Answers to the questions our clients ask most often, organised by topic to match the assessment tools above.
Cyber Essentials and ISO 27001
How much does Cyber Essentials cost in the UK?
Cyber Essentials costs £330–£500 + VAT depending on organisation size: micro (1–9 staff) pays £330, small (10–49) £400, medium (50–249) £450, and large (250+) £500. IASME, the NCSC’s official delivery partner, sets these fees. The assessment fee covers unlimited self-assessment attempts for 12 months and includes complimentary Cyber Liability Insurance for eligible UK organisations. Budget an additional £1,000–£5,000 for preparation and remediation work on top of the assessment fee. Use our Cyber Essentials Readiness tool above to check your position before paying.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Both levels cover the same five controls (firewalls, secure configuration, access control, malware protection, and patch management) but differ in how compliance is verified. Cyber Essentials is a self-assessment reviewed remotely by a Certification Body. Cyber Essentials Plus requires an independent technical audit including external vulnerability scans and hands-on device testing. From November 2025, missing MFA where it is available is an auto-fail on CE Plus. CE Plus provides independent technical assurance but costs significantly more than the base level.
How much does ISO 27001 certification cost in the UK?
ISO 27001 certification cost in the UK varies by organisation size. Typical first-year totals (consultancy + audit + internal effort): micro orgs (1–10 staff) £8,000–£20,000; small (11–50) £12,000–£40,000; medium (51–250) £40,000–£120,000; large (250+) £100,000–£300,000+. UKAS-accredited certification audits start at around £6,250 for small organisations. Commission a gap analysis first to understand your implementation scope before committing to audit costs.
How long does ISO 27001 take to achieve?
ISO 27001 timeline: most UK organisations take 3–9 months from scoping to receiving the certificate, with 6–9 months realistic for those without a mature existing security programme. The longest phase is control implementation and documentation (2–6 months). After that comes an internal audit, a management review, and the two-stage certification audit (Stage 1 documentation review, Stage 2 on-site or remote audit). ISO 27001 operates on a three-year certification cycle with annual surveillance audits.
Do I need Cyber Essentials if I have ISO 27001?
If you bid for UK government contracts, yes. Procurement Policy Note PPN 014 mandates Cyber Essentials for contracts involving personal data or ICT products and services — ISO 27001 is not accepted as a substitute. MoD contracts require Cyber Essentials Plus. In the private sector, ISO 27001 alone may suffice, but many organisations hold both: CE is far cheaper to maintain annually and signals baseline hygiene quickly to a wider audience including insurers and SME supply chains.
How much does Cyber Essentials Plus cost?
Cyber Essentials Plus cost has two components: the IASME assessment fee (£330–£500 + VAT, same banded rate as base CE) plus an independent assessor audit fee (typically £1,500–£8,000 + VAT). Most small-to-medium UK businesses pay £1,500–£3,000 + VAT for the audit. Cost drivers include device count, number of external IP addresses, number of locations, and whether the audit is remote or on-site. The Plus audit must be conducted within three months of your base CE certificate date.
What is the difference between ISO 27001 and Cyber Essentials?
ISO 27001 is an internationally recognised management system standard covering 93 Annex A controls across all information assets — it requires third-party certification audits and costs tens of thousands of pounds over months. Cyber Essentials is a UK government scheme covering five specific technical controls, verified by self-assessment, achievable in weeks for £330–£500. CE proves foundational technical hygiene; ISO 27001 proves a complete, governed security management system. The five CE controls map directly into ISO 27001 Annex A, so the two complement each other.
How do I do an ISO 27001 gap analysis?
An ISO 27001 gap analysis compares your current security posture against the 93 Annex A controls and mandatory clauses of ISO/IEC 27001:2022. Six steps: define scope; review the standard (approx £120–£160 from BSI); assess existing controls against each clause; identify and score gaps; produce a gap report; build a prioritised action plan that feeds your Statement of Applicability. A professional external gap analysis costs £1,500–£5,000. IASME and ISMS.online provide free templates for a self-directed first pass.
How do I check my Cyber Essentials readiness?
Cyber Essentials self-assessment readiness means being able to truthfully answer “yes” across five control areas: firewalls (all internet-connected devices protected, unnecessary ports closed); secure configuration (default passwords changed, unnecessary software removed); access control (least privilege enforced, MFA active); malware protection (up-to-date anti-malware on all in-scope devices); and patch management (patches applied within 14 days). From April 2026, missing MFA where available is an auto-fail. Download IASME’s free preview question set before paying for the official assessment.
