
Richard May at virtualDCS argues that mastering the ‘when not if’ mindset is essential for strengthening cyber-security protocols
In today’s hyper-connected world, the reality of cyber threats looms over every organisation, big and small. The consensus among cyber-security experts is unequivocal: it’s not a matter of if, but when a cyber-attack will occur.
Embracing this mindset is crucial for strengthening cyber-security protocols and ensuring business resilience. By planning for inevitable cyber-incidents, organisations can significantly mitigate the impact and recover more swiftly.
Ransomware continues to dominate headlines as one of the most publicised security threats. In 2024, for the fourth consecutive year, cyber-attacks were the leading cause of ’impactful outages,’ with three out of four organisations experiencing at least one ransomware attack in the past 12 months.
As the ransomware footprint has increased, so has the price of the ransom itself, with some extreme cases seeing attackers demand as much as $80 million. The overall cost of cyber-attacks is staggering, with projections indicating it could reach $10.5 trillion worldwide by 2025.
However, businesses are increasingly vulnerable to insider attacks and user errors, such as accidental deletions or malicious activities by disgruntled employees. The financial implications of a ransomware attack are staggering, with the ransom itself comprising only 32% of the total financial impact a business will experience, according to the Veeam Ransomware Trends Report 2024. The remaining costs are attributed to downtime, lost data, and recovery efforts.
To effectively combat these threats, organisations must shift from a reactive to a proactive cyber-security posture. This involves anticipating potential incidents and preparing for their eventuality. Planning for what might happen reduces the overall impact when an attack does occur.
Several established frameworks guide businesses in adopting a ’when it happens’ approach to cyber-security, including NIST (National Institute of Standards and Technology), Cyber Essentials, and ISO certifications. Among these, the NIST framework is gaining popularity, often compared to ISO 27001, for its comprehensive approach to cyber-security.
The NIST framework offers a robust structure for managing and mitigating cyber-security risks. It is built around five core functions, each playing a critical role in ensuring a comprehensive cyber-security posture:
1 Identify: Understanding and managing cyber-security risks
To effectively manage cyber-security risks, regularly evaluate your organisation’s systems, assets, data, and capabilities through thorough risk assessments. This process helps identify vulnerabilities and potential threats.
Prioritise your security efforts by mapping out the most critical assets and their interdependencies. Establish governance structures to define roles and responsibilities, ensuring a coordinated and strategic approach to cyber-security.
2 Protect: Developing and implementing appropriate safeguards
Safeguarding critical services involves multiple protective measures. Implement firewalls, encryption, and multi-factor authentication (MFA) to secure data and systems from unauthorised access.
Develop and enforce comprehensive security policies and procedures tailored to your organisation’s needs. Regularly conduct training and awareness programs to equip employees with the knowledge to recognise and respond to threats.
Additionally, ensure that physical security measures are in place to protect critical infrastructure from physical breaches and tampering.
3 Detect: Implementing tools to identify cyber-security threats
To effectively detect cyber-security threats, deploy advanced monitoring tools that continuously scan for unusual activities and potential threats. Implement intrusion detection systems to identify unauthorised access and other malicious activities.
Regularly review and assess your security measures through audits to identify and address gaps. Maintain up-to-date threat intelligence feeds to stay informed about the latest threats and vulnerabilities, enabling a proactive defence strategy.
4 Respond: Taking action regarding a detected cyber-security incident
Develop comprehensive incident response plans detailing the steps to be taken when a cyber-security incident occurs, and regularly rehearse these plans to ensure readiness.
In the event of an incident, quickly isolate compromised systems to prevent the attack from spreading. Ensure clear and timely communication with all relevant parties to maintain coordination and transparency. Conduct forensic investigations to understand the breach’s scope and nature, which will aid in mitigating its impact and preventing future occurrences.
5 Recover: Maintaining plans for resilience and restoring capabilities impaired by incidents
Create detailed disaster recovery plans that outline strategies for recovering data and systems post-incident. Regularly test these plans through drills and simulations to ensure preparedness.
After an incident, analyse what occurred to improve future responses and enhance overall resilience. Continuously refine your recovery roadmap based on lessons learned to adapt to evolving threats and ensure robust recovery capabilities.
A critical aspect of adopting a ’when, not if’ mindset is developing a comprehensive disaster playbook. This outlines various potential scenarios and provides detailed instructions on how the organisation should respond to each situation. By simulating different attacks, businesses can identify vulnerabilities and refine their response strategies.
Early detection of threats is paramount. Businesses must equip themselves with tools that quickly detect changes in their environment. For example, changes to Entra ID (formally Azure Active Directory) can have catastrophic consequences if not promptly identified and addressed. Utilising tools that create a "blueprint" of your environment and notify you of changes, malicious or otherwise, ensures any anomalies are swiftly rectified.
The detect and recover phases are vital components of any disaster playbook. Detecting a cyber-security event early can prevent extensive damage. Once an incident is detected, having robust recovery mechanisms in place is essential.
Implementing off-site backup or disaster recovery solutions is one of the most efficient ways to recover from a ransomware attack, while avoiding repeat infections. Depending on the identified recovery point objectives (RPOs), these solutions ensure that data can be restored to a point before the attack occured, minimising data loss and operational disruption.
This approach includes deploying a clean room environment where systems are isolated and thoroughly cleansed of any malware before being reintroduced to the network.
A clean room environment is crucial in ensuring that recovery efforts do not inadvertently reintroduce the threat. This methodical approach to recovery helps maintain the integrity and security of the restored data and systems. Additionally, a clean room environment can store the data temporarily or even permanently, depending on the business’s circumstances, providing flexibility in managing the recovery process.
Cyber-security is not a one-time effort but an ongoing process. Organisations must continually evolve their strategies and defences in response to the ever-changing threat landscape. Regularly updating the disaster playbook, conducting periodic training and simulations, and staying informed about the latest threats and vulnerabilities are essential practices.
As attack vectors continue to grow and cyber-attackers’ tactics advance, adopting a ’when not if’ mindset is essential for building resilient organisations. By leveraging established frameworks like NIST, developing comprehensive disaster playbooks, and implementing robust detection and recovery solutions, businesses can significantly mitigate the impact of cyber-attacks.
The key lies in proactive planning, continuous improvement, and an unwavering commitment to safeguarding critical assets. As cyber-threats become increasingly sophisticated, strengthening cyber-security protocols with a forward-thinking approach is not just advisable but imperative.
Richard May is CEO of virtualDCS
Main image courtesy of iStockPhoto and Viorika
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543