face meetings.
- In March 2025, the Polish Space Agency (POLSA) suffered a cyber-attack and, according to reports “staff are being told to use phones for communication instead of email”.
Out with the Old
Most organizations have an archeology of IT systems. These legacy systems may still work but the software may not be supported, and replacement parts may be difficult to obtain. Another complexity when a cyber-incident occurs is personalization. Bespoke configurations of commercial off the shelf software can be difficult to recover.
- The report into the incident at the British Library identified that their reliance on legacy infrastructure was the primary contributor to the length of time that the it took to recover from the attack.
- One of the lessons learned by Gloucester City Council in the report on their cyber incident was “the danger of customizing applications to fit local needs as this caused ongoing compatibility issues between off-the-shelf versions and backed-up files”.
Clean Rooms and Cloud
One of the major problems when recovering from a cyber-attack is to be sure that you have removed all the malware. This has led to vendors offering “clean room” recovery services. These are usually hosted in a cloud and replicate the customer’s clean applications.
- In the Gloucester City cyber-incident, the council was running a hybrid system. The cloud-hosted applications were not affected except where they interfaced with data held on the council’s own server.
- Data backup to cloud also provides an air gap as well as immutable storage that helps to ensure clean restoration and recovery.
Learn and Improve
In all the examples where organizations have recovered from a cyber-incident, they report that they have learnt from the experience. Most commonly they learned that their organization is a target. Many previously did not think they were significant enough to be one. Every organization took steps to improve their cyber defense capabilities as well as their incident response plans.
Opinion
Organizations now face a constant barrage of cyber-attacks. It is essential that they not only invest in strong protection against these threats but also build cyber resilience into their business systems. Cyber resilience is different from high availability; cyber resilience builds rapid recovery from failure into the design and implementation of critical business systems. In this blog I have touched on the lessons that can be learnt from organizations that have recovered from cyber-attacks.
By learning from these examples your organization can strengthen business continuity and resilience against cyber-threats. To explore best practices in cyber resilience, join us at Identity-Centric Cybersecurity Impact Day 2025 in Frankfurt November 6th, 2025.