How do I prepare for Cyber Essentials Plus?
Cyber Essentials Plus audit preparation starts with holding a valid base CE certificate — you must apply for Plus within three months. Key steps: ensure all SAQ answers are technically accurate, as the Plus audit verifies them hands-on; patch all in-scope devices to the 14-day standard; enforce MFA wherever available (auto-fail from November 2025); run an internal vulnerability scan; check your external attack surface using the NCSC Web Check service; and book an IASME-authorised assessor early, as slots fill weeks in advance.
Cyber security, governance and board
What questions should a board ask about cyber security?
The NCSC Board Toolkit provides 22 structured cyber security board questions across five principles: Risk Management, Strategy, People, Incident Planning and Response, and Assurance and Oversight. Core questions include: “What are our most significant cyber risks?”, “Do we have a tested incident response plan?”, and “How do we gain assurance from our supply chain?” Boards that cannot satisfactorily answer these questions have a governance gap that should be addressed at board level, not delegated to the IT team.
How much does a data breach cost?
The IBM Cost of a Data Breach Report 2024 puts the global average data breach cost at USD 4.88 million — a 10% increase on 2023 and the highest figure ever recorded. The UK average was approximately £3.4 million in 2023. That figure is separate from regulatory fines: the ICO can impose penalties up to £17.5 million or 4% of global annual turnover under UK GDPR. Boards should model both the operational cost and the regulatory fine exposure as separate, additive risk scenarios.
How do I assess cyber security risk for my business?
Cyber security risk assessment starts with the NCSC Cyber Assessment Framework (CAF) v3.2, which covers 14 security principles across four objectives: Managing Security Risk, Protecting Against Attacks, Detecting Security Events, and Minimising Impact. Begin by identifying your crown-jewel assets, mapping digital dependencies, and analysing threat scenarios. The NCSC recommends bi-annual risk reviews. Cyber Essentials certification provides a structured technical baseline that many UK insurers and public sector buyers now require as the minimum floor. Use our Cyber Risk Assessment tool above for a scored starting point.
How do I know if my business is prepared for ransomware?
Ransomware readiness comes down to four questions: Has your most recent backup been tested as a full recovery from an isolated copy? Is your incident response plan stored offline and practised? Are endpoints protected with up-to-date detection and response tools? Do you have a pre-contracted Cyber Incident Response provider? The NCSC’s December 2024 guidance on ransomware-resistant backups is the authoritative UK reference. Use our Ransomware Readiness assessment above for a scored review across backup integrity, endpoint protection, and incident planning.
How do I prepare for an IT security audit?
IT security audit preparation depends on the standard. For Cyber Essentials, you need to evidence five technical controls with MFA now a mandatory auto-fail item where available. For ISO 27001, you need a documented ISMS, risk assessment, Statement of Applicability, and evidence of operating controls over a defined period. Commission a gap analysis before either audit to avoid wasted cost on unresolved non-conformities. For ISO 27001, a formal internal audit and management review are mandatory prerequisites before the Stage 2 certification audit.
How do I assess vendor or supplier security?
Vendor security assessment in the UK follows the NCSC’s 12 Principles of Supply Chain Security (updated October 2022). Tier your suppliers by risk — those with network or data access are highest priority. Require Cyber Essentials as a minimum threshold, issue security questionnaires covering access controls and incident response, and build audit rights into contracts. Reassess at contract renewal, not just onboarding. For critical suppliers, require them to cascade the assessment process down their own supply chain. Use our Supplier Security Assessment tool above.
What is a SOC 2 readiness assessment?
A SOC 2 readiness assessment maps your existing controls against the AICPA’s five Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy), identifies gaps, and produces a remediation roadmap before the formal audit. UK SaaS and technology companies increasingly pursue SOC 2 because US enterprise buyers require it as a vendor approval condition. SOC 2 Type I assesses design at a point in time; Type II tests operating effectiveness over 6–12 months. From scratch, readiness typically takes 3–6 months.
What is the Cyber Governance Code of Practice?
The Cyber Governance Code of Practice was published by DSIT in April 2025 and establishes five governance principles for UK boards: Risk Management, Cyber Strategy, People, Incident Planning and Response, and Assurance and Oversight. While currently voluntary, it is explicitly designed as a stepping stone toward future regulatory requirements. The NCSC Board Toolkit has been updated to align with all five principles. Download the Code from the NCSC Cyber Governance for Boards page and use the Board Toolkit training modules for director-level awareness sessions.
