How to act in case of a total IT outage in the workplace?
25 March 2025One of the NIS2 measures is the duty of care. This measure is intended to ensure a structured approach with clear responsibilities during a cyber crisis. The consequences of a data breach, cyberattack or power outage can have a huge impact on the continuity of an organization. Even if you are not dealing with NIS2, our advice is to be well prepared for possible incidents.
How do you resolve cyber incidents?
When employees can no longer work, customers can no longer be served, and no revenue can be generated. Customers get angry, may leave, employees do not get paid, they will become dissatisfied and look for another job. You can imagine that this cannot last too long. So when there is a cyber incident, you want to resolve it as quickly as possible, but how do you do that and how do you prepare the organization for it? A first step is to ensure an Incident Response Plan (IRP).
Incident Response Plan (IRP)
If you only take action when it is already too late, you are mainly busy putting out the big fire. That is why this NIS2 measure proposes to think in advance about what can happen. Even if you do not have to take NIS2 into account, an IRP helps with damage limitation and recovery. The IRP describes actions, steps, and responsible employees in case of incidents. The goal is to respond quickly, limit damage and resume work.
Drawing up an IRP
The content of an IRP differs per company. This step-by-step plan can help in drawing it up.
- Risk analysis
In our daily work we constantly use digital tools and process important and sensitive information. However, not everyone is aware of the risks associated with possible cyber incidents. It is good to understand which information is essential for the work and the consequences if access to customer data, product information or invoice details is prevented. Possible causes for this can range from system vulnerabilities, fire, power outages, dependence on a specific employee, to cyberattacks or data breaches. - Think about what can happen
Work out incidents in detail and make a step-by-step plan for situations such as fire, prolonged power outage, a DDOS attack or a Phishing email. What do you do if an external USB stick causes damage? What steps do you take? Make sure you can continue working after system, power or internet outages. Is there a backup? Are there spare devices? - Who is responsible?
Which employees are involved? Who is informed and how? Are those involved aware and trained? Do they recognize incidents? Is there system monitoring? Who monitors the threats? - When to take action?
How can an incident or threat be reported? Who will communicate this? With whom will it be communicated? Ensure you have the details of those involved, such as contact details of the IT supplier, but also think of the emergency services. Draw up a call list. - Communication
Are all those involved informed about the procedures in case of an incident? Is every employee aware of their tasks and responsibilities? Does everyone know where the plan is stored? Is the plan accessible during a power outage? What is minimally needed to communicate effectively? - Knowledge
Are employees trained? Are they aware of the correct procedures? How is knowledge kept up to date? Is there regular practice? - Incident Response
What steps must be taken if an incident actually occurs? The NIS2 directive prescribes that organizations are obliged to report incidents to the regulator within 24 hours if the incident causes a significant disruption of the service.|
Prevention is important!
It is better to prevent problems than to solve them later. Ensure good virus scanners, up-to-date software and systems, regular backups, alternative internet connections and training for employees. Do you want to check whether these matters are properly arranged? We are happy to look at the possible risks and can advise and support you in achieving cybersecurity.
Contact us today here and be prepared for cyber incidents.