
teissLondon2022 kicked off on Thursday, 8th September, bringing in expert insights from cyber security industry leaders and practitioners on addressing the major cyber security pain points of organisations across industries. In this session, cyber security experts discussed the best practices for developing an incident response playbook for critical suppliers.
The critical infrastructure sector- composed of water supply and energy providers, nuclear and thermal power plants, railway operators, airports, and healthcare organisations, has been targeted by malicious actors, particularly nation-state hackers, heavily over the past decade. The targeting of Colonial pipeline, the NHS, and most-recently South Staffordshire Water were some of the most publicized attacks on critical infrastructure organisations in the recent past.
Critical infrastructure organisations are mostly enterprise-scale entities, running diverse legacy industrial hardware, software and applications and relying on hundreds of supply chain vendors for daily operations. Securing their vast IT networks and distributed assets takes plenty of investment in cyber security tools and solutions and manpower as well as strategies so that they can stay a step ahead of hackers at all times.
Securing critical infrastructure networks and endpoints can be an incredibly complex task. Considering the challenges, teissLondon2022 organised an expert panel, composed of Paul Harragan, Global Cyber Security Lead at KKR, Andy Giles, Head of Security and Resilience, Nationwide Building Society, and Deborah Haworth, Director of Information Security, Penguin Random House to learn about the best practices for developing an incident response playbook for critical suppliers.
The experts talked about how to assess the visibility of supply chain risk and the mitigation processes that are in place, maintain clarity in data moving between platforms and suppliers to eliminate false positives, and how Extended or Managed detection and response (EDR/MDR) can help critical infrastructure organisations allocate resources to create defence in depth.
According to Andy Giles, time is of essence when it comes to responding to a cyber attack. The SOC team can identify abnormal activity within a network, but the IT team has to have absolute visibility into the network to determine which IP addresses are affected and to shut those IPs to limit damage.
There also has to be an all-of-organisation response in the aftermath of a cyber attack. While the legal department may determine liability, the finance team, IT and cyber security departments have to be on board as well to determine the scale of exposure, the business impact, impact on operations, and the possible remediation measures that can be implemented.
Critical infrastructure organisations can respond effectively to a cyber attack if they have an incident response toolkit in place. The toolkit can help business decision-makers ask the right questions and determine the best way forward to mitigate a cyber attack’s impact on operations, on commercial relationships and ultimately, on the organisation’s reputation.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543