What should a CISO report to the board?
A CISO board report must translate technical posture into business risk language — probable financial loss, operational downtime, regulatory exposure, and reputational harm — rather than raw vulnerability counts or patch percentages. The Cyber Governance Code of Practice requires boards to set a cyber risk appetite, so CISO reports must state explicitly whether current posture is within that appetite. Key items: quantified cyber risk exposure; control effectiveness against top threats (ransomware, BEC, supply chain attack); ICO and regulatory obligations; and progress against the cyber investment roadmap.
AI readiness and governance
Is my business ready for AI adoption?
An AI readiness assessment evaluates your organisation across six pillars: Strategy, Infrastructure, Data, Governance, Talent, and Culture. Only 16% of UK organisations are fully equipped to deploy and scale AI, according to Cisco’s AI Readiness Index 2025 — with data quality the single largest gap at 43% of organisations (Informatica CDO Insights 2025). Before committing AI budget, conduct a data audit: map what you hold, whether it is clean and labelled, and whether it is sufficient for your specific AI use case. Use our AI Readiness tool above.
Do I need an AI policy for my business?
An AI policy for your UK business is not mandated by a single statute, but the obligation is functionally equivalent to one. Under UK GDPR and the Data (Use and Access) Act 2025, AI that processes personal data requires a documented lawful basis, human oversight, and transparency obligations. The ICO’s AI and Data Protection Guidance states organisations must document human review mechanisms for AI-driven decisions affecting individuals. Start with: a list of approved tools, prohibited uses, data handling rules, human oversight requirements, and a named owner.
How do I know if my AI project will fail before I start?
AI project failure is almost always operational, not technical. Five pre-start warning signs: vague success criteria (outcomes described in adjectives, not numbers); no executive sponsor with budget authority; unmapped data foundations (if you cannot describe input data provenance and quality, do not start); no MLOps plan for model monitoring and retraining; no baseline metric for the process being automated. The AI project failure rate exceeds 80% (RAND Corporation), and 95% of generative AI pilots show no measurable P&L impact (MIT NANDA 2025).
What questions should a board ask about AI strategy?
Boards must own AI governance, not delegate it to IT. The IoD’s “AI Governance in the Boardroom” (September 2025) identifies seven essential board questions: What AI is already in use, including unapproved shadow AI? Who owns AI strategy at board level? What is our regulatory and reputational risk exposure? Does our AI supply chain meet our data obligations? What human oversight exists for AI-driven decisions? Do we have skills to evaluate AI outputs? How will we measure AI’s business contribution and on what cadence will the board review it?
How do I create an AI policy?
To create an AI policy: (1) Scope — list every AI tool in use by business function. (2) Classify — distinguish productivity tools from higher-risk AI affecting decisions about people. (3) Assign ownership — name a responsible person. (4) Define approved and prohibited uses — document what is permitted, what needs approval, and what is banned (such as inputting client personal data into public large language models). (5) Set human oversight rules. (6) Build a review cadence. ISO/IEC 42001:2023 provides the international management system structure. The ICO’s AI and Data Protection Guidance is the UK legal baseline.
What is AI governance and do I need it?
AI governance in the UK means the policies, roles, processes, and controls that ensure AI systems are used responsibly, legally, and in a way that can be audited. Three frameworks define the field: ISO/IEC 42001 (international management system standard); the NIST AI Risk Management Framework (globally adopted, non-prescriptive); and the ICO’s AI and Data Protection Guidance (legally binding where AI processes personal data under UK GDPR). If AI touches customer data, credit, employment, healthcare, or financial decisions, governance is a legal necessity now — not a future consideration.
Technology leadership and IT investment
How much does a fractional CIO cost in the UK?
Fractional CIO cost in the UK runs £5,000–£16,000 per month depending on days committed and seniority. Day rates for senior practitioners are £1,000–£1,500. One day per week from a capable operator costs £4,000–£6,000 per month; two to three days per week from a proven board-level CIO costs £12,000–£16,000. Compared to a full-time CIO at £150,000–£220,000 total employment cost per year, a fractional engagement typically saves 40–60% for businesses that do not need five-day-a-week executive presence. Book a discovery call to scope your engagement.
What is a fractional CIO?
