Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What do organisations get wrong when preparing for…
Cyber Security

What do organisations get wrong when preparing for future cyber attacks?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Cyber Security

A common mistake is overfocusing on technical controls while neglecting people, recovery, and commercial readiness. The article points to weak security training, incomplete ransomware protection, poor backup testing, and unclear cyber insurance terms. Organisations also underestimate how fast a business can be forced into response mode when extortion, data leakage, or operational disruption occur together.

What organisations miss when they plan for the next attack

Preparation often breaks down because teams plan for a tidy technical incident instead of a fast-moving business disruption. The real failure is assuming that tools alone create resilience. When extortion, leakage, and downtime collide, organisations need trained people, tested recovery, decision rights, and a workable commercial response, not just controls on paper.

That is why weak exercise discipline matters as much as weak tooling. If teams have never rehearsed who decides, what gets shut down, what gets restored first, and when external support is engaged, the response will be slower and more chaotic than the incident plan suggests.

Where the preparation gap usually sits

The most common blind spot is imbalance. Organisations invest in prevention and detection, but underinvest in readiness for the moments when those measures fail or arrive too late. Training can be superficial, backup design can be technically correct but operationally untested, and insurance can exist without anyone knowing the notice periods, exclusions, or evidence requirements that matter during a real claim.

Preparation also tends to stop at the security team boundary. Future attacks are rarely contained within one function. Legal, finance, communications, operations, and executive leadership all become part of the response, especially when attackers threaten data release, business interruption, or customer impact. If those teams are not already aligned, the organisation is improvising under pressure.

  • Test recovery as an operational process, not just a storage feature.
  • Make sure incident roles, escalation paths, and executive approval thresholds are pre-agreed.
  • Review ransomware and cyber insurance terms before an incident, not after one.
  • Validate that training covers real decision points, including extortion and data exposure.

Risk and Threat Considerations

The risk is not only compromise, but compounding pressure. Attackers increasingly combine encryption, data theft, and disruption so the organisation has to manage business continuity, legal exposure, and negotiation pressure at the same time. That combination exposes gaps in recovery, communication, and decision-making that a pure control checklist will not reveal.

Failure mechanism: Organisations assume backups, training, and insurance are independent safety nets, then discover that recovery is slow, exclusions apply, or the response chain is unclear once the attack becomes operationally urgent.

Impact: The result is longer downtime, weaker bargaining position, delayed containment, and avoidable financial and reputational damage because the response cannot keep pace with the attack.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0RC.RP — Recovery PlanningRecovery planning directly addresses restoring operations after disruptive cyber attacks.
RS.CO — CommunicationsCoordinated communications are central when extortion, leakage, and downtime happen together.
GV.RR — Roles, Responsibilities, and AuthoritiesClear decision rights are essential when multiple business functions must respond fast.
Recommendation — Test restore paths and recovery objectives against realistic outage scenarios. Define who communicates what, to whom, and when during an active incident. Assign incident authority, escalation, and approval ownership before an event occurs.
CIS Controls v811 — Data RecoveryData recovery controls map to the need for tested backups and restoration readiness.
17 — Incident Response ManagementIncident response management covers rehearsed response, escalation, and coordination.
14 — Security Awareness and Skills TrainingTraining gaps are a recurring weakness in real-world cyber preparedness.
Recommendation — Validate backup integrity and restoration ability on a recurring schedule. Run incident exercises that include legal, operations, and executive decision points. Train staff on ransomware, extortion, and recovery actions that affect their role.

Practitioner Guidance

What to prioritise: Treat recovery readiness as a business capability. The first question is not whether backups exist, but whether they can be restored under pressure, within the required timeframe, and with the right people available to make decisions.

What to verify: Confirm that backup tests include full restoration, not just successful completion reports, and that the organisation can prove coverage for the systems most likely to affect revenue, operations, and regulatory exposure. Also verify that insurance and response contracts are understood by the people who would activate them.

Decision rule: If a control only works when nothing is rushed, it is not enough for future attack preparation. Anything that depends on ideal conditions should be treated as a weak assumption until it has been exercised in a realistic scenario.

Practitioner takeaway: Strong preparation is less about predicting the next technique and more about reducing the time it takes for the organisation to become coordinated, recoverable, and decision-ready when the attack turns disruptive.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org