The UK National Cyber Security Centre knows a thing or three about securing your business. After all, as part of GCHQ, it helps protect the UK’s critical infrastructure and provides frameworks for businesses to secure their online services and devices.
As such, you’d expect the newly published NCSC annual review to be all about AI being the security silver bullet everyone needs, right? Wrong, very wrong indeed; and thank goodness for that.
In fact, my main takeaway from the report is the advice that businesses must “take concrete action to protect themselves from cyber attacks,” and that includes good old pen and paper as a backup.
Although it’s not a pleasant thing to do, think back to the attacks on Marks and Spencer, The Co-op and, more recently, Jaguar Land Rover. Those attacks caused massive service disruption as computer systems went offline. “The recent cyber attacks must act as a wake-up call,” said Richard Horne, the NCSC CEO, warning that every organisation must “have a plan for how they would continue to operate without their IT (and rebuild that IT at pace) were an attack to get through.”
Write down your passwords… and your incident response plans
That plan is useless if it’s only accessible through the computer systems that have been taken offline. Now, I know I will be crucified by some in the security industry for saying so, but writing down passwords isn’t the cyber-antichrist of secure strategies in certain circumstances. And, in exactly the same way, writing down your incident response plans concerning internal communications without email, without all the digital help you would normally rely upon, is far from reckless.
“The Government advice of paper playbooks is sensible,” Javvad Malik, Lead CISO Advisor at KnowBe4 told me, “but not necessarily applicable for all organisations.” Malik is referring to those businesses “born in the cloud” whose workforces have never shared a physical office and have no physical processes to fall back on.
“Many techniques contribute towards resilience,” he added, “layered controls such as segregation of networks, multiple independent backups, offline or out-of-band access to crisis playbooks, and pre-agreed communications channels that don’t depend on a single provider.”
Malik isn’t alone in these thoughts. “Having a hard copy of your cyber incident response plan is a smart move,” insisted Dray Agha, EMEA Senior Manager, Security Operations Centre at Huntress.
“If systems go offline during an attack, you need a fail-safe way to coordinate your response without relying on compromised technology.”
Indeed, the NCSC guidance is a reinforcement of cyber-fundamentals: preparedness is not just digital. “A simple, tangible backup like a printed plan can make the difference between a quick recovery and prolonged chaos,” Agha concluded.
Davey’s view on writing down plans
And what do I think?
Pen and paper, good old-fashioned analogue tech, still has a place in business and still has a place in cybersecurity; no matter how uncomfortable that makes you feel.
I still write to-do lists on a notepad, I still keep a physical copy of my password manager master password (I dare you to break in and find it – you won’t) and I heartily endorse the NCSC.
Relying upon digital systems when attackers are doing their utmost to kneecap them is like putting your trust in jelly as a building foundation: it ain’t going to hold up to real-world pressure.
More articles by Davey Winder