A fractional CIO is a senior technology executive providing board-level IT leadership on a part-time, retained basis — typically one to three days per week — rather than as a full-time employee. The role covers the full CIO brief: aligning IT strategy with business priorities, owning the technology roadmap, governing suppliers, managing cybersecurity posture, and acting as the executive accountable for IT investment and risk. Fractional CIOs are most common in UK SMEs with £5m–£100m revenue that have outgrown founder-led IT but cannot justify a permanent C-suite hire.
When should I hire a fractional CIO?
Hire a fractional CIO when IT decisions are blocking growth or creating unquantified risk and nobody in the business has the seniority to resolve them. Specific triggers: the board cannot articulate its technology strategy or top IT risks; IT is run by a capable manager without strategic authority; the business is pursuing a major ERP or cloud migration without an accountable technology lead; or a key-person dependency in IT represents material operational risk. For most UK SMEs, this inflection point arrives between £5m and £20m revenue.
How much should my business spend on IT?
Most UK businesses spend 3%–6% of revenue on IT, with Gartner’s cross-industry average at approximately 3.6%. Sector is a stronger predictor than company size — financial services spends 8%–11%, manufacturing 1%–3%. The more useful question is not whether your spend matches the benchmark but whether you are getting measurable business value from it. Decompose spend into Run (keeping systems operational), Change (improvements), and Transform (new strategic capability). A healthy growth business targets approximately 50/30/20 across those three categories.
What percentage of revenue should go to IT?
IT budget as a percentage of revenue varies significantly by sector. 2025 benchmarks: financial services 8%–11%; professional services 4%–7%; retail and consumer 3%–5%; manufacturing 1%–3%; healthcare and regulated sectors 5%–8%. UK businesses across all sectors averaged 3%–6% in 2025. A manufacturing business spending 6% is likely overinvested; a financial services firm spending 3% is probably dangerously underinvested. The IT spend percentage should rise during active digital transformation programmes and fall once platforms stabilise.
When should I hire a full-time CISO vs a fractional one?
A fractional CISO (£3,000–£12,000 per month for 1–3 days per week) suits most UK SMEs until security complexity demands daily executive presence. Use a fractional CISO when pursuing Cyber Essentials Plus or ISO 27001, responding to customer security questionnaires, entering a regulated sector, or preparing for fundraising or M&A. Hire a full-time CISO (£180,000–£280,000 total employment cost per year) when security is mission-critical to daily operations, regulatory oversight is continuous (FCA, NHS, MoD supply chain), or the security team exceeds 5–8 people needing daily leadership.
Is my IT function fit for purpose?
An IT health check assesses whether your function reliably delivers services at acceptable cost and risk, and can adapt as the business changes. Six diagnostic signals: Does IT have documented SLAs? Is the team structured to support operations or permanently firefighting? Are IT costs visible and benchmarked at board level? Is cyber posture tested and reported regularly? Do business leaders see IT as a strategic enabler? Is there a technology roadmap aligned to the business plan? Absence of a CIO-level owner is the most reliable single indicator that the function is not fit for strategic purpose.
Do I have a technology leadership gap?
A technology leadership gap exists when no one in the business has both the authority and the capability to make strategic technology decisions — and the consequences show as slower growth, higher IT cost, unresolved risk, or missed digital opportunity. Six signals: IT decisions default to the CEO or CFO by default; there is no current technology strategy document; technical debt accumulates without a plan; IT vendors manage upward rather than being managed; recurring failures are not resolved at root cause; the board has no IT risk visibility. Three or more signals indicate a fractional CIO should be appointed.
What is the difference between a fractional and interim CIO?
A fractional CIO provides ongoing, part-time strategic leadership (1–3 days per week, typically 12+ months) at £5,000–£12,000 per month. An interim CIO is a full-time, temporary appointment (5 days per week for 3–9 months) to manage a specific transition — filling a sudden vacancy, stabilising a function in crisis, or leading a major transformation — at £10,000–£15,000 per month. Use interim for a time-bounded crisis requiring full executive bandwidth. Use fractional for a permanent structural need for CIO-level leadership at less than full-time scale.
What is process maturity and how is it measured?
Process maturity measures how consistently and predictably an organisation executes its processes — whether outcomes depend on individual heroics or on repeatable, documented, and continuously improving systems. The three main frameworks are CMMI (Capability Maturity Model Integration), COBIT 2019, and ITIL, all using a five-level scale: Level 1 (ad hoc/reactive), Level 2 (documented and tracked), Level 3 (standardised across the organisation), Level 4 (measured and controlled with data), Level 5 (continuously improving). Most UK SMEs operating without a CIO sit at Level 1–2. Level 3 is the threshold for genuine board assurance.
What is an IT operating model?
An IT operating model defines how the IT function delivers value to the business: who does what, how services are structured, where decisions are made, how costs are allocated, and how investment is governed. It answers four questions: (1) Organisation — centralised, federated, or hybrid? (2) Processes — how mature are core IT service management and governance processes? (3) Technology architecture — what platforms and integrations underpin operations? (4) Sourcing — what is in-house versus outsourced? Many UK SMEs have an implicit, undocumented operating model. An explicit model is typically the first output a new fractional CIO delivers.
How do I assess the hidden cost of running without a CIO?
The hidden cost of no IT leadership accumulates across five categories: failed or overrun IT projects (30–40% of projects fail without CIO-level governance); shadow IT and duplicated spend (typically 15–30% redundancy in SaaS and software estate); vendor management deficit (suppliers negotiate against an unsophisticated buyer); compounding technology debt (£200k to fix today becomes £500k in three years); and opportunity cost (digital transformation stalls). For a £20m revenue business spending 4% on IT (£800k/year), a conservative 20% waste estimate is £160,000/year — more than a fractional CIO costs annually.
Technology due diligence and M&A
What should I check in technology due diligence?
A technology due diligence checklist covers six workstreams: architecture and scalability; cybersecurity posture (pen test results, vulnerability history, MFA status); technical debt (code quality, end-of-life dependencies, test coverage); licensing and IP ownership (open-source licence audit, contractor IP assignment agreements); people and key-person risk; and operational resilience (BCP, DR test results). Apply a 1–5 maturity scale so findings translate into quantified remediation costs. A 2025 benchmark found 74% of tech DD exercises surface at least one high-risk finding. Request evidence, not management assertion.
What are the IT risks when integrating after an acquisition?
IT integration risks after an acquisition cluster into five categories: data architecture incompatibility (mismatched data models preventing system consolidation); cybersecurity exposure expansion (the acquirer inherits the target’s attack surface from Day One); licensing and contract cliff-edges (change-of-control clauses and auto-renewals); operational disruption (ERP or CRM cutover failures); and talent flight (key engineers leaving when uncertainty peaks). Produce a Day One IT Readiness checklist before close covering network segregation, access provisioning, and email routing, and assign a dedicated IT integration lead from both sides.
How do I assess the IT risk I am inheriting in an acquisition?
IT due diligence for acquisitions requires a three-layer review: technical (infrastructure, applications, security controls); contractual (licences, vendor agreements, open-source obligations); and compliance (GDPR, ISO 27001, sector-specific regulations). Start passively — request and review documentation before active scanning. Run a maturity assessment against NIST CSF 2.0 or ISO 27001 as the scoring baseline, producing a RAG heat map across identity, data, endpoint, network, and governance domains. Quantify findings as breach probability multiplied by impact cost to feed indemnity negotiations and W&I insurance scope.
What is data maturity and how do I assess it?
A data maturity assessment measures how systematically an organisation manages data as a strategic asset across five dimensions: governance (ownership, policies, stewardship); quality (accuracy, completeness, timeliness); architecture (integration, lineage, master data management); analytics capability; and culture (data literacy and data-driven decision-making). The CMMI Data Management Maturity model uses a 1–5 scale; the data maturity model most widely adopted commercially is Gartner’s Data and Analytics Maturity Model. Most mid-market companies assessed sit at Level 2–3. A Level 2 target adds 6–12 months to post-acquisition ERP consolidation.
How do I know if my ERP project is heading for distress?
ERP implementation failure follows a consistent pattern with seven leading indicators visible before go-live: scope creep without formal change control; executive sponsor disengagement or change; testing phase compression (UAT cut short or test environment not production-equivalent); data migration perpetually deferred; parallel running abandoned prematurely due to cost pressure; vendor or systems integrator over-dependence with no internal challenge capability; and end-user training appearing only in the final month. 55–75% of ERP projects exceed budget or timeline, with average overruns of 30–50%. Book an independent programme assurance review at 25%, 50%, and 75% completion.
What are the red flags in technology due diligence?
Technology due diligence red flags fall into five categories. Architecture: monolithic systems with no API layer; no Software Bill of Materials; cloud cost without governance. Security: no MFA on admin accounts; critical CVEs unpatched for 60+ days; no endpoint detection tooling; undisclosed prior breaches. Technical debt: undocumented codebases; end-of-life dependencies; test coverage below 20%. People: a single engineer holding irreplaceable knowledge of core systems; high engineering attrition in the past 12 months. IP: GPL-licenced open-source in proprietary products (copyleft risk); contractor-built software without IP assignment agreements.
Data protection and compliance
When do I need to do a DPIA?
A DPIA is required under UK GDPR Article 35(1) when processing is likely to result in high risk to individuals, particularly when using new technologies or conducting large-scale processing. Three automatic triggers under Article 35(3): systematic and extensive profiling to make significant decisions about people; large-scale processing of special category data; and systematic large-scale monitoring of publicly accessible areas. The ICO has published a list of ten further processing types requiring a DPIA. If your processing meets two or more of the ICO’s nine screening criteria, a DPIA is strongly indicated. Document your reasoning even when you conclude one is not required.
What should a data protection policy include?
A data protection policy must demonstrate UK GDPR Article 5(2) accountability and cover: commitment to the seven data protection principles; staff roles and responsibilities including the DPO (if appointed); how data subject rights will be upheld; procedures for reporting personal data breaches to the ICO within 72 hours (Article 33); and your approach to data protection by design and by default (Article 25). The policy must also address lawful bases for processing, retention schedules, international transfer safeguards, and third-party processor contracts (Article 28). Use the ICO’s Accountability and Governance toolkit as your drafting template.
How do I comply with UK GDPR?
UK GDPR compliance rests on six obligations: (1) Identify a lawful basis for every processing activity. (2) Provide transparent privacy information to data subjects at the point of collection (Articles 13–14). (3) Honour individual rights requests within one calendar month. (4) Implement appropriate technical and organisational security measures. (5) Maintain a Record of Processing Activities if you have 250+ employees or regularly process high-risk data. (6) Report personal data breaches to the ICO within 72 hours. Fines for serious infringements reach £17.5 million or 4% of global annual turnover, whichever is higher.
Does NIS2 apply to businesses in the UK?
NIS2 does not apply in the UK. The EU Directive was adopted after Brexit and has no direct legal force in UK law. The UK’s equivalent is the Network and Information Systems (NIS) Regulations 2018, which applies to Operators of Essential Services (energy, transport, water, health, digital infrastructure) and to Relevant Digital Service Providers (cloud, online marketplaces, search engines) above the small-business threshold. The Cyber Security and Resilience Bill, introduced to Parliament in November 2025, will expand this regime to cover managed service providers, data centres, and critical supply chain participants.
What should an information security policy include?
An information security policy template covers ten areas aligned to the NCSC’s 10 Steps framework: (1) Scope and risk appetite. (2) Access control and identity management including MFA. (3) Asset and configuration management with patch timescales. (4) Network security (firewalls, segmentation, remote access). (5) Malware and ransomware protection. (6) Data backup and recovery including offline copies and tested restoration. (7) Incident detection and response with escalation contacts. (8) Supply chain security requirements. (9) Staff awareness and training. (10) Governance and accountability with an annual review cycle. Cyber Essentials certification validates the five core technical controls within this framework.
How do I create a cyber incident response plan?
A cyber incident response plan documents your six-phase response: Prepare, Identify, Contain, Eradicate, Recover, and Learn (NCSC framework). Key contents: named response team with at least two contacts per role (IT, legal, HR, PR, cyber insurance); triage and severity classification with ICO notification trigger (UK GDPR Article 33 requires notification within 72 hours of a personal data breach); containment and evidence preservation steps; communication templates for staff, customers, and regulators; recovery procedures including backup invocation; and a post-incident review process. Store the plan offline. Test it annually using the NCSC’s free Exercise in a Box tool.
How do I create a business continuity plan?
A business continuity plan template follows ISO 22301:2019 across five stages: (1) Business Impact Analysis — identify critical processes and set a Recovery Time Objective for each. (2) Risk assessment — map credible threats to those processes. (3) Recovery strategies — manual workarounds, secondary sites, alternative suppliers, cloud failover. (4) Plan documentation — activation criteria, named invoker, step-by-step actions, communication templates. (5) Testing — tabletop exercises and full simulation tests at minimum annually. Store the BCP offline and link it to your cyber incident response plan and disaster recovery plan as an interlocking